Your data, your Mac

Privacy Policy

MyFIREDesk is designed to give you a useful financial overview while minimizing data collection and keeping sensitive information under your control.

Effective August 26, 2026Controller: Sandro Dzneladze · Georgia
01

Overview

MyFIREDesk is a native macOS portfolio dashboard and retirement planner. The app is read-only: it displays and analyzes financial information but does not place trades, transfer money, or take custody of assets.

For the MyFIREDesk website and support communications, Sandro Dzneladze, based in Georgia (country), is the data controller and can be contacted at sandro@myfiredesk.com. Most information used by the app remains on your Mac or travels directly from your Mac to a service you choose; it does not pass through a MyFIREDesk portfolio-data server.

The short version

Your broker secrets stay in macOS Keychain. Planning data stays in local app preferences. MyFIREDesk never asks for a crypto recovery phrase or private key.

02

Data the app uses

Depending on the accounts and features you choose to configure, MyFIREDesk may process:

  • Broker connection details, such as an Interactive Brokers Flex token and query ID, or read-only eToro API keys.
  • Portfolio information, including holdings, cash balances, values, currencies, cost basis, and unrealized profit or loss returned by connected services.
  • Public wallet information, such as public Ethereum, BNB Smart Chain, Bitcoin, or Solana addresses and, if you add one, a Bitcoin extended public key.
  • Locally entered financial data, including cash and deposit balances, asset-class overrides, allocation targets, FIRE scenarios, assumptions, future cash flows, and stress-test scenarios.
  • App preferences, including your reporting currency and display settings.
  • Optional local AI data, consisting of a sanitized portfolio and FIRE-planning export when you explicitly enable Local AI (MCP) access.
  • Purchase and entitlement information supplied by Apple StoreKit, such as the Full Access product identifier, purchase status, verification result, and any revocation status needed to unlock paid features.

Never enter a recovery phrase or crypto private key. MyFIREDesk does not need either one.

03

How data is stored

  • Broker credentials and tokens are stored in macOS Keychain.
  • The latest display-ready portfolio snapshot and a bounded history of portfolio totals are stored locally in the app’s shared container so the MyFIREDesk widget can display them.
  • FIRE scenarios, simulation assumptions, stress-test scenarios, allocation targets, and related preferences are stored locally on your Mac.
  • Public wallet addresses and local cash or deposit entries are stored locally so the app can refresh and display them.
  • If you enable Local AI access, a reduced export and a one-way digest of its pairing token are stored in a dedicated protected App Group. If you separately allow portfolio refresh, that container also holds short-lived authenticated action requests and sanitized status replies while the app processes them. Broker credentials, account names, wallet addresses, and provider identifiers are excluded.
  • The app caches only the current Full Access entitlement state for use by the app and widget. StoreKit obtains and verifies the underlying transaction information from Apple; MyFIREDesk does not send purchase receipts to a developer-operated server.

MyFIREDesk does not operate a cloud account system for your app data. Data sent to a third-party financial or market-data service is limited to what is needed to perform the connection or refresh you requested.

04

Third-party services

When you refresh data, the app communicates directly with services needed for the accounts you configured. These may include Interactive Brokers, eToro, Blockscout, BNB Smart Chain RPC providers, Blockstream, Solana RPC providers, Kraken, DEX Screener, and Frankfurter. Frankfurter supplies European Central Bank reference rates for supported currency pairs and National Bank of Georgia reference rates when GEL is involved.

Those services receive the technical data necessary to answer a request—for example, a public wallet address, instrument identifier, token contract address, currency pair, your read-only broker credentials, and normal network information such as IP address and request time. Their handling and retention of data is governed by their own terms and privacy policies.

A Bitcoin extended public key is processed locally. MyFIREDesk derives public addresses on your Mac and queries balances for those derived addresses; the extended public key itself does not need to leave your Mac.

Full Access purchases and restorations use Apple StoreKit. Apple processes the App Store account and payment and provides the app with signed product and transaction status needed to verify your entitlement. Apple's handling of this information is described in App Store & Privacy.

See the Data Sources disclosure for the exact services, request data, and official policy links used by the current version.

05

Website privacy

The public MyFIREDesk website is informational. This version of the site does not include user accounts, advertising trackers, analytics cookies, or forms that collect personal information.

