Privacy
Privacy policy
What personal data GradTensor collects through Forge and forgeprivate.com, why we hold it, who it is shared with, and what you can ask us to do about it.
Last updated August 2026. Forge is operated by GradTensor. For anything on this page, write to forge@gradtensor.com.
01
What this policy covers, and what it does not
There are two different kinds of personal data around Forge, and they are governed differently. This distinction decides which document applies to you.
Data about you, held by us
Your account, your access request, records of your use of the service. We decide why and how it is held, so we are responsible for it. This policy covers that, and nothing on this page is about anything else.
Data inside a customer’s workspace
The documents, records and conversations a customer puts into Forge, which may contain personal data about their own clients or staff. The customer decides what goes in and why; we process it on their instruction. A data processing agreement covers that, agreed with each customer.
If your employer uses Forge and you want to know what they have put into it, ask them. We hold it on their behalf and cannot make decisions about it without them.
02
What we collect, and why
Access request details
Email address, and optionally your name, organisation, industry, role, and anything you write in the message field.
Why: To respond to your request for access and decide whether Forge fits what you need.
On what basis: Your request. You choose to send it, and you can ask us to delete it at any time.
Account details
Email address and a password, which is stored hashed by our authentication provider and is never visible to us.
Why: To create and secure your account, and to identify you inside your organisation.
On what basis: Necessary to provide the service you or your organisation asked for.
Usage records
Which account made a request, in which organisation, the model used, token counts, cost, and the time.
Why: To meter and bill use, and to give your organisation's admin visibility of spend. Not the content of what you asked.
On what basis: Necessary to provide and bill for the service.
Activity records
Who accessed or changed what, and when.
Why: The audit log your organisation's admin can read, and our own record of access. It records that something happened, never what was in it.
On what basis: Our legitimate interest in a secure, accountable service, and our customers' need for oversight.
A visitor identifier
A random identifier stored in your browser when you use a publicly published Forge page. It is not linked to a name or an email.
Why: To count distinct visitors to a published page for the customer who published it.
On what basis: Our customer's legitimate interest in knowing how their published page is used.
Session cookies
An authentication session cookie and a cookie recording which organisation you are currently working in.
Why: To keep you signed in and in the right workspace.
On what basis: Strictly necessary. Without them you cannot stay signed in.
Our hosting providers also hold ordinary technical logs of requests to the service, which can include an IP address. That is standard infrastructure logging and is held under their terms, listed in section 3.
03
Cookies, tracking and marketing
Forge uses no third-party analytics, no advertising trackers, and no cross-site tracking of any kind. There is nothing on this site that follows you elsewhere.
The only cookies are the two in section 2: an authentication session and a record of which organisation you are working in. Both are strictly necessary to use the service, which is why there is no consent banner asking you to accept things you have no real choice about.
We do not sell personal data, and we do not share it for anyone else’s marketing. If you send an access request we may email you about it. We will not add you to a marketing list you did not ask for.
05
Where it is stored, and for how long
Data is stored in the ap-southeast-2 (Sydney) region, and the application runs there too. Our email and AI providers operate from other countries, including the United States, so sending an email or asking a question involves a transfer outside that region. Those transfers are covered by the terms we hold with each provider.
There is one more, and it is listed here because it is a transfer rather than because this policy governs what moves. If your organisation uses a program app, the run happens on Cloudflare’s network rather than in the region above, and is constrained to the Asia-Pacific area rather than placed freely. That is a region and not a country, so it says a run stays within that area rather than which country inside it was used. What that handles, and the controls around it, are on the security page; the content itself is covered by the data processing agreement, not by this policy.
- Account details are kept while your account exists, and are deleted when it is closed.
- Access requests are kept while we are considering or acting on them, and are deleted on request at any time.
- Usage and activity records are kept as the record of what the service did, which is what makes them useful for billing and oversight.
- Conversations follow the retention window your organisation sets, and are deleted automatically when it passes. Documents stay until deleted.
Retention controls and deletion behaviour are described in more detail on the security page.
06
Your rights
Depending on where you are, you can ask us to do the following with the personal data we hold about you. We will not charge you for asking, and we will respond within a reasonable time.
- Tell you what we hold about you and why.
- Correct it if it is wrong or incomplete.
- Delete it, where we do not need to keep it for a legal or contractual reason.
- Give you a copy in a portable form.
- Stop a particular use, or withdraw a consent you gave us.
- Nominate someone to exercise these rights on your behalf if you are unable to.
Write to forge@gradtensor.com and we will handle it. That address is also where to raise a complaint about how we have handled your data. If you are not satisfied with our answer, you can complain to your data protection authority.
If your data is inside a customer’s workspace rather than held by us directly, section 1 applies: we will pass your request to that customer, who decides how to answer it.
07
How it is protected
Encryption in transit and at rest, invite-only access, per-organisation separation, an append-only audit log, and no use of your data to train any AI model. The controls, and the ones we do not yet have, are set out on the security page.
08
Changes, and how to reach us
If we change what we collect or what we do with it, we will update this page and the date at the top. Where a change is significant and affects you, we will tell you rather than rely on you noticing.
Forge is operated by GradTensor. For any question about this policy, to exercise a right, or to raise a complaint, write to forge@gradtensor.com.
