Privacy Policy

GABFORGE UNLIMITED. Hosted at gabforge.ai/legal/privacy.


1. At a glance

Question Answer
Do you sell my data? No. Never. Not to advertisers, not to data brokers, not to AI-training partners.
Do you use my chats to train your models? No by default. Training uses opt-in donated data only.
Where does my data live? Germany — app data and our self-hosted GPU servers for AI inference are both in Germany.
If I use BYOK, does my data pass through you? We orchestrate the call (prompt assembly, plugin execution) and then forward to your provider using your key. We don't store the AI response beyond what your session needs.
How long do you keep it? See §8 Retention. Account data for as long as you're a user; chats until you delete them; logs ≤ 90 days.
How do I delete my account? Settings → Account → Delete. One-click, 30-day grace window, then hard delete.
Who do I contact? privacy@ on the TLD you used. India users: additionally [email protected].

2. Who we are (data controllers)

All GabForge domains are operated by a single company, GABFORGE UNLIMITED, which is the data controller for every GabForge product:

Site What it's for Contact
gabforge.ai, gabforge.live, gabforge.in The GabForge Everyday app and subsite hosting [email protected]
gabforge.org Open-source projects, community forum, donations [email protected]
gabforge.com Company site (investor / press / careers) [email protected]

One GabForge account. You have a single GabForge account that works across all of these products. You sign in once with GabForge OAuth — the same simple "sign in with GabForge" button, just like signing in with Google — and you're signed in everywhere. There is no separate per-site account and nothing to link up. GABFORGE UNLIMITED is the data controller across the board. If the company is ever sold or reorganised, your data moves with the product it belongs to (see the Terms of Service for the details).

For India users: GABFORGE UNLIMITED has appointed Founder and CEO T. V. Rao as the Interim Grievance Officer under IT Rules 2021 §3(2). Contact: [email protected]. The role is filled by the founder in the interim pending a dedicated hire. As an early-stage startup, we are not currently classified as a Significant Data Fiduciary and do not maintain a statutory Data Protection Officer (DPO).


3. What we collect

3.1 Account data (you give us this at signup)

3.2 Usage data (generated as you use the product)

3.3 BYOK credentials (if you add them)

3.4 Technical and security logs

3.5 Telemetry (opt-in)

If you enable the gabforge.privacy.telemetry toggle (off by default), the client sends one ping every 24 hours containing:

No prompts, no responses, no file contents, no account identifiers are transmitted. See ../Research/Telemetry_Install_Tracking for the full payload spec.

3.6 What we do NOT collect


4. How we use it (and why we're allowed to)

Purpose Data used Legal basis (GDPR) DPDP equivalent
Provide the product (answer your chats, store your personas, run your tasks) Account + usage Contract (Art. 6(1)(b)) Consent + legitimate use
Security (rate limiting, abuse detection, fraud prevention) Auth events + request logs Legitimate interests (Art. 6(1)(f)) Legitimate use
Billing (process your subscription and Boosters) Account + subscription state Contract (Art. 6(1)(b)) Consent + legitimate use
Legal compliance (retain records where law requires) As mandated Legal obligation (Art. 6(1)(c)) Legal obligation
Service improvement (aggregate, anonymised metrics) Telemetry (if opted in), de-identified logs Consent (Art. 6(1)(a)) / legitimate interests Consent
Email us for support Whatever you send Consent (Art. 6(1)(a)) Consent

We do not process your data for:

Consent Audit-Trail: When you provide explicit consent (e.g., agreeing to these terms or opting into telemetry), the consent event is logged and stored securely in the GabForge database with a UTC timestamp for compliance auditing.


5. Payments

We do not store payment card numbers, CVVs, or bank account numbers. Payments are processed by:

From those providers we receive only: a payment token, transaction status, amount, and the last 4 digits of the card for your receipt. Refund and dispute contact: refunds@ / billing@ on your TLD.


6. One GabForge account across all products

You sign in to every GabForge product with a single GabForge account using GabForge OAuth — the "sign in with GabForge" button that works the same way as signing in with Google. One sign-in covers gabforge.ai, gabforge.live, gabforge.in, gabforge.org, and any product we add later.


7. AI inference — where your chats actually go

This section matters more than any other, so we've written it in plain language.

7.1 Default path (self-hosted GF Everyday v1)

When you chat with GF Everyday on the free tier or on Pro without BYOK, your message goes to our own GPU servers in Germany. The model runs on hardware we own and operate ourselves. Your message and its response are:

7.2 BYOK path

If you've added a third-party API key (OpenAI, Anthropic, Google, etc.) and selected that provider for a chat, your message is:

  1. Assembled into a prompt on our servers (so plugins, tools, and your persona instructions are applied).
  2. Sent from our server to your chosen provider's API, authenticated with your key.
  3. The response comes back to us, is returned to you, and saved in your chat history.

