Sign inGuideTermsPrivacySubprocessorsDPA

Privacy

Controller vs processor

For a typical B2B deployment, your organization is the data controller for end-user and organization content. The operator hosting Forge acts as processor under instructions you configure (retention, SSO, exports).

What we process

  • Account identifiers and email from Supabase Auth.
  • Organization name, branding metadata, membership roles.
  • AI release payloads: project objectives, generated blueprints, logs, approval state, optional linked tickets.
  • Audit events and export manifests as configured.
  • Billing identifiers when Stripe is enabled.
  • When AI SaaS Inference API or Managed agents are enabled: endpoint identifiers, aliases, and usage metadata for Forge-operated delivery.
  • When workspace Forge model learning is set to AI SaaS: scrubbed learning events (intent previews, option accepts, eval summaries, inference metadata)—not Build-tier releases by default.

AI providers

When blueprint or insight features are enabled, objective text (after server-side scrub metadata) may be sent to the LLM backend you configure. For AI SaaS Inference API or Managed agents, Phantom Forge Labs may send prompts to PFL-selected providers that back Forge-operated aliases. See /legal/subprocessors.

Retention and deletion

Retention is governed by your Supabase project settings and operational procedures. Organization delete and export paths are available per your deployment configuration and commercial agreement.

Contact

Privacy inquiries: privacy@phantomforgelabs.com