Privacy
Designed to keep your workspace under your control.
This preview policy explains where FireCursor stores operational data and which external services are involved.
Updated August 18, 2026
Data FireCursor stores
- Pairing endpoints, the bearer token, the optional Cursor API key, and the FireCursor account session normally use private, backup-disabled Android storage encrypted with AES-256 through Android Keystore. If encrypted storage cannot recover on a device, FireCursor keeps new credentials in process memory only and requires sign-in or pairing again after restart rather than persisting plaintext secrets.
- The desktop pairing token in Cursor or VS Code secret storage.
- Session records on your computer.
- Images you attach inside the active workspace under .firecursor/attachments.
- Your FireCursor account email, account status, entitlement state, referral code, and immutable first-account referral attribution in FireCursor's Supabase project.
- Daily active-use records containing platform, release channel, app version, first and last activity times, and a one-way SHA-256 hash of a random installation identifier. FireCursor does not store the raw installation identifier.
- If you join the optional preview list, your normalized email address, consent timestamp and policy version, signup source, referral path, and any valid referral code.
- A daily one-way HMAC of the signup request's IP address is retained for abuse prevention. The signup service does not store the raw IP address.
- Future referral commission ledger entries may include the referred account, payment-provider transaction identifier, gross amount, currency, locked commission rate, earned amount, service period, and payout status. Full card details are not stored by FireCursor.
Data in transit
Control messages travel between your phone and computer through a temporary Cloudflare tunnel or the same-network fallback. Tunnel traffic is TLS protected. The LAN fallback is token authenticated but currently unencrypted.
Account sign-in, access checks, referral attribution, active-user heartbeats, and one-time extension capability issuance travel directly between the Android app and Supabase over HTTPS. Supabase access and refresh tokens use the same private, backup-disabled Android storage and are never sent to the Cursor extension.
FireCursor does not operate a hosted workspace mirror. The selected agent provider—Cursor, OpenAI Codex, or Anthropic Claude—may process prompts, source context, tool results, and model output according to that provider account and its privacy settings.
FireCursor does not receive ChatGPT or Claude subscription credentials. Codex and Claude Code retain those credentials in their own supported local authentication stores. An optional Anthropic API fallback is stored in VS Code SecretStorage on the computer and is never sent to Android.
Device permissions and optional input
- Camera access is requested only when you scan a pairing QR code or choose to take a workspace attachment. Captured attachments are sent to your paired computer and stored in the active workspace; FireCursor does not upload them to a hosted workspace mirror.
- Voice input opens Android's system speech-recognition activity. The selected recognition provider may process microphone audio under its own terms. FireCursor receives the resulting text, not the raw recording, and does not request direct microphone access.
- Notification permission is optional and is used for connection state, completion, failure, and approval-needed alerts. Notifications intentionally omit prompts, source code, file paths, and pairing credentials.
- A visible data-sync foreground service keeps an active paired connection alive when FireCursor is in the background. It does not create an unattended connection to an unpaired computer.
Preview email list
The preview list is optional and is used only for meaningful preview releases, safety updates, and store availability. Supabase processes and stores the signup record for FireCursor. FireCursor does not sell the list or use it for third-party advertising.
Duplicate signups refresh the consent record rather than creating another profile. If a valid referral code is saved with the signup, FireCursor may apply it when the same normalized email creates a new account and no referral was already attached. Before promotional email begins, every message must include a working unsubscribe mechanism. You can request removal now at hello@firecursor.com.
Accounts, referrals, and active use
A FireCursor account is required for current app access. New users verify their email, create a password, and then sign in with email and password on the web or Android. Secure email links are also used for account verification and password recovery. Sessions normally persist until sign-out, revocation, or account policy requires a new sign-in.
A valid referral code is applied only when a new account is created and cannot be replaced by the referred user. Referral and commission data is used to operate the FireCursor referral program, prevent duplicate credit, and support future payouts.
Daily activity aggregation lets FireCursor measure daily and monthly active accounts, release adoption, and upgrade compliance without collecting prompts, source code, file paths, tool arguments, or agent transcripts.
Payments
Paid checkout and referral payouts are not active in the current preview. If billing is enabled later, the payment provider will process payment details. FireCursor's entitlement and commission services are designed to retain customer, subscription, referral, and payout state—not full card details.
Your choices
- Stop remote control to close the active tunnel.
- Delete imported sessions from FireCursor.
- Remove workspace attachments through your normal file tools.
- Uninstall the app and extension to remove their local application data, subject to platform behavior.
- Ask FireCursor to remove your preview-list email and consent record.
- Sign out to revoke the local FireCursor session and stop remote control on that phone.
- Delete your account directly in Android Settings > Account & referrals > Delete account and data, or begin an external request at firecursor.com/delete-account.
- Contact hello@firecursor.com with privacy questions.
Policy changes
Material changes will be reflected on this page with a new updated date. No retention period, support service level, or jurisdiction is promised by this preview policy.