Privacy Policy
Effective Date: December 1, 2025
Last Updated: November 19, 2025
Our Privacy Promise
We take your privacy seriously. This Privacy Policy explains what data we collect, why we collect it, and how you can control it.
The short version:
- We collect only what we need to make The Forge work
- We NEVER sell your data to third parties
- You can delete your account and data anytime
What Data We Collect
- Account Information: Email, name (optional), encrypted password
- OAuth Tokens: Instagram and Google tokens (encrypted)
- Brand Profile Data: Brand name, industry, DNA test results, colors
- Content Data: Generated ideas, approval history, images
- Usage Analytics: Anonymized usage data via Google Analytics
How We Use Your Data
- Provide The Forge service (generate content, store your brand profile)
- Send you notifications (e.g., "7 new ideas ready for review")
- Process payments (via Stripe)
- Improve the platform (analyze usage patterns, fix bugs)
- Provide customer support
We do NOT:
- ❌ Sell your data to advertisers
- ❌ Share your content with other users
- ❌ Use your data for unrelated marketing
Data Security
- Encryption: All data encrypted in transit (HTTPS) and at rest
- Storage: Supabase (SOC 2 compliant)
- Access Controls: Only authorized team members
- Backups: Daily backups for disaster recovery
Your Rights
PIPEDA Rights (Canadian Users)
- ✅ Access your personal information
- ✅ Challenge the accuracy of your information
- ✅ Withdraw consent for data use
- ✅ File a complaint with our Privacy Officer
GDPR Rights (EU Users)
- ✅ Access your data
- ✅ Correct your data
- ✅ Delete your data
- ✅ Export your data
- ✅ Restrict processing
- ✅ Object to processing
CCPA Rights (California Users)
- ✅ Know what data we collect
- ✅ Delete your data
- ✅ Opt out of data sharing (though we don't share for advertising)
Data Deletion & Account Closure
To delete your account:
- Go to Settings → Account
- Click "Delete Account"
- Confirm deletion
All your data is permanently deleted within 30 days. Your subscription is canceled immediately.
Contact Us
Questions about privacy? Email us at legal@masterforgemedia.com.
For GDPR/CCPA requests, include your full name, email address, and specific request. We will respond within 30 days.
Bottom Line: Your data is yours. We collect only what we need, protect it carefully, and give you full control.