EngineForge Privacy Policy

Last updated 7/23/2026

EngineForge Privacy Policy

Version: 2026-07-23-alpha-1
Effective date: July 23, 2026

1. Scope

This Privacy Policy explains how EngineForge, a Pennsylvania sole proprietorship (“EngineForge,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal information in connection with:

  • engineforge.dev and related EngineForge pages.
  • Customer registration and authentication.
  • The customer dashboard and builder.
  • Deployment, update, export, and hosted-management services.
  • Customer support and alpha feedback.
  • EngineForge-operated authentication and other centralized services used by deployed customer sites.
  • Related administrative, security, and operational functions.

This Policy primarily addresses EngineForge customers, prospective customers, website visitors, waitlist members, and people who communicate directly with EngineForge.

A separate Runtime End-User Privacy Policy addresses people who register for or use an EngineForge-powered customer site.

2. Who operates EngineForge

EngineForge is operated as a sole proprietorship based in Pennsylvania, United States.

Privacy questions and requests may be sent to support@engineforge.dev.

3. Information we collect

Account and identity information

We may collect:

  • Name or display name.
  • Email address.
  • Authentication-provider identifiers.
  • Email-verification status.
  • Password-authentication and password-reset events.
  • Multifactor-authentication status.
  • Session, recovery, and account-security information.
  • Account status and creation dates.
  • Legal-document acceptance records.

Passwords are handled through authentication systems and are not intended to be stored by EngineForge in readable form.

Waitlist and communication information

We may collect:

  • Email address.
  • Invitation or alpha-access status.
  • Waitlist source.
  • Product-update consent.
  • Messages, replies, and communication history.

Project and site information

We may collect or process:

  • Project and build names.
  • Site names, domains, and URLs.
  • Site configuration and settings.
  • Character information and assets.
  • Prompts, instructions, images, uploads, and generated output.
  • Membership, role, usage, and feature settings.
  • Deployment and update state.
  • Runtime configuration and compatibility information.

Provider and connection information

When you connect a provider or hosting account, we may process:

  • Provider account identifiers.
  • Service, project, or deployment identifiers.
  • API keys, tokens, or connection credentials.
  • Provider configuration and selected models.
  • Usage status, error information, and account-readiness information.

Where supported, sensitive credentials are stored using encryption or comparable security controls. You should still treat all connected credentials as sensitive.

Deployment and operational information

We may collect:

  • Hosting service IDs.
  • Database and deployment metadata.
  • Build and source revision information.
  • Deployment, update, migration, and readiness status.
  • Error codes and diagnostic details.
  • Operational events and audit records.
  • IP address, browser, device, request, and security-log information.
  • Rate-limit and abuse-prevention data.

Support and feedback information

We may collect:

  • Support tickets and messages.
  • Attachments and screenshots.
  • Alpha feedback.
  • Troubleshooting details.
  • Authorized support snapshots.
  • Information about the affected project, site, deployment, or provider.

A support snapshot may contain site configuration, operational state, selected content, provider metadata, schema information, or other site data reasonably needed to investigate a problem. A snapshot is submitted only through the applicable authorization flow.

Billing information

If paid EngineForge features become available, we may collect:

  • Plan and subscription status.
  • Billing contact information.
  • Transaction and invoice identifiers.
  • Payment status.
  • Limited payment-method metadata supplied by the processor.

Payment-card numbers and similar payment credentials are generally handled by the payment processor rather than stored directly by EngineForge.

Information from third parties

We may receive information from:

  • Authentication providers.
  • Hosting and infrastructure providers.
  • AI and model providers.
  • Email-delivery providers.
  • Payment processors.
  • A person who invites or administers your account.
  • Security, fraud-prevention, and abuse-prevention services.

4. How we use information

We use personal information to:

  • Create and secure accounts.
  • Verify identity and email addresses.
  • Provide customer support.
  • Operate the dashboard, builder, and related tools.
  • Generate requested AI output.
  • Connect and communicate with third-party providers.
  • Package, deploy, update, and troubleshoot sites.
  • Maintain service reliability and compatibility.
  • Detect abuse, fraud, security incidents, and unauthorized access.
  • Enforce usage limits and legal requirements.
  • Record legal acceptance.
  • Process payments where applicable.
  • Send service, security, and account communications.
  • Send product updates where consent or another lawful basis permits.
  • Analyze and improve Service operation.
  • Comply with law and protect legal rights.
  • Investigate and resolve disputes.

EngineForge does not itself use Customer Content to train a general-purpose AI model unless the customer separately and affirmatively agrees.

5. AI-provider processing

When you use AI features, prompts, instructions, images, training data, and other inputs may be transmitted to the provider selected or configured for that feature.

Providers may include services such as OpenAI, OpenRouter, FAL, or other providers supported by EngineForge.

Those providers may process and retain information under their own:

  • Terms of service.
  • Privacy policies.
  • Enterprise or API data-use terms.
  • Account settings.
  • Safety and abuse-monitoring practices.

You are responsible for reviewing the provider terms applicable to your connected account and intended use.

