Privacy notice

Last updated 30 September 2026.

Firelog reads supported bank statements inside your browser. Importing and browsing do not send the PDF, extracted text or transaction history to Firelog. Data leaves only when you use an explicit report or contribution action after reviewing what will be sent. This page identifies those actions, their payloads, protection and retention.

The short version.

Your imported transaction database stays in this browser. The app has no Firelog user accounts, advertising trackers or product-analytics scripts. This website (firelog.sg) uses cookieless Cloudflare Web Analytics to count visits; the app does not. If you affirmatively share selected parser evidence, contribute an exact description/template report, or send a visible app diagnostic, the selected payload is encrypted in your browser to a public key whose private half is held by the operator, then travels over HTTPS to a Cloudflare Worker. The Worker and temporary R2 storage receive sealed ciphertext and cannot decrypt it. Minimal report-status metadata is held separately in Cloudflare D1, as explained below.

Who is responsible for your data

Firelog is operated from Singapore by an individual, not yet an incorporated company. The operator is responsible for personal data submitted to Firelog. Under Singapore's Personal Data Protection Act 2012 (PDPA), Firelog designates a Data Protection Officer and publishes the role's business contact details below.

What stays on your device

Statement PDFs you import are parsed in your browser. Transactions are written as a plain SQLite database in the browser's origin-private file system (OPFS). Firelog does not separately encrypt that database or synchronise it to a Firelog server. The browser isolates it from other sites, but code served later from the same Firelog origin could access it. That isolation is between websites only. On disk the database is an ordinary file in your browser's profile folder: programs running under your device account, the device's administrators and browser extensions with access to Firelog's pages can read it, and so can anyone holding the disk itself unless device encryption (BitLocker on Windows, FileVault on macOS) is turned on. Protect it as you would the statement PDFs it was built from. Clearing Firelog's site data erases it; an incognito/private session normally erases it when that session closes.

Firelog also keeps local report receipts, access secrets and cached statuses in IndexedDB, plus legacy submission references; and, if you choose a reusable statement folder, a browser-managed directory handle in IndexedDB. The handle is not a copy of the files and the browser asks for read permission again. These items stay local unless you explicitly include their text in a report.

The app includes no product analytics, advertising or tracking scripts and has no user accounts. The app makes same-origin requests for its own code and assets, including the optional sample. Ordinary healthy import and browsing do not POST financial data. Cloudflare necessarily receives request metadata such as IP address, URL, headers and time when serving or protecting the site; Firelog does not use that metadata for advertising or behavioural profiles.

What you can choose to send us

The app's “Report a problem” action covers wrong values, missing or duplicate transactions, import problems, description feedback and app errors. It asks what you noticed; knowing the correct answer is optional. Available context is attached automatically and shown in the complete preview. This can include a selected transaction's fields, labels, exact raw description, bank/product/parser context, local import-failure details or the displayed application diagnostic. Comments and suggested values are included exactly as entered.

Statement evidence is optional. Selecting a PDF reads it in your browser and prepares exact page text and word coordinates. Names, addresses, account/card numbers, references, dates, amounts, whitespace and coordinates are not randomized, substituted, automatically redacted or rounded. The original PDF is sent only if you separately choose it, including when extraction fails or is still pending. Its filename and checksum are included inside the encrypted evidence.

Every submission, including additional evidence for an existing report, requires a previously unchecked consent checkbox beside the complete preview. Changing the content clears consent. The developer can decrypt the evidence. Reporting is optional; your financial database is not uploaded. App diagnostics are designed to describe app/build/browser versions, storage capability, time, failure stage and error text; unexpected error messages can contain private context, so review them too.

Older cached versions may still use the earlier statement, description or diagnostic channels, optionally include an email, or send redacted evidence. They keep their original intake and retention rules. Removed or randomized legacy values are never treated as original evidence.

