Privacy Statement
This statement explains what happens to your information when you use FireFlow Studio for FDS, visit fireflowstudio.com.au, or buy a licence from us. It is written in plain English, because you should not need a lawyer to work out what happens to your data.
1. Who we are and how to contact us
FireFlow Studios for FDS (ABN 38 592 552 472) is a registered business name of the Van der Walt Investments Trust, based in Queensland, Australia. In this statement, "we", "us" and "our" mean that business, and we are responsible for the personal information described here.
The software publisher named on the code signing certificate is Van der Walt Investments Pty Ltd (ACN 659 714 995). FireFlow Studio for FDS is developed by Dirk van der Walt, a practising fire safety engineer.
You can reach us about anything in this statement, including access, correction or a complaint, at info@fireflowstudio.com.au.
We handle personal information in accordance with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).
2. The short version
- The desktop application collects nothing. No telemetry, no analytics, no usage tracking and no automatic crash reporting.
- Licence activation is fully offline. There is no account and no licence server, and activating sends nothing to us.
- Your models, your results and any files you open or save stay on your own device.
- The only connection the application makes on its own is an optional check of GitHub's public API for the latest NIST FDS solver release, and an optional download of that solver. It transmits nothing about you or your models.
- Bug reports are never sent automatically. The application composes a report and opens it in your own email client, so you see and control exactly what is sent, including whether your model goes with it.
- The website has no analytics, no tracking cookies and no advertising pixels.
- To download the trial we ask for your email address only. To buy a licence, Stripe handles the payment and we receive your name and email address, never your card number.
3. What the desktop application does and does not collect
What it does not do
- It does not collect telemetry, analytics or usage statistics.
- It does not report crashes or errors automatically.
- It does not send your models, results, file names or project details anywhere.
- It does not create an account, sign you in, or contact a licence server.
- It does not run anything in the background that gathers information about you.
Licences
Your licence key is an Ed25519 signed key that is verified locally on your own machine. The check happens entirely on your computer and sends nothing to us or to anyone else. Because there is no account and no activation server, we do not know when, where or how often you use the software.
The one outbound connection
The application can optionally check GitHub's public API (api.github.com) for the latest release of the NIST FDS solver, and can optionally download that solver for you. That request asks GitHub for public release information. It does not include your licence key, your name, your email address, your models or anything else about you or your work. As with any internet request, GitHub will see the connection itself, including your IP address, under its own privacy terms. Apart from that, the only other time the application reaches the internet is when you deliberately click a link, which opens in your own browser.
Your files
Models, results, input files, output files and anything else you open or save remain on your own device or on storage you control. We have no access to them.
4. Bug reports and model files
Nothing is ever transmitted automatically when something goes wrong. If you use the in-app "Report a Problem" dialog, the application composes a report and opens it in your own email client. You can read it, edit it, decide whether to send it, and cancel at any point. Nothing is uploaded to us or to any server of ours.
The dialog includes a tick box for attaching the model you currently have open. When a model is open, that box is ticked for you, so please check it. If you do not want to send your model, untick the box before continuing. If the box is ticked, the model is written to a file on your own computer, which you then attach and send yourself. You always see what is being sent before it leaves your machine.
Our commitment if you do send us a model
If you choose to send a model file with a bug report, we will use it only to reproduce and diagnose the issue you reported, and only if doing that is necessary. We will not use it for any other purpose, we will not share it with anyone else, we will not use it to build new features, and we will not use it to train any system.
Once the issue is resolved, we delete the file. Bug reports reach us by email, not by upload, so deletion means removing the file and any working copies we made from the mailbox it arrived in, including any copy in sent items if we replied with it attached, and then clearing it from deleted items. We do this as soon as the issue is resolved. To be honest about how email works: after we delete an item, our mail provider may hold it in a trash or recovery folder for a short time under its own settings before it is permanently purged. Beyond that, we do not retain the file and we do not keep it in any archive or backup of our own.
If you would prefer not to send a model at all, please untick the box and describe the problem instead. We will always try to help without it.
5. The website: trial signups, purchases and emails
Trial download
The trial download form collects your email address and nothing else. The form is submitted through Netlify Forms and your address is then added as a contact in Brevo, our email service. Brevo sends you a short automated sequence of trial emails. Every one of those emails has an unsubscribe link, and you can use it at any time without contacting us.
Buying a licence
Purchases are handled by Stripe Checkout. Stripe collects and processes your payment details directly. We never see or hold your full card number. What we receive from Stripe is your name and email address, plus the record of the transaction.
After your purchase we generate your licence key and email it to you. That email is delivered using Brevo's SMTP service. We also mark your contact in Brevo as a purchaser so the trial email sequence stops.
Other emails
If you email us at info@fireflowstudio.com.au, we will have whatever you put in that email, and we will use it to answer you.
If you are a customer, we may also email you about the software itself, for example a new release or a fix that affects you. Tell us if you would rather not receive those and we will stop.
