Legal
Privacy Policy
Last updated 28 August 2026
In short
- Forge stores your name and an identifier from your HarithKavish account.
- When you connect a platform, Forge stores an encrypted access token and a read-only inventory of what it finds there.
- There are no analytics, no tracking, and no advertising.
- Nothing is sold, and nothing is shared with anyone.
- You can delete everything yourself, at any time.
Who runs Forge
Forge is operated by Harith Kavish at forge.harithkavish.com. For any question about this policy or your data, contact harithkavish40@gmail.com.
What Forge collects
When you sign in
Forge does not sign you in itself. You sign in to your HarithKavish account at auth.harithkavish.com, and Forge is told your account identifier and your name. That is all it receives. How you proved your identity is decided there, and Forge is not told which method you used.
Forge holds no password, and no token belonging to any authentication provider. Your account identifier is issued by the identity service, so changing how you sign in never moves your data.
When you connect a platform
Connecting a platform such as GitHub, Cloudflare, Vercel or Neon stores two things: an access token for that platform, encrypted at rest, and an inventory of the resources it can see — names, identifiers, types, regions, status, creation and last-activity timestamps, and platform metadata such as language or visibility.
Forge only ever issues read requests. It does not create, modify or delete anything in your connected accounts. It does not read the contents of your repositories, files, databases or environment variables.
What Forge does not collect
No analytics, no tracking pixels, no advertising identifiers, no session recording, no third-party scripts. Forge does not build a profile of you and there is nothing to opt out of.
Cookies
Forge sets only cookies it needs to work. There are no advertising or analytics cookies.
- authjs.session-token — keeps you signed in. HTTP-only, so scripts in your browser cannot read it. Expires after 30 days.
- forge.oauth_state.* — a short-lived anti-forgery value used while connecting a platform. Expires after ten minutes.
Your light or dark theme preference is kept in your browser’s own storage and never sent to the server.
How your data is protected
- Platform access tokens are encrypted with AES-256-GCM before they are stored, and each is cryptographically bound to the connection it belongs to.
- A token is decrypted in memory only for the moment Forge is talking to that platform. It is never written to logs, never returned by any API, and never sent to your browser.
- Every record is scoped to your own workspace. Queries are filtered by workspace at the data layer, so one account’s data is not reachable from another.
- All traffic is served over HTTPS.
Where your data is held
Forge runs on Vercel and stores data in a Neon PostgreSQL database hosted in the United States (AWS us-east-2). Using Forge means your data is processed there.
How long it is kept
Your account and inventory are kept until you delete them. Disconnecting a platform immediately destroys that platform’s stored token and removes the resources discovered through it.
Deleting your data
Go to Settings → Account and choose Delete account. This removes your user record, its link to your HarithKavish account, your workspace, and every project, resource, connection and encrypted token in it. It takes effect immediately and cannot be undone.
Deleting your Forge account does not touch anything in your connected platforms. To revoke Forge’s access at the source, remove it from that platform’s own settings — for example github.com/settings/applications.
Your rights
You can access, correct, export or delete your data. Most of it is visible in the product; deletion is self-service. For anything else, including a copy of your data in a portable form, email harithkavish40@gmail.com and you will get a response within 30 days.
Your name comes from your HarithKavish account, so correcting it is done at account.harithkavish.com rather than in Forge.
Children
Forge is a tool for people managing software infrastructure and is not directed at children under 13.
Changes
If this policy changes materially, the date at the top changes and anyone with an account will be told by email before it takes effect.