Do not submit highly sensitive personal information to an AI feature unless you have determined that the feature, provider, settings, and legal basis are appropriate.

6. How we disclose information

We may disclose personal information to:

Service providers

We may use companies that provide:

  • Hosting and databases.
  • Authentication.
  • AI inference, generation, and model training.
  • Email delivery.
  • Payment processing.
  • Storage and content delivery.
  • Monitoring and security.
  • Rate limiting and abuse prevention.
  • Customer support and communications.

They may process information only as necessary to provide the applicable service, subject to their agreements and legal obligations.

Providers selected by you

When you connect or select a provider, we disclose information necessary to fulfill your request. Your provider account and provider agreement may independently control that processing.

Your authorized users and administrators

Information may be visible to people authorized to manage your EngineForge account, project, or deployed site.

Legal and safety disclosures

We may disclose information when reasonably necessary to:

  • Comply with law, court process, or valid government requests.
  • Protect the security or integrity of the Service.
  • Investigate fraud, abuse, or threats.
  • Protect the rights and safety of EngineForge, customers, end users, or others.
  • Enforce agreements.
  • Establish or defend legal claims.

Business transfers

Information may be transferred as part of a proposed or completed sale, merger, financing, reorganization, asset transfer, or succession of EngineForge, subject to appropriate confidentiality and legal protections.

With your direction or consent

We may disclose information when you request, authorize, or consent to the disclosure.

7. Sale and targeted advertising

EngineForge does not currently sell personal information for monetary payment.

EngineForge does not currently use personal information for cross-context behavioral advertising.

If these practices materially change, we will update this Policy and provide any notice or choices required by law.

A Site Operator may add independent tools or conduct independent processing on a deployed site. Those practices are the Site Operator’s responsibility and should be disclosed separately.

8. Cookies and similar technologies

EngineForge may use cookies, local storage, tokens, and similar technologies for:

  • Authentication and session continuity.
  • Security and fraud prevention.
  • Preferences.
  • Feature operation.
  • Performance and reliability.
  • Remembering legal or account state.

Blocking essential storage may prevent parts of the Service from working.

9. Retention

We retain information for as long as reasonably necessary for the purposes described in this Policy, including to:

  • Maintain an active account.
  • Provide and support projects and deployed sites.
  • Complete requested transactions.
  • Preserve security and audit records.
  • Maintain legal-acceptance evidence.
  • Resolve disputes.
  • Enforce agreements.
  • Comply with tax, accounting, recordkeeping, and legal obligations.
  • Maintain limited backups and disaster-recovery systems.

Retention varies based on the information’s nature, sensitivity, purpose, account status, and legal requirements.

Deleting an account may not immediately remove information from backups, legal records, security logs, support history, or systems controlled by a third-party provider.

10. Security

We use administrative, technical, and organizational safeguards designed to protect personal information.

These safeguards may include:

  • Authentication and access controls.
  • Encryption of selected credentials and sensitive fields.
  • Session protection.
  • Rate limiting.
  • Audit and operational logging.
  • Restricted administrative access.
  • Provider and deployment validation.
  • Security review and testing.

No method of storage or transmission is completely secure. We cannot guarantee that unauthorized access, loss, or misuse will never occur.

If a qualifying data breach occurs, we will provide legally required notices.

11. Your choices and privacy rights

Depending on applicable law, you may have rights to:

  • Request access to personal information.
  • Request correction of inaccurate information.
  • Request deletion.
  • Request a portable copy.
  • Object to or restrict certain processing.
  • Withdraw consent.
  • Opt out of marketing communications.
  • Appeal a denied privacy request where required.

To submit a request, email support@engineforge.dev.

We may need to verify your identity and authority before completing a request. We may deny or limit a request where permitted, including when information must be retained for security, fraud prevention, legal claims, transaction records, legal acceptance, or compliance obligations.

You can unsubscribe from promotional email through the provided unsubscribe method. You may still receive account, security, transactional, legal, and service communications.

12. Children

EngineForge and the closed-alpha Service are intended only for people age 18 or older.

Customers may not use EngineForge during the closed alpha to operate a site directed to minors without prior written approval and appropriate legal and technical safeguards.

We do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information, contact support@engineforge.dev.

13. International processing

EngineForge is based in the United States.

Information may be processed in the United States and in other countries where service providers operate. Those countries may have privacy laws different from those in your jurisdiction.

Where required, we will use appropriate mechanisms for international transfers.

14. Third-party sites and services

The Service may link to or integrate with third-party services.

This Policy does not govern the independent privacy practices of:

  • Hosting providers.
  • AI providers.
  • Authentication providers.
  • Payment processors.
  • Customer-operated sites.
  • Other linked websites or services.

Review their privacy notices before providing information.

15. Changes to this Policy

We may update this Policy to reflect changes in law, technology, providers, features, or business practices.

We will post the updated version with a new effective date. When required or appropriate, we may provide additional notice or require renewed acknowledgment.

16. Contact

Privacy questions, requests, and general support:

EngineForge Support
support@engineforge.dev