Controller, contacts, and scope
[LEGAL ENTITY NAME], at [REGISTERED ADDRESS], is intended to be the controller of personal data described in this notice. Privacy requests: [PRIVACY EMAIL]. Data Protection Officer: [DATA PROTECTION OFFICER, IF APPOINTED]. EU representative: [EU REPRESENTATIVE, IF REQUIRED]. These fields must be completed before launch.
This notice applies to the Fireflies website, accounts, event map, evidence submissions, moderation and appeal tools, data-rights tools, and communications that link to it. A separate notice may apply to a future mobile app, employment, or business-to-business service.
Personal data we collect
- Account & authentication
- Email address, password authentication records managed by Clerk, Google or Apple sign-in identifiers, verification state, login history, account age confirmation, and account-security signals. Fireflies should not receive your Google or Apple password.
- Firefly identity
- Generated Firefly ID, procedural glow seed, public contribution history, account standing, accepted corrections, and internal account-to-public-ID mapping.
- Uploads & evidence
- Images, short video, audio where enabled, descriptions, source details, capture time, submitted event time, ownership answers, file hashes, technical metadata, and the original file. Content can incidentally include faces, voices, vehicle plates, health information, beliefs, political activity, or other sensitive details.
- Location
- Location you enter, device location you choose to share, coordinates embedded in media, confidence and precision fields, and moderator adjustments. Original exact coordinates may be retained privately as evidence even when public coordinates are generalized.
- Moderation & trust
- Reports, notices, appeals, review notes, content status, evidence-quality signals, warnings, restrictions, removal reasons, statements of reasons, and suspected coordinated or abusive activity.
- Usage & device
- IP address, date and time, browser and device attributes, session identifiers, requested pages, crash and security logs, cookie choices, and approximate region derived from IP where needed for security or localization.
- Communications
- Support messages, privacy requests, legal notices, survey responses, and records needed to resolve or document the request.
- News & public sources
- Publisher, headline, author/byline where supplied, source URL, publication date, event date, location, short excerpt, language, correction data, and other publicly available material imported from allowlisted RSS feeds or data providers. This may contain names or information about people mentioned in news.
Please do not submit more personal data than an event needs. Do not upload private medical records, private communications, identity documents, intimate material, or exact home or shelter locations unless Fireflies specifically requests them through a protected channel and there is a lawful, necessary reason.
Where data comes from
- Directly from you when you create an account, submit evidence, choose a location, contact support, report content, or appeal.
- From Clerk and your selected sign-in provider when they authenticate you and return account identifiers and verification state.
- Automatically from your device, browser, session, and interactions with the service.
- From media files and their metadata, including time and location embedded by the capturing device.
- From publishers, allowlisted RSS feeds, public agencies, open-data providers, and canonical linked sources used for news ingestion.
- From other users, witnesses, moderators, rights-holders, authorities, or people who report content involving you.
- From safety, fraud, file-scanning, geocoding, or content-integrity providers added after a documented vendor review.
When personal data comes from a public or third-party source, Fireflies will provide notice where required and feasible, subject to lawful exceptions and safeguards for journalism, expression, archives, safety, and the rights of others.