Dealing with us anonymously
You can browse the website and use the software without telling us who you are. We need an email address to send you the trial, and Stripe needs your name and email to sell you a licence and issue your key. We do not ask for sensitive information such as health details, biometrics or government identifiers, and we have no use for it.
6. Cookies, tracking and embedded content
We do not use analytics, tracking cookies or advertising pixels. There is no Google Analytics, no tag manager, no Meta pixel, no Plausible and no Hotjar. We do not build a profile of visitors and we do not know who you are when you browse the site. That is also why you do not see a cookie consent banner: we are not setting anything that would need one.
The site does load two things from other companies, and we would rather tell you than let you find them in your network tab:
- Google Fonts. Our pages use the Inter typeface, loaded from fonts.googleapis.com and fonts.gstatic.com. When your browser fetches the font, Google receives that request, including your IP address, under Google's own terms.
- Video preview images. The walkthrough videos are shown as a still preview picture that is served from YouTube's image servers (i.ytimg.com), so YouTube receives a request, including your IP address, when a page containing a video preview loads.
The video player itself is not loaded until you choose to play it. The preview is a click to load facade: only when you press play do we load the player, from youtube-nocookie.com, and from that point YouTube's own terms and privacy practices apply to the playback.
Our hosting provider, Netlify, may keep standard server logs, such as IP addresses and requested pages, for delivering and securing the site. Installer downloads are served from GitHub Releases, so GitHub sees those download requests.
7. Who else processes your information
We keep the list of third parties short on purpose. These are the only ones involved:
- Netlify: hosts the website and receives trial signup form submissions.
- Stripe: processes payments and provides us with your name, email address and transaction record.
- Brevo: stores contact details for the trial email sequence and delivers our emails, including your licence key.
- GitHub: hosts installer downloads and the public release information the application can optionally check.
- Google Fonts: serves the typeface used on our pages, as described in section 6.
- YouTube: serves the video preview images, and the player itself if you press play.
- Our email provider: carries the email we send and receive, including any bug report you send us.
We do not sell your personal information, and we do not disclose it to anyone for advertising or marketing by others. We may disclose information if we are required to by law.
Overseas processing
Netlify, Stripe, Brevo, GitHub, Google and YouTube are based overseas and may process or store your information outside Australia, including in the United States and in Europe. Our email provider may also handle your email outside Australia. If you buy a licence, download the trial or use the website, some of your information will be handled outside Australia by these providers under their own privacy terms.
8. How long we keep information
- Trial signups: we keep your email address in Brevo while you are on our list. If you unsubscribe or ask us to remove you, we remove you.
- Customers: we keep your name, email address and licence record for as long as you hold a licence, so that we can support you and reissue your key if you need it, and for as long as we are required to keep business and tax records.
- Payment records: Stripe holds payment information under its own retention terms. We hold only the transaction record we receive from Stripe.
- Bug reports and model files: model files are deleted as soon as the reported issue is resolved, as described in section 4. We may keep a plain text note of the bug itself so the fix is documented, without your model.
- Emails: we keep correspondence for as long as it is useful for supporting you, and we delete it when it is not.
9. Keeping your information secure
The strongest protection we can offer is to hold very little. The application sends us nothing, so almost everything you do in FireFlow Studio for FDS never reaches us at all. What we do hold is your name, your email address, your licence record and our correspondence with you.
That information sits in our email account and in the accounts we hold with Stripe, Brevo, Netlify and GitHub. We protect those accounts with strong, unique passwords and, where the provider offers it, multi-factor authentication, and access is limited to the people who run the business. Those providers apply their own security measures, which you can read about in their privacy terms.
No system is completely secure and we will not pretend otherwise. If personal information we hold is lost or disclosed without authorisation and it is likely to cause you serious harm, we will tell you as soon as we reasonably can, and we will notify the Office of the Australian Information Commissioner where the Notifiable Data Breaches scheme requires it.
10. Your rights
You can ask us to:
- tell you what personal information we hold about you and give you access to it;
- correct anything that is wrong, out of date or incomplete;
- remove you from our email list, or delete your details where we are not required to keep them.
Email info@fireflowstudio.com.au and we will respond as quickly as we reasonably can, and in any case within 30 days. There is no charge for making a request. We may need to confirm your identity first, usually by replying from the email address we hold for you. In the limited situations where the Australian Privacy Principles allow us to refuse a request, we will tell you why.
Complaints
If you think we have mishandled your personal information, please tell us first at info@fireflowstudio.com.au. We will look into it and let you know the outcome. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Customers in the EU and the UK
If you are in the European Union or the United Kingdom, you may exercise equivalent rights over your personal information, including access, correction, erasure, restriction, objection and data portability, and you may withdraw consent to marketing emails at any time. Use the same address, info@fireflowstudio.com.au, and we will deal with your request. You may also lodge a complaint with your local supervisory authority.
11. Changes to this statement
If we change how we handle personal information, we will update this statement and change the effective date at the top. If a change is significant, and we hold an email address for you, we will tell you by email. The current version is always published at fireflowstudio.com.au. This statement covers our own site, software and emails, not any third party website you reach from a link.
FireFlow Studio for FDS