Legal

Privacy Policy

Last updated: 31 July 2026 · Effective immediately for all users of ForgeFlow AI.

The short version. We collect the minimum we need to run ForgeFlow AI: your account details, the projects you build, and usage metrics used for billing and abuse prevention. We never sell your data, never use your private project code to train our own models, and you can export or delete everything at any time from Settings.

1.Who we are

ForgeFlow ("ForgeFlow", "we", "us"), the seller and operator of the ForgeFlow AI service, is the data controller for the personal data described in this policy. We provide an AI-assisted platform for describing, generating, previewing and publishing web applications. This policy explains how we handle personal data when you use our website, the in-app builder, and any published site you deploy through us.

Privacy questions, corrections and data requests are handled from inside the product: sign in and use Account settings, where you can export, correct or delete the data held against your account.

2.Data we collect

Account data. Email address, display name, optional avatar image, authentication provider (email/password or Google), and password hashes managed by our authentication provider. We never see or store your plaintext password.

Content you create. Project names and descriptions, prompts and chat messages you send to the AI, generated source files, version snapshots, database schema changes you request, and any files you attach to a message — including images, documents and archives, from which we extract text so the AI can read them.

Workspace and billing data. Workspace membership and roles, invitations you send or receive, plan tier, credit grants, credit spend records, top-up purchases, and invoices.

Technical and security data. IP-derived country, coarse access logs, a randomly generated device identifier used for anti-abuse rate limits, CAPTCHA outcomes, error reports, and records of policy violations or takedowns.

Network reputation checks. When you open a project we check the network address you are connecting from against third-party IP-reputation services to determine whether it is a VPN, anonymising proxy, hosting provider or similar relay, because access through those networks is not permitted (see the Terms). We store the outcome of that check and the coarse network metadata it returns, not a browsing history.

Metering integrity signals. To stop credit metering from being bypassed, each build request carries a short-lived single-use token, and we record signals about whether the app's own network and messaging functions have been modified in your browser, along with request timing and counts. These signals are used only to protect billing accuracy and are not used to profile you.

Invite programme data. If you use the invite programme, we store your invite code, the accounts that signed up through it, whether each of them subscribed, and the credits awarded, so we can pay rewards and enforce the fair-use caps described in the Terms.

Analytics for your published sites. If you publish a project, we record page path, referrer, coarse country, and a rotating one-way hash of visitor identifiers so you can see traffic. We do not store raw visitor IP addresses and we do not set advertising cookies on your published sites.

3.Why we use it (legal bases)

To provide the service (contract). Authenticating you, storing your projects, running AI generations, building previews, and publishing deployments.

To bill accurately (contract). Metering credit usage per prompt, per workspace, and per member, and issuing receipts.

To keep the platform safe (legitimate interest). Detecting automated abuse, enforcing device and cooldown limits, scanning published projects for illegal content, and preventing credit farming through repeated transfers or duplicate accounts.

To keep the service reliable (legitimate interest). Diagnosing errors and improving the product.

To comply with law (legal obligation). Retaining transaction records and responding to lawful requests.

We do not use your data for behavioural advertising, and we do not build advertising profiles.

4.AI processing

When you send a prompt, the prompt, relevant project files, and conversation context are transmitted to third-party model providers so a response can be generated. Those providers process the data solely to return a completion for your request.

We do not use your private project content to train ForgeFlow models, and we contract with providers on terms that exclude your content from their general model training. AI output can be inaccurate or insecure — review generated code before running it in production.

Prompts and generations may be retained briefly in operational logs for debugging, cost accounting, and abuse investigation.

5.Emails we send

We send account emails only: email confirmation, password reset, workspace invitations, purchase receipts, and critical service or security notices. These are required to operate your account and cannot be turned off while the account is active. We do not send marketing newsletters.

6.Who we share data with

We share personal data only with processors that help us run the service:

  • Cloud hosting and managed database/authentication providers (project storage, sessions, file storage).
  • AI model providers (prompt and context processing, as described above).
  • Email delivery infrastructure (confirmation, reset, invite and receipt emails).
  • Deployment and CDN providers used to publish your projects.
  • Paddle.com, our Merchant of Record, when paid plans and top-ups are purchased — Paddle handles payment processing, subscription management, invoicing, tax compliance and refunds. Card details are handled by Paddle; we never receive full card numbers.
  • Source-control providers, only when you explicitly connect a repository.
  • IP-reputation providers used to detect VPNs, proxies and relays, which receive only the network address being checked.

We also disclose data where legally required, or where necessary to investigate fraud, abuse, or threats to safety. We never sell personal data and never share it with data brokers.

Child safety reporting. Where our safety systems detect an attempt to generate or host sexual content involving minors, we preserve the prompt, generated or uploaded content, account identifiers, timestamps, network address and device identifiers, and refer them to law-enforcement authorities and child-safety reporting bodies. This referral happens without notice to the account holder and is not subject to deletion requests.

7.Security

All records are protected with row-level security scoped to your account and workspace, so one user's data is not readable by another. Credit balances, plan changes and role grants can only be modified by privileged server code, never directly from the browser. Traffic is encrypted in transit. Passwords are checked against known-breach databases at signup and on change.

No system is perfectly secure. If you believe you've found a vulnerability, please report it responsibly and give us a reasonable window to fix it before disclosing it publicly.

8.Retention

Account and project data is retained while your account is active. When you delete a project, its files, versions and conversations are deleted along with it. When you delete your account, personal data is removed, except records we must keep for a limited period: billing and invoice records, and abuse/enforcement records such as device blocks, transfer flags and takedown decisions, which are retained to stop the same abuse recurring.

Records relating to child-safety enforcement, and the account, device and network identifiers tied to a permanent termination, are retained indefinitely so the same person cannot return to the platform, and to satisfy our legal reporting obligations.

Site-visit analytics for published projects are retained on a rolling window and are stored in an aggregated, pseudonymised form.

9.Your rights

Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal data, to object to processing based on legitimate interests, and to lodge a complaint with your local data protection authority.

You can exercise most of these directly: account details in Settings, project export via source control, and account deletion in Settings. For anything else, email us and we will respond within 30 days.

10.Cookies and local storage

We use strictly necessary storage only: a session token so you stay signed in, a theme preference, and a random device identifier used for anti-abuse limits. We do not use third-party advertising or cross-site tracking cookies.

11.Children

ForgeFlow AI is not directed at children under 13 (or the minimum digital-consent age in your country). If we learn that we hold data from a child below that age, we delete it.

12.International transfers

Our providers may process data in countries other than yours, including the United States and the European Union. Where required, transfers rely on standard contractual clauses or an equivalent safeguard.

13.Changes to this policy

We may update this policy as the product evolves. Material changes will be announced in the in-app "What's new" panel and reflected in the "Last updated" date above. Continuing to use ForgeFlow AI after a change means you accept the updated policy.