Legal

Terms of Service

Last updated: 31 July 2026

The short version. ForgeFlow is the seller; Paddle.com is our Merchant of Record and handles orders, invoicing and refunds. You own the code you generate, and purchases are covered by a 30-day money-back guarantee. Don't build illegal or abusive things, don't try to farm free credits, and don't strip the ForgeFlow badge without a Pro plan. AI output needs human review before production.

1.Agreement

These Terms form a binding agreement between you and ForgeFlow, the seller and operator of the ForgeFlow AI service ("ForgeFlow", "we", "us"). By creating an account, using the builder, or publishing a project, you accept them. If you use ForgeFlow on behalf of a company, you confirm you are authorised to bind that company.

If you do not agree, do not use the service.

2.Eligibility and accounts

You must be at least 13 years old (or the minimum digital-consent age where you live) and legally able to enter contracts. You are responsible for everything done under your account and for keeping your credentials secure.

Accounts created with an email address must confirm that address before signing in. To limit automated abuse, we restrict the number of accounts that may be created or signed into from the same device per day, and we may require a verification challenge. Circumventing these limits — including by using additional devices, browsers, or disposable addresses — is a breach of these Terms.

One person may not operate multiple accounts to obtain additional free credits.

No VPNs, proxies or relays. Projects may not be opened through a VPN, anonymising proxy, Tor, hosting/datacentre relay or similar network. We check the connecting network address against IP-reputation services and block access when one is detected. Turn the network off to continue; attempting to disguise it is a breach of these Terms.

No tampering with metering. Build requests are authorised by a short-lived, single-use, server-signed token, and must come from the ForgeFlow app itself. Using a browser extension, patched script, proxy, script, relay or third-party client to obtain builds without the correct credit charge is a breach of these Terms, and the resulting work may be reversed and the account suspended.

3.Credits, plans and billing

Credit model. Almost everything on ForgeFlow draws from a single credit balance held by a workspace. A prompt typically costs between 0.5 and 1.7 credits depending on complexity. Plan Mode costs a flat 1 credit per planning turn. Attaching an image adds 1 credit. A build you cancel mid-run is charged 1 credit, because the work has already been performed.

Free allowance. Free workspaces receive a small daily credit allowance. The allowance is per workspace, is not cumulative, and cannot be claimed multiple times per day. Attempting to multiply it — for example by moving a project between workspaces repeatedly, or by cycling workspace ownership — will flag that project and pause transfers on it for 7 days.

Paid plans. Pro is billed monthly at the price shown at checkout and grants a monthly credit allotment plus Pro-only capabilities. Additional credits may be purchased in prepaid top-up packs. Purchases are billed to the workspace owner and receipted by email.

Merchant of Record. Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders. Paddle provides all customer service inquiries and handles returns. Payment, billing, currency, tax, invoicing, cancellation and refund mechanics are therefore governed by the Paddle Checkout Buyer Terms.

Refunds. We offer a 30-day money-back guarantee on purchases, as set out in our Refund Policy. Refund requests are handled by Paddle at paddle.net or through our support team. Credits expire on the date shown on each grant and are consumed oldest-first; cancelling a subscription stops future renewals.

Downgrades. A Pro plan ends immediately — not at the end of a grace period — when it reaches its renewal date with auto-renew switched off, or when the payment method on file is declined. At that moment Pro-only features stop: hidden badges become visible again, connected custom domains are disconnected, and the workspace returns to the 5-seat Free cap (see section 4). Remaining purchased credits stay until they expire.

Invite rewards. Bonus credits earned through the invite programme are a promotional benefit, not a purchase, and carry no cash value. A new account may claim one invite code, within 7 days of being created and only after confirming its email address. Self-referrals, duplicate accounts and accounts sharing a device with the referrer are not eligible. Reward credits are capped at 5 invited subscriptions per rolling 3-day period; exceeding that cap suspends the invite link for 1 month, during which no further reward credits are issued. You can generate a new invite link at any time — the previous link stops working immediately and reports as expired — but your reward cap is counted per account, not per link, so rotating a link does not reset the remaining rewards in the current window. We may withhold or reverse rewards obtained through automation, fake accounts, or any other circumvention of these limits.

Attachments. You may attach up to 10 files per message in build mode and 5 in plan mode. Text is extracted from documents (for example PDFs, archives and office files) so the AI can read them; do not attach content you do not have the right to share.

Purchase limit. To limit fraud and card testing, no more than 3,000 credits may be purchased in any rolling 24-hour period, counted per account, per workspace and per network address. Purchases above that limit are simply not accepted; the limit is applied on our servers and cannot be raised by splitting an order across accounts, workspaces, cards or devices.

