intellity← back to site

Legal

Privacy Policy

Last updated: 17 July 2026 · Swiss FADP (revDSG), and the GDPR where it applies

Intellity is a security tool for Firebase apps. It is built to collect as little as possible. It never reads your database, your users, or your files: it works only with your security-rules text, either the text you paste or the rules you have deployed, read through a read-only connection you grant. This policy explains what we process across the whole product, an account, scanning, the optional Firebase connection, continuous monitoring, and billing, and why.

1. Who is responsible

The controller for the processing described here is AppFocus GmbH, Haselstrasse 19, 5400 Baden, Switzerland (see the Imprint). Contact for anything in this policy: nikola@appfocus.ch.

2. The rules you scan

When you run a scan, the Firestore and Cloud Storage rules involved, whether you pasted them or we read them from a connected project, are loaded into an isolated instance of the Firebase rules engine on our servers, probed, and turned into your report. The rules text is held only in memory for the duration of the scan and is never written to a database or to disk. It is not shared with anyone and is not used to train anything. Rules describe access structure; the scan never sees your users or their data.

3. Your account

To save scans, connect a project, or turn on monitoring you create an account. We store your email address and a Firebase Authentication user record, including whether your email is verified. If you sign in with Google, Google provides your email address and basic profile to create the account. Passwords are handled entirely by Firebase Authentication (Google); we never see or store your password. We use your email to operate your account and to send the service emails described in section 8.

4. Your saved scans

When you are signed in, each scan you run is saved to your dashboard. We store a name you choose, the counts (numbers of findings and probes, a clean/not-clean flag), a timestamp, and an anonymised list of finding types (severity and category only). We do not store the rules text, and we do not store any path, collection, or project name from your rules. This lives in our database on Google Cloud in Zürich, Switzerland, and clients cannot read that database directly; it is reachable only through our server.

5. Connecting your Firebase (read-only)

Connecting a project is optional. When you connect, you grant a read-only Google authorisation, the firebase.readonly scope (and cloud-billing.readonly only if you separately opt into the cost checks). We store the resulting Google refresh token encrypted at rest so we can, on your behalf, list your projects and read the security rules you have deployed. We use it for nothing else: it does not permit reading or writing your database, your users, or your stored files, and it cannot change anything in your project. You can disconnect at any time from within Intellity or from your Google Account, which revokes the access.

6. Continuous monitoring (Pro)

If you turn on monitoring for a connected project, our scheduler periodically re-reads that project's deployed rules through the read-only access above, re-scans them, stores the same anonymised finding types as in section 4, and emails you when a new issue appears. You can turn monitoring off for any project at any time.

7. Billing (Pro subscriptions)

Paid subscriptions are processed by Stripe (Stripe Payments Europe, Ltd. and Stripe, Inc., USA). Stripe collects and handles your payment details directly; we never see or store your card number. We store a Stripe customer identifier and your subscription status and plan so we can grant access and manage the subscription. Stripe processes your payment data under its own terms and privacy policy.

8. Emails we send

We send service emails tied to your account and your use of Intellity: email verification, a welcome message, trial and subscription notices, monitoring alerts when a connected project changes, and password resets. If you send feedback, that text reaches us by email. Delivery is handled by the email provider Resend (Resend, Inc., USA), bound by its data-processing terms; your email address is shared with it only to deliver these messages. Any purely promotional email would be sent only with your consent and always with an unsubscribe path.

9. Rate limiting and technical logs

To keep the service available we enforce per-network hourly limits, a per-account daily cap, and a global daily cap. For the network limits the application computes a salted SHA-256 hash of your IP address; the counters reference only that hash and the hour or day they cover. Independently, our infrastructure provider records standard request logs (IP address, timestamp, user agent), which we keep for around 30 days for security and operations.

10. Cookies and tracking

We use only the browser storage needed to keep you signed in, set by Firebase Authentication. We run no third-party analytics, no advertising technology, no cross-site tracking, and no fingerprinting.

11. Purposes and legal bases

We process the data above to provide the Service you ask for (your account, scans, the connection, monitoring, and your subscription), to protect the Service against abuse, and to improve our checks using anonymised statistics. Where the GDPR applies, the legal bases are: performance of a contract (operating your account and the features you use); legitimate interests (security, abuse prevention, and product improvement on anonymised data); and consent for any promotional email, which you can withdraw at any time. Under the Swiss FADP, processing is carried out in good faith, proportionately, and for the stated purposes.

12. Who processes data for us, and where

  • Google (Google LLC / Google Ireland Ltd.): Firebase Authentication, our database, the scan engine and backend, and key storage run on Google Cloud in region europe-west6, Zürich, Switzerland. Google is also the provider of the read-only Firebase authorisation you grant.
  • Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc., USA): subscription payments, as described in section 7.
  • Resend, Inc. (USA): delivery of the service emails in section 8.
  • Vercel Inc. (USA): delivery of the website itself.

Where a provider processes data outside Switzerland or the EU/EEA, transfers are protected by recognised safeguards such as the EU Standard Contractual Clauses and their Swiss addendum, or an applicable adequacy decision.

13. Retention

  • Rules text: not retained. In memory only, for the seconds a scan runs.
  • Account, saved scans, connections, and monitoring settings: kept while your account exists; removed when you delete your account (section 14).
  • The read-only Google token: kept encrypted until you disconnect or delete your account.
  • Billing records: your subscription record with us is removed with your account; Stripe retains transaction records as required by law.
  • Anonymised scan statistics: kept indefinitely; they contain no personal data.
  • Infrastructure request logs: around 30 days.
  • Rate-limit counters: reference only a salted hash and become irrelevant after the hour or day they cover.

14. Deleting your account

You can delete your account yourself from Settings at any time. This cancels any active subscription, revokes the read-only Firebase connection at Google, and permanently erases your account, your saved scans, your connections, and your monitoring settings from our systems. Anonymised statistics that contain no personal data, and records third parties must keep by law (for example Stripe's transaction records), are not affected.

15. Sharing

We do not sell your data, and we do not share scan results linked to you with anyone. Data is disclosed only to the processors listed above, or where we are legally required to disclose it.

16. Your rights

You can request access to, correction of, or deletion of your personal data (and you can delete your account yourself), object to or restrict certain processing, and, where the GDPR applies, request portability. Email nikola@appfocus.ch and we will handle it; we may need to verify that a request really comes from you. You can also complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), in the EU your local authority.

17. Security

All traffic is encrypted in transit. Scans run in an isolated engine on our own infrastructure. The read-only Google token is encrypted at rest, our database is not readable by clients, secrets are held in a managed key store, access is restricted to what the service needs, and we minimise what we collect in the first place, as this policy shows.

18. Changes

Intellity is in active development. We will update this policy as the service grows and revise the date at the top when we do.

19. Contact

Questions about this policy or your data: nikola@appfocus.ch.

© 2026 AppFocus GmbH, Baden, Switzerland
ImprintPrivacyTerms