Privacy Policy | Forge
Last updated: 18 August 2026
Who We Are
Forge is an AI-assisted development and website-building platform. The data controller is Digital Footprint Ltd, trading as Forge, London, United Kingdom. Privacy enquiries: info@digital-footprint.uk
Information We Collect
Depending on how you use Forge, we may collect:
- Account information: name, email address, account identifier, profile information, authentication information, account preferences, organisation or workspace information.
- Project information: project names, website content, uploaded files, images and media, source code, configuration information, AI prompts, AI-generated outputs, templates, build and deployment information, project activity.
- Technical information: IP address, browser type, device type, operating system, date and time of access, pages or features used, session information, error reports, security logs, performance information.
- Billing information: subscription plan, payment status, billing history, transaction identifiers. Payment card information is handled directly by our payment provider.
AI Services
Forge may allow users to connect or use artificial intelligence providers. Information submitted to an AI feature may include prompts, project instructions, code, uploaded content, selected project context, and previous conversation context where required. Forge will only send information to an AI provider where necessary to provide the feature requested by the user.
Connected Services and Integrations
Forge may allow users to connect third-party services including development platforms, cloud services, payment providers, communication platforms and social-media services. When you choose to connect an external service, Forge may receive information made available by that service according to the permissions you approve.
Meta, Facebook and Instagram Data
Forge may provide integrations with services operated by Meta Platforms, including Facebook and Instagram. If you choose to connect a Meta account, Facebook Page, Instagram account or another supported Meta service, Forge may receive information authorised by you and permitted by Meta.
Depending on the feature and permissions approved, this may include:
- Meta user identifier
- Name or profile information
- Email address where provided by Meta and authorised
- Facebook Page identifiers and Page names
- Instagram professional or business account identifiers
- Account information necessary to establish the integration
- Access tokens or authorised connection credentials
- Content selected for publishing or management
- Publishing status
- Post or media identifiers
- Page or account information
- Engagement or performance information where specifically authorised
- Other information made available through approved Meta APIs
Forge does not obtain access to your Facebook or Instagram password.
Information received from Meta is used only for legitimate Forge functionality that you request or authorise, such as: connecting your Meta account to Forge, identifying authorised Pages or accounts, displaying connected account information, creating or managing authorised integrations, publishing content where you explicitly request that functionality, retrieving permitted content or account information, providing analytics or reporting where authorised, maintaining and securing the Meta integration, and diagnosing connection or API errors.
Forge will not use Meta Platform Data for purposes that are materially different from those disclosed to you when access is requested.
Meta Platform Compliance
Our use of information received from Meta APIs is intended to comply with applicable Meta Platform Terms, Meta Developer Policies, Meta permissions and App Review requirements, and applicable data-protection legislation.
Access to Meta information is limited to the permissions granted by the user and approved for the Forge application.
We do not sell Meta Platform Data.
We do not provide Meta Platform Data to data brokers.
We do not use Meta Platform Data for unauthorised surveillance, profiling or purposes prohibited by Meta.
We do not request Meta permissions that are unnecessary for the functionality being provided.
Meta Access Tokens
Where a Meta integration requires an access token or similar credential, Forge may securely store the credential so the authorised integration can operate. Access tokens are treated as confidential credentials, restricted from public access, used only for authorised integration functionality, and removed, invalidated or made unusable where appropriate following account disconnection, revocation or deletion.
How We Use Personal Information
We may use information to: create and manage Forge accounts, provide Forge functionality, operate AI-assisted development features, store projects and user settings, authenticate users, manage subscriptions, process payments, operate authorised integrations, provide customer support, send service-related communications, detect misuse or fraud, protect accounts and infrastructure, diagnose technical problems, improve reliability and performance, comply with legal obligations, and establish, exercise or defend legal claims.
Legal Bases for Processing
Where UK GDPR or similar legislation applies, we may process personal information on one or more of the following legal bases:
- Contract — processing necessary to provide Forge services that you have requested.