The site is delivered by AWS Amplify Hosting. AWS processes access-log information such as IP address, requested page, timestamp, response details, and normal browser or request metadata for delivery, reliability, security, and abuse prevention. AWS documents that Amplify access logs remain available for the life of the hosted application. See the AWS Privacy Notice.

If you email support, the email provider and Sandro Dzneladze process your email address, message, attachments, and normal message metadata to respond and resolve your request. Do not send broker credentials, recovery phrases, private keys, or other secrets.

06

Purposes and legal bases

Where Georgian or other applicable data-protection law applies, information is processed only for the purposes and legal bases below:

  • To provide app features, connections you request, and Full Access purchases or restorations: performance of a contract or steps taken at your request.
  • To deliver and secure the website, prevent abuse, diagnose failures, and protect the service: legitimate interests in operating a reliable and secure service.
  • To answer support requests: steps taken at your request and legitimate interests in customer support and product improvement.
  • To keep records or disclose information when required: compliance with legal obligations and establishment, exercise, or defense of legal claims.

MyFIREDesk does not use personal information for advertising, cross-app tracking, or automated decisions that produce legal or similarly significant effects.

07

Retention

  • Local app data remains on your Mac until you remove the relevant source or plan, clear the available app data, or remove the app and its associated data.
  • Local AI action files and status replies are short-lived and are cleaned up by the app; disabling Local AI removes its shared export and pairing material.
  • Support correspondence is kept only while reasonably needed to resolve the request, maintain necessary support records, protect legal rights, or meet legal obligations, and is then deleted or anonymized.
  • AWS Amplify retains website access logs for the life of the hosted application under its current service behavior.
  • Apple and each financial, blockchain, market-data, hosting, or email provider apply their own retention rules to information they receive directly.
08

International processing

Apple, AWS, the email provider, and the financial, blockchain, market-data, or AI services you choose may process information in countries outside Georgia. A direct app connection sends only the information needed for the refresh or feature you requested. Processing locations and safeguards depend on the provider and are described in the provider notices linked from this policy and the Data Sources disclosure. Contact sandro@myfiredesk.com for available information about safeguards applicable to website or support processing.

09

Your choices and control

You decide which accounts, wallets, and local entries to add. You can remove configured sources and locally stored scenarios from within the app. You can also delete the app and its associated local data using macOS.

Because MyFIREDesk does not maintain a cloud profile for your app data, there is generally no remote MyFIREDesk account record to access, export, or delete.

Local AI access is off by default. You can disable it at any time to delete its shared export and revoke copied configurations. Portfolio refresh through MCP requires a second opt-in permission and works only while MyFIREDesk is running; provider requests and credentials remain handled by the main app. The MCP connection itself uses local process communication, but the AI application you connect may send returned data to its own model provider; that application's privacy policy and data controls apply.

10

Your privacy rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability for personal information controlled by Sandro Dzneladze, and to withdraw consent where consent is the legal basis. You may also complain to your local data-protection authority.

Send a request to sandro@myfiredesk.com. Identity may need to be verified before completing a request. Georgia residents may also seek relief through the State Audit Office of Georgia or a court as provided by applicable law. Because MyFIREDesk cannot access information stored only on your Mac, local app data must be managed using the app or macOS. Requests concerning data held by Apple or another provider should also be directed to that provider.

11

Security

MyFIREDesk reduces risk through read-only connections, local storage, macOS Keychain protection for credentials, and by never requesting private keys or recovery phrases. No method of storage or transmission is completely secure, so keep your Mac, macOS account, and connected-service credentials protected.

An extended public key cannot spend funds, but it can reveal the activity and balances of derived addresses. Treat it as privacy-sensitive.

The optional MCP helper is sandboxed, has no network entitlement, does not listen on a localhost or network port, and can access only its dedicated reduced-data container. A paired AI client, malware running as you, or a compromised Mac may still access information available to that client.

12

Children’s privacy

MyFIREDesk is a personal-finance product intended for adults. It is not directed to children, and the website does not knowingly collect personal information from children.

13

Changes to this policy

This policy may be updated as MyFIREDesk evolves. Material updates will be reflected on this page, along with a revised effective date.

14

Contact

The controller is Sandro Dzneladze, Georgia (country). Questions, requests, or concerns about this privacy policy can be sent to sandro@myfiredesk.com.