This Privacy Policy describes how Forge ("we," "us," or "our") collects, uses, and discloses your information when you use our content-generation service, and explains your privacy rights and how the law protects you.
We use your personal data to provide and improve the Service. By using Forge, you agree to the collection and use of information in accordance with this Privacy Policy.
1. Interpretation and Definitions
Interpretation
Words with the initial letter capitalized have meanings defined under the following conditions. These definitions have the same meaning whether they appear in singular or plural.
Definitions
- Account means a unique account created for you to access Forge or parts of it.
- Company (referred to as "the Company," "We," "Us," or "Our") refers to Forge, operated by Chextr Inc., a Delaware corporation.
- Service refers to the Forge web application and website at forge.chextr.com.
- Content means the briefs, source material, prompts, and generated articles you submit to or produce with the Service.
- API Keys means the third-party AI provider credentials you optionally add to your account to run your own models ("bring your own key").
- Cookies are small files placed on your device by a website.
- Personal Data is any information relating to an identified or identifiable individual.
- Service Provider / Sub-processor means a third party that processes data on our behalf to facilitate or provide the Service.
- Usage Data refers to data collected automatically from your use of the Service or its infrastructure.
- You means the individual or legal entity accessing or using the Service.
2. Information We Collect
Personal Data
When you use Forge, we may collect personally identifiable information you provide, including:
- Email address and name (via Google Sign-In)
- Your Google account identifier used to authenticate you
- Billing information, if you subscribe to a paid plan (processed by our payment provider — we do not store full card numbers)
Content You Submit and Generate
To run the Service, we process the briefs, uploaded files, prompts, and the articles Forge generates for you. This Content is stored in your account so you can revisit your run history and export your work.
API Keys (Bring Your Own Key)
If you add your own AI provider API keys, they are encrypted at rest and used solely to run model requests on your behalf. We never display your full keys back to you and never share them with other users.
Usage Data
Usage Data is collected automatically and may include your IP address, browser type and version, the pages you visit, the date and time of your visit, time spent on pages, unique device identifiers, and other diagnostic data.
Cookies and Tracking
We use cookies and similar technologies to operate and secure the Service. We use:
| Essential Session Cookies | These authenticate you and keep you signed in. Required for the Service to work. |
| Functional Cookies | These persistent cookies remember your preferences (e.g., selected pipeline or model). |
You can instruct your browser to refuse cookies, but some parts of the Service may not function without them.
3. How We Use Your Information
We process your Personal Data for the following business and legal purposes:
- To provide and maintain the Service, including running your content pipelines and saving your run history.
- To manage your account and give you access to plan features (Free, Pro, or BYOK).
- To process payments and manage subscriptions, transactions, and credits.
- To contact you about updates, security notices, administrative alerts, or account matters.
- To improve the Service through aggregate analysis of usage trends, system optimization, and performance.
- To prevent abuse, detect fraud, enforce usage limits, and protect the security of the Service.
4. AI Providers, Sub-processors, and Data Sharing
Forge routes your Content to third-party AI model providers to generate articles. Depending on the pipeline or keys you choose, these may include Anthropic (Claude), OpenAI, Google (Gemini), Groq, OpenRouter, DeepSeek, and Together AI. Your Content is sent to these providers only to fulfill your requests.
We also rely on the following sub-processors to operate Forge:
| Cloudflare | Hosting, application runtime, CDN security, and database (D1) storage. |
| Google Sign-In | Authentication and optional Google Drive file export. |
| Dropbox / Microsoft (OneDrive) | Optional cloud export, initiated solely by you. |
Other Disclosures of Your Data
- Business Transfers: If the Company is involved in a merger, acquisition, asset sale, or bankruptcy, your Personal Data may be transferred as a business asset.
- Legal Enforcement: We may disclose your data if required by law, court order, or lawful government request.
- Consent: We may disclose your information for any other purpose with your explicit consent.
We do not sell your personal data, and we do not use your Content to train our own or third-party AI models.
5. Retention and Automatic Deletion of Your Data
5.1 Retention Limits
We retain your Personal Data only as long as necessary to provide the Service, fulfill the purposes outlined in this Policy, comply with our legal obligations (such as tax or accounting laws), resolve disputes, and enforce our agreements.
5.2 Automatic Content Deletion Timeline
To protect user privacy and minimize data liability, the Service enforces an automated retention and data deletion schedule for generated content:
- Unexported Content and History: All briefs, uploaded files, prompt inputs, and AI-generated article outputs stored in your account run history are automatically and permanently deleted from our primary servers ninety (90) days after the date of creation.
- Account Deletion: If you request account deletion, all personal data, saved keys, and remaining content history will be purged from our database within thirty (30) days of your request.
- Backup Lifecycle: Residual copies of deleted content may persist in our encrypted system backups for up to an additional thirty (30) days before being completely overwritten.
6. International Data Transfers (GDPR / UK GDPR Notice)
The Company operates primarily out of the United States. Your information, including Personal Data, is processed at our operating offices and in cloud hosting environments located in the US and other global jurisdictions where our sub-processors operate.
