Privacy Policy
How Forgeo collects, uses, and safeguards information across your account, connected platforms, and AI-generated products.
This Privacy Policy explains how Forgeo (“Forgeo,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you use our website at forgeoapp.com, our applications, and the related services (collectively, the “Service”).
This Policy is incorporated into our Terms of Service and should be read together with our Cookie Policy. By using the Service, you acknowledge the practices described here.
1.Overview
Forgeo helps creators build, launch, and grow digital products using AI. To do that, we process information you provide directly, information from platforms you choose to connect (such as Google, YouTube, and Instagram), and information generated as you use the Service.
We do not sell personal information, and we do not use your uploaded Content or generated Outputs to train foundation AI models.
2.Information Collected
We collect the following categories of information:
- Account information you submit when you sign up, such as name, email, and authentication identifiers.
- Content you upload, including PDFs, documents, images, brand assets, and reference material.
- Connected Platform data that you authorize us to access (for example, YouTube channel data or Instagram profile data).
- Usage data such as feature interactions, generation events, and error logs.
- Device and network data such as IP address, user-agent, and language settings.
- Billing data processed on our behalf by Stripe.
3.Account Information
When you create an Account, we collect the information necessary to authenticate you and provide the Service, including your name, email address, and profile image (where provided). We also maintain your subscription status, plan, and account preferences.
4.Google Data
If you sign in with Google, we receive basic profile information that you authorize during the OAuth consent flow, typically your name, email address, and profile image. We do not receive your Google password. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke Forgeo’s access at any time in your Google account security settings.
5.YouTube Data
When you connect a YouTube channel, we request access to public channel metadata, video metadata, and public engagement signals necessary to analyze your audience and content. We do not modify, upload, or delete videos on your behalf without your explicit action, and we do not access private videos beyond what you authorize.
Our use of YouTube API Services is governed by the YouTube Terms of Service and the Google Privacy Policy.
6.Instagram Data
When you connect an Instagram account, we request access to the public profile metadata and content signals necessary to analyze your positioning and audience. We do not post on your behalf without your explicit action. Our use of Instagram data is subject to Meta’s Platform Terms and applicable Instagram policies.
7.Uploaded Files
Files you upload (such as PDFs, documents, images, and brand assets) are stored in secure cloud storage and are used to power the features you request, including reference-based generation. You can delete uploaded files from your Account at any time.
8.Creator DNA
Creator DNA is a structured profile derived from the signals you provide and from your Connected Platforms. It may include your voice attributes, positioning, audience insights, and content themes. Creator DNA is used to personalize the Service and to steer AI Outputs so they reflect your creator identity.
9.AI Processing
When you use an AI feature, your prompts, selected Content, and derived signals may be sent to AI model providers, including OpenAI, solely to generate the Output you requested. We do not authorize these providers to use your inputs or Outputs to train their foundation models.
11.Analytics
We use analytics tools to understand how the Service is used, to diagnose issues, and to improve features. Analytics data is aggregated and used to inform product decisions and reliability improvements.
12.Device Information
We automatically collect certain device and network information when you use the Service, such as IP address, browser type, operating system, referring URLs, language, and timestamps. This information is used for security, fraud prevention, debugging, and product analytics.
13.Payment Information
Payment information (such as card number, expiry, and CVC) is entered directly with our payment processor and is not stored on our servers. We receive limited billing metadata such as the last four digits of your card, brand, subscription status, invoice history, and country.
14.Stripe
We use Stripe, Inc. to process payments and manage subscriptions. Stripe processes your payment information under its own privacy policy, available at stripe.com/privacy.
15.OpenAI
We use OpenAI and other AI providers to generate Outputs based on your inputs. OpenAI’s handling of API data is described at openai.com/policies. Under our current configuration, API inputs and Outputs are not used by OpenAI to train its models.
16.How We Use Information
We use information to:
- Provide, personalize, and improve the Service.
- Generate Outputs that you request, including Creator DNA, products, and launch assets.
- Operate accounts, process payments, and provide customer support.
- Monitor and protect the security and integrity of the Service.
- Comply with legal obligations and enforce our Terms.
18.International Transfers
The Service is operated from the United States and may involve transferring, storing, and processing your information in the United States and other countries where we or our service providers operate. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
19.Security
We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit, access controls, and monitoring. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
20.Data Retention
We retain information for as long as needed to provide the Service, to comply with our legal obligations, resolve disputes, and enforce our agreements. Content and Outputs are generally retained while your Account is active; when you delete your Account, we delete or de-identify personal information within a reasonable period, subject to legitimate business or legal retention needs.
21.User Rights
Depending on where you live, you may have rights with respect to your personal information, including the rights described in Sections 22–26. To exercise these rights, contact us at forgeo.support@gmail.com. We will verify your request and respond within the timeframes required by applicable law.
22.Access
You may request confirmation that we process your personal information and a copy of the information we hold about you.
23.Correction
You may request that we correct inaccurate or incomplete personal information. You may also update most Account information directly in your settings.
24.Deletion
You may request that we delete personal information we hold about you, subject to exceptions permitted by law (for example, to comply with legal obligations, resolve disputes, or enforce our agreements).
25.California Privacy Rights
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA (“CCPA”), provides you with additional rights, including the right to know the categories and specific pieces of personal information we collect, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the “sale” or “sharing” of personal information (we do not sell or share as those terms are defined under the CCPA), and the right to not be discriminated against for exercising these rights.