Why we use data and our lawful bases
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Create and secure an account; provide sign-in, upload, map, correction, and appeal features | Account, authentication, Firefly ID, service activity | Performance of a contract; legitimate interests in service security and continuity |
| Receive, store, format, display, and organize user-requested contributions | Uploads, descriptions, public Firefly ID, approximate location | Performance of a contract; legitimate interests in operating an event-first information service |
| Verify, cluster, contextualize, correct, and preserve event history | Evidence, timestamps, location confidence, hashes, source and correction records | Legitimate interests in reliability, public understanding, fraud prevention, and defending claims; legal obligations where applicable |
| Moderate content and protect people, the service, and the public | Uploads, reports, account and security signals, review records | Legitimate interests; compliance with legal obligations; protection of vital interests in a genuine emergency |
| Process device or embedded precise location you intentionally provide | Exact coordinates and related metadata | Performance of a user-requested feature and legitimate interests in evidence integrity; device permission will also be requested. Consent will be used where applicable law requires it. |
| Ingest and link news and public-source material | Source metadata, public article data, names in public reporting | Legitimate interests in organizing public-interest event information; exercise of expression and information rights, subject to applicable law |
| Respond to privacy, legal, safety, and support requests | Contact details, request, identity-verification and resolution records | Legal obligations; performance of a contract; legitimate interests in documenting resolution |
| Send essential service and safety messages | Email, account and incident details | Performance of a contract; legal obligations; legitimate interests |
| Optional analytics, product research, or marketing if introduced | Consent record and the specifically described usage data | Consent where required. Optional analytics and marketing cookies are disabled at launch. |
Where Fireflies relies on legitimate interests, it will assess necessity, expected benefit, and the effect on people. You may object to this processing. Fireflies will stop unless it demonstrates compelling overriding grounds or the processing is needed for legal claims. A device permission is not automatically the same as GDPR consent.
What becomes public
An approved contribution may publicly show its media, description, event association, generalized location, capture or event time, verification label, source label, correction history, and your public Firefly ID. Public information can be copied, indexed, quoted, or archived by others beyond Fireflies’ control.
- Private intake
New files enter restricted storage for validation, malware scanning, metadata review, safety checks, and moderation. A submission is not automatically public.
- Evidence review
Authorized reviewers may inspect the original, embedded metadata, exact coordinates, source claims, duplicates, and signals of manipulation.
- Public presentation
Fireflies normally strips public file metadata and publishes an approximate, rounded, or city-level location. Exact locations may be shown only when safe, necessary, and justified for the event.
- Correction or restriction
Fireflies may blur, crop, relabel, reduce visibility, move, correct, or remove content and keep a proportionate audit record.
Who receives data
- The public, for approved content and public event information described above.
- Clerk, as authentication and identity infrastructure for email/password, Google, and Apple sign-in.
- Railway and infrastructure vendors supporting application hosting, PostgreSQL, Redis, private object storage, logs, networking, and backups.
- Vetted providers used for email delivery, malware scanning, geocoding, safety, support, or moderation, only if added and under appropriate terms.
- Publishers, source partners, or rights-holders where needed to validate attribution, correct a record, or resolve a rights claim.
- Professional advisers, auditors, insurers, transaction counterparties, or new owners subject to confidentiality and lawful safeguards.
- Courts, regulators, law enforcement, emergency services, or other parties when disclosure is legally required, necessary to protect vital interests, or needed to establish, exercise, or defend legal claims.
Fireflies does not sell personal data. Before launch, Fireflies must publish a current processor register or equivalent vendor detail identifying the providers actually deployed, their role, and relevant processing locations.
International transfers
Some providers or support personnel may process data outside the European Economic Area, the United Kingdom, or your country. Before any such transfer, Fireflies will identify the destination and rely on an applicable adequacy decision, approved standard contractual clauses or another lawful transfer mechanism, and supplementary technical or organizational measures where required.
Request information about relevant safeguards or a copy, with protected details redacted, at [PRIVACY EMAIL]. The final notice must identify material transfer destinations and mechanisms after hosting regions and processor contracts are fixed.