What this means for you: that message is now subject to the chosen provider's privacy policy too. OpenAI, Anthropic, and Google each have their own data-handling terms for API usage — most do not train on API inputs by default, but please verify your provider's settings. We cannot speak for them.

7.3 Plugins and tools

Plugins that call third-party APIs (e.g., a weather plugin calling OpenWeather, a calendar plugin calling Google Calendar) send only the data necessary for that call. Each plugin declares what it transmits in its manifest; you can review this in Settings → Plugins → [plugin] → Permissions.


8. Retention

Category Retention
Account profile Until you delete the account
Chat history Until you delete it (per-message, per-conversation, or bulk)
Uploaded files Until you delete them
Deleted account data 30-day grace window, then hard-deleted from live databases. Backup purge within 90 days.
Request logs ≤ 90 days
Auth logs (success / failure) ≤ 90 days
Crash reports ≤ 30 days then aggregated
Telemetry (if opted in) ≤ 13 months, then aggregated
Billing records 8 years (Companies Act 2013 §128 — statutory minimum for books of account)
Legal-hold data For the duration of the hold

9. Your rights

Everyone, regardless of jurisdiction, has the following rights with us:

9.1 EU / UK residents (GDPR + UK GDPR)

In addition to the above:

Controller-of-record for EU/UK: GABFORGE UNLIMITED. Please note that GabForge primarily targets the India and Global markets and does not actively target the European Union. We therefore do not maintain an EU Representative under GDPR Art. 27.

9.2 India residents (DPDP Act 2023)

In addition to the above:

Interim Grievance Officer: T. V. Rao (Founder & CEO), contactable at [email protected] or by mail at 142, Spanzilla, Gulam Ali Guda, Parvathapur Road, Medipally, Hyderabad 500098.

9.3 California residents (CCPA / CPRA)

We do not "sell" or "share" personal information as defined under CCPA. You still have the right to know, delete, correct, and limit use of sensitive personal information — exercise via Settings → Privacy or [email protected].


10. International transfers


11. Cookies and similar

We use the minimum necessary:

A cookie banner is shown on first visit where legally required (EU, UK, India).


12. Security


13. Children

GabForge is not intended for children under 18. We do not knowingly collect data from children under 18. If you believe a child has created an account, email privacy@ and we will delete the account and its data.

The Student persona in our onboarding is written for post-secondary students (college, university, graduate). Primary/secondary school students should use the product only under a parent or guardian's account and supervision, with all data subject to that adult's control.


14. Changes to this policy


15. Contact

Purpose Address
General privacy questions, access / deletion requests privacy@ on the TLD you used
India Interim Grievance Officer (T. V. Rao) [email protected]
Copyright / DMCA takedown dmca@ on the TLD hosting the content
Security vulnerabilities security@ on any TLD
Legal notices legal@ on the TLD of incorporation

Note: As an early-stage startup, we do not require a statutory Data Protection Officer (DPO) or Nodal Contact Person under current Indian regulations.

Full list with scope and SLA: Email_Addresses. Physical correspondence: GABFORGE UNLIMITED, 142, Spanzilla, Gulam Ali Guda, Parvathapur Road, Medipally, Hyderabad 500098.


Which sections apply to which users

This Privacy Policy is the same across every GabForge site that publishes it. Every user gets the same policy; the table below is a reader's guide to which sections materially apply to which user group.

User group Sections that apply in addition to the baseline
Any user (global baseline) §1–§8 (collection, use, retention), §9.1 (universal rights), §10–§12 (transfers, security, incidents), §13–§16 (children, updates, contact)
India residents / gabforge.in users + §9.2 (DPDP Act 2023 rights), Interim Grievance Officer contact at [email protected] (T. V. Rao), IT Rules 2021 §3(2) SLAs
EU / UK residents + §9.4 (GDPR / UK GDPR rights); Art. 27 representative not currently appointed (see §9.4)
California residents + §9.3 (CCPA / CPRA rights and non-sale attestation)
gabforge.live subsite publishers + §7.3 (user-as-controller for subsite content), DMCA path at [email protected]
gabforge.org users OSS-specific: Pro / Booster sections do not apply; donations are governed separately — see Donation_Page
gabforge.com visitors Corporate-only scope: no user-product data collected; investor / press / careers contact applies