Legal

Privacy policy

What Fisshat LLC collects, why, where it is kept, and what you can ask us to do with it.

Last updated: 13 August 2026
Applies to: fisshat.com and all products operated by Fisshat LLC, including the Squirrel mobile app and browser extension.

1. Who we are

Fisshat LLC is a Limited Liability Company registered in California, United States, with a business mailing address at 28 Geary St., Ste. 650, San Francisco, CA 94108. Fisshat is the data controller for the information described here. Privacy questions and requests go to info@fisshat.com.

2. What we collect

Account information

When you create an account we store your email address, the display name you provide, and a securely hashed password. If you sign in with Google we receive your email address, name, and profile identifier from Google instead — we never see your Google password.

Product data you enter

Squirrel stores what you put into it: daily journal entries and their evaluations, savings goals and their targets, logged spending and saving amounts with their categories and any memo you attach, and the figures entered into the discretionary income calculator. This is the substance of the product and is stored against your account.

Settings and lists

Your product settings are stored so they can follow you between devices: which extension modes are enabled, whether the dismiss button is available, notification preferences and reminder times, and the domains on your blocklist and allowlist.

Browser extension activity

The extension checks the address of pages you visit against your own blocklist and allowlist. That check happens on your device. When the extension actually shows you an appeal, it records an event containing the domain name of the site, the cart total it detected on the page if there was one, which step of the appeal you reached, and what you chose. This is what makes your own history of interventions visible to you in the app.

We do not record full page addresses, page contents, form fields, or the sites you visit where no appeal is shown. We do not build an advertising or browsing profile from any of it.

Support correspondence

If you write to us we keep the message, your address, and our reply, so that a later conversation has the earlier context.

Technical information

Our systems log ordinary technical data when software connects to them — IP address, timestamp, and the type of request — for security and diagnosis. This website does not use advertising or analytics cookies and does not track visitors between sites.

3. What we never collect

Squirrel has no bank connection. It does not link to your accounts, does not read transactions, and never asks for online banking credentials — every amount in the product is one you typed yourself. We also do not handle your card details: subscription payments are processed by the app store you purchased through, and only the resulting subscription status reaches us.

4. How we use it

  • To operate the products, keep you signed in, and sync your data between devices.
  • To show you your own history, totals, and progress toward goals.
  • To send transactional messages such as verification and password reset emails.
  • To send optional reminders and nudges, which you control and can switch off.
  • To answer your support requests.
  • To diagnose faults, prevent abuse, and keep the service secure.
  • To meet legal, tax, and accounting obligations.

We do not sell personal information, we do not share it with advertisers, and we do not use your product data to train machine learning models.

5. Legal grounds

Where the UK or EU General Data Protection Regulation applies, we rely on performance of our contract with you for anything necessary to run the products; your consent for optional notifications, withdrawable at any time; our legitimate interests in securing the service and answering correspondence; and legal obligation for records we are required to keep.

6. Where it is stored, and how it is protected

Product data is held in a PostgreSQL database operated on our behalf by Supabase. Every table enforces row-level security, which means access rules are applied by the database itself against the identity of the signed-in account rather than only by application code. An account can read and write its own rows and no others.

Traffic between your device and our systems is encrypted in transit using TLS. Passwords are stored only as salted hashes and are never readable by us. Access to production systems is limited to those who need it to operate the service.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data we will notify you and the relevant regulator as the law requires.

7. Who else is involved

We use a small number of service providers, each handling data only to provide their service to us:

  • Supabase — database, authentication, and hosting of product data.
  • Google — sign-in, where you choose to use it.
  • Apple and Google app stores — distribution and subscription billing.
  • Our email provider — delivery of transactional and support mail.

We may also disclose information where we are legally required to, or to establish or defend legal claims. If Fisshat is ever sold or restructured, personal data may transfer with the business, and you would be told before that changed anything about this policy.

8. International transfers

Our providers may process data in the United States and other countries. Where data leaves the UK or European Economic Area, transfers are made under an approved safeguard such as the UK International Data Transfer Agreement or the European Commission's standard contractual clauses.

9. How long we keep it

Account and product data is kept for as long as your account exists. When you delete your account, the data attached to it is deleted, other than records we must retain for legal, tax, or fraud-prevention reasons, which are kept only for as long as required. Support correspondence is kept for up to two years. Technical logs are kept for a short period and then discarded.

10. Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to how we use it, receive it in a portable format, or withdraw consent you previously gave. Californian residents additionally have the right to know what is collected and to opt out of any sale of personal information — we do not sell it, so there is nothing to opt out of.

To exercise any of these, write to info@fisshat.com from the email address on your account. We will respond within 30 days and usually much sooner. Exercising these rights costs nothing and we will not treat you differently for it.

If you are in the UK or EU and think we have handled your data badly, you may complain to your national data protection authority. We would rather you told us first so we can put it right.

11. Children

Our products are not directed at children and are not intended for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has given us their information, write to info@fisshat.com and it will be deleted.

12. Changes to this policy

This policy may change as the products change. The date at the top records the last revision. Where a change materially affects your rights we will give notice in the product or by email before it takes effect, rather than relying on you to notice.

13. Contact

Fisshat LLC
28 Geary St., Ste. 650
San Francisco, CA 94108
United States

Email: info@fisshat.com
Telephone: +1 808-319-3090