SpecForge

Privacy Policy

Last updated: July 13, 2026

Information We Collect

We collect information you provide directly, including account details (email, name) and project data (specifications, tickets, epics). We also collect technical data such as IP address, browser type, and device information through standard server logs, along with product usage metrics (see Usage Analytics below).

How We Use Information

Your information is used to operate and improve the SpecForge platform, maintain account security, process payments, and communicate service updates. Specifications and project content are stored so you and your agents can work against them; we do not run your specifications through any AI model of our own — AI interactions happen through the coding agent or CLI that you run on your side. We do not sell your personal information to third parties.

Data Storage

Your data is stored securely on AWS infrastructure in the United States. We employ encryption at rest and in transit, regular security reviews, and access controls to protect your information. Project data is isolated per account.

Third-Party Processors

SpecForge relies on a small set of third-party service providers to operate the platform. Each processes only the data needed for its function, under its own privacy policy:

  • AWS — cloud infrastructure, hosting, and data storage.
  • Stripe — payment processing. When you subscribe to a paid plan, your card details are collected and processed directly by Stripe and are never stored on our systems; we retain only a Stripe customer identifier and subscription metadata (plan, status, billing dates).
  • Resend — transactional and authentication email delivery (for example, verification codes, password resets, and account notifications). Resend receives the recipient email address and the message content required to deliver these emails.

Usage Analytics

We collect anonymized and pseudonymized usage data to understand how the platform is used and to improve it. This telemetry consists of aggregate product and usage metrics with a bounded set of dimensions (such as feature names and event types). Where an event is associated with an account, the identifier is a salted hash recorded only as a log field — never your email or name in clear text. Because a salted hash can in principle be reversed with the salt, we describe this data as pseudonymized rather than fully anonymous.

This telemetry never includes your message content, specification content, or project data. It is used solely to operate and improve SpecForge — never for advertising or third-party tracking — and is never sold.

By accepting our Terms of Service you consent to this use of anonymized/pseudonymized usage data.

Cookies

We use essential cookies for authentication and session management. We do not use third-party advertising or tracking cookies. You can control cookie settings through your browser preferences, though disabling essential cookies may affect service functionality.

Your Rights

You have the right to access, correct, or delete your personal data. You can export your data at any time from your account Settings, and you can permanently delete your account and its data from Settings as well. To exercise any of these rights or ask a question, contact us at the address below. We will respond to requests within 30 days.

Data Retention & Deletion

We retain your account data for as long as your account is active. Deleting your account permanently deletes your data from our production systems immediately. Residual copies in our encrypted backups are purged within the backup window (approximately 35 days), after which no copy remains.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the service. Continued use after changes constitutes acceptance of the updated policy.

Contact

For privacy-related inquiries, contact us at contact@solutionsforge.tech.