Report receipts and status

Before sending, your browser saves a random report ID and a separate random access secret for that report. My reports stores a local summary, submission date, evidence-attempt IDs, cached statuses and the last-check time. Source PDFs and extracted evidence are not saved for retries. Viewing cached reports contacts nobody. “Check for updates”, additional-evidence submissions and deletion requests explicitly contact Firelog. A received report is not necessarily a confirmed bug. A fix in a named release does not mean your existing imported data has been repaired.

Cloudflare D1 stores minimal plaintext workflow metadata: opaque report/evidence/issue IDs, a hash of each access secret, ciphertext checksums, receipt and update times, outcome codes, issue associations, status history, regression-test and fixing-commit references, and release names. It does not store financial descriptions, personal filenames, report text, private investigation notes or raw evidence. Daily rotating hashes of requesting IP addresses and bounded counters support abuse controls; these pseudonymous counters are removed after two days by the operator's cleanup job. Cloudflare also sees ordinary request metadata when serving the service.

The secret is sent in an authorization header, never a URL, and is not logged by Firelog's report handlers or analytics. A report reference alone grants no access. There is no public report list or endpoint for downloading original evidence. Recovery export/import is deliberate: exported secrets allow their holder to check statuses, add evidence and request deletion. Store recovery files privately. Clearing local data or removing a receipt deletes its local secret; retain a recovery export if you need continued access.

The legal basis

We rely on your consent, expressed by the confirmation control or affirmative Send action shown with each submission. You may withdraw consent with reasonable notice by emailing the DPO; after withdrawal Firelog will cease future collection, use and disclosure of identifiable data for that purpose, subject to applicable exceptions. Separately, Firelog accepts requests for earlier deletion where the submission can be located. Withdrawal does not undo prior lawful use or remove facts already embodied in an invented, non-personal test fixture.

How long anything is kept

Two different places are involved: Cloudflare's temporary inbox and the operator's working machine. The times below are retention intentions and policy, not a guarantee that a failed job can never delay deletion.

WhatWhereHow long
Report metadata, secret hashes, associations and report historyCloudflare D1 Access expires 365 days after submission. The private drain deletes the records and related evidence after expiry or an authenticated deletion request. Provider backups may retain older metadata under the account's D1 backup policy; live-row deletion is not immediate backup erasure.
Local receipts and recovery secretsYour browserUntil you remove them or clear site data. Exported recovery files remain under your control.
Public issue/release code provenanceCloudflare D1 and operator workflow May remain for regression tracking, without private evidence. Completed operator outbox records are pruned after a year; unresolved updates remain until reviewed.
Anything you share Cloudflare R2 (hosting provider) It is intended to be collected promptly and the R2 copy deleted once collected, including a submission that turns out to be invalid or cannot be decrypted. Nothing removes a submission from R2 automatically: if the operator's machine, credentials or network is unavailable, it stays there, encrypted, until the next successful collection.
A shared statement PDF Our working machine in Singapore Until the report is resolved or no longer needed; the local retention policy is 90 days from receipt, and copies may be deleted sooner.
Your email address Our working machine in Singapore Deleted with the associated statement or when no longer needed for that report, subject to the same 90-day retention policy. It is never added to a mailing list.
Transaction descriptions Our working machine in Singapore Deleted when no longer needed; subject to the same 90-day retention policy.
Application diagnostics Our working machine in Singapore Deleted when no longer needed; subject to the same 90-day retention policy.
A submission that fails validation Our working machine in Singapore Set aside rather than used, and subject to the same 90-day retention policy.

When we build a parser from a statement you sent, we keep only an invented test file that imitates the layout — made-up names, made-up account numbers, made-up transactions. Your actual statement is deleted. This matters because it is what lets us keep testing the parser forever without keeping your document forever.

Local cleanup code and successful-deletion logging exist, but no live schedule is assumed by this notice. An operator or job failure can delay deletion; that operational gap must be monitored and corrected rather than hidden behind an absolute promise.

