Privacy Policy
Effective Date: 2026-08-05 · Last Updated: 2026-08-21 · Version: 2026-08-21
Introduction
This Privacy Policy explains how GenieForge Technologies Inc. ("GenieForge," "we," "us," or "our") collects, uses, and protects information when you visit our website, create a Builder account, or use our platform to build applications.
This policy applies to platform users ("Builders") and visitors to genieforge.ai. If you are an end-user of an application built on GenieForge, please refer to our End-User Privacy Policy.
Information We Collect
Information You Provide
- Account information: Name, email address, phone number (if provided), company name (if provided), and authentication credentials. Builder passwords are handled by our self-hosted identity service on our infrastructure and stored in irreversible hashed form.
- Billing information: Payment details processed by our payment provider (Stripe). We do not store full card numbers. We retain billing identifiers, emails, and subscription records as needed to bill you.
- App content: System prompts, tool configurations, page designs, schemas, environment-variable metadata, and other content you create while building applications
- Conversations and AI activity: Messages exchanged with AI assistants, tool call inputs and results, uploaded attachments, and optional per-user memories when enabled
- Support, feedback, and usage signals: Bug reports, feature requests, product-assistant feedback, and usage signals captured from Apps (title and description text) so we can help you improve those Apps and improve the Platform. That text is stored in Platform tables, clustered with embeddings, and reviewed by authorized GenieForge staff. Enhancement proposals created from those signals are reviewed the same way.
- Communications: Emails and messages you send to support or legal contacts
Information Collected Automatically
- Usage data: Features used, pages visited, session timestamps, and similar product analytics events
- Device and browser information: Browser type, operating system, screen resolution, and similar technical data
- IP address: For security, rate limiting, approximate region detection, and abuse prevention
- Cookies and similar technologies: Session cookies (required for authentication), preference cookies, and analytics cookies as described in the Cookies section
Information We Do Not Collect (by default)
- We do not use third-party advertising trackers or sell personal information to data brokers
- We do not collect biometric identifiers for Platform authentication
- We do not collect precise GPS geolocation
Apps you build may collect additional categories of data from End-Users under your control. That collection is described in your notices and our End-User Privacy Policy.
How We Use Your Information
| Purpose | Basis (where applicable) |
|---|---|
| Provide, maintain, and secure the Platform | Necessary for service delivery / contract |
| Process payments and manage your subscription | Contractual obligation |
| Send account-related communications (password resets, billing alerts, security notices) | Necessary for service delivery / legitimate interest |
| Improve the Platform (including aggregate or de-identified usage patterns and Feedback) | Legitimate interest |
| Platform improvement review of App blueprints and Builder conversations (see below) | Legitimate interest / contract |
| Detect and prevent fraud, abuse, or security incidents | Legitimate interest / legal obligation |
| Respond to support and privacy requests | Contractual obligation / legal obligation |
| Comply with law and enforce our Terms | Legal obligation / legitimate interest |
Platform improvement review
Authorized GenieForge personnel may occasionally inspect Apps to improve the Platform. Reviews typically focus on App blueprints (tools, pages, schemas, prompts, configurations) and, when needed for context, Builder conversations and related build activity. They also include usage signals and enhancement proposals: builder-submitted free text copied into Platform staff-review tables, plus embeddings used to cluster similar items. Purposes include making the Platform more robust, identifying missing Platform primitives, and learning from general Builder behavior. Insights may inform our product roadmap in aggregated or de-identified form where practical.
These reviews are not used to train or fine-tune AI models, are not used to share your confidential App materials with other customers, and are subject to access controls. HIPAA-enabled Apps under a BAA are excluded from product-improvement inspection of App content and conversations, except as permitted under the BAA for Platform services, security, or support (including processing of usage signals and enhancement proposals as named in the BAA). End-User business data and End-User chat are not the focus of this review.
We do NOT:
- Sell your personal information
- Share your data with advertisers or data brokers for their independent marketing
- Use your app content or build conversations to train or fine-tune AI models (Platform policy)
AI Processing
When you use AI features, your prompts, relevant App context, conversation history, and necessary attachments are processed by AI model providers to generate responses in real time. Categories of providers are listed on our Subprocessors page. For HIPAA-enabled Apps, AI processing is restricted to providers permitted under our Business Associate arrangements (currently AWS Bedrock within the HIPAA boundary).
Your conversations are not used by GenieForge to train or fine-tune AI models. Processing occurs under our agreements with providers. Model providers may process data in the regions where their services operate, as described on the Subprocessors page.
AI outputs can be wrong. Do not rely on them as sole professional advice.
Data Sharing
We share your information with service providers that help us operate the Platform, under contracts that restrict use of the data to providing services to us. Categories include:
| Category | Purpose | Examples |
|---|---|---|
| Cloud infrastructure | Hosting, compute, storage, databases, email delivery, and our self-hosted identity service | Amazon Web Services (United States) |
| CDN / edge / custom domains | CDN, DDoS protection, TLS termination, and vanity / custom hostname routing | Cloudflare |
| Payment processing | Subscription billing and invoicing | Stripe |
| AI inference | Generate assistant and agent responses | AWS Bedrock; and for non-HIPAA Apps, providers such as Anthropic, OpenAI, and xAI |
| Product analytics | Aggregate product usage analytics (opt-out; consent where required; disabled for HIPAA-touching builder contexts) | PostHog |
| Optional Platform tools | Features you or your App enable (web search, transcription, scraping, image generation, push delivery, form captcha, currency conversion) | Tavily, Soniox, Apify, OpenAI images, FCM / web push, hCaptcha, Frankfurter, jsDelivr, as configured |
| Customer-directed integrations | Services you connect (OAuth, webhooks, outbound HTTP) | Destinations you authorize (Google, Slack, Notion, Stripe Connect, and others) |
A living list of subprocessors is published at /subprocessors. We may update that page as providers change. For material changes affecting how personal information is processed, we will provide notice consistent with this Policy and applicable law.
