Privacy Policy

Last Modified: March 25, 2026

Thank you for your interest in InsForge, Inc. ("InsForge," "we", "our" or "us"). InsForge provides a comprehensive Backend-as-a-Service (BaaS) platform specifically designed for AI coding agents, offering database services, authentication, file storage, API management, and agent orchestration capabilities. This Privacy Notice explains how information about you, that directly identifies you, or that makes you identifiable ("personal information") is collected, used and disclosed by InsForge in connection with our website at insforge.com (the "Site") and our services offered in connection with the Site (collectively with the Site, the "Service").

What Does This Privacy Notice Apply To?

This Privacy Notice explains how we use your personal information when you use the Service, either as an individual customer, through AI agents, or when you access the Service through one of our enterprise customers' accounts. We are the data controller of your personal information when we use it as described in this Privacy Notice, meaning that we determine and are responsible for how your personal information is processed.

Our Service allows customers to submit, manage or otherwise use content relating to others, including data generated by AI agents, end users of applications built and managed through the Service, or their employees and contractors ("Customer Data"). We use such Customer Data primarily as a processor, meaning we process such Customer Data on behalf of and under the instructions of the relevant customer, in accordance with our data processing agreements. This Privacy Notice does not apply to our processing of Customer Data in our capacity as a processor. If you are an end user of an application built on InsForge, please refer to the privacy notice of the relevant InsForge customer for information about how your data is handled.

This Privacy Notice does not apply to information about our employees or contractors, or to aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you.

Region-specific Disclosures

  • California - Your California Privacy Rights: If you are a California resident, California Civil Code Section 1798.83 permits you to request information regarding the disclosure of personal information to third parties for their direct marketing purposes. We do not sell your personal information as defined under the California Consumer Privacy Act (CCPA). You have the right to know what personal information we collect, the right to request deletion of your personal information, the right to correct inaccurate personal information, and the right to opt-out of the sale or sharing of personal information. To exercise these rights, contact us at [email protected]. We will not discriminate against you for exercising any of these rights.
  • Nevada: We do not sell your personal information within the meaning of Chapter 603A of the Nevada Revised Statutes. However, if you would like to submit an opt-out request, please contact us at [email protected].
  • European Economic Area, United Kingdom or Switzerland: If you are located in the EEA, UK, or Switzerland, please see Section 11 - European-Specific Disclosures below for additional privacy disclosures, including lawful bases for processing, international data transfer mechanisms, and your rights regarding personal information.
  • Note for International Visitors: Personal information may be transferred to, stored and processed in countries other than where it was collected. Our Services are primarily hosted in and provided from the United States. Where we transfer personal information internationally, we use appropriate safeguards as described in Section 12 - International Data Transfers.

1. Information We Collect and Our Use

We collect personal information in connection with your visits to and use of the Service, including information from AI agents operating on your behalf.

Information That You Provide

Registration information: We collect personal and/or business information when you register for an account, including your name, email address, GitHub username, and organization details. We use this information to administer your account, provide services, and communicate with you.

AI Agent Configuration: We collect information about AI agents you configure to use our Service, including agent identifiers, authentication credentials, and operational parameters. This helps us provide agent-specific services and monitor agent behavior.

Payment information: We collect transactional information for subscriptions and usage-based billing. We use third-party payment processors (including Stripe) and do not retain credit card numbers.

Communications: When you communicate with us, we collect your contact information and communication contents to respond to inquiries and improve our services.

User Content and AI-Generated Data: After registration, you may create, upload, or transmit files, documents, data, or information as part of your use of the Service, including data generated by AI agents. This includes inputs provided to AI systems and outputs generated in response. You have full control over this information.

Information from Third Party Sources

Single Sign-On: We use SSO services like GitHub to authenticate accounts. We receive information such as your name, username, email address, and profile information in accordance with third-party authorization procedures.

AI Agent Integrations: We may receive information from third-party AI services, development platforms, and code repositories that integrate with our Service to provide enhanced functionality for AI agents.

