Privacy Policy — BrandForge OS

Effective: 26 August 2026 • Last updated: 26 August 2026 (hosted hybrid)

1. The short version

BrandForge OS is local-first. Your campaigns, client profiles, memory files, and API keys are stored on your machine. The desktop app does not phone home and stores campaigns on your machine. The optional hosted cloud product stores account and campaign data on our servers as described below. Neither product sells your content.

2. What happens when you connect an AI provider

If you connect an online provider, the prompts you send are transmitted to that provider's servers and processed under their privacy policy. The app currently supports: Groq, Gemini (Google), Anthropic (Claude), OpenRouter, DeepSeek, Kimi (Moonshot), xAI (Grok), and a local Ollama endpoint (the default is localhost; a remote operator-configured URL is possible). Online campaign mode may make one live web-search request (the query is your industry and product name only — never your full campaign content) via the configured search backend (DuckDuckGo by default; Brave and Tavily if you set their API keys). When an online provider is connected, campaign visuals may additionally call the configured image API with a short product-and-style prompt only (never your full campaign content). Offline engine mode, and local Ollama mode for the automatic search/image steps, make no cloud AI-provider, image-API, or automatic search calls; it labels the research step unavailable rather than fabricating data. The dashboard also shows a live network ledger — an exact per-host count of every outbound request the app has made this session — so "offline means zero network" is verifiable on your screen, not a claim. The update check (GitHub releases) runs only if you opt in via the one-time dashboard prompt or BRANDFORGE_UPDATE_CHECK=1 — off by default — and when on, it appears in that ledger like every other call.

2b. Hosted cloud accounts (hybrid)

If you use BrandForge OS Hosted (browser login at our app domain), we store your email, password hash (PBKDF2 — we never store plaintext passwords), name, plan tier, brand profiles, and campaign content you generate on our servers so the product can function. Session cookies identify your logged-in browser. Hosted Free/Pro/Agency limits are enforced server-side. You may request export or deletion of hosted account data at support@brandforgeos.com. The desktop one-time app remains local-first: campaign files stay on your machine unless you connect an online AI provider.

3. Payments

Payments are processed by Paddle (merchant of record). Paddle handles card data, taxes and invoicing; we never see or store your payment card. We receive an order reference (email + product) for license delivery and support.

3b. Waitlist

If you join the pre-launch waitlist, the email address and selected tier are sent through FormSubmit.co to the configured BrandForge inbox. We use that information to contact you about launch availability and related product updates; do not submit sensitive information in the form. To opt out or request deletion, email support@brandforgeos.com.

4. Analytics

The sales website may use privacy-respecting analytics (e.g., GA4 with IP anonymization) to understand aggregate visits. We do not run remarketing pixels that build ad profiles of individual visitors.

5. Your rights

Because your data lives on your machine, you can export or delete it at any time — the output/, memory/ and agency_clients/ folders are plain files. For order-related data we hold, email support@brandforgeos.com to request access or deletion.

6. Contact

support@brandforgeos.com

Part of the Forge AI Ecosystem · CopyForge AI © 2026 BrandForge OS