Legal
Privacy Policy
Version 2026-08-20. This policy describes what Midfire processes when you use the Service.
1. What we process
Account data. Your GitHub login and the OAuth tokens GitHub issues when you sign in. Tokens live in an encrypted session cookie on your browser and in server memory while a request runs; we keep no user database.
Workspace content. The content of your connected GitHub repository: the knowledge, signals, and decisions your team works with. It lives in your repository, under your organization's control. We read it to operate the Service and write the results back; we do not keep a separate copy.
Billing data. Your plan, seats, and payment details are held by Stripe. We store a non-secret billing summary in your own workspace repository, and we record your acceptance of the Terms (login, timestamp, version) with your Stripe customer record. Card numbers never touch our systems.
Usage and cost data. We meter each workspace's model usage so we can operate and price the Service honestly.
2. How the AI processes your content
When the Service drafts proposals or assessments, relevant workspace content is sent to our model providers (Anthropic) under Midfire managed keys, scoped per customer workspace. We do not train models on your content, and our provider agreements govern their handling of API data.
3. Subprocessors
The Service runs on a small, named set of providers:
- GitHub (your workspace repository and sign-in)
- Vercel (application hosting)
- Anthropic (language models)
- Stripe (billing and the terms acceptance record)
We add a subprocessor only when the Service needs it, and this page changes when we do.
4. Retention and deletion
Your workspace content stays in your repository, under your control, for as long as you keep it. Signing out clears your session. If you cancel, your repository and its history remain yours; ask us at hello@midfire.ai and we will delete the billing customer record and any Midfire-side configuration for your workspace.
5. Your rights and contact
You can ask us what we hold about you, ask for corrections, or ask for deletion at hello@midfire.ai. If you are in a jurisdiction with specific data protection rights (such as the GDPR), we honor them.