Privacy policy
Last updated/Effective date: 8/31/2026
Forged AI, Inc., doing business as Forged ("Forged," "we," "us," or "our"), provides software-planning, development, deployment, and product-improvement services.
This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our website, applications, AI agents, integrations, and related services (collectively, the "Service").
It applies to the public website and to the authenticated Service alike, covering site visitors, waitlist and marketing-form submissions, account holders, organization members, authenticated application users, AI-agent interactions, repository and third-party integrations, Customer Content processing, Service Usage Data, billing and Usage Credit activity, and support communications. Capitalized terms not defined here have the meanings given in our Terms of Service.
1. Information we collect
Information you provide
We may collect information you provide directly, including:
- Your name, email address, account credentials, and profile information;
- Organization, workspace, and team information; and
- Information submitted through waitlists, forms, surveys, or marketing sign-ups.
Customer Content
Customer Content is the material you or your authorized users submit to the Service, or that we obtain from connected services at your direction, including product ideas, prompts, clarification answers, product decisions, plans, files, documents, configurations, source code, repositories, and customer-provided product data. Customer Content does not include Service Usage Data, Aggregated Data, or Feedback. See our Terms of Service for the corresponding ownership and license terms.
Billing and transaction information
We collect information related to Usage Credit purchases, balances, Auto Reload settings, and transaction history.
Payment-card information is generally collected and processed by our payment provider rather than stored directly by Forged.
Communications and feedback
We collect your communications with us, including support requests, and any feedback, ideas, recommendations, or suggestions you send about Forged. Feedback is not Customer Content, and the rights that apply to it are described in ourTerms of Service.
Information from connected services
When you connect a source-control platform, cloud provider, deployment service, or other third-party account, we may receive information made available through that connection, such as:
- Account and repository identifiers;
- Repository content and metadata;
- Branches, commits, pull requests, and issues;
- Installation and permission information;
- Deployment and configuration information; and
- Information needed to perform actions you request or authorize.
The information we receive depends on the permissions you grant and the third party's settings.
Information from visitor-identification providers
On our public website we use a third-party visitor-identification provider that attempts to match a visit to a business contact record the provider already holds. Where a match is made, we may receive:
- Name;
- Business email address and job title;
- Employer, company domain, and company information; and
- A link to a public professional profile.
This information comes from the provider and its own data sources, not from you. A match can happen even if you never submit a form, create an account, or otherwise identify yourself to us. We use it to understand which businesses are interested in Forged and to contact potential customers.
The provider identifies individual people only for visitors it determines are located in the United States. We do not run it for visitors in the European Economic Area or the United Kingdom, or for visitors whose location we cannot establish.
You can prevent this before it happens by turning analytics off through the "Cookie settings" link in the website footer, or by browsing with a Global Privacy Control signal enabled. Section 5 describes your opt-out rights in more detail, and Section 9 covers how to ask us to delete information we have already received.
Service Usage Data collected automatically
When you use the Service, we may automatically collect Service Usage Data, meaning technical, operational, billing, diagnostic, performance, and interaction data generated through the use or operation of the Service. It does not include the substantive contents of Customer Content or customer-specific Output. It may include:
- IP address;
- Browser, device, and operating-system information;
- Pages and features viewed;
- Actions taken in the Service;
- Model and compute usage, and Usage Credit consumption;
- Latency, system events, and similar operational signals;
- Referring URLs;
- Dates, times, and approximate location derived from IP address;
- Error reports, diagnostics, and performance information; and
- Cookie and similar-technology identifiers.
2. How we use information
We may use personal information to:
- Provide, operate, secure, maintain, support, and improve the Service;
- Create and manage accounts and workspaces;
- Process Customer Content to perform the work you request;
- Generate plans, code, tests, recommendations, and other Output;
- Connect to and interact with repositories and third-party services;
- Perform actions you request or authorize;
- Process Usage Credit purchases, manage Free AI Usage and Usage Credit balances, and process Auto Reload purchases where you have enabled it;
- Provide customer support;
- Measure performance and reliability, diagnose problems, and improve the Service;
- Create and use Aggregated Data;
- Carry out analytics and benchmarking, and develop products and workflows, using Aggregated Data and de-identified Service Usage Data rather than information that reasonably identifies you, an individual, a repository, or proprietary source code, unless you authorize broader use;
- Protect the Service, users, repositories, and systems from fraud, abuse, and security threats;
- Communicate about the Service, transactions, updates, and changes;
- Send marketing communications where permitted, subject to your choices;
- Comply with legal obligations and enforce our agreements; and
- Support business transactions such as a financing, acquisition, or sale.
