Privacy
Designed to keep your workspace under your control.
This preview policy explains where FireCursor stores operational data and which external services are involved.
Updated July 23, 2026
Data FireCursor stores
- Pairing endpoints and the bearer token in encrypted (AES-256) private Android app storage.
- The desktop pairing token in Cursor or VS Code secret storage.
- Session records on your computer.
- Images you attach inside the active workspace under .firecursor/attachments.
- Your FireCursor account email, account status, entitlement state, referral code, and immutable first-account referral attribution in FireCursor's Supabase project.
- Daily active-use records containing platform, release channel, app version, first and last activity times, and a one-way SHA-256 hash of a random installation identifier. FireCursor does not store the raw installation identifier.
- If you join the optional preview list, your normalized email address, consent timestamp and policy version, signup source, referral path, and any valid referral code.
- A daily one-way HMAC of the signup request's IP address is retained for abuse prevention. The signup service does not store the raw IP address.
- Future referral commission ledger entries may include the referred account, payment-provider transaction identifier, gross amount, currency, locked commission rate, earned amount, service period, and payout status. Full card details are not stored by FireCursor.
Data in transit
Control messages travel between your phone and computer through a temporary Cloudflare tunnel or the same-network fallback. Tunnel traffic is TLS protected. The LAN fallback is token authenticated but currently unencrypted.
Account sign-in, access checks, referral attribution, active-user heartbeats, and one-time extension capability issuance travel directly between the Android app and Supabase over HTTPS. Supabase access and refresh tokens are encrypted at rest on Android and are never sent to the Cursor extension.
FireCursor does not operate a hosted workspace mirror. Cursor may process prompts, source context, and model output according to your Cursor account and privacy settings when cursor-agent performs AI work.
Preview email list
The preview list is optional and is used only for meaningful preview releases, safety updates, and store availability. Supabase processes and stores the signup record for FireCursor. FireCursor does not sell the list or use it for third-party advertising.
Duplicate signups refresh the consent record rather than creating another profile. If a valid referral code is saved with the signup, FireCursor may apply it when the same normalized email creates a new account and no referral was already attached. Before promotional email begins, every message must include a working unsubscribe mechanism. You can request removal now at hello@firecursor.com.
Accounts, referrals, and active use
A FireCursor account is required for current app access. Email magic links verify identity without a reusable password. Sessions normally persist until sign-out, revocation, or account policy requires a new sign-in.
A valid referral code is applied only when a new account is created and cannot be replaced by the referred user. Referral and commission data is used to operate the FireCursor referral program, prevent duplicate credit, and support future payouts.
Daily activity aggregation lets FireCursor measure daily and monthly active accounts, release adoption, and upgrade compliance without collecting prompts, source code, file paths, tool arguments, or agent transcripts.
Payments
Paid checkout and referral payouts are not active in the current preview. If billing is enabled later, the payment provider will process payment details. FireCursor's entitlement and commission services are designed to retain customer, subscription, referral, and payout state—not full card details.
Your choices
- Stop remote control to close the active tunnel.
- Delete imported sessions from FireCursor.
- Remove workspace attachments through your normal file tools.
- Uninstall the app and extension to remove their local application data, subject to platform behavior.
- Ask FireCursor to remove your preview-list email and consent record.
- Sign out to revoke the local FireCursor session and stop remote control on that phone.
- Contact FireCursor to request account deletion, subject to records that must be retained for fraud prevention, accounting, tax, or legal obligations once payments exist.
- Contact hello@firecursor.com with privacy questions.
Policy changes
Material changes will be reflected on this page with a new updated date. No retention period, support service level, or jurisdiction is promised by this preview policy.