Privacy Policy
forgein ("we", "us", "our") operates the forgein service, including the web application at app.forgein.ai, the API at api.forgein.ai, the forgein CLI, and the forgein Chrome extension. This policy explains what data we collect, how we use it, and your rights.
Chrome Extension — Data Disclosure
Required disclosure under the Chrome Web Store Developer Program Policies (User Data Privacy). The forgein Chrome extension ("the Extension") has a single purpose: to inject your forgein developer context into ChatGPT and Gemini so you do not need to re-paste it manually.
Permissions used and why
| Permission | Why it is needed |
|---|---|
storage | Stores your forgein API token locally in chrome.storage.localon your device only. No token data leaves your device via Chrome sync. No other data is stored by the Extension. |
Host access tochatgpt.com,gemini.google.com | Content scripts inject your context text into the chat input field on these pages. The scripts write to the page; they do not read, capture, or transmit the page's content or your conversation history. |
Host access toapi.forgein.ai | Makes authenticated fetch requests to retrieve your context file from the forgein API. No other external domains are contacted. |
User data categories — complete disclosure
| Data category | Collected? | Details |
|---|---|---|
| Authentication information | Yes | Your forgein API token (fg_…) is stored on-device in chrome.storage.local. It is not synced to Google servers. It is transmitted to api.forgein.ai on each context-retrieval request, over HTTPS. It is not transmitted to any other party. |
| Personally identifiable information | No | The Extension does not collect name, email, or any PII independently. |
| Website content / page content | No | Content scripts run on ChatGPT and Gemini pages to inject text into input fields. They do not read, record, or transmit any content from those pages. |
| Web history / browsing activity | No | The Extension does not access or collect browsing history. |
| Personal communications | No | Conversations in ChatGPT or Gemini are not read or transmitted. |
| Financial or payment information | No | The Extension handles no payment data. |
| Health information | No | Not applicable. |
| Location | No | The Extension does not access location data. |
| User activity | No | No keystrokes, clicks, or tab activity are monitored or recorded. |
Data sharing — Extension: The only external party that receives data from the Extension is forgein (api.forgein.ai), which receives your API token as a Bearer header to authenticate context-retrieval requests. No data is transmitted to OpenAI, Google, Anthropic, or any other AI company or third party. We do not sell data collected via the Extension. The Extension contains no remote code execution, no analytics SDKs, and no ad networks.
1. Data we collect (web app, API, CLI)
Account data
- Email address and name (provided when you sign up)
- Authentication tokens (generated when you log in)
- Billing information (processed by Stripe — we never see raw card numbers)
Memory and context files
- Memory files you explicitly sync using
forgein mem syncor the web app - Org context templates you create in your workspace
- These files are stored on our servers and associated with your account
Usage data (adapter telemetry)
Collected per adapter request. Field-by-field:
adapter_type— which tool fetched context (e.g. "copilot", "chatgpt")project_path— normalized directory path (e.g.-Users-alice-projects-myapp). Contains no file contents.created_at— timestamp of the requestuser_id— your account identifier
To opt out of adapter telemetry, set FORGEIN_NO_TELEMETRY=1 in your environment before running the CLI, or pass -H "X-No-Telemetry: 1" in direct API calls. No telemetry is recorded when this flag is present.
We do not log the content of adapter responses or the content of your memory files as telemetry.
2. How we use your data
- To provide the forgein service — syncing and serving your context files
- To authenticate your requests and secure your account
- To generate org-level adoption analytics visible to your organization owners
- To send transactional emails (account creation, billing receipts, webhook failure alerts)
- We do not use your data for advertising
- We do not sell your data to third parties
3. Data sharing
We share data only with:
- Stripe — payment processing. Governed by Stripe's Privacy Policy.
- Microsoft Azure — infrastructure hosting (EU and US regions). Data is encrypted at rest and in transit.
- Your organization — if you are a member of a forgein org, org owners can see aggregated usage analytics (tool usage counts, last-seen timestamps). They cannot see the content of your memory files.
We do not share data with AI companies (OpenAI, Google, Anthropic, etc.). We fetch context for you — we do not send your data to those platforms.
4. Data retention
- Memory files and context templates are retained until you delete them or close your account
- Adapter usage logs are retained for 90 days
- Audit log entries are retained for 1 year
- On account deletion, all your data is permanently removed within 30 days
5. Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data. To exercise these rights, email us at [email protected]. We will respond within 30 days.
EU/EEA users: forgein is operated from Georgetown, TX, USA. For GDPR requests, contact us at the address below.
6. Security
All data is transmitted over HTTPS. API tokens are hashed before storage. We use row-level security on our database to enforce access controls. Auth tokens expire and can be revoked from your account settings at any time.
7. Cookies
The web application uses a single session cookie for authentication. No third-party tracking cookies are used.
8. Changes to this policy
We will notify you by email if we make material changes to this policy. Continued use of forgein after changes take effect constitutes acceptance of the updated policy.
Contact
forgein
Georgetown, TX, USA
[email protected]