Privacy Policy
Last updated September 29, 2026
The registered company details for Webforgia are being finalised and will be added here. Until then, questions go to [email protected].
This explains what Webforgia collects when you use it, why, who else handles it, and what you can do about it. The short version: we collect what it takes to build and host your projects and to bill you for them, we never sell it or use it for ads, and most of the controls are yours to use directly.
On this page
1.Who we are
Webforgia is operated by the Webforgia team. For the personal data in your account, we are the controller: we decide why and how it is used.
For the data your published sites collect from their visitors — contact and newsletter forms — you are the controller and we process it on your behalf. Section 4 covers that.
Questions about this policy or your data: [email protected].
2.What we collect
Your account. Your name, email address, an optional username and profile picture, your language, and whether your profile is public (it is private unless you change it). Your password is stored only as a one-way scrypt hash; we cannot read it. If you sign in with Google, we receive your Google name, email and picture.
Security. If you turn on two-factor authentication, its secret is stored encrypted and its backup codes are stored hashed. Each signed-in device is a session with the time it started and its IP address; sessions end after 30 days.
What you make. Your prompts and chat messages, the files and images you attach, the projects and site specifications Webforgia generates, images generated for you, your published sites, and the skills, brand details and notes you save.
Workspace and team. Workspace names and settings, members and their roles, invitations, groups, verified domains and single sign-on settings, and an audit log of changes to the workspace, which records the email of the person who made each one.
Billing. Your plan, your credit balance and its history, and references to your Stripe customer and subscription. Card details are entered on Stripe and held by Stripe; they never reach our servers.
Integrations. If you connect GitHub, an access token (stored encrypted) and your GitHub username. If you connect a delivery channel such as Slack, Discord, a webhook or email, its address is stored encrypted. Public links you add, like a booking or payment link, are stored as they appear on your site.
API keys. A name, the key’s scopes, when it expires and when it was last used. The key itself is shown to you once and stored only as a hash.
Usage. Which pages of webforgia.com are visited, counted under an anonymous visitor ID (see section 7). The path of the page is recorded, not what you type on it. We also record builds and their cost, which is how credit is charged.
Messages to us. Whatever you send when you email support or send feedback.
3.How we use it
- To run Webforgia: sign you in, build and host your projects, publish your sites, and deliver form submissions to you.
- To charge for what you use and keep your balance and invoices correct.
- To keep accounts and sites secure: two-factor sign-in, session management, and the Security center’s checks of your own workspace.
- To understand which parts of the product are used, from page-view counts, and to fix what breaks.
- To answer you when you contact us, and to tell you about changes to the service or these terms.
- To meet legal obligations and to prevent abuse of the service.
We do not sell your personal data, we do not use it for advertising, and we do not use your prompts or projects to train AI models of our own.
Where the law asks for a legal basis: running the service and billing are necessary to perform our contract with you; security, abuse prevention and usage counts are our legitimate interests; and anything we would otherwise need your consent for, we will ask for first.
4.Visitors to sites you publish
A published Webforgia site sets no cookies and runs no tracking. Its contact and newsletter forms send what the visitor types — typically a name, an email address and a message — to Webforgia, which stores it for the site’s owner under Submissions and forwards it to any delivery channel the owner has connected.
For that data the site owner is the controller and we are their processor: we store and deliver it only to provide the service to them. If you publish a site that collects submissions, you are responsible for telling your visitors how you use what they send, and for answering their requests about it. Deleting a workspace deletes its submissions.
5.AI processing
Building and editing a project sends your prompt, the files and images you attach, and the relevant project content to the AI model providers listed in section 6, Anthropic and OpenAI, and their answer comes back to Webforgia. Generating an image sends a description of it.
These providers process that data to return a result to us. Both state in their API terms that they do not use API data to train their models by default. Avoid putting information into a prompt that you would not want processed this way.
8.How long we keep it
- Your account, projects and published sites: for as long as you keep them.
- Signed-in sessions: 30 days, or until you sign out or sign the device out.
- Form submissions: until the site owner deletes them or the workspace.
- Billing records: as long as tax and accounting law requires, which can outlast the account.
- Deleting a workspace permanently deletes its projects, published sites, domains and form submissions. Copies can remain in backups for a limited period before they are overwritten.
9.Your choices and rights
Much of this you can do yourself, right now:
- Get a copy of your account and every project in your workspace: Settings → Privacy → Export everything.
- Correct your name, username and language: Settings → Account.
- Sign out devices you do not recognise: Settings → Devices & apps.
- Stop page-view counting for your workspace, and keep sites out of search engines: Settings → Privacy.
- Delete a workspace and everything in it: Settings → Workspace (the owner).
To delete your own account, or for anything else — access, correction, objecting to a use, restricting it, or moving your data elsewhere — email [email protected]. We will answer within 30 days, and we may need to confirm it is you first. Depending on where you live you may also have the right to complain to your data protection authority.
10.How we protect it
Everything travels over HTTPS. Passwords are hashed with scrypt, and stored credentials — two-factor secrets, GitHub tokens and delivery channel addresses — are encrypted with AES-256-GCM. Every workspace’s data is separated at the database level, so one workspace cannot read another’s. Two-factor sign-in is available on every plan, and the Security center checks your own workspace for weak spots. No system is perfectly secure; if something goes wrong that affects your data, we will tell you as the law requires.
11.Where your data is processed
Webforgia’s servers and database run in New York, United States, and most of the services in section 6 are in the United States. If you are elsewhere, your data is transferred there. Where the law requires it, those transfers rely on safeguards such as the European Commission’s standard contractual clauses.
12.Children
Webforgia is not for anyone under 16, and we do not knowingly collect data from them. If you believe a child has an account, email [email protected] and we will remove it.
13.Changes to this policy
When this policy changes, the date at the top changes with it. If a change matters — a new kind of data, or a new use of it — we will tell you in the product or by email before it takes effect.
14.Contact
Webforgia · [email protected]
See also the Terms of Service.