For a typical B2B deployment, your organization is the data controller for end-user and organization content. The operator hosting Forge acts as processor under instructions you configure (retention, SSO, exports).
When blueprint or insight features are enabled, objective text (after server-side scrub metadata) may be sent to the LLM backend you configure. For AI SaaS Inference API or Managed agents, Phantom Forge Labs may send prompts to PFL-selected providers that back Forge-operated aliases. See /legal/subprocessors.
Retention is governed by your Supabase project settings and operational procedures. Organization delete and export paths are available per your deployment configuration and commercial agreement.
Privacy inquiries: privacy@phantomforgelabs.com