Privacy Policy
Last updated: 14 August 2026
This policy explains what Phirepass collects when you use the dashboard and run an agent, why we collect it, and what we do with it. We have tried to describe the system as it actually works rather than in the broadest terms the law allows.
1. Who we are
Phirepass is operated by [Company legal name], [registered address] (“we”, “us”). For anything in this policy, contact [privacy contact email].
2. Account information
You sign in with GitHub. We request the read:user and user:email scopes and store only what we need to identify your account:
- your email address;
- your GitHub username;
- your avatar URL;
- the identity provider used (currently always GitHub).
We never receive your GitHub password, and we do not ask for or store a password of our own.
3. Information your agents report
When you install an agent on a machine and connect it to your account, that agent sends us information about itself so the dashboard can show it to you:
- Once, at login: hostname, operating system, agent version, process id, local and interface IP addresses, MAC address, and the public IP address the machine appears from, together with the approximate geographic location derived from that address.
- Periodically, while connected: CPU, memory, load, uptime, process and connection counts for the machine and for the agent process.
- Identity: the public half of an Ed25519 key pair the agent generates on first run. The private key never leaves your machine.
Where a machine is used by a person, some of this — a hostname, an IP address, a location — may be personal data about that person. Install agents only on machines you are entitled to administer.
4. Monitoring data
For each uptime monitor you create we store the check’s configuration (the target URL, method, expected status codes, any keyword you ask us to look for, timeouts and thresholds) and the result of every check: the status code, the response time, the verdict, any error message, and where relevant certificate or domain registration details. Results are retained as history so we can show you uptime over time.
5. What we do not collect
We do not record the contents of your sessions. Terminal output, files transferred over SFTP, RDP screens and the bodies of proxied HTTP requests pass through our relay in order to reach your browser, but they are forwarded rather than stored. We keep no transcripts and no copies of your files.
Operational logs may record connection metadata — timestamps, node identifiers, error conditions — for the purpose of running and debugging the service.
6. Cookies and analytics
When you sign in we set one cookie, phirepass_auth_token. It holds a signed session token, is HttpOnly and SameSite=Lax, and expires after seven days. It is strictly necessary: without it you cannot stay signed in.
Our public pages load Google Tag Manager, which may in turn load analytics tags that set their own cookies and receive your IP address and browsing activity on this site. Google acts as a separate controller for that data; see Google’s own privacy documentation for how it is handled.
7. Why we are allowed to process this
We process account, agent and monitoring data because it is necessary to perform the contract we have with you — you cannot be given remote access to a machine without us knowing which machine. We process security and operational logs on the basis of our legitimate interest in keeping the service working and protected from abuse. Analytics is based on consent where consent is required in your jurisdiction.
8. Who we share it with
- GitHub — identity provider, at the moment you sign in.
- Google — tag management and analytics on our public pages.
- [Hosting provider] — infrastructure on which the service and its databases run, located in [region].
We do not sell personal data, and we do not share it for advertising. We may disclose data where we are legally required to.
9. How long we keep it
Account data is kept while your account exists. Node records and their reported details are kept until you delete the node. Monitor results are kept as rolling history for [retention period]. Deleting your account removes your account record, your nodes, your access tokens and your monitors; backups are cycled out within [backup retention period].
10. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to your data protection authority. Write to [privacy contact email] and we will respond within the period the applicable law requires.
11. Security
Agents authenticate with an Ed25519 key pair whose private half never leaves the machine, and hold only short-lived tokens; a personal access token is used once, to enrol a node, and then not again. Browser sessions use a signed, HttpOnly cookie over TLS. Access to a node can be revoked instantly, after which it cannot reconnect without being enrolled again. No system is perfectly secure, and we cannot guarantee absolute security.
12. Children
Phirepass is not intended for anyone under 16, and we do not knowingly collect data from them.
13. Changes
If we change this policy we will update the date at the top of this page, and for material changes we will tell you in the dashboard or by email before the change takes effect.
14. Contact
Questions about this policy, or about the Terms of Service, go to [privacy contact email].