How long we keep data
| Record | Provisional period | Why / end condition |
|---|---|---|
| Account and private identity mapping | Account life, then normally 30 days | Provide the account, allow recovery, complete deletion, prevent accidental re-creation |
| Rejected or abandoned quarantine uploads | Normally 30 days after final rejection or abandonment | Complete review and permit an appeal; longer only for safety, legal hold, or abuse evidence |
| Published evidence and event records | For the event record’s useful life, subject to periodic review | Maintain source, context, corrections, and public-interest history; remove, restrict, or de-identify when no longer justified |
| Original files and exact evidence metadata | While needed for verification; review at least annually after removal or resolution | Authenticate, investigate manipulation, support corrections and legal claims; minimize access |
| Moderation, notice, appeal, and strike records | Normally 3 years after final resolution or account closure | Explain decisions, detect proportionate repeat misuse, meet legal duties, defend claims |
| Security and access logs | Normally 90 days | Detect incidents, investigate abuse, and protect the service; longer when tied to an incident |
| Support and data-rights records | Normally 3 years after closure | Demonstrate response and preserve necessary correspondence |
| Backups | Rotating schedule, target deletion within 90 days | Resilience and disaster recovery; deleted data is not restored to active use |
| Ingested news metadata and correction links | While the event archive remains relevant, with periodic review | Preserve source attribution, chronology, and correction integrity |
A legal hold, investigation, court order, safety incident, unresolved appeal, or limitation period may justify longer retention. Fireflies should then restrict the data to that purpose and delete or de-identify it when the reason ends.
AI and automated tools
Fireflies may use automated tools to detect duplicate media, extract text, suggest captions or translations, identify location clues, flag malware or harmful material, estimate whether content may be synthetic, and prioritize review. These signals can be wrong and are not proof that an event is true or false.
Fireflies does not intend to make a solely automated decision that produces legal or similarly significant effects on you. High-risk publication, removal, account, and appeal decisions should have meaningful human review. If that changes, Fireflies will provide the required information about logic, significance, consequences, and available safeguards before the processing begins.
Your rights and choices
- Be informed about processing and request access to your personal data.
- Correct inaccurate data and complete incomplete data.
- Ask for erasure where the legal conditions apply.
- Restrict processing while a dispute or request is assessed.
- Receive eligible data you provided in a structured, commonly used, machine-readable format and, where technically feasible, transmit it to another controller.
- Object to processing based on legitimate interests, including profiling based on those interests.
- Withdraw consent at any time for future processing where consent is the basis; earlier processing remains lawful.
- Not be subject to a decision based solely on automated processing where it has legal or similarly significant effects, subject to legal exceptions.
- Lodge a complaint with the data-protection authority where you live, work, or believe an infringement occurred, and seek a judicial remedy.
Use the in-product data controls when available or contact [PRIVACY EMAIL]. Fireflies may verify identity proportionately and will normally respond without undue delay and within one month, subject to lawful extensions. Rights may be limited where necessary to protect expression and information, others’ privacy, confidential sources, public safety, legal claims, or other applicable exceptions.
Security and incident response
Fireflies will use role-based access, encryption in transit, appropriate encryption at rest, private upload buckets, separated public derivatives, authentication controls, audit logs, secrets management, backup protection, dependency patching, and incident procedures proportionate to the risk. No system can be guaranteed completely secure.
If a personal-data breach creates a risk requiring notification, Fireflies will notify the competent authority and affected people within the periods and with the information required by applicable law. Report a suspected security issue through [SUPPORT EMAIL]; a dedicated security address must be added before launch.
Age limit and children
Fireflies is for people aged 18 and over. We do not knowingly permit minors to create accounts. If we learn that an under-18 account has provided personal data, we will restrict the account and assess deletion, preservation, or safeguarding steps required by law.
Reporting may still involve images or information about children. Contributors must minimize exposure and never identify a child in a way that creates a safety risk. A parent, guardian, or appropriate authority can contact [PRIVACY EMAIL] to raise a concern.
Changes, complaints, and contact paths
Fireflies will date material revisions and provide proportionate notice before they take effect. Where processing requires new consent, the service will ask rather than treating continued use as consent.
- Controller
- [LEGAL ENTITY NAME], [REGISTERED ADDRESS]
- Privacy
- [PRIVACY EMAIL]
- Support
- [SUPPORT EMAIL]
- DPO
- [DATA PROTECTION OFFICER, IF APPOINTED]
- EU representative
- [EU REPRESENTATIVE, IF REQUIRED]