Cookie and privacy information
This page describes the current FIREBAL service. FIREBAL uses one essential authentication cookie and does not currently use analytics, advertising, or marketing cookies.
Essential session cookie
| Name | session_id |
|---|---|
| Purpose | Authenticates your browser, keeps jobs and object-storage actions associated with your account, and prevents unauthenticated GPU use. |
| Lifetime | 24 hours. Signing out revokes the server-side session and removes the browser cookie. |
| Protection | HTTP-only, so page JavaScript cannot read it; Secure on deployed HTTPS sites; and SameSite=Lax. |
| Required? | Yes. Account-only application and API routes cannot work without it. |
Choosing “Got it” on the information banner stores firebal_cookie_notice_v1 in your browser’s local storage. The app also stores firebal_tutorial_v1 after you finish or skip its first-run tutorial. These values contain only interface acknowledgements, are not cookies, are not sent to FIREBAL, and remain until you clear site data.
Information FIREBAL handles
Accounts and security
FIREBAL stores your username, unique email address, password hash, verification status, account role/tier, sessions, and verification tokens. Passwords are not stored in readable form. IP addresses and account identifiers are used for authentication throttles, quotas, and misuse prevention.
Processing jobs
When you submit a job, FIREBAL handles the uploaded image and optional PSF, output image, filenames, processing settings, job and object keys, image/result dimensions, status, timing information, and errors. Pixel data is transferred through OCI Object Storage and processed by the RunPod GPU worker. Objects are scoped to the account that created them.
Operational logs and feedback
Internal logs contain usernames, filenames, IP addresses, job identifiers, normalized processing parameters, system timings, GPU/tiling information, result metadata, and structured errors. They exclude passwords, session cookies, credentials, presigned URLs, and image/PSF pixel data. Optional job feedback is linked to your account and job; comment text stays in the private feedback database rather than the activity logs.
Why the information is used
- to create and verify accounts and keep sessions secure;
- to process, return, and authorize access to deconvolution jobs;
- to enforce free-tier limits and prevent misuse;
- to diagnose failures, monitor reliability, and improve processing defaults;
- to understand and respond to optional job feedback.
Service providers and storage
The web proxy and account database run on Oracle Cloud Infrastructure. OCI Object Storage holds uploaded and processed objects. RunPod provides GPU processing. The configured email provider receives the address and message needed to deliver verification email. These providers necessarily receive the technical data required to perform those functions.
Retention
- Browser and server sessions expire after 24 hours.
- Operational logs use 12 compressed rotations, normally around 12 weeks and potentially shorter when size-based rotation occurs.
- The operator maintenance policy targets 365 days for feedback and 30 days for throttle/quota history.
- User, job, and object-ownership records are retained to support accounts and download authorization.
- OCI uploads and results are currently retained; an automatic object lifecycle deletion policy has not yet been enabled.
Database backups and private exports may require separate operator cleanup. Retention maintenance is an operational process rather than a browser function.
Your choices
You can sign out to revoke the current session and clear this site’s local data in your browser. You can ask the FIREBAL project team through the channel you use to access the service about account information, correction, or deletion. Some operational records may need to be retained for security and service integrity.
Future non-essential cookies
If analytics or marketing cookies are introduced, FIREBAL will request opt-in consent before setting or loading them and will update this page. Acknowledging the current essential-cookie information does not grant consent for future non-essential cookies.
Last updated: 5 August 2026