- Legitimate interests — processing necessary for legitimate business purposes such as maintaining service security, preventing fraud, improving reliability, providing customer support, and protecting our systems. We consider the impact on your privacy before relying on legitimate interests.
- Consent — where required, we may process information based on your consent. You may withdraw consent where applicable.
- Legal obligation — we may process or retain certain information where required by law.
Sharing Information
We may share information with service providers where necessary to operate Forge. These may include providers of: cloud hosting, databases, authentication, AI services, payment processing, email delivery, analytics, error monitoring, security, infrastructure, and connected third-party integrations. Service providers should receive only the information reasonably necessary to provide their service.
Selling Personal Information
Forge does not sell personal information in the ordinary meaning of selling data for monetary consideration. Forge does not sell information received through Meta APIs.
Data Retention
We retain personal information only for as long as reasonably necessary for: providing Forge services, maintaining your account, maintaining authorised integrations, security, fraud prevention, resolving disputes, meeting contractual obligations, and meeting legal or regulatory requirements. When information is no longer required, it will be deleted or anonymised where reasonably practicable. Backups may retain information for a limited additional period before being automatically overwritten or securely deleted.
Account and Data Deletion
You may request deletion of your Forge account and associated personal information. Where available, this may be performed through your Forge account settings. You may also submit a deletion request using our Data Deletion Instructions or contact info@digital-footprint.uk.
We may need to verify your identity before completing a deletion request. Once a valid deletion request has been verified, we will delete or anonymise applicable personal information unless retention is required by law or another lawful reason applies.
Facebook and Instagram Data Deletion
If you have connected Facebook, Instagram or another Meta service to Forge, you may request deletion of information obtained through that integration. You can do this by: disconnecting the relevant Meta integration within Forge where that option is available; removing Forge from the Apps and Websites or connected-app settings provided by Meta; submitting a deletion request through our Data Deletion page; or contacting us at info@digital-footprint.uk.
Following a valid deletion request, Forge will delete or anonymise applicable Meta Platform Data held by Forge unless retention is required by law.
Your Data Protection Rights
Depending on where you live, you may have rights including: the right to access personal information, the right to correct inaccurate information, the right to request deletion, the right to restrict processing, the right to object to certain processing, the right to data portability, the right to withdraw consent, and the right to complain to a data-protection authority. In the United Kingdom, you may have the right to complain to the Information Commissioner's Office.
Security
We use reasonable technical and organisational measures designed to protect information against unauthorised access, loss, misuse, disclosure, alteration and destruction. Measures may include authentication controls, access restrictions, encrypted connections, credential protection, logging and monitoring. No internet-based service can guarantee absolute security.
International Data Transfers
Some service providers used by Forge may process information outside the United Kingdom. Where required, appropriate safeguards will be used for international transfers of personal information. These may include approved contractual protections or other lawful transfer mechanisms.
Cookies and Similar Technologies
Forge may use cookies, browser storage or similar technologies to: maintain login sessions, protect accounts, remember preferences, provide essential functionality, understand service performance, and diagnose problems. Where non-essential cookies require consent under applicable law, consent will be requested before those cookies are used.
Children's Privacy
Forge is not intended for children under the minimum age permitted to use the service. We do not knowingly collect personal information from children where doing so would be unlawful. We do not knowingly provide Meta with information about children in circumstances prohibited by Meta's applicable developer requirements.
User Content
Users remain responsible for ensuring that information, files, media and other content uploaded to Forge may lawfully be processed. You should not upload personal information belonging to another person unless you have an appropriate legal basis or permission to do so.
Changes to This Privacy Policy
We may update this Privacy Policy as Forge, applicable laws or third-party platform requirements change. The current version will always display the date on which it was last updated. Where appropriate, we may provide additional notice of material changes.
Contact Us
For privacy questions, requests or complaints, contact:
Digital Footprint Ltd
Trading as Forge
London, United Kingdom
Email: info@digital-footprint.uk
For requests specifically concerning deletion of your information, use our Data Deletion Instructions.
You are viewing the plain-text version of this policy because JavaScript is disabled in your browser. For the full experience, please enable JavaScript.