Privacy Policy
Effective Date: August 12, 2026
1. Effective Date
This Privacy Policy describes Fireground Lab’s information practices beginning on the date above.
2. Who Operates Fireground Lab
Fireground Lab is operated by Reverse Flow LLC. Reverse Flow LLC is responsible for the service and its handling of customer information.
3. Information We Collect
Account information: name, email address, authentication and account identifiers, account status, and session information.
User content: uploaded building photographs, scenario descriptions, manual compositions, accepted manual or AI-generated Pictures, scenario state, actions, outcomes, and history.
Billing and AI records: Stripe customer, subscription, Checkout, and purchase identifiers; subscription and payment status; AI balances, grants, reservations, and provider-attempt records. We do not collect or store full payment-card details.
Technical and support information: request identifiers, timestamps, request method and endpoint, response status and timing, authenticated user ID, error and security events, and information you send to support. An IP address is transiently processed for Presentation pairing protection; Fireground Lab stores only a keyed hash for short-term rate limiting, not the raw address in its application database. Hosting and service providers may process ordinary network and device information in their infrastructure logs.
4. How We Use Information
We use information to create and manage accounts; save, restore, build, run, and present scenarios; process photos; create manual and AI Pictures; manage subscriptions and AI balances; provide support; diagnose failures; protect accounts and the platform; maintain reliability; evaluate advertising performance; and meet legal and accounting obligations.
Fireground Lab does not sell customer personal information or use scenario media for third-party advertising.
5. Uploaded Photos and Scenario Media
Uploaded photos and scenario media are associated with your account and stored privately by default. Accepted manual and AI Pictures support saved scenario functionality. Only upload photographs and content you have the right and authority to use.
Owner-only development diagnostics may temporarily retain an automatically rejected AI candidate in private Storage for up to 7 days. This is disabled for ordinary customer accounts and retained imagery never appears in Run or Presentation.
6. AI Processing
When you use AI-generation features, Fireground Lab sends the information needed to perform that request, which may include uploaded or current scenario images, accepted parent images, scenario instructions, action and outcome context, and structured visual-state instructions, to our AI service provider.
Our current AI image provider is OpenAI. Fireground Lab is not intentionally opted into provider data-sharing or model-training programs for API inputs and outputs. Provider processing and limited retention may still occur under the provider’s applicable security, abuse-monitoring, and service policies.
7. Payments and Billing
Stripe processes subscription and one-time AI-pack payments and provides the hosted Checkout and billing portal. Fireground Lab receives and stores identifiers and status needed to manage subscriptions, purchases, grants, and access. Fireground Lab does not collect or store full payment-card numbers.
8. Service Providers
Current providers include Supabase for authentication, database, and private Storage; Vercel for application hosting and runtime; Stripe for subscriptions, payments, and the billing portal; OpenAI for AI image generation when requested; Resend for transactional and operational email; and Meta for browser-based advertising measurement. Providers process information only for their service roles and under their applicable terms and policies. Providers may change as the service evolves.
9. Presentation and Sharing
An instructor intentionally pairs a student display with a durable Presentation channel. A paired display receives only the currently released, instructor-accepted Picture and minimal lifecycle state. Draft, rejected, pending, and review imagery remains private. Pairing is a limited read-only display capability, not public publication.
10. Logs, Cookies, Analytics, Security, and Reliability
Fireground Lab uses an encrypted, HTTP-only session cookie for account access and a separate HTTP-only viewer cookie for paired Presentation displays. The instructor application uses local browser storage to remember the active scenario on that device. Stripe may use its own cookies during hosted Checkout and billing.
On the production Fireground Lab website and instructor application, the Meta Pixel records page views and limited events for landing-page viewing, account registration, trial activation, paid subscription confirmation, and first-scenario creation. Meta may receive ordinary browser and network information and use cookies or similar technologies to attribute activity after an advertisement. Fireground Lab does not send scenario photos, scenario descriptions, passwords, payment-card details, or authentication tokens to Meta through this integration.
Application logs record limited request, timing, user-ID, error, and security information needed for reliability and investigation. Fireground Lab does not intentionally log passwords, authentication tokens, payment-card details, or image bytes.
We use reasonable safeguards including authenticated access, private object Storage, database access controls and row-level security, secure transport, scoped viewer credentials, and restricted server-side service credentials. No system can guarantee absolute security.
11. Data Retention
Active-account scenario content is retained while needed to provide the service; no arbitrary active-content deletion period is imposed by this policy. After paid subscription access ends, scenario and media content is locked and retained for 12 months from the actual paid-through date. Reactivation during that period restores access and retained purchased AI balances.
Fireground Lab will provide advance notice before scheduled deletion of retained scenario content. Billing, tax, fraud-prevention, legal, and accounting records may be retained separately as required. Information may remain in secured backups for a limited period after deletion while backup copies cycle out, subject to legal and security requirements.
12. Your Choices and Requests
You can manage subscription and payment settings through Account and Manage Billing. You may contact us to request access, correction, or deletion of account information, subject to applicable law and records we are required to retain. Send privacy and account requests to fireground-lab@reverse-flow.app.
13. Children and Intended Audience
Fireground Lab is intended for adult fire-service instructors and training professionals and is not directed to children.
14. Changes to This Privacy Policy
We may update this Privacy Policy and will revise the Effective Date. We will communicate material changes where appropriate or required.
15. Contact
For privacy questions or requests, email fireground-lab@reverse-flow.app. Fireground Lab is operated by Reverse Flow LLC.