Social Media: When you interact with our Site through social media, we may receive profile information, usernames, and other data you permit the social network to share.

Information Collected Automatically

Device and Usage Data: We automatically collect information about your device and how you interact with our Service, including IP address, browser type, operating system, device identifiers, access times, pages viewed, links clicked, and referring URLs.

AI Agent Interaction Data: We collect metadata about AI agent interactions with our Service, including API call patterns, performance metrics, and error logs, to maintain and improve service quality.

2. How We Share Personal Information

We may share your personal information in the following instances:

  • Service Providers: We share information with third-party service providers who help deliver or improve our Services. These providers are contractually bound to use personal information only as instructed and subject to confidentiality obligations. Our key service providers include:
    • Cloud Infrastructure: Amazon Web Services (AWS) for hosting and compute
    • Payment Processing: Stripe for payment and billing
    • Analytics: Mixpanel for product analytics
    • Error Monitoring: Sentry for error tracking and performance monitoring
    • Email: Resend for transactional email delivery
    • Authentication: GitHub for SSO authentication
  • AI Service Partners: We may share data with AI service providers (such as OpenAI, Anthropic, or other AI model providers) solely to provide AI-powered features of our Service, subject to appropriate data protection agreements. We do not permit AI service partners to use your data for training their models.
  • Legal Requirements: We may share information as required by law, to comply with legal process, or to protect the rights, property, or safety of InsForge, our customers, or others.
  • Business Transfers: We may transfer information in connection with any merger, acquisition, or sale of assets, with reasonable efforts to ensure consistent treatment of personal information.
  • With Your Consent: We may share information for any other purpose with your prior authorization.
  • Aggregated/Anonymized Data: We may share aggregated or anonymized information that does not reasonably identify you directly or indirectly.

We do not sell your personal information to third parties. We do not share your personal information with third parties for their direct marketing purposes.

3. Your Rights and Control Over Your Information

Depending on your location, you may have the following rights with respect to your personal information. To exercise any of these rights, please contact us at [email protected].

Right of Access: You may request confirmation of whether we process your personal information and, if so, a copy of the personal information we hold about you, the categories of data, the purposes of processing, and the recipients to whom data has been disclosed.

Right to Rectification: You may request correction of inaccurate or incomplete personal information without undue delay.

Right to Erasure (Right to Delete): You may request that we delete your personal information where continued processing is no longer justified. Upon receiving a verified deletion request, we will delete your personal information from our active systems without undue delay, and instruct our service providers to do the same, unless we are required to retain it for legal, regulatory, or legitimate business purposes (such as fraud prevention or resolving disputes). See Section 6 - Data Deletion Requests for our detailed deletion procedure.

Right to Data Portability: You may request to receive a copy of the personal information you have provided to us in a structured, commonly used, machine-readable format (such as JSON or CSV).

Right to Restriction of Processing: You may request that we limit the processing of your personal information in certain circumstances, such as when you contest the accuracy of your data.

Right to Object: You may object to processing of your personal information based on our legitimate interests. For direct marketing, you may object at any time for any reason.

Right to Withdraw Consent: Where we rely on your consent to process personal information, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws. See Section 11 for relevant authority contact information.

Exercising Your Rights

To submit a request, email [email protected] with the subject line "Data Subject Request." We will respond to verified requests within 30 days. We may require you to verify your identity before fulfilling a request by providing information associated with your account. If we cannot verify your identity, we may be unable to fulfill the request.

You may also designate an authorized agent to make a request on your behalf, provided the agent can demonstrate valid authorization (such as a signed power of attorney or your direct written confirmation).

Email Communications

You may receive emails regarding Service updates, products, or promotional offers. Our marketing emails include tracking technologies to assess engagement. You can unsubscribe using the links in our emails. Note that you cannot unsubscribe from certain service-related communications.

Modifying Account Information

You can modify certain account information through your account settings. If you have provided consent for AI-powered services, you can update preferences or withdraw consent through account settings. For User Content, you can use Service features to edit or delete information.

