FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Hosting
  4. Firebase

Firebase

OtherWebsite

Related services

A

actionhero.js

actionhero.js is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. actionhero.js integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, actionhero.js helps organizations maintain robust websites that meet user expectations and technical requirements.

Other

Adminer

Adminer is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Adminer supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Adminer ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Akka HTTP

Akka HTTP is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Akka HTTP integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Akka HTTP helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
A

Alibaba Cloud Object Storage Service

Alibaba Cloud Object Storage Service is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Object Storage Service provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Object Storage Service ensures optimal.

Other

AlmaLinux

AlmaLinux is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AlmaLinux supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AlmaLinux ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

AlternC

AlternC is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AlternC supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AlternC ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Firebase do?

Firebase is a Google Cloud platform of mobile and web backend services widely used in Europe for authentication, real-time databases, push notifications, hosting and analytics. Most Firebase products run on Google infrastructure with default multi-region storage; Cloud Firestore, Cloud Storage and Cloud Functions can be pinned to EU regions while Firebase Analytics and Cloud Messaging currently process data globally with US storage.

What is Firebase?

Firebase is a Google Cloud platform that bundles mobile and web backend services into a single SDK. Common products include Firebase Authentication, Cloud Firestore, Realtime Database, Firebase Cloud Messaging, Firebase Analytics, Crashlytics, Firebase Hosting and Cloud Functions. It is widely used in Europe for both mobile apps and web applications because it removes the need to operate authentication, database and analytics infrastructure independently.

Cookies and data collected

Firebase Authentication stores user credentials, refresh tokens and session identifiers. Cloud Firestore and Realtime Database store the application data the developer chooses to write. Firebase Cloud Messaging stores device tokens for push notifications. Firebase Analytics collects events, screen views, device information, IP addresses and a persistent app instance identifier (the Firebase Installation ID). Crashlytics collects stack traces, device state and user identifiers if attached.

GDPR and ePrivacy implications

Authentication, Cloud Firestore and Realtime Database used to deliver the app rely on contract performance (Art. 6(1)(b) GDPR). Firebase Analytics and Crashlytics rely on consent (Art. 6(1)(a) GDPR) and on Art. 5(3) ePrivacy because they read and write identifiers on the device. Firebase Cloud Messaging marketing campaigns require consent. Use Firebase Consent Mode (Google Consent Mode v2) to enforce consent signals on Analytics.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and hosting

Cloud Firestore, Cloud Storage and Cloud Functions can be configured to store data in EU regions (europe-west1, europe-west3, eur3, etc.). Firebase Authentication, Firebase Analytics and Cloud Messaging currently process data globally with US storage. Transfers rely on Google''s certification under the EU US Data Privacy Framework and on Standard Contractual Clauses included in the Google Cloud Data Processing Addendum.

Practical compliance steps

Sign the Google Cloud Data Processing Addendum from your Firebase console. Pin Cloud Firestore and Cloud Storage to an EU region. Enable Firebase Consent Mode and gate Firebase Analytics and Crashlytics behind your consent management platform. For mobile apps, request iOS App Tracking Transparency before enabling Analytics and follow the Android Privacy Sandbox guidance. Document the Firebase services in use, the regions, and the EU US Data Privacy Framework basis in your privacy notice.

GDPR consent category

Other

Websites using Firebase must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) for Firebase Analytics, Crashlytics, Cloud Messaging marketing campaigns and any tracking-style identifiers. Contract performance (Art. 6(1)(b)) for Authentication and database operations strictly necessary to deliver the requested service. Strictly necessary cookies and identifiers rely on Art. 5(3) ePrivacy.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, EU US Data Privacy Framework, CCPA, German TDDDG

DPIA considerations

A DPIA is recommended for Firebase deployments that combine Authentication, Analytics and Crashlytics with significant user volumes, given the global Google Cloud processing and the persistent identifiers used for analytics and marketing.

Sample consent text

This application uses Firebase (Google LLC) for authentication, data storage and analytics. Firebase Analytics and Crashlytics are activated only after your consent. Personal data may be transferred to Google infrastructure outside the EEA under the EU US Data Privacy Framework or Standard Contractual Clauses.

