Privacy Policy
Last updated: July 18, 2026
This Privacy Policy describes how Morison LLC ("we") handles information in the desktop application "Firescope" (the "App"). Firescope is a client tool that lets you browse and edit Firestore databases in your own Google Cloud / Firebase projects.
1. Core principle — your data stays on your device
Firescope does not collect or store your credentials or your Firestore data on our servers. The App connects directly from your device to Google / Firebase services. We never read, retain, or share your Firestore data.
2. Information accessed when you sign in with Google
When you use "Sign in with Google," the App requests the following OAuth 2.0 scopes. The resulting authorization (refresh token) is stored encrypted only on your device, using the operating system's secure storage (macOS Keychain / Windows DPAPI), and is never sent to our servers.
openid/.../auth/userinfo.email— to identify and display which Google account you are connected with..../auth/datastore— to read and edit documents in the Firestore database you choose (the App's core function)..../auth/firebase.readonly— to list the Firebase projects you have access to so you can pick which one to connect to..../auth/identitytoolkit— to view and manage Firebase Authentication users in the project you choose.
Access granted through these scopes is used solely to operate your own Firestore / Firebase projects at your direction. We do not use this data for any purpose other than providing the App's features, and we never sell it or share it with third parties.
3. Limited Use of Google user data
Firescope's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, we do not allow humans to read it (except as you direct, or where required for security or by law), and we do not transfer it to others except to provide user-facing features of the App.
4. Credential storage (service accounts and gcloud included)
In addition to Google Sign-In, the App supports connecting with a service account private key (JSON) or gcloud Application Default Credentials. All credentials are encrypted with the operating system's secure storage and kept only on your device; they are never sent to us or to any third party.
5. Information the App sends externally
The App makes the following network requests to provide its features:
- License validation: to verify a paid license, the license key is sent to our backend (Supabase).
- Feedback: if you choose to send feedback, the message, an optional contact email you enter, and a masked license key are sent to our backend.
- Update check: to check for a newer version, the App fetches public files from the distribution repository (GitHub). No personally identifying information is sent.
- Field label translation (optional): only if you use the field-label auto-translation feature, the relevant field names are sent to a free translation API (MyMemory). Document values are not sent.
- Shared log (optional, opt-in per connection): only if you enable this feature, metadata about write operations (who, when, and what action) is sent so your team can share it. Document values are not recorded.
- Anonymous usage statistics: to improve the product, two events — the start of a trial and an upgrade to a paid plan — are recorded to our backend (Supabase) together with a randomly generated anonymous ID. This ID is derived from random numbers and contains no information that could identify you or your device — no name, email address, device details, or Firestore data — and is never linked to any of them. If you purchase a paid plan, this anonymous ID is included in the subscription metadata at our payment processor (Stripe) so that the purchase can be matched to the anonymous ID.
6. Measurement on this website (fire-scope.com)
To understand visit and download counts, this website uses a first-party cookie (name: fs_aid, lifetime: up to 400 days) that stores a randomly generated anonymous ID. The cookie contains no personally identifying information. We may also record UTM parameters from the URL (such as utm_source) to understand where visitors come from. This website also uses Google Analytics. You can delete cookies at any time in your browser settings.
7. What we do not do
- Collect or store your Firestore data on our servers.
- Use your data for advertising or user profiling.
- Sell or rent credentials or data to third parties.
8. Your control and deletion
You can remove connection and credential data stored on your device at any time by deleting the connection in the App. You can also revoke Firescope's access at any time from your Google Account's third-party access settings.
9. Contact
For questions about this policy, please contact:
Morison LLC
Email: upform2004@yahoo.co.jp
10. Changes to this policy
We may revise this policy as needed. If we make material changes, we will note them on this page.