AI Agent Data Management

You can manage AI agent configurations, review agent activity logs, and control data sharing preferences for AI-powered features through your account dashboard.

4. How We Use Cookies and Other Tracking Technology

We and our third-party partners automatically collect usage information through tracking technologies including cookies, web beacons, and similar technologies.

Cookies We Use

Strictly Necessary Cookies: Required for the Service to function. These include session cookies for authentication, CSRF protection tokens, and load balancing cookies. These cannot be disabled.

Analytics Cookies: We use Mixpanel to understand how users interact with our Service. These cookies collect information about pages visited, features used, and navigation patterns. You may opt out of analytics cookies through our cookie preferences or browser settings.

Third-Party Cookies: Our payment processor (Stripe) and authentication providers may set cookies for fraud detection and session management.

Information We Collect Automatically

  • Device and software information (IP address, browser type, operating system)
  • Mobile device identifiers and location information (where permitted)
  • Usage patterns and navigation behavior
  • AI agent interaction patterns and performance metrics

How We Use This Data

  • Remember user preferences and settings
  • Provide custom content and AI agent recommendations
  • Monitor Service effectiveness and AI agent performance
  • Analyze usage patterns and demographic information
  • Diagnose technical problems
  • Provide and enhance our services

Managing Your Preferences

You can manage cookie preferences through your browser settings. Note that blocking cookies may negatively impact your experience with AI-powered features. We honor "Do Not Track" signals sent by your browser; when detected, we will disable non-essential tracking technologies.

5. Data Retention

We retain personal information for the length of time needed to fulfill the purposes outlined in this Privacy Notice, unless a longer retention period is required by law. The specific retention period depends on the nature and sensitivity of the information, the purposes for which it is processed, and applicable legal requirements.

Account Information: We retain your account information for as long as your account is active. Upon account closure or deletion, we retain contact information for 60 days to allow for account recovery, after which it is permanently deleted from our active systems.

User Content and AI-Generated Data: Retained for the duration of your account. Upon account deletion, User Content is deleted within 30 days from our active systems. Backup copies may persist for up to 90 days before being overwritten.

Payment Records: Retained for as long as necessary to comply with tax, accounting, and financial reporting obligations (typically 7 years from the date of the transaction).

Usage and Analytics Data: Retained in identifiable form for up to 24 months, after which it is aggregated or anonymized.

AI Agent Interaction Logs: Retained for up to 12 months for service quality and debugging purposes, unless you request earlier deletion.

Communications: Support communications are retained for up to 24 months after resolution.

Legal Hold: If we are involved in litigation or a legal obligation requires it, we may retain information beyond normal retention periods until the matter is resolved.

6. Data Deletion Requests

You may request deletion of your personal information at any time. We take data deletion seriously and have established the following procedure:

How to Submit a Request: Send an email to [email protected] with the subject line "Data Deletion Request." Include your account email address and specify whether you want deletion of specific data or complete account and data deletion.

Identity Verification: To protect your privacy, we will verify your identity before processing a deletion request. We may ask you to confirm your identity via the email address associated with your account or provide additional identifying information.

Processing Timeline: We will acknowledge your request within 5 business days and complete the deletion within 30 days of verification. If we need additional time (up to 90 days for complex requests), we will notify you of the reason and expected completion date.

Scope of Deletion: Upon a verified deletion request, we will:

  • Delete your personal information from our active databases and systems
  • Instruct our service providers and sub-processors to delete your data
  • Remove AI agent configurations and associated interaction logs
  • Delete User Content you have created, uploaded, or transmitted through the Service

Exceptions: We may retain certain information where required by law, for fraud prevention, to resolve disputes, to enforce our agreements, or where deletion is technically infeasible. Backup copies may persist for up to 90 days before being overwritten in the normal course of backup rotation. We will inform you of any data we are unable to delete and the reason for retention.

