Privacy Policy

How Forgeo collects, uses, and safeguards information across your account, connected platforms, and AI-generated products.

Effective date: July 28, 2026Last updated: July 28, 2026

This Privacy Policy explains how Forgeo (“Forgeo,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you use our website at forgeoapp.com, our applications, and the related services (collectively, the “Service”).

This Policy is incorporated into our Terms of Service and should be read together with our Cookie Policy. By using the Service, you acknowledge the practices described here.

1.Overview

Forgeo helps creators build, launch, and grow digital products using AI. To do that, we process information you provide directly, information from platforms you choose to connect (such as Google, YouTube, and Instagram), and information generated as you use the Service.

We do not sell personal information, and we do not use your uploaded Content or generated Outputs to train foundation AI models.

2.Information Collected

We collect the following categories of information:

  • Account information you submit when you sign up, such as name, email, and authentication identifiers.
  • Content you upload, including PDFs, documents, images, brand assets, and reference material.
  • Connected Platform data that you authorize us to access (for example, YouTube channel data or Instagram profile data).
  • Usage data such as feature interactions, generation events, and error logs.
  • Device and network data such as IP address, user-agent, and language settings.
  • Billing data processed on our behalf by Stripe.

3.Account Information

When you create an Account, we collect the information necessary to authenticate you and provide the Service, including your name, email address, and profile image (where provided). We also maintain your subscription status, plan, and account preferences.

4.Google Data

If you sign in with Google, we receive basic profile information that you authorize during the OAuth consent flow, typically your name, email address, and profile image. We do not receive your Google password. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke Forgeo’s access at any time in your Google account security settings.

5.YouTube Data

When you connect a YouTube channel, we request access to public channel metadata, video metadata, and public engagement signals necessary to analyze your audience and content. We do not modify, upload, or delete videos on your behalf without your explicit action, and we do not access private videos beyond what you authorize.

Our use of YouTube API Services is governed by the YouTube Terms of Service and the Google Privacy Policy.

6.Instagram Data

When you connect an Instagram account, we request access to the public profile metadata and content signals necessary to analyze your positioning and audience. We do not post on your behalf without your explicit action. Our use of Instagram data is subject to Meta’s Platform Terms and applicable Instagram policies.

7.Uploaded Files

Files you upload (such as PDFs, documents, images, and brand assets) are stored in secure cloud storage and are used to power the features you request, including reference-based generation. You can delete uploaded files from your Account at any time.

8.Creator DNA

Creator DNA is a structured profile derived from the signals you provide and from your Connected Platforms. It may include your voice attributes, positioning, audience insights, and content themes. Creator DNA is used to personalize the Service and to steer AI Outputs so they reflect your creator identity.

9.AI Processing

When you use an AI feature, your prompts, selected Content, and derived signals may be sent to AI model providers, including OpenAI, solely to generate the Output you requested. We do not authorize these providers to use your inputs or Outputs to train their foundation models.

10.Cookies

We use cookies and similar technologies for authentication, security, functionality, and analytics. For details, see our Cookie Policy.

11.Analytics

We use analytics tools to understand how the Service is used, to diagnose issues, and to improve features. Analytics data is aggregated and used to inform product decisions and reliability improvements.

12.Device Information

We automatically collect certain device and network information when you use the Service, such as IP address, browser type, operating system, referring URLs, language, and timestamps. This information is used for security, fraud prevention, debugging, and product analytics.

13.Payment Information

Payment information (such as card number, expiry, and CVC) is entered directly with our payment processor and is not stored on our servers. We receive limited billing metadata such as the last four digits of your card, brand, subscription status, invoice history, and country.

14.Stripe

We use Stripe, Inc. to process payments and manage subscriptions. Stripe processes your payment information under its own privacy policy, available at stripe.com/privacy.

15.OpenAI

We use OpenAI and other AI providers to generate Outputs based on your inputs. OpenAI’s handling of API data is described at openai.com/policies. Under our current configuration, API inputs and Outputs are not used by OpenAI to train its models.

16.How We Use Information

We use information to:

  • Provide, personalize, and improve the Service.
  • Generate Outputs that you request, including Creator DNA, products, and launch assets.
  • Operate accounts, process payments, and provide customer support.
  • Monitor and protect the security and integrity of the Service.
  • Comply with legal obligations and enforce our Terms.

17.Data Sharing

We share information only as necessary to operate the Service or as required by law. Categories of recipients include:

  • Service providers such as cloud hosting, storage, authentication, analytics, email delivery, and customer support providers.
  • Payment processors such as Stripe.
  • AI providers such as OpenAI, to fulfill your generation requests.
  • Connected Platforms, when you initiate an action that requires it.
  • Legal, safety, and enforcement recipients when disclosure is required to comply with law, respond to lawful requests, prevent fraud, or protect rights, property, or safety.
  • Successors in the event of a merger, acquisition, financing, or sale of assets, subject to equivalent privacy protections.

We do not sell personal information.

18.International Transfers

The Service is operated from the United States and may involve transferring, storing, and processing your information in the United States and other countries where we or our service providers operate. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

19.Security

We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit, access controls, and monitoring. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

20.Data Retention

We retain information for as long as needed to provide the Service, to comply with our legal obligations, resolve disputes, and enforce our agreements. Content and Outputs are generally retained while your Account is active; when you delete your Account, we delete or de-identify personal information within a reasonable period, subject to legitimate business or legal retention needs.