To exercise your CCPA rights, contact us at forgeo.support@gmail.com. You may also designate an authorized agent to make a request on your behalf.
26.GDPR Rights
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the rights of access, rectification, erasure, restriction of processing, portability, and objection under the General Data Protection Regulation and equivalent laws. Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing based on consent before withdrawal.
The legal bases we rely on include performance of a contract (providing the Service), our legitimate interests (operating, securing, and improving the Service), your consent (for optional processing), and compliance with legal obligations. You have the right to lodge a complaint with a supervisory authority.
27.Children’s Privacy
The Service is not directed to children under 13 and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
28.Subprocessors
To operate the Service we engage a limited set of trusted subprocessors that process personal information on our behalf under written agreements that require appropriate security and confidentiality safeguards. The categories and current subprocessors include:
- Cloud infrastructure and databases. Managed cloud hosting, storage, and database providers used to run the Service and store your Account data, Uploaded Files, and generated Outputs.
- AI providers. OpenAI and other model providers engaged to generate Creator DNA, product content, cover imagery, and other AI-assisted features, as described in Sections 9 and 15.
- Payments. Stripe, Inc., which processes subscription payments and stores payment credentials on our behalf, as described in Section 14.
- Authentication. Google LLC, which provides the Google Sign-In identity flow described in Section 4.
- Connected Platforms. YouTube (Google LLC) and Instagram (Meta Platforms, Inc.), which return public and authorized data when you connect an account.
- Communications. Transactional email providers used to send Account, billing, and support messages.
- Analytics and observability. Product analytics, error monitoring, and logging providers used to measure performance and diagnose issues, as described in Section 11.
We evaluate the privacy and security practices of each subprocessor before engagement and periodically thereafter. We will update this list when we materially change our subprocessors. You may request the current list at forgeo.support@gmail.com.
29.Legal Bases for Processing
Where the GDPR, UK GDPR, or a similar law applies, we rely on the following legal bases to process personal information:
- Performance of a contract — to create and maintain your Account, deliver the Service, process subscriptions, and provide customer support.
- Legitimate interests — to operate, secure, measure, and improve the Service; to prevent fraud, abuse, and unauthorized access; and to develop new features. We balance these interests against your rights and freedoms.
- Consent — for optional features (such as connecting a third-party platform), non-essential cookies, and certain marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation — to comply with tax, accounting, anti-fraud, and other regulatory requirements, and to respond to lawful requests from public authorities.
30.Retention Schedule
We retain personal information only for as long as necessary to provide the Service and to comply with our legal obligations. Our indicative retention periods are:
- Account records — for the life of the Account plus up to 24 months after closure, after which we delete or irreversibly anonymize the records.
- Creator DNA and generated Outputs — until you delete them or close your Account, subject to reasonable backup retention for up to 90 days.
- Uploaded Files — until you delete them or up to 90 days after Account closure.
- AI provider processing. Prompts and Outputs transmitted to OpenAI are subject to OpenAI’s zero-retention or 30-day abuse-monitoring windows applicable to API traffic and are not used to train third-party foundation models.
- Billing and tax records — retained for the period required by applicable tax, accounting, and anti-money-laundering laws, typically seven years.
- Support communications — retained for up to 36 months to service ongoing issues and audit responses.
- Security logs — retained for up to 12 months to investigate incidents and prevent abuse.
31.Automated Decision-Making
Forgeo uses automated processing to generate Creator DNA, recommendations, and product content. These features assist you but do not produce legal or similarly significant effects concerning you, and every Output is subject to your review, editing, and control before use. We do not use automated decision-making for creditworthiness, employment, insurance, or similar consequential decisions.
32.Sensitive Personal Information
We do not ask you to submit, and we do not want to receive, special categories of personal data (such as health data, biometrics, racial or ethnic origin, political opinions, religious beliefs, or precise geolocation). You are responsible for not uploading such information to the Service. If you do, you consent to our processing it solely for the purpose of providing the requested feature.
33.Do Not Track Signals
Some browsers transmit “Do Not Track” signals. Because no industry standard has been finalized, the Service does not currently respond to Do Not Track signals. Where required by law, we honor Global Privacy Control (GPC) signals as an opt-out of the sale or sharing of personal information as described in Section 25.
34.Data Breach Notification
We maintain an incident response program designed to detect, investigate, contain, and remediate security incidents. If a breach of security leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to your personal information, we will notify you and any applicable regulator without undue delay where required by law, including under GDPR Articles 33–34 and applicable U.S. state breach-notification statutes.
35.Data Protection Officer and EU/UK Representative
You may contact our privacy team, including any designated Data Protection Officer, at forgeo.support@gmail.com. If you are located in the European Economic Area or the United Kingdom and are unable to resolve a concern with us directly, you have the right to lodge a complaint with your local supervisory authority. Where a representative under Article 27 of the GDPR or UK GDPR is required, we will designate one and publish the representative’s contact details at the same email address on request.
36.Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice (for example, by email or in-product notification) before the changes take effect. The “Effective date” at the top indicates when this version was last updated.
37.Contact
If you have questions about this Privacy Policy or our privacy practices, contact us at forgeo.support@gmail.com.