We may also disclose information when required by law (for example, a valid court order or subpoena), to protect rights and safety, or in connection with a merger, acquisition, or asset sale (with appropriate safeguards).
Personnel in Canada may access systems and data as reasonably necessary to operate, support, and secure the Platform, and to perform Platform improvement review as described above.
Data Retention
| Data Type | Retention Period |
|---|---|
| Account and profile | Until you delete your account or we close it |
| App content and configurations | Until you delete the app or your account |
| Build conversations and attachments | Until you delete the conversation or your account |
| Usage signals and product feedback | Until resolved/deleted in-product or account deletion, subject to de-identified improvement use |
| Billing records | As required by tax/financial law (typically up to 7 years) |
| Security and audit logs | As required by applicable law and our security program (multi-year for certain audit records) |
| Encrypted backups | Limited rolling window (on the order of about 35 days) before purge |
Upon account deletion, personal data is removed from active systems within a commercially reasonable period, subject to legal retention and backup windows described above. To request deletion, email privacy@genieforge.ai.
Your Rights
Depending on your jurisdiction, you may have the right to:
- Access a copy of the personal data we hold about you
- Correction of inaccurate data
- Deletion of your account and personal data (subject to legal retention)
- Data portability of data you provided, in a structured, commonly used format where technically feasible (App blueprint export is available in-product; full account portability packages are handled via privacy requests)
- Object to certain processing activities
- Withdraw consent where processing is based on consent
To exercise any right, email privacy@genieforge.ai. We aim to respond within 30 days, or within the period required by applicable law if shorter or longer.
Canadian privacy (PIPEDA and applicable provincial laws)
If you are in Canada, you may request access to and correction of personal information we hold about you, subject to limited exceptions. Contact privacy@genieforge.ai. You may also contact the Office of the Privacy Commissioner of Canada regarding unresolved concerns.
California (CCPA / CPRA)
If you are a California resident, you may have rights to know, delete, and correct personal information, and to opt out of "sale" or "sharing" for cross-context behavioral advertising. GenieForge does not sell personal information and does not share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics about you beyond providing the Platform. To exercise rights, email privacy@genieforge.ai. We will not discriminate against you for exercising privacy rights.
European Economic Area / UK
If GDPR or UK GDPR applies, our legal bases are described in the table above. For transfers outside the EEA/UK, we may rely on legally recognized transfer mechanisms and safeguards permitted by applicable law. Contact privacy@genieforge.ai for questions. You may have the right to lodge a complaint with a supervisory authority.
Cookies
We use the following categories of cookies and similar technologies:
| Category | Purpose | Duration | Required? |
|---|---|---|---|
| Session / authentication | Keeps you logged in and secures the session | Browser session or as set by our identity service | Yes |
| Preferences | Remembers UI settings (for example, theme) | Up to 1 year | No (functional) |
| Analytics (PostHog) | Product analytics (page views, feature usage) to improve the Platform | Per PostHog configuration | No; opt-out via cookie preferences (consent where required) |
We do not use third-party advertising cookies.
Analytics are disabled for HIPAA-touching builder contexts and on certain End-User surfaces (for example, intake and portal) as implemented in the product. You can decline analytics cookies in our cookie preferences UI where shown. See also /subprocessors.
Security
We implement technical and organizational measures we consider reasonable for a service of this type, which may include encryption in transit and at rest, access controls, audit logging of security-sensitive actions, and periodic security reviews. Details for enterprise diligence may be available on request. No method of transmission or storage is 100% secure, and we do not guarantee that unauthorized access will never occur.
HIPAA-Eligible Accounts
If you enable HIPAA mode for an application and execute a BAA, additional safeguards apply to how End-User data is handled within that application under the BAA. Enabling HIPAA mode does not change how your Builder account data is handled for Platform administration; it applies to End-User data within that specific App. GenieForge does not claim a general "HIPAA certification" of your App; compliance depends on your configuration and practices as well as ours. Custom domains may route traffic through Cloudflare; for PHI, use GenieForge-provided hostnames unless we have confirmed that the custom-domain path is covered under applicable Business Associate arrangements. See /subprocessors.
International Users
GenieForge Technologies Inc. is based in Canada. Infrastructure is hosted in the United States. Personnel in Canada may access systems and data as reasonably necessary to operate, support, and secure the Platform. Your use of the Platform may involve transfer and processing of personal information in the United States and Canada. We may rely on legally recognized transfer mechanisms and safeguards permitted by applicable law.
Children
GenieForge Builder accounts are for individuals 18 and older. The Platform is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact privacy@genieforge.ai and we will take appropriate steps to delete it.
Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a new Version and Last Updated date. For material changes, we will provide notice via email and/or in-app notification when practicable. Unless we state a later effective date, changes take effect when posted. Continued use after the effective date constitutes acceptance of the updated Policy.
Contact
For privacy inquiries:
- Email: privacy@genieforge.ai
- Entity: GenieForge Technologies Inc.