Privacy Policy

Effective Date: 2026-08-05 · Last Updated: 2026-08-21 · Version: 2026-08-21

Introduction

This Privacy Policy explains how GenieForge Technologies Inc. ("GenieForge," "we," "us," or "our") collects, uses, and protects information when you visit our website, create a Builder account, or use our platform to build applications.

This policy applies to platform users ("Builders") and visitors to genieforge.ai. If you are an end-user of an application built on GenieForge, please refer to our End-User Privacy Policy.


Information We Collect

Information You Provide

  • Account information: Name, email address, phone number (if provided), company name (if provided), and authentication credentials. Builder passwords are handled by our self-hosted identity service on our infrastructure and stored in irreversible hashed form.
  • Billing information: Payment details processed by our payment provider (Stripe). We do not store full card numbers. We retain billing identifiers, emails, and subscription records as needed to bill you.
  • App content: System prompts, tool configurations, page designs, schemas, environment-variable metadata, and other content you create while building applications
  • Conversations and AI activity: Messages exchanged with AI assistants, tool call inputs and results, uploaded attachments, and optional per-user memories when enabled
  • Support, feedback, and usage signals: Bug reports, feature requests, product-assistant feedback, and usage signals captured from Apps (title and description text) so we can help you improve those Apps and improve the Platform. That text is stored in Platform tables, clustered with embeddings, and reviewed by authorized GenieForge staff. Enhancement proposals created from those signals are reviewed the same way.
  • Communications: Emails and messages you send to support or legal contacts

Information Collected Automatically

  • Usage data: Features used, pages visited, session timestamps, and similar product analytics events
  • Device and browser information: Browser type, operating system, screen resolution, and similar technical data
  • IP address: For security, rate limiting, approximate region detection, and abuse prevention
  • Cookies and similar technologies: Session cookies (required for authentication), preference cookies, and analytics cookies as described in the Cookies section

Information We Do Not Collect (by default)

  • We do not use third-party advertising trackers or sell personal information to data brokers
  • We do not collect biometric identifiers for Platform authentication
  • We do not collect precise GPS geolocation

Apps you build may collect additional categories of data from End-Users under your control. That collection is described in your notices and our End-User Privacy Policy.


How We Use Your Information

PurposeBasis (where applicable)
Provide, maintain, and secure the PlatformNecessary for service delivery / contract
Process payments and manage your subscriptionContractual obligation
Send account-related communications (password resets, billing alerts, security notices)Necessary for service delivery / legitimate interest
Improve the Platform (including aggregate or de-identified usage patterns and Feedback)Legitimate interest
Platform improvement review of App blueprints and Builder conversations (see below)Legitimate interest / contract
Detect and prevent fraud, abuse, or security incidentsLegitimate interest / legal obligation
Respond to support and privacy requestsContractual obligation / legal obligation
Comply with law and enforce our TermsLegal obligation / legitimate interest

Platform improvement review

Authorized GenieForge personnel may occasionally inspect Apps to improve the Platform. Reviews typically focus on App blueprints (tools, pages, schemas, prompts, configurations) and, when needed for context, Builder conversations and related build activity. They also include usage signals and enhancement proposals: builder-submitted free text copied into Platform staff-review tables, plus embeddings used to cluster similar items. Purposes include making the Platform more robust, identifying missing Platform primitives, and learning from general Builder behavior. Insights may inform our product roadmap in aggregated or de-identified form where practical.

These reviews are not used to train or fine-tune AI models, are not used to share your confidential App materials with other customers, and are subject to access controls. HIPAA-enabled Apps under a BAA are excluded from product-improvement inspection of App content and conversations, except as permitted under the BAA for Platform services, security, or support (including processing of usage signals and enhancement proposals as named in the BAA). End-User business data and End-User chat are not the focus of this review.

We do NOT:

  • Sell your personal information
  • Share your data with advertisers or data brokers for their independent marketing
  • Use your app content or build conversations to train or fine-tune AI models (Platform policy)

AI Processing

When you use AI features, your prompts, relevant App context, conversation history, and necessary attachments are processed by AI model providers to generate responses in real time. Categories of providers are listed on our Subprocessors page. For HIPAA-enabled Apps, AI processing is restricted to providers permitted under our Business Associate arrangements (currently AWS Bedrock within the HIPAA boundary).

Your conversations are not used by GenieForge to train or fine-tune AI models. Processing occurs under our agreements with providers. Model providers may process data in the regions where their services operate, as described on the Subprocessors page.

AI outputs can be wrong. Do not rely on them as sole professional advice.


Data Sharing

We share your information with service providers that help us operate the Platform, under contracts that restrict use of the data to providing services to us. Categories include:

CategoryPurposeExamples
Cloud infrastructureHosting, compute, storage, databases, email delivery, and our self-hosted identity serviceAmazon Web Services (United States)
CDN / edge / custom domainsCDN, DDoS protection, TLS termination, and vanity / custom hostname routingCloudflare
Payment processingSubscription billing and invoicingStripe
AI inferenceGenerate assistant and agent responsesAWS Bedrock; and for non-HIPAA Apps, providers such as Anthropic, OpenAI, and xAI
Product analyticsAggregate product usage analytics (opt-out; consent where required; disabled for HIPAA-touching builder contexts)PostHog
Optional Platform toolsFeatures you or your App enable (web search, transcription, scraping, image generation, push delivery, form captcha, currency conversion)Tavily, Soniox, Apify, OpenAI images, FCM / web push, hCaptcha, Frankfurter, jsDelivr, as configured
Customer-directed integrationsServices you connect (OAuth, webhooks, outbound HTTP)Destinations you authorize (Google, Slack, Notion, Stripe Connect, and others)

A living list of subprocessors is published at /subprocessors. We may update that page as providers change. For material changes affecting how personal information is processed, we will provide notice consistent with this Policy and applicable law.

