Privacy Policy
Short version: we hold your sign-in details and the ideas you submit, we send those ideas to model providers to analyse them, we do not sell anything to anyone, and you can have all of it deleted by asking.
Last updated 23 July 2026
What we collect
- Account. Your email address and display name, passed to us by Google or GitHub when you sign in. We never see your password.
- Ideas and analyses. The text you submit, and everything generated from it, including canvases, versions, and verdicts.
- A hash of your IP address. Used to rate-limit analyses and to count pricing events. It is salted with a server-only secret, so the original address cannot be recovered from it, and it is never stored in the clear.
- Local preferences. Your language and theme live in your browser's local storage. They never reach us.
There are no advertising trackers, no analytics pixels, and no cross-site cookies, which is why this site has no cookie banner.
What we do with it
We use it to run the service: to sign you in, to produce the analysis you asked for, to show you your own history, to keep usage within limits, and to answer you when you write in. We do not sell personal data, and we do not use your ideas to train models.
The legal basis is performance of the contract between us for account data and analyses, and legitimate interest in keeping the service working for the rate-limiting hash.
Who else processes it
These are the third parties involved, and what each one handles:
- Supabase. Database and sign-in. Stores your account, ideas, and analyses.
- Vercel. Hosting. Serves the site and keeps short-lived request logs.
- Anthropic. Generates the analysis. Receives the idea text you submit.
- OpenAI. Generates the analysis. Receives the idea text you submit.
- Paddle. Merchant of record. Collects payment and billing details directly.
- Google, GitHub. Sign-in. We receive your email address and display name.
Paddle collects your billing details directly at checkout. We never receive or store your card number.
Producing an analysis also queries public sources including Hacker News, Reddit, Product Hunt, TechCrunch, the App Store, and SEC EDGAR. Those queries carry search terms derived from your idea. The full idea text goes only to the model providers listed above.
These providers operate outside your country in most cases, including in the United States. Where required, transfers rely on the providers' own standard contractual clauses.
How long we keep it
Your ideas and analyses stay until you delete them or ask us to close your account. Rate limiting hashes are only useful inside a rolling window and are not retained beyond what that needs. Paddle keeps transaction records for as long as tax law requires them, which is outside our control.
Your choices
Write to support@forgepod.dev to get a copy of your data, correct it, or have it deleted. Deletion is permanent and removes your analyses along with the account. We aim to answer within 30 days.
Security
Data is held in Supabase with row-level security, so one account cannot read another's rows. Access is over HTTPS. No system is perfect, and if a breach ever affects your data we will tell you.
Children
ForgePod is not for anyone under 16, and we do not knowingly collect their data.
Changes
If this policy changes, the date at the top changes with it. See also the Terms of Service.
Contact
ForgePod is reachable at support@forgepod.dev. Write to that address for anything on this page, including refunds, data requests, and questions about these terms.