Privacy Policy

Last updated: August 12, 2026

1. Introduction and Service Context

This Privacy Policy explains how Forge ("we", "us", or "our") collects, uses, and discloses information about you. It is explicitly specified that this site is an API provider which uses AI (Artificial Intelligence). Due to the nature of operating an AI model routing gateway, we process API requests ("Inputs") and generate responses ("Outputs") on your behalf. We prioritize your privacy and strictly govern how API data is handled in relation to these AI systems.

2. Information We Collect

Account Data: We collect personal information you provide when creating an account, such as your name, email address, and billing details.

API Data: We process the text, prompts, and parameters you send through our API (Inputs) and the resulting generated content (Outputs).

Telemetry and Usage Data: We automatically collect technical metadata when you use our Service, including IP addresses, browser types, API request timestamps, token counts, model routing choices, and latency metrics.

3. How We Use Your Information

We use your Account Data to manage your account, process payments, and communicate with you. We use Telemetry Data for billing, load balancing, security auditing, and improving our routing algorithms.

Crucially, regarding API Data (Inputs/Outputs): We only process this data to provide the Service. We DO NOT use your API Data to train, fine-tune, or improve our own foundational AI models, nor do we permit our downstream model providers to use your API Data for training, subject to our enterprise agreements with them.

4. Data Sharing and Disclosure

We do not sell your personal information. We may share data with:

Model Providers: To fulfill your API requests, your Inputs are securely routed to third-party AI providers (e.g., OpenAI, Anthropic). We have agreements in place restricting their use of your data.

Service Providers: We use third-party vendors for hosting (e.g., AWS, Vercel), payment processing (e.g., Stripe), and analytics. These vendors are bound by strict confidentiality obligations.

Legal Requirements: We may disclose information if required by law, subpoena, or other legal processes, or to protect our rights and the safety of our users.

5. Data Security

We implement robust, industry-standard security measures including end-to-end encryption (TLS/SSL) for data in transit and AES-256 encryption for data at rest. API keys are hashed and salted. Despite these measures, no system is entirely secure, and we cannot guarantee absolute security of your information against sophisticated attacks.

6. Data Retention

Account Data is retained as long as your account is active. API Data (Inputs and Outputs) is typically retained temporarily in memory for routing purposes and securely logged for up to 30 days exclusively for debugging and abuse detection, after which it is permanently purged, unless you explicitly opt into longer retention for prompt logging features.

7. International Data Transfers

Our servers are primarily located in the United States. If you access our Service from outside the US, your information will be transferred to, stored, and processed in the US. We ensure appropriate safeguards, such as Standard Contractual Clauses, are in place for cross-border data transfers.

8. Your Privacy Rights

Depending on your jurisdiction (e.g., GDPR, CCPA), you may have the right to access, correct, delete, or export your personal data. You may also object to processing or withdraw consent. You can exercise these rights directly through your account dashboard or by contacting our privacy team.

9. Changes to this Policy

We may update this Privacy Policy to reflect changes in our practices or legal obligations. We will provide prominent notice of any material changes via email and an in-app notification before they take effect.

10. Contact Information

For any questions, concerns, or requests regarding this Privacy Policy or your data rights, please contact us at developer@forgeapi.org