Refunded credits and workspace debt. If a purchase is refunded or reversed after some of its credits have been spent, the spent portion becomes a debt owed by the workspace and the balance may go negative. While a debt is outstanding the workspace is locked — building, publishing and further purchases stop — and any sites published from it are replaced with a notice stating that payment is outstanding. Settling the debt restores the workspace and republishes the affected sites. Debt is tracked server-side per workspace and is not cleared by deleting projects, leaving or recreating a workspace, or opening a new account.

4.Workspaces and roles

A workspace is a shared organisation with one credit pool and one billing account. There are exactly three roles: Owner (full control over billing, members, ownership transfer and deletion), Editor (builds, edits and publishes projects and spends workspace credits) and Viewer (read-only access, cannot build or spend credits). Seat caps apply per plan: 5 members on Free, 10 on Pro.

The Owner is responsible for all charges incurred by workspace members. Only the Owner may set per-member monthly credit limits, change roles, remove members, and transfer projects or ownership. Removing a member does not refund credits they have spent.

Seat enforcement on downgrade. If a workspace returns to the Free plan, its seat cap drops back to 5. Members above that cap are removed automatically, starting with those who have been inactive in the workspace the longest. The Owner is never removed, and pending invitations are cancelled.

5.Your content and ownership

You own the prompts you write and the code ForgeFlow generates for you, to the extent such output is capable of ownership. We claim no licence over your generated applications beyond what is needed to host, build, preview, publish, back up, and support them.

You are responsible for ensuring your project — including any third-party assets, fonts, images, or packages you introduce — does not infringe anyone's rights.

Identical or similar output may be generated for other users. We make no guarantee of uniqueness and cannot warrant that generated code is free of third-party claims.

6.Acceptable use

You may not use ForgeFlow AI to build, host, or distribute anything that:

  • breaks the law or facilitates illegal activity;
  • infringes intellectual property or impersonates a brand or person;
  • creates malware, phishing pages, credential harvesters, or scam storefronts;
  • harasses, threatens, or targets individuals or protected groups;
  • contains sexual content involving minors, or non-consensual intimate imagery;
  • attempts to bypass platform safety controls, rate limits, credit metering, or billing.

We run automated safety review of published projects. Projects found to breach this section may be taken down without notice: the deployment is replaced with a safety notice, and the project may be removed from your account. Repeat or severe breaches result in account termination.

6.1 Child sexual abuse material — zero tolerance

Any attempt to generate, request, build, upload, host, describe or distribute sexual content involving minors is met with a single, immediate and permanent response, with no warning, no strike, no appeal and no refund: your account is terminated, every project you own is taken offline and removed, and the device fingerprint and network address used are blocked from creating further accounts. The prompt, timestamps, account identifiers, network address and device identifiers involved are preserved and referred to the relevant law-enforcement authorities and child-safety reporting bodies. This applies whether the request was "a test", "fictional", "a joke", or phrased indirectly, and it applies to both prompts and generated or uploaded files.

6.2 Safety bypass attempts (jailbreaking)

Deliberately attempting to bypass, disable, or trick the AI's safety controls — including prompt injection, role-play framing, encoded instructions, or repeated rephrasing of a refused request — results in an automatic 3-day AI ban on the project involved. During the ban the project can still be opened, but no new AI turns can be started in it. Repeated bans across projects are treated as platform abuse under Section 7 and may lead to workspace-wide restriction or termination. Credits are not refunded for turns blocked by safety review.

7.Enforcement: limits, strikes, termination and workspace deletion

This section explains exactly what gets an account restricted, what gets it closed, and why each rule exists. Enforcement is applied automatically by our systems and recorded permanently. We do not require a report or a complaint to act.

7.1 Behaviour that will limit your account

  • Creating multiple accounts. More than five accounts created or signed into from the same device in a day is blocked, and the device is placed in a cooldown. Why: free daily credits are funded per person; account farming turns a free allowance into an unlimited one and pushes the cost onto paying customers.
  • Invite (referral) abuse. Self-referrals, referrals between accounts on the same device, disposable-address signups, and more than five converted invites in a rolling three-day window pause your invite link for one month. Why: invite credits are a promotional reward for genuine word-of-mouth, not a credit generator.
  • Password-reset flooding. Reset requests carry an escalating cooldown, and more than five per day blocks the address and device for seven days. Why: repeated reset mail is how accounts get brute-forced and how our sending domain gets blacklisted.
  • Transfer cycling. Moving a project repeatedly between workspaces to re-claim daily credits flags the project and pauses transfers on it for seven days. Why: the daily allowance is per workspace and is not meant to be re-claimed by shuffling projects.
  • Hiding the ForgeFlow badge without Pro, or asking the AI to remove it. Why: the badge is how the free tier pays for itself; removing it is a paid feature.
  • Automation, scraping, or tampering with credit metering, rate limits, the verification challenge, or billing. Why: these controls protect capacity and cost for everyone on the platform.

Limits of this kind are temporary and self-clearing unless they are repeated. Credits already spent are not returned when a limit is applied.

7.2 Safety strikes

Every time a published site is taken down by safety review under Section 6, a strike is recorded permanently against both the account that owns the project and the workspace the project was published from. A strike is tied to the project itself, so it is not removed by deleting the project, unpublishing it, renaming it, moving it to another workspace, or changing project ownership. Strikes never expire.

7.3 Account termination at three strikes

If an account accumulates three sites taken down for safety reasons, the account is terminated permanently. When that happens:

  • all remaining projects on the account are archived and taken offline;
  • building, publishing, spending credits, and every other workspace action stop immediately;
  • any unspent credits, including purchased credits, are forfeited;
  • signing in still works, but every session shows only the termination notice: the reason, the number of strikes, and the list of removed sites with their dates. There is no way back into the product from that screen.

The decision is enforced on our servers, not in your browser, so it cannot be bypassed by clearing storage, calling our APIs directly, using a different device, or editing anything client-side. Creating a replacement account to continue the same activity is itself a breach of these Terms and results in that account being closed as well.

7.4 Workspace deletion at three strikes

If a single workspace accumulates more than three sites taken down for safety reasons — whichever members published them — that workspace is deleted. Its projects, files, version history, deployments and connected domains are removed, pending invitations are cancelled, and all members lose access. The Owner and every member receive a notice in their inbox stating the reason, the strike count, and which sites were removed and when. Workspace deletion does not refund the workspace credit balance and does not end the Owner's separate responsibility under Section 7.3 for their own account.

7.5 Why these rules exist

Phishing pages, malware, scam storefronts and harassment sites do real harm to people who never chose to use ForgeFlow, and repeated hosting of them puts the whole platform's domains, mail reputation and hosting accounts at risk. A three-strike limit leaves genuine room for a mistake or a false positive while making deliberate, repeated abuse impossible to sustain.

7.6 Mistakes

If you believe a takedown, a limit, or a termination was applied in error, contact support from the address on the account. We review the underlying decision on request; we do not lift enforcement simply because it is inconvenient.

8.The ForgeFlow badge

Every published project displays a "Built with ForgeFlow" badge. The badge may only be removed by enabling the setting on a workspace with an active Pro plan. Removing, hiding, overlaying, or obscuring the badge by any other means — including CSS, script injection, or asking the AI to do it for you — is a breach of these Terms and may result in the project being unpublished.

9.Publishing and custom domains

Publishing makes your project publicly accessible. You are the publisher of that site and are responsible for its content, its privacy notices, and its compliance with law.

Connecting a custom domain requires an active Pro plan and a domain you control. If the plan lapses, the custom domain is disconnected. We may suspend a deployment that breaches Section 6 or that generates abusive traffic.

10.AI output disclaimer

ForgeFlow generates code and configuration automatically. Output may be incorrect, insecure, incomplete, or unsuitable for your purpose. You must review, test, and secure anything before relying on it, and you remain solely responsible for what you deploy.

11.Service availability and changes

We aim for high availability but do not guarantee uninterrupted service. Features, model routing, credit costs and plan contents may change as the product evolves; material changes to pricing or credit costs will be announced in-app before taking effect.

12.Suspension and termination

You may stop using ForgeFlow and delete your account at any time. We may suspend or terminate access immediately for breach of these Terms, for suspected fraud or abuse, or where required by law. On termination, unspent credits are forfeited unless the termination was our fault or the law requires otherwise.

13.Warranty disclaimer

The service is provided "as is" and "as available", without warranties of any kind, whether express, implied, or statutory, including merchantability, fitness for a particular purpose, non-infringement, accuracy, and uninterrupted operation, to the maximum extent permitted by law.

14.Limitation of liability

To the maximum extent permitted by law, ForgeFlow AI is not liable for indirect, incidental, special, consequential, or punitive damages, nor for lost profits, lost revenue, lost data, or business interruption.

Our total aggregate liability arising out of or relating to the service is limited to the greater of (a) the fees you actually paid us in the twelve months before the event giving rise to the claim, or (b) USD 100.

15.Indemnity

You agree to indemnify and hold ForgeFlow AI harmless from claims, damages and reasonable legal costs arising from your projects, your published sites, your content, or your breach of these Terms.

16.Governing law and disputes

These Terms are governed by the laws of the jurisdiction in which ForgeFlow AI is established, without regard to conflict-of-law rules. The courts of that jurisdiction have exclusive jurisdiction, except where mandatory consumer law grants you the right to bring proceedings locally.

17.Changes

We may update these Terms. Material changes will be announced in the in-app "What's new" panel and reflected in the date above; continued use after the change means acceptance.

Guidance on how the product works, including billing, workspaces, publishing and safety rules, is kept current in the ForgeFlow docs.