We aim to collect and retain only information reasonably necessary for legitimate business and operational purposes. Appropriate data collection, security, and disposal practices are central elements of FTC privacy and security guidance. (Federal Trade Commission)
3. AI processing and model training
Forged uses AI systems to provide planning, implementation, testing, analysis, and related features.
This section distinguishes five different activities, because they carry different commitments.
1. Processing Customer Content to provide requested features
We may send Customer Content and related instructions to AI service providers as necessary to provide the features you request. Those providers process information under their applicable contracts and data-use terms.
2. Automated review
Customer Content and AI-generated Output may be reviewed through automated processes for security, quality, reliability, abuse prevention, evaluation, and service operation. Providing, securing, testing, and improving the Service requires that processing, so we do not claim that no automated system ever evaluates Customer Content.
3. Service Usage Data and Aggregated Data
Forged may use Aggregated Data and de-identified Service Usage Data to evaluate, benchmark, develop, and improve the Service, rather than information that reasonably identifies you, an individual, a repository, or proprietary source code, unless you authorize broader use. Forged will not attempt to use Aggregated Data to identify a customer, user, individual, repository, or proprietary source-code asset.
4. Training of AI models
Forged does not use Customer Content to train or fine-tune AI models, whether general-purpose models or Forged's own models, except in the form of Aggregated Data as defined in our Terms of Service.
5. Human access
A limited number of authorized Forged personnel, and personnel of our service providers, may access Customer Content and Output where necessary to provide support you have requested, investigate suspected abuse or a security incident, diagnose errors, comply with law, or establish, exercise, or defend legal claims. Access is limited to personnel who need it for one of those purposes and is subject to confidentiality obligations.
4. How we disclose information
We may disclose information to:
Service providers
Companies that help us provide the Service, such as providers of:
- Cloud hosting and infrastructure;
- AI models and processing;
- Authentication;
- Source-control and repository integrations;
- Payments and billing;
- Email and customer communications;
- Analytics and error monitoring;
- Security; and
- Customer support.
These providers, sometimes called subprocessors, may receive Customer Content, Service Usage Data, and personal information only as reasonably necessary to provide their services to us, subject to applicable contractual, confidentiality, security, and data-protection obligations.
We may add, replace, or discontinue providers as the Service evolves.
Connected third-party services
We disclose information to third-party services when you direct us to connect to or interact with them.
Your organization
If you use an organization or shared workspace, administrators and authorized members may access information associated with that organization, subject to their roles and permissions.
Legal and safety purposes
We may disclose information when we reasonably believe disclosure is necessary to:
- Comply with law, legal process, or government requests;
- Enforce our agreements;
- Detect or prevent fraud, abuse, or security incidents;
- Protect the rights, property, or safety of Forged, our users, or others; or
- Establish, exercise, or defend legal claims.
Business transactions
Information may be disclosed or transferred in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of some or all of our business or assets.
With your direction
We may disclose information when you direct us to do so or otherwise consent.
5. Sale, sharing, and targeted advertising
We do not share personal information for cross-context behavioral advertising or targeted advertising based on activity across unrelated businesses, and we do not receive money in exchange for personal information.
We do use the visitor-identification provider described in Section 1. That provider receives activity from our public website and draws on information it already holds about you, and it acts as an independent controller of that information rather than on our behalf alone. Some state privacy laws treat an arrangement of this kind as a "sale" or "sharing" of personal information, and we treat it that way here so that your rights do not depend on how it is categorized.
You have the right to opt out. You can do so at any time by:
- Turning analytics off through the "Cookie settings" link in the website footer; or
- Browsing with a Global Privacy Control signal enabled, which we honor automatically as a valid opt-out.