21.User Rights

Depending on where you live, you may have rights with respect to your personal information, including the rights described in Sections 22–26. To exercise these rights, contact us at forgeo.support@gmail.com. We will verify your request and respond within the timeframes required by applicable law.

22.Access

You may request confirmation that we process your personal information and a copy of the information we hold about you.

23.Correction

You may request that we correct inaccurate or incomplete personal information. You may also update most Account information directly in your settings.

24.Deletion

You may request that we delete personal information we hold about you, subject to exceptions permitted by law (for example, to comply with legal obligations, resolve disputes, or enforce our agreements).

25.California Privacy Rights

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA (“CCPA”), provides you with additional rights, including the right to know the categories and specific pieces of personal information we collect, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the “sale” or “sharing” of personal information (we do not sell or share as those terms are defined under the CCPA), and the right to not be discriminated against for exercising these rights.

To exercise your CCPA rights, contact us at forgeo.support@gmail.com. You may also designate an authorized agent to make a request on your behalf.

26.GDPR Rights

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the rights of access, rectification, erasure, restriction of processing, portability, and objection under the General Data Protection Regulation and equivalent laws. Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing based on consent before withdrawal.

The legal bases we rely on include performance of a contract (providing the Service), our legitimate interests (operating, securing, and improving the Service), your consent (for optional processing), and compliance with legal obligations. You have the right to lodge a complaint with a supervisory authority.

27.Children’s Privacy

The Service is not directed to children under 13 and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.

28.Subprocessors

To operate the Service we engage a limited set of trusted subprocessors that process personal information on our behalf under written agreements that require appropriate security and confidentiality safeguards. The categories and current subprocessors include:

  • Cloud infrastructure and databases. Managed cloud hosting, storage, and database providers used to run the Service and store your Account data, Uploaded Files, and generated Outputs.
  • AI providers. OpenAI and other model providers engaged to generate Creator DNA, product content, cover imagery, and other AI-assisted features, as described in Sections 9 and 15.
  • Payments. Stripe, Inc., which processes subscription payments and stores payment credentials on our behalf, as described in Section 14.
  • Authentication. Google LLC, which provides the Google Sign-In identity flow described in Section 4.
  • Connected Platforms. YouTube (Google LLC) and Instagram (Meta Platforms, Inc.), which return public and authorized data when you connect an account.
  • Communications. Transactional email providers used to send Account, billing, and support messages.
  • Analytics and observability. Product analytics, error monitoring, and logging providers used to measure performance and diagnose issues, as described in Section 11.

We evaluate the privacy and security practices of each subprocessor before engagement and periodically thereafter. We will update this list when we materially change our subprocessors. You may request the current list at forgeo.support@gmail.com.

30.Retention Schedule

We retain personal information only for as long as necessary to provide the Service and to comply with our legal obligations. Our indicative retention periods are:

  • Account records — for the life of the Account plus up to 24 months after closure, after which we delete or irreversibly anonymize the records.
  • Creator DNA and generated Outputs — until you delete them or close your Account, subject to reasonable backup retention for up to 90 days.
  • Uploaded Files — until you delete them or up to 90 days after Account closure.
  • AI provider processing. Prompts and Outputs transmitted to OpenAI are subject to OpenAI’s zero-retention or 30-day abuse-monitoring windows applicable to API traffic and are not used to train third-party foundation models.
  • Billing and tax records — retained for the period required by applicable tax, accounting, and anti-money-laundering laws, typically seven years.
  • Support communications — retained for up to 36 months to service ongoing issues and audit responses.
  • Security logs — retained for up to 12 months to investigate incidents and prevent abuse.

31.Automated Decision-Making

Forgeo uses automated processing to generate Creator DNA, recommendations, and product content. These features assist you but do not produce legal or similarly significant effects concerning you, and every Output is subject to your review, editing, and control before use. We do not use automated decision-making for creditworthiness, employment, insurance, or similar consequential decisions.

32.Sensitive Personal Information

We do not ask you to submit, and we do not want to receive, special categories of personal data (such as health data, biometrics, racial or ethnic origin, political opinions, religious beliefs, or precise geolocation). You are responsible for not uploading such information to the Service. If you do, you consent to our processing it solely for the purpose of providing the requested feature.

33.Do Not Track Signals

Some browsers transmit “Do Not Track” signals. Because no industry standard has been finalized, the Service does not currently respond to Do Not Track signals. Where required by law, we honor Global Privacy Control (GPC) signals as an opt-out of the sale or sharing of personal information as described in Section 25.

34.Data Breach Notification

We maintain an incident response program designed to detect, investigate, contain, and remediate security incidents. If a breach of security leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to your personal information, we will notify you and any applicable regulator without undue delay where required by law, including under GDPR Articles 33–34 and applicable U.S. state breach-notification statutes.

35.Data Protection Officer and EU/UK Representative

You may contact our privacy team, including any designated Data Protection Officer, at forgeo.support@gmail.com. If you are located in the European Economic Area or the United Kingdom and are unable to resolve a concern with us directly, you have the right to lodge a complaint with your local supervisory authority. Where a representative under Article 27 of the GDPR or UK GDPR is required, we will designate one and publish the representative’s contact details at the same email address on request.

36.Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice (for example, by email or in-product notification) before the changes take effect. The “Effective date” at the top indicates when this version was last updated.

37.Contact

If you have questions about this Privacy Policy or our privacy practices, contact us at forgeo.support@gmail.com.