Privacy Policy
Last updated: 12 June 2026
Forge ("we", "us") is an automation platform that builds and runs AI-written automation tools on your behalf. This policy explains what we collect, why, and what we do with it.
What we collect
- Account data — your name, email address and password hash; or, if you sign in with Google, your Google account's name, email and profile picture. We never see your Google password.
- Connection credentials — API keys and OAuth tokens for the services you connect (e.g. Gmail, Sheets, your shop). These are encrypted at rest with AES-256-GCM; the encryption key is held outside the database. The AI never sees credential values — only named references.
- Automation content — the tools you build (their code, configuration and version history), their execution logs and the data those executions process, and your conversations with the AI builder.
- Usage and billing data — AI model usage (tokens, model, cost), run counts, credit balance, and an audit trail of security-relevant actions (sign-ins, credential access, tool changes) including IP address.
How we use it
- To operate your automations: store them, run them on their triggers, and show you their results.
- To bill AI usage against your credit transparently (per call, per tool).
- To secure the platform: rate limiting, audit logging, abuse prevention.
- We do not sell your data or use your automation content for advertising.
AI processing
When you use the AI builder or a tool calls an AI model, the relevant content (your instructions, tool context, and data the tool passes to the model) is sent to the selected model provider via OpenRouter, Inc. acting as a routing service. Model providers process this data under their own terms; we route requests with provider data-retention minimisation options where available. Your stored credentials are never included in AI requests.
Third parties
- OpenRouter / AI model providers — AI request routing and processing, as above.
- Google — if you use Google sign-in or connect Google services, per Google's policies and the scopes you approve.
- The services you connect — your tools exchange data with them exactly as the tools you build instruct.
Forge's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention & deletion
Your data is retained while your account is active. Deleting a connection destroys its stored credentials. Deleting a tool retires it and retains its history for audit purposes. To delete your account and all associated data, contact us at the address below; we will action it within 30 days. Encrypted backups are kept for 14 days, after which deleted data ages out of them too.
Your rights
Depending on where you live (e.g. UK/EU GDPR), you may have rights to access, correct, export or erase your personal data, and to object to or restrict processing. Contact us to exercise them.
Contact
Questions or requests: ben@unicorp.ltd