Opting out does not require an account, and we will not ask you to create one or to justify the request. We also do not run this provider for visitors in the European Economic Area or the United Kingdom. If you would rather submit the request in writing, Section 9 explains how.
You can change your choice at any time through the
We may use service providers to measure use of our website and Service, understand performance, and improve our own products.
6. Cookies and analytics
We and our service providers may use cookies, local storage, pixels, and similar technologies to:
- Keep you signed in;
- Remember settings and preferences;
- Maintain security;
- Understand use of the Service;
- Identify business visitors to our public website;
- Diagnose errors; and
- Measure website and product performance.
Some of these technologies are used by a third-party visitor-identification provider that can associate a visit to our public website with a named individual and their employer. Section 1 describes what we receive, and Section 5 describes your right to opt out.
You can control certain cookies through your browser settings. Blocking necessary cookies may prevent parts of the Service from working.
Where legally required, we request consent before using nonessential cookies or similar technologies. You can accept, reject, or change your preferences at any time through the
7. Data retention
We retain personal information for as long as reasonably necessary to:
- Provide the Service;
- Maintain your account and Usage Credit balance;
- Complete transactions;
- Meet legal, tax, accounting, and reporting obligations;
- Resolve disputes;
- Enforce our agreements;
- Maintain security; and
- Support legitimate business operations.
After your account is closed, or your access is otherwise terminated, we may retain Customer Content for a limited period for recovery, security, legal compliance, and dispute-resolution purposes. We may then delete or de-identify it. Where Customer Content belongs to an organization, that retention and deletion begin when the organization's account is closed or its access is terminated, not when an individual member closes their account.
Residual copies may remain in backups until deleted through our ordinary backup-retention processes. Some information may be retained longer where required by law or reasonably necessary to establish, exercise, or defend legal claims.
8. Security
We use reasonable administrative, technical, and organizational safeguards intended to protect personal information.
However, no method of transmission or storage is completely secure. You are responsible for protecting your credentials, configuring repository and integration permissions appropriately, and deciding whether the Service is suitable for the information you submit.
Notify us at support@tryforged.ai if you believe your account or information has been compromised.
9. Your choices and rights
You may update certain account information through the Service.
You may unsubscribe from promotional emails by using the unsubscribe link in the message. We may still send transactional or service-related communications.
Depending on where you live and applicable law, you may have rights to:
- Access personal information we hold about you;
- Correct inaccurate information;
- Request deletion;
- Receive a portable copy of certain information;
- Restrict or object to certain processing;
- Opt out of the sale or sharing of personal information;
- Withdraw consent where processing relies on consent; and
- Appeal our response to a privacy request.
To submit a request, email legal@tryforged.ai. We may need to verify your identity before completing a request. Authorized agents may submit requests where permitted by law.
We may deny or limit a request where permitted by law, including where information must be retained for security, legal compliance, transactions, or the rights of others.
10. International users and transfers
Forged is based in the United States. We and our service providers may process information in the United States and other countries that may have different data-protection laws from your country.
Where European data-protection law applies, Forged generally acts as the controller for account, billing, security, support, communications, and service-usage information. When we process personal information contained in Customer Content solely on a customer's instructions, we generally act as that customer's processor or service provider.
Where required by applicable law, we take appropriate measures to protect personal information transferred internationally.
For users in the European Economic Area, United Kingdom, or similar jurisdictions, we generally process personal information where necessary to:
- Perform our contract with you;
- Pursue legitimate interests such as operating, securing, and improving the Service;
- Comply with legal obligations; or
- Act with your consent.
You may also have the right to complain to the data-protection authority where you live. European privacy rules contemplate disclosures about processing purposes, legal grounds, recipients, retention, transfers, and individual rights. (European Commission)
11. Children
The Service is not intended for anyone under 18 years old. We do not knowingly collect personal information from anyone under 18.
12. Third-party services
The Service may contain links to or integrations with third-party services.
Their collection and use of information are governed by their own privacy policies and terms. We are not responsible for the privacy practices of third parties you choose to use or connect.
13. Changes to this Privacy Policy
We may update this Privacy Policy periodically.
If a change materially affects how we use personal information, we will provide reasonable notice through the Service, by email, or through another appropriate method. The revised policy will identify its effective date.