Forge OS
PrivacyTermsPartnersHome

Privacy Policy

Draft notice: This document is provided for transparency and to inform users of how Forge OS operates. It is not legal advice and has not been individually negotiated with you. Forge OS recommends users consult their own attorney before relying on any statement herein.

Privacy Policy

Our Privacy Mission

Forge OS is built on the principle that personal data should serve the user, not be sold for profit. We do not sell, rent, or trade your personal data to advertisers, data brokers, lead-generation networks, or marketing partners. We never have and we never will.

Information We Collect (Minimal by Design)

  • Email address & hashed password (account creation)
  • Housing readiness profile (DTI, credit score, income, monthly debt) — your shard only
  • Financial goals you choose to track
  • Chat history with the AI assistant (so you can resume conversations)
  • Saved listings — minimal shard (price, short address, lat/lng, approval-odds snapshot)
  • Support ticket information you submit
  • Basic usage telemetry (errors, performance) for self-healing

We do not maintain a listing warehouse, nationwide MLS mirror, or property catalog tied to you. Live property searches run on demand and are discarded after display unless you explicitly save a listing.

What We Persist Long-Term

  • Your readiness profile (per-user row, row-level security)
  • Saved listing shards you created with the heart / save action
  • Aggregated city-level analytics (~200 bytes per metro — no addresses)

We keep only what you choose to save and aggregated metro analytics — never a permanent copy of every listing you browse.

How We Protect Your Data

  • Passwords hashed with bcrypt — never stored in plaintext
  • Data stored in Supabase with row-level security on user shards
  • HTTPS / TLS for all data transmission
  • Optional TOTP-based two-factor authentication on user accounts
  • Authentication tokens stored in localStorage and cookies (see Cookies & Local Storage below)

Cookies & Local Storage

Forge OS uses essential cookies and browserlocalStorage for:

  • Keeping you signed in (auth token)
  • Remembering your last viewed splash / onboarding state
  • Holding ephemeral search context (ZIP, tier, readiness) between page refreshes

We do not run third-party advertising trackers, behavioral ad networks, or cross-site fingerprinting scripts.

Third-Party Service Providers

To run the platform we rely on the following processors, each governed by their own privacy policy:

  • Supabase — database, authentication, row-level security
  • Vercel — application hosting / edge runtime
  • Groq & Google Gemini — AI chat inference (prompts may be sent for processing)
  • Resend — transactional email (account verification, password reset)
  • Stripe — payment processing for paid tiers (optional; sandbox by default)

We only send these providers the minimum data required to complete the requested operation.

Your Rights

  • Access — request a copy of the data we hold about you
  • Correction — fix inaccurate readiness or profile data
  • Deletion — request account closure and shard removal
  • Export — download your data as a structured file
  • Opt out — disable non-essential telemetry where offered

Email dev.forgeos.io@gmail.com to exercise any of the above. Residents of CA, CO, CT, VA, UT, and the EU/UK retain all rights granted by CCPA/CPRA, GDPR, and equivalent statutes regardless of what is listed here.

Last updated: July 2026  |  Contact: dev.forgeos.io@gmail.com

Draft — for transparency only. Not legal advice; attorney review recommended.