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, your data is transferred outside your region. For these transfers, we rely on appropriate legal safeguards, including:
- Standard Contractual Clauses (SCCs): Approved by the European Commission (and the UK Addendum) executed with our infrastructure and AI sub-processors.
- Adequacy Decisions: Where data is transferred to countries recognized as providing an adequate level of data protection.
Legal Bases for Processing (EEA/UK users)
Under the GDPR, we process your data under the following legal bases:
- Performance of a Contract: To fulfill our Terms of Service and provide the application.
- Legitimate Interests: To secure, monitor, analyze, and optimize our platform.
- Legal Obligation: To comply with statutory accounting, tax, or legal mandates.
- Consent: Where you explicitly choose to connect external integrations (e.g., Google Drive).
7. State-Specific Privacy Notices (United States)
A. California Privacy Notice (CCPA / CPRA)
This section applies solely to residents of California. Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), we disclose the following details regarding our data collection and sharing habits over the past 12 months:
| CCPA Data Category | Specific Elements Collected | Source | Purpose of Collection | Categories of Third Parties Disclosed To |
| A. Identifiers | Name, email address, IP address, Google account identifier. | Directly from you (Google OAuth), Automatically via browser. | Account creation, authentication, security, communication. | Cloudflare, Google Authentication. |
| B. Commercial Information | Subscription tiers, billing history, payment tokens. | Directly from you / Payment processor. | Payment processing, transaction history. | Third-party payment provider. |
| F. Internet / Electronic Network Activity | Browser type, operating system, page interaction logs, diagnostic data. | Automatically via system logs. | Technical monitoring, platform security, analytics. | Cloudflare. |
| H. Geolocation Data | General location inferred via IP address (City/Country level). | Automatically via IP address. | Localization, security, compliance. | Cloudflare. |
| I. Professional / Employment Information | Job titles or company briefs if explicitly typed into prompts. | User-submitted input (Content). | Generating requested AI articles. | Selected AI Providers (e.g., OpenAI, Anthropic). |
Notice of Collection, Sale, and Sharing
- Notice of Collection: We collect the categories of personal information listed above for business and commercial operational goals as detailed in Section 3.
- No Sale of Personal Information: We do not sell your personal information for monetary or valuable consideration.
- No Sharing for Cross-Context Behavioral Advertising: We do not share your personal information with third parties for cross-context behavioral or targeted advertising.
- No Use of Sensitive Personal Information: We do not collect or process "Sensitive Personal Information" as defined by California law to infer characteristics about you.
- Shine the Light Law: We do not share personal information with third parties for their direct marketing purposes under California Civil Code Section 1798.83.
B. Other US State Privacy Rights (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, etc.)
Depending on your state of residence (under frameworks like VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA), you are granted specific protections regarding your data. We fulfill these obligations uniformly through our central privacy workflows. We do not engage in profiling that results in legal or similarly significant effects, and we do not engage in targeted advertising using your personal data.
8. Your Global Privacy Rights and How to Exercise Them
Regardless of whether you are located in California, other US states, the EEA, or the UK, we extend comprehensive control over your personal data. You have the right to:
- Right to Know / Access: Request a copy of the specific pieces of Personal Data we have collected about you.
- Right to Correction / Rectification: Request that we correct inaccurate or incomplete Personal Data.
- Right to Deletion ("Right to be Forgotten"): Request that we erase your account and associated historical log data, subject to specific regulatory retentions.
- Right to Data Portability: Request an export of your information in a structured, machine-readable format.
- Right to Opt-Out of Automation / Profiling: Object to any processing based purely on automated decisions (Note: Forge does not use automated decision-making or profiling to make automated decisions that impact your legal status).
- Right to Non-Discrimination: We will never penalize, deny service, charge different prices, or alter the quality of your Service for exercising your legal privacy rights.
How to Exercise Your Rights
To exercise any of these protections, or to appeal a decision we have made regarding a privacy request, please submit a verifiable request to us via:
Email: support@forge.chextr.com
Only you, or a person registered with the appropriate state authority that you authorize to act on your behalf, may make a verifiable consumer request. We will verify your identity by matching the email address of the request with the Google Sign-In records in our database before executing your request. We respond to all verified inquiries within 45 days for US state requests (or 30 days for GDPR requests) as required by law.
9. Security of Your Data
We use industry-standard administrative, technical, and physical safeguards, including encryption of API keys at rest and encrypted transit protocols (HTTPS/TLS). However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
10. Children's Privacy
The Service is not directed to anyone under the age of 13 (or the age of majority in your jurisdiction). We do not knowingly collect personal identifiable information from children. If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from anyone under the age of 13 without verification of parental consent, we take immediate steps to remove that information from our servers.
11. Links to Other Websites
Our Service may contain links to third-party websites or services that are not owned or controlled by the Company. We are not responsible for the content, privacy policies, or practices of any third-party websites. We strongly encourage you to read the privacy policies of every website you visit.
12. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this Privacy Policy.
For material changes that significantly affect your rights, we will provide a more prominent notice via email or through a clear notification within the Forge application interface prior to the change becoming effective.
13. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or our data management compliance practices, you can contact us at:
Email: support@forge.chextr.com