We may also disclose information when required by law (for example, a valid court order or subpoena), to protect rights and safety, or in connection with a merger, acquisition, or asset sale (with appropriate safeguards).

Personnel in Canada may access systems and data as reasonably necessary to operate, support, and secure the Platform, and to perform Platform improvement review as described above.


Data Retention

Data TypeRetention Period
Account and profileUntil you delete your account or we close it
App content and configurationsUntil you delete the app or your account
Build conversations and attachmentsUntil you delete the conversation or your account
Usage signals and product feedbackUntil resolved/deleted in-product or account deletion, subject to de-identified improvement use
Billing recordsAs required by tax/financial law (typically up to 7 years)
Security and audit logsAs required by applicable law and our security program (multi-year for certain audit records)
Encrypted backupsLimited rolling window (on the order of about 35 days) before purge

Upon account deletion, personal data is removed from active systems within a commercially reasonable period, subject to legal retention and backup windows described above. To request deletion, email privacy@genieforge.ai.


Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access a copy of the personal data we hold about you
  • Correction of inaccurate data
  • Deletion of your account and personal data (subject to legal retention)
  • Data portability of data you provided, in a structured, commonly used format where technically feasible (App blueprint export is available in-product; full account portability packages are handled via privacy requests)
  • Object to certain processing activities
  • Withdraw consent where processing is based on consent

To exercise any right, email privacy@genieforge.ai. We aim to respond within 30 days, or within the period required by applicable law if shorter or longer.

Canadian privacy (PIPEDA and applicable provincial laws)

If you are in Canada, you may request access to and correction of personal information we hold about you, subject to limited exceptions. Contact privacy@genieforge.ai. You may also contact the Office of the Privacy Commissioner of Canada regarding unresolved concerns.

California (CCPA / CPRA)

If you are a California resident, you may have rights to know, delete, and correct personal information, and to opt out of "sale" or "sharing" for cross-context behavioral advertising. GenieForge does not sell personal information and does not share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics about you beyond providing the Platform. To exercise rights, email privacy@genieforge.ai. We will not discriminate against you for exercising privacy rights.

European Economic Area / UK

If GDPR or UK GDPR applies, our legal bases are described in the table above. For transfers outside the EEA/UK, we may rely on legally recognized transfer mechanisms and safeguards permitted by applicable law. Contact privacy@genieforge.ai for questions. You may have the right to lodge a complaint with a supervisory authority.


Cookies

We use the following categories of cookies and similar technologies:

CategoryPurposeDurationRequired?
Session / authenticationKeeps you logged in and secures the sessionBrowser session or as set by our identity serviceYes
PreferencesRemembers UI settings (for example, theme)Up to 1 yearNo (functional)
Analytics (PostHog)Product analytics (page views, feature usage) to improve the PlatformPer PostHog configurationNo; opt-out via cookie preferences (consent where required)

We do not use third-party advertising cookies.

Analytics are disabled for HIPAA-touching builder contexts and on certain End-User surfaces (for example, intake and portal) as implemented in the product. You can decline analytics cookies in our cookie preferences UI where shown. See also /subprocessors.


Security

We implement technical and organizational measures we consider reasonable for a service of this type, which may include encryption in transit and at rest, access controls, audit logging of security-sensitive actions, and periodic security reviews. Details for enterprise diligence may be available on request. No method of transmission or storage is 100% secure, and we do not guarantee that unauthorized access will never occur.


HIPAA-Eligible Accounts

If you enable HIPAA mode for an application and execute a BAA, additional safeguards apply to how End-User data is handled within that application under the BAA. Enabling HIPAA mode does not change how your Builder account data is handled for Platform administration; it applies to End-User data within that specific App. GenieForge does not claim a general "HIPAA certification" of your App; compliance depends on your configuration and practices as well as ours. Custom domains may route traffic through Cloudflare; for PHI, use GenieForge-provided hostnames unless we have confirmed that the custom-domain path is covered under applicable Business Associate arrangements. See /subprocessors.


International Users

GenieForge Technologies Inc. is based in Canada. Infrastructure is hosted in the United States. Personnel in Canada may access systems and data as reasonably necessary to operate, support, and secure the Platform. Your use of the Platform may involve transfer and processing of personal information in the United States and Canada. We may rely on legally recognized transfer mechanisms and safeguards permitted by applicable law.


Children

GenieForge Builder accounts are for individuals 18 and older. The Platform is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact privacy@genieforge.ai and we will take appropriate steps to delete it.


Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy with a new Version and Last Updated date. For material changes, we will provide notice via email and/or in-app notification when practicable. Unless we state a later effective date, changes take effect when posted. Continued use after the effective date constitutes acceptance of the updated Policy.


Contact

For privacy inquiries: