Privacy Policy
This policy explains what Firsay processes, why it is needed, and how to request access or deletion.
Data we process
- Account email, password hash, role, account status, and authentication cookie.
- Search tasks, selected filters, provider queries, saved runs, candidate records, feedback, and outreach drafts.
- Payment invoice identifiers, selected plan, asset, amount, payment address, provider status, transaction timing, and subscription period. Firsay does not store wallet private keys or seed phrases.
- Operational metadata such as request counts, estimated provider cost, timestamps, error codes, and security events.
- Public professional information returned by configured sources, including public profiles, posts, project links, and public contact paths.
How we use data
We use data to authenticate users, execute requested research, verify and deduplicate results, rotate previously shown candidates, save workspaces, control abuse and cost, diagnose failures, and provide support.
Service providers
Firsay may send the minimum necessary query, public-source identifiers, or payment invoice data to Vercel, Turso, NOWPayments, TwitterAPI.io, Tavily, Telegram, GitHub, DexScreener, and a configured language-model provider. Their processing is governed by their own terms and policies.
Retention and security
Account and workspace data is retained while the account is active and as needed for security, billing, dispute handling, and legal obligations. Candidate history is used to reduce repeated results. Secrets are stored server-side; passwords are stored as salted hashes. No online service can guarantee absolute security.
Your choices
You can request a copy, correction, or deletion of your account data. Some records may be retained when required for fraud prevention, security, or legal compliance. Do not submit private credentials, private messages, or sensitive personal data in a search task.
Contact
Send privacy requests to @firsayai on Telegram. Include the account email and the request type, but never send your password, API key, or session string.