Privacy Policy
At ForgeKit, we believe in transparency and minimal data collection. This Privacy Policy explains how we collect, use, and protect your information when you use our platform.
TL;DR: We collect only what's necessary to run the service, never sell your data, and you can delete everything at any time.
Information We Collect
Account Information
- Email address - For account creation and communication
- Display name - Optional, for personalization
- Avatar URL - If provided via OAuth (GitHub, Google)
Project & Deployment Data
- Project slugs and URLs - To route your deployments
- Deployment metadata - Creation dates, framework info, build status
- Environment variables - Encrypted at rest, only you can access
- Container logs - For debugging, automatically deleted after 14 days
Analytics Data (Optional)
- Page views and paths - For your deployed projects
- Referrer information - Where visitors came from
- Screen resolution - To help optimize your sites
- IP addresses - For unique visitor counts (not linked to personal identity)
Billing Information
- Stripe Customer ID - Links your account to billing
- Subscription status - Active, canceled, etc.
- Note: Payment details are handled exclusively by Stripe - we never see or store your credit card information
How We Use Your Information
Service Delivery
Deploy your projects, manage containers, route traffic, and provide the core ForgeKit platform features.
Account Management
Authenticate logins, manage billing, send important service notifications, and provide customer support.
Analytics & Insights
Provide you with visitor statistics for your deployed projects (you control this data).
Security & Abuse Prevention
Monitor for violations of our Acceptable Use Policy and protect the platform from malicious activity.
Data Sharing & Third Parties
We share data with these trusted partners only:
- Supabase - Database hosting for your account and project data
- Stripe - Payment processing (they handle all payment data)
- Hetzner - Server infrastructure where your deployments run
✓ We never sell, rent, or share your personal data with advertisers or marketers
✓ We only share data when legally required (court orders, etc.)
✓ All partners are bound by strict data protection agreements
Data Retention & Deletion
Automatic Deletion
- • Container logs: 14 days
- • Analytics events: 90 days
- • Daily analytics: 2 years
- • Free tier deployments: 7 days
Your Control
- • Delete projects anytime
- • Cancel account anytime
- • Request full data export
- • Request complete deletion
Your Privacy Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data
- Export your data
- Opt out of analytics
- Withdraw consent
Data Security
We implement industry-standard security measures to protect your data:
- Encryption at rest - All data encrypted in our databases
- Encryption in transit - All connections use HTTPS/TLS
- Access controls - Role-based access with Row Level Security
- Regular security audits - Continuous monitoring and updates
Contact & Updates
Questions about this policy? Email us at privacy@forgekit.ai
Data requests? Email support@forgekit.ai for access, corrections, or deletion.
Policy updates: We'll notify you of material changes via email or platform notification. Continued use means you accept the updated policy.
Jurisdiction & Compliance
ForgeKit operates under United States privacy laws. We comply with applicable regulations including GDPR for EU users and CCPA for California residents. This policy is governed by the laws of Delaware, USA.
Privacy-first, data-light, transparency-heavy. That's the ForgeKit way.
— The ForgeKit Team