Technical details

Tracking methodmobile and web SDK and backend services from Google Cloud (Firebase Authentication, Cloud Firestore, Realtime Database, Firebase Cloud Messaging, Firebase Analytics, Firebase Hosting, Firebase Crashlytics)
Server locationglobal Google Cloud infrastructure (default multi-region; explicit EU regions available for Cloud Firestore, Cloud Functions and Cloud Storage)
Data transferred outside the EUFirebase is operated by Google LLC, a US company. Most Firebase services run on Google Cloud infrastructure. Some products such as Cloud Firestore, Cloud Storage and Cloud Functions allow selecting EU regions; others (Authentication, Cloud Messaging, Analytics) currently process data globally with US storage. Transfers rely on the Google EU US Data Privacy Framework certification and Standard Contractual Clauses.

Third-party domains contacted

firebase.googleapis.comfirebaseio.comfirebaseinstallations.googleapis.comfcmregistrations.googleapis.comfirebaselogging-pa.googleapis.com

Cookies placed

NameTypeDurationPurpose
firebase_id_tokenfirst_party1 hourShort-lived ID token issued by Firebase Authentication after a successful login.
firebase_refresh_tokenfirst_partyVariable (long-lived)Refresh token stored locally so the app can request new ID tokens without forcing re-authentication.
FIREBASE_INSTALLATION_IDfirst_partyPersistentPersistent app instance identifier used by Firebase Analytics, Crashlytics and Cloud Messaging to attribute events.
FCM_TOKENfirst_partyPersistentDevice token used by Firebase Cloud Messaging to deliver push notifications.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What identifiers does Firebase set?

Firebase Authentication issues an ID token (1 hour) and a long-lived refresh token. Firebase Installations creates a persistent app instance identifier used by Analytics, Crashlytics and Cloud Messaging. Firebase Cloud Messaging stores a device token. Firebase Analytics and Crashlytics also write event payloads with device and IP information when active.

Do I need consent to use Firebase on my website or app?

Firebase Authentication and the database services that simply deliver the requested feature do not require a separate cookie banner. Firebase Analytics, Crashlytics and Cloud Messaging marketing campaigns require freely given consent under Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy. Use Firebase Consent Mode to gate data collection.

What is the legal basis for processing personal data through Firebase?

Authentication, Cloud Firestore and Realtime Database used to deliver the app rely on contract performance (Art. 6(1)(b)). Firebase Analytics, Crashlytics and Cloud Messaging marketing rely on consent (Art. 6(1)(a)). Tax retention may rely on legal obligation (Art. 6(1)(c)). Strictly necessary identifiers rely on Art. 5(3) ePrivacy.

Does Firebase transfer data to third countries?

Yes for several Firebase products. Cloud Firestore, Cloud Storage and Cloud Functions can be pinned to EU regions. Firebase Authentication, Firebase Analytics and Cloud Messaging currently process data globally with US storage. Transfers rely on the Google EU US Data Privacy Framework certification and on Standard Contractual Clauses included in the Google Cloud Data Processing Addendum.

Do I need a DPIA for Firebase?

A DPIA is recommended for Firebase deployments that combine Authentication, Analytics and Crashlytics with significant user volumes, given the global Google Cloud processing and the persistent identifiers used. A DPIA is normally not required for a small Authentication only or hosting only project.

How do I implement Firebase compliantly?

Sign the Google Cloud Data Processing Addendum from the Firebase console. Pin Cloud Firestore and Cloud Storage to an EU region. Enable Firebase Consent Mode and gate Firebase Analytics and Crashlytics behind your CMP. For mobile apps, request iOS App Tracking Transparency before enabling Analytics. Document Firebase services, regions and the DPF basis in your privacy notice.

Are there privacy-friendly alternatives to Firebase?

EU-based alternatives include Supabase (managed in EU regions on AWS), Appwrite (open source, self hosted or EU cloud), Hasura with EU hosting, and Nhost (EU hosting). For analytics specifically, prefer Plausible, Matomo, Pirsch or Posthog with EU hosting. Selection depends on whether you need full backend services or only specific Firebase products.

How should I update my privacy policy for Firebase?

List the Firebase services in use (Authentication, Cloud Firestore, Storage, Functions, Cloud Messaging, Analytics, Crashlytics) with their purpose, the regions configured and the persistent identifiers issued. State that data may be transferred to Google infrastructure outside the EEA under the EU US Data Privacy Framework or Standard Contractual Clauses, and reference the Google Cloud Data Processing Addendum.