Confirmation: Once deletion is complete, we will send you confirmation to the email address you provided with your request, including a summary of what was deleted and any data that was retained with the applicable legal basis for retention.

7. Security

We implement commercially reasonable physical, technical, and organizational measures to protect the security of personal information, including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls and multi-factor authentication for internal systems
  • Regular security assessments, penetration testing, and vulnerability scanning
  • Incident response procedures with defined escalation paths
  • Employee security awareness training
  • Audit logging and monitoring of access to personal information

However, no security system is completely secure, and we cannot guarantee the absolute security of your information.

Security Breach Notification

In the event of a security breach that affects your personal information, we will investigate the incident promptly and take appropriate steps to contain and remediate the breach. Where required by applicable law, we will notify affected individuals and relevant data protection authorities without undue delay, and in any event within the timelines required by applicable law (such as 72 hours under GDPR for authority notification). Our notification will include the nature of the breach, the categories of data affected, likely consequences, and the measures we have taken or propose to take to address the breach.

8. Links to Third-Party Websites and Services

Our Site may provide links to third-party websites or services, including AI model providers and development tools. We are not responsible for the practices of these third parties. Your interactions with third-party services are subject to their respective terms and policies. We encourage you to review the privacy notices of any third-party services you access through our Site.

9. Children's Privacy

Our services are not intended for children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected such information, we will delete it promptly. Contact us at [email protected] if you believe we have collected information from a child under 13.

10. Changes to Privacy Notice

We reserve the right to change this Privacy Notice from time to time. We will notify you of material changes through appropriate means, such as email notification to the address associated with your account or prominent notice on our Site, at least 30 days before the changes take effect. The "Last Modified" date at the top of this page indicates when this Privacy Notice was last revised. Your continued use of the Service after changes become effective constitutes your acceptance of the revised Privacy Notice.

11. European-Specific Disclosures (EEA, UK, Switzerland)

Legal Bases for Processing

If you are located in the EEA, UK, or Switzerland, we process your personal information only where we have a valid legal basis to do so:

  • Contract Performance: Processing necessary to provide the Service to you, including account creation, authentication, service delivery, and payment processing.
  • Legitimate Interests: Processing necessary for our legitimate business interests, including service improvement and analytics, fraud prevention and security, customer support, and enforcing our Terms of Service. We balance our interests against your rights and will not process where your interests override ours.
  • Consent: Processing based on your freely given, specific, informed, and unambiguous consent, including marketing communications, non-essential analytics and tracking technologies, and data sharing for AI-powered services. You may withdraw your consent at any time.
  • Legal Obligation: Processing necessary to comply with our legal obligations, including tax and accounting requirements, law enforcement disclosures, and regulatory compliance.

Your European Privacy Rights

In addition to the rights described in Section 3, EEA, UK, and Swiss residents have the right to lodge a complaint with their local supervisory authority:

12. International Data Transfers

InsForge is headquartered in the United States, and our Service is primarily hosted in the United States. If you are accessing the Service from outside the United States, your personal information will be transferred to the United States and potentially to other countries where our service providers operate.

Where we transfer personal information from the EEA, UK, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we use appropriate safeguards to protect your information, including:

  • Standard Contractual Clauses (SCCs): We use SCCs approved by the European Commission and the UK Information Commissioner's Office to govern transfers of personal information to the United States and other countries.
  • Data Processing Agreements: We maintain data processing agreements with all sub-processors that include appropriate data transfer mechanisms and security obligations.
  • Supplementary Measures: We implement additional technical and organizational safeguards, including encryption and access controls, to ensure the continued protection of transferred data.

You may request a copy of the relevant transfer mechanisms by contacting us at [email protected].

13. Contact Us

For inquiries about this Privacy Notice, to exercise your data subject rights, or to raise a privacy concern, please contact us:

We are committed to resolving complaints and concerns about your privacy and our collection and use of your personal information. If you are unsatisfied with our response, you have the right to lodge a complaint with the appropriate data protection authority in your jurisdiction.

Protecting Your Data Privacy | InsForge