Privacy Policy

Last updated: June 2, 2026

AppForge prioritizes your data privacy. This policy explains how we collect, use, process, share, and protect information when you use our AI App Factory platform.

This policy covers the website, user accounts, AppForge projects, GitHub/Cloudflare/Billing integrations, and AI providers or API keys configured by you.

1. Information We Collect

Account information such as email address, display name, verification status, admin permission, and information required to authenticate or recover an account.

Project information such as app ideas, Plan First answers, requirements, design briefs, prompts, AI agent outputs, selected muai-kits, app shell, style tokens, and workflow status.

Configuration information such as selected providers/models, API keys or secrets, runtime settings, GitHub/Cloudflare/OAuth configuration, and billing configuration.

Operational information such as logs, audit trails, error events, build/deploy status, usage metrics, and data needed for security review or technical support.

2. How We Use Information

We use information to analyze, design, scaffold, implement, QA, and deploy apps through the workflow you start, and to preserve project history so work can resume later.

We use information to recommend muai-kits, app shells, design tokens, providers/models, and cost estimates before code generation begins.

We use information to operate the service, prevent abuse, verify permissions, debug issues, improve performance, and provide support when you contact us.

Billing information is used only as needed to manage subscriptions, payment status, invoices, and access to paid features.

3. AI Provider Processing

When you ask AppForge to use AI, prompts, requirements, design context, code context, or related information may be sent to the AI provider selected by the system or by you.

If you use your own API key, some processing occurs under your account with that provider. You should review the terms and privacy policy of the provider you choose.

We aim to send only the information needed for the agent task. Users should avoid placing unnecessary sensitive personal data or confidential information into prompts.

4. Secrets, API Keys, and Integrations

Secrets and API keys stored in AppForge are masked in the UI and protected according to the platform's security controls.

Users can change, remove, or revoke keys through supported tools. If a key belongs to an external provider account, you should also revoke it with that provider when it is no longer needed.

AppForge will not use your keys outside workflows, key tests, deployments, integrations, or actions that you initiate or enable.

5. Third-party Sharing

We do not sell personal information and do not publish your project data without authorization.

Information may be shared with service providers required to operate AppForge, such as AI providers, GitHub, Cloudflare, Stripe, OAuth/email providers, logging/monitoring services, or infrastructure providers.

Sharing happens to perform actions you request, such as generating code, pushing repositories, deploying production environments, testing API keys, processing payments, or sending notifications.

6. Retention and Deletion

We retain information as long as needed to provide the service, maintain project history, support security review, meet accounting obligations, or resolve disputes.

Users may request account or data deletion through support. Some information may remain temporarily in backups, audit logs, or systems required for security and compliance.

When deleting projects or disconnecting integrations, you should also review repositories, deployments, DNS records, provider keys, and third-party services outside AppForge's control.

7. User Controls

You can manage account data, projects, runtime settings, provider keys, selected models, GitHub connections, billing plans, and related settings through the dashboard or admin/settings according to your role.

You may request access, correction, export, or deletion of personal information, subject to security and legal limitations.

Workspace or organization administrators are responsible for assigning appropriate permissions and avoiding unnecessary sensitive data in AI workflows.

8. Cookies and Local Storage

The service may use cookies or local storage to remember sessions, access tokens, language, theme, sound preference, and values required for the user experience.

Clearing cookies or local storage may require you to log in again or reset display preferences.

9. Data Security

We apply reasonable safeguards such as encryption at rest, masked secrets, access control, audit trails, runtime configuration protection, and role-based permissions.

No online system is completely secure. Users should use strong passwords, enable secure sign-in methods when available, and protect their API keys carefully.

10. Policy Updates

We may update this policy when product functionality, providers, laws, or security practices change. The latest update date is shown on this page.

For material changes, we may notify users through the website, email, or another appropriate channel based on available contact information.