How it is protected

Before transmission, your browser encrypts each report object using a one-off ephemeral key agreement (P-256 ECDH with AES-256-GCM). It then sends the sealed ciphertext over HTTPS to a Cloudflare Worker. The Worker and R2 storage can check the protocol, envelope structure and size, but cannot decrypt or validate the PDF, checksum, extraction integrity or report content. The private decryption key is controlled by the operator, including an offline backup, and is not deployed to or held by Cloudflare.

Someone obtaining only the stored R2 objects without the private key would obtain ciphertext, timestamps and coarse submission metadata such as channel/type and file count. Stored object names contain no user name, source filename, email address or checksum.

Browser-side encryption protects report contents from the Worker and R2, but not from a compromised live application origin: altered JavaScript could read a report before it is sealed. It also does not protect the operator's working machine or private decryption key.

Which problems Firelog offers to share is decided in your browser, and the endpoint cannot check that decision, because it only ever receives sealed ciphertext. The service enforces what it can: an explicit consent flag, the application's own address, fixed size and file-count limits, request rate limits and a spending ceiling. After decryption on the operator's machine, a submission is used only if it passes validation; anything that does not is set aside rather than used, and deleted under the retention policy above.

Who else is involved

Cloudflare, Inc. hosts the site, application, reporting endpoints and temporary storage, and processes ordinary request metadata to deliver and protect them. Cloudflare may process data outside Singapore. No claim is made that an R2 placement hint, if configured, is a guarantee of Singapore-only or Asia-Pacific-only processing. Stored submissions are encrypted to a private key Cloudflare does not hold, subject to the live-endpoint limitation above.

Cloudflare Web Analytics runs on this website, firelog.sg, to count visits. For each page view it records which page was viewed, the site that linked to it, page-load performance measurements, and the country, browser, operating system and device type Cloudflare derives from the request. It sets no cookies, uses no other storage in your browser, and does not fingerprint visitors; its script loads from Cloudflare and reports to firelog.sg itself. The app at app.firelog.sg does not load it, and nothing about your statements or transactions is ever part of it.

Cloudflare Email Routing and the operator's destination email provider process messages sent to hello@firelog.sg or dpo@firelog.sg. Copied report or diagnostic text emailed after an in-app send fails follows that email path, not the encrypted R2 inbox, and is subject to the email providers' storage and security controls. Do not email an original statement PDF; retry the in-app statement-report channel instead.

We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use it to build profiles of you.

Your rights

Subject to applicable PDPA exceptions, you may ask Firelog to:

Email dpo@firelog.sg. We will respond as soon as reasonably possible. If an access or correction request cannot be completed within 30 days, we will tell you in writing within 30 days when to expect the response. You may also request early deletion under Firelog's policy, subject to locating the submission and any applicable legal or business retention requirement.

Use My reports to request deletion of a current report. Its saved secret authorizes the request. The private drain removes shared evidence before revoking online access and deleting its status metadata. Removing a local receipt alone does not delete shared evidence. Do not email access secrets. For older reports, quote the earlier submission reference when contacting the DPO; it locates a submission but does not itself authorize access or disclosure.

Without a saved receipt/recovery secret, or sufficient information for an older submission, we may be unable to identify your evidence safely. Scheduled retention still applies. Operator or network failures can delay physical deletion, as described above.

If something goes wrong

Firelog will assess a data breach and notify the Personal Data Protection Commission and affected individuals when it is likely to cause significant harm and/or is of significant scale, as the PDPA requires. Where we still retain affected data and contact details, email is how we will try to reach you; otherwise Firelog may publish a notice on this site.

If you are unhappy with how we have handled your data, please contact the DPO first — and if that does not resolve it, you may complain to the Personal Data Protection Commission.

Changes

If this notice changes materially we will update the date at the top and, where the change affects data already shared with us, take reasonable steps to notify people whose affected contact details we still hold. Firelog is in beta and its features are still moving; this page is updated when behaviour changes, not on a schedule.