Back to home

Last updated: March 2026

Privacy Policy

1. Introduction

FORGE (operated by the entity behind forgeyoursite.dev) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our platform and use our services. Please read this policy carefully. If you do not agree with our policies and practices, please do not use our platform.

2. Information We Collect

Account Information

When you create an account, we collect your full name and email address through Clerk authentication. You may optionally provide additional profile information such as company name or website URL.

Usage and Activity Data

We collect data about your interactions with FORGE, including pages visited, features accessed, generation requests, timestamps, browser type, operating system, IP address, and referring URLs. This helps us understand how you use the service and improve functionality.

Generated Content

Your prompts, generation requests, and the AI-generated website code output are stored in our Supabase database. You retain ownership of this generated content. We may use anonymized generation metadata to improve our AI models.

Payment Information

Payment processing is handled by Stripe. We do not directly collect or store credit card numbers, bank account details, or full payment method information. Stripe handles all payment processing and storage in compliance with PCI-DSS standards.

OAuth and Third-Party Authentication

When you authenticate using GitHub, Google, or Vercel OAuth, we receive limited profile information (email, name, profile picture) from those providers. These providers' privacy policies govern data collection through their services.

Cookies and Tracking Technologies

Session cookies are set by Clerk for authentication purposes. Essential cookies are necessary for platform functionality. You may disable non-essential cookies through your browser settings, though this may impact your ability to use certain features.

3. How We Use Your Information

  • Provide, maintain, and improve the FORGE service and user experience
  • Process payments and billing through Stripe
  • Send transactional emails (account confirmations, password resets, billing receipts)
  • Send service announcements and security alerts when necessary
  • Analyze usage patterns and generate anonymized statistics to improve AI quality and platform performance
  • Respond to your inquiries, support requests, and customer service issues
  • Comply with legal obligations and enforce our Terms of Service
  • Detect and prevent fraud, abuse, and security incidents
  • Improve our machine learning models using anonymized generation data

4. Data Storage and Security

Data Location: User data is stored on Supabase, which uses AWS infrastructure and employs industry-standard encryption (AES-256 for data at rest and TLS 1.2+ for data in transit).

Authentication Security: Clerk provides SOC 2 Type II compliant authentication services with support for multi-factor authentication and secure password handling.

Payment Security: Stripe handles all payment processing and is PCI-DSS Level 1 compliant, the highest certification available.

Data Protection: We implement reasonable technical, administrative, and physical safeguards to protect your data. However, no system is 100% secure. We cannot guarantee absolute security of your information.

No Sale of Data: We do not sell, trade, or rent your personal information to third parties.

Data Retention: We retain your data as long as your account is active. Upon account deletion, we delete personal information within 30 days, except where required to retain for legal compliance.

5. Third-Party Services and Providers

We use the following third-party services to operate FORGE:

  • Clerk — Authentication and account management (SOC 2 compliant)
  • Supabase — Database and file storage (PostgreSQL with encryption)
  • Stripe — Payment processing (PCI-DSS Level 1)
  • Anthropic (Claude API) — AI code generation
  • Vercel — Application hosting and deployment
  • Resend — Transactional email delivery

Each provider has their own privacy policy. We encourage you to review them. We have data processing agreements in place with all providers where applicable.

6. Your Privacy Rights

Access: You have the right to access your personal data and obtain a copy of it.

Correction: You may request correction of inaccurate or incomplete personal data.

Deletion: You have the right to request deletion of your account and associated personal data, except where we are required to retain it for legal reasons.

Data Portability: You may request export of your data in a structured, commonly used format.

Opt-Out: You may opt out of non-essential marketing communications at any time. You cannot opt out of transactional or service-critical emails.

GDPR and CCPA: If you are a resident of the EU (GDPR) or California (CCPA), you have additional rights. For inquiries related to GDPR or CCPA, please contact privacy@forgeyoursite.dev with your request details.

7. Children's Privacy

FORGE is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it and terminate the child's account. If you believe we have collected information from a child under 13, please contact us at privacy@forgeyoursite.dev.

8. International Data Transfers

FORGE operates in the United States. Your information may be transferred to, stored in, and processed in the United States or other countries outside your country of residence. These countries may have data protection laws that differ from your country. By using FORGE, you consent to the transfer of your information to countries outside your country of residence.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to the address associated with your account. Your continued use of FORGE after changes become effective constitutes your acceptance of the updated policy. We will update the "Last updated" date at the top of this page.

10. Data Breach Notification

In the event of a data breach involving your personal information, we will notify affected users without unreasonable delay and in compliance with applicable laws. Notification will be made via email or through the FORGE platform.

11. Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or want to report a privacy concern, please contact us at:

privacy@forgeyoursite.dev

We will respond to your inquiry within 30 days of receipt.