Privacy policy
How Forge handles data, including anything read from Google. Written plainly, because a policy nobody can read protects nobody.
Forge is a single user application used by Dante St James. It has no public sign up, so in practice the only person whose data it holds is its owner. This policy is written to be accurate for that, and to be checkable by anyone reviewing the application.
Who is responsible
Dante St James, trading as Clickstarter, in Australia, is the data controller. Contact: dante@clickstarter.com.au.
What is collected
- What the user types
- Goals, tasks, recurring commitments, session records, journal entries, saved links and the text of pages saved for reading, drafts, and settings.
- Google Calendar
- Event titles, times, and which calendar they came from, for a window of roughly three weeks back and one month forward. Cached so the application can work out where free time is.
- Google Health, if connected
- Daily step counts, active minutes, sleep duration and resting heart rate, for the last thirty days. Stored as one row per day. No intraday detail is kept.
- Account
- A single password hash. There are no user accounts, no profiles, no names and no email addresses stored by the application.
- Not collected
- No analytics, no tracking pixels, no advertising identifiers, no location history, no contacts, no third party scripts on the public pages.
How Google user data is used
Data read from Google APIs is used only to provide features the user is looking at, inