Privacy Policy
Last updated: August 24, 2026
ForgeMuse (“ForgeMuse”, “we”, “us”) respects your privacy. This policy explains what personal data we collect when you visit forgemuse.net (the “Site”), join our beta, or use a ForgeMuse account and the desktop app (together, the “Service”), why we collect it, and the rights you have, including the rights granted to people in the European Economic Area (EEA), the United Kingdom and Switzerland under the GDPR.
Who we are
ForgeMuse, registered in the Netherlands (KVK 42109815, btw-id NL869775716B01), is the data controller for personal data processed through the Service. For any privacy question, or to exercise your rights, contact us at [email protected].
The short version
Your creative work stays on your machine. The code the swarm writes, the projects it builds, the prompts you give it: those live locally and run against your own Claude subscription. They do not pass through our servers. What does reach us is the minimum needed to run accounts, billing and the voice features, listed honestly below.
What we collect
- Beta signup details: the email address (and optionally name and project idea) you submit to join the beta.
- Account details: when you sign in, our authentication provider WorkOS gives us your name, email address and avatar. We also store the sign-in tokens that connect your devices, so you can see and revoke them on your dashboard.
- Billing details: payments are handled by Stripe. Stripe collects your card details and billing address; we never see your full card number. We store your Stripe customer reference and your subscription status.
- Voice audio: when you use voice features, your audio is relayed through our server to a speech-to-text provider (Groq), and text is relayed to a text-to-speech provider (ElevenLabs), so that our provider keys stay off your machine. We relay this data; we do not store your recordings or transcripts on our servers.
- Technical / server logs: our server automatically records basic technical data for security and reliability: your IP address, browser type (user-agent), the page requested and a timestamp. These logs are short-lived. We also keep an aggregate daily counter of how often each page was viewed; it is a bare number per page per day, with no cookie, IP address or anything else about you attached.
- Error diagnostics: if something breaks, our error-monitoring service (Sentry) receives technical details of the failure so we can fix it. We configure it not to include personally identifying content beyond what a request inherently carries (such as an IP address).
- What we do not collect: no advertising or analytics tracking, no behavioural profiling, no data sold or shared with advertisers, no third-party tracking pixels, and no copies of the code or projects the swarm builds for you.
Why we process your data (legal bases)
- Contract: running your account, your subscription and billing, and relaying voice audio when you use voice features. Without this processing the Service cannot work.
- Consent: adding your email to the beta list and sending you beta updates. Every such email contains an unsubscribe link, and you can withdraw consent at any time.
- Legitimate interests: keeping the Service secure and operational (short-lived server logs, error diagnostics, abuse prevention). We balance this against your rights and freedoms.
- Legal obligation: keeping invoices and payment records for as long as Dutch tax law requires.
Who processes data for us
We do not sell or rent your personal data. We share it only with the processors that run parts of the Service for us, under data-processing agreements:
- Stripe (payments and invoicing),
- WorkOS (sign-in),
- Groq (speech-to-text for voice input),
- ElevenLabs (text-to-speech for voice output),
- Resend (sending our email),
- Sentry (error monitoring),
- Cloudflare (serving app downloads) and our hosting provider.
Your prompts to the AI go from your machine to your own model provider (Anthropic) under your own subscription and their terms; they do not pass through our servers. We may disclose data where we are required to by law.
International transfers
Several of these providers process data in the United States. Where data leaves the EEA, we rely on an appropriate safeguard: the EU–US Data Privacy Framework where the provider is certified, and otherwise the European Commission’s Standard Contractual Clauses.
Cookies
We use only strictly necessary cookies required for the Site to function securely:
- a session cookie and a CSRF-protection token, set by our framework (Laravel) to keep signed-in sessions and forms secure.
Because these are essential and are not used for tracking or analytics, they are exempt from the consent-banner requirement under the EU ePrivacy rules, which is why you will not see a cookie banner. We do not set any advertising, analytics or tracking cookies. If that ever changes, we will ask for your consent first.
Fonts and third parties
The Site’s fonts are self-hosted on our own servers. We do not load fonts, scripts or other resources from Google or other third parties in a way that would share your IP address with them.
How long we keep it
- Beta signup emails: until the beta ends or you unsubscribe or ask us to remove you, whichever comes first.
- Account details: until you delete your account (which you can do yourself from the dashboard) or ask us to.
- Voice audio: not stored; relayed and discarded.
- Server logs: a short period (typically up to 30 days) for security, after which they are deleted or anonymised.
- Invoices and payment records: seven years, as Dutch tax law requires, even after account deletion.
Your rights
If you are in the EEA, the UK or Switzerland, you have the right to access your data, correct it, delete it (the “right to be forgotten”), restrict or object to processing, port your data, and withdraw consent at any time. To exercise any of these, email [email protected] and we will respond within the timeframe the law requires (usually one month). You also have the right to lodge a complaint with your local data protection authority; in the Netherlands that is the Autoriteit Persoonsgegevens.
California residents
We do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. California residents may exercise their rights to know, delete and correct by emailing [email protected]; we do not discriminate against anyone for exercising them.
Children
The Service is not directed at children under 16, and we do not knowingly collect their personal data.
Changes to this policy
We may update this policy as ForgeMuse grows. We will post the new version here and update the “Last updated” date above. Material changes will also be communicated by email to account holders and beta subscribers.
Contact
Questions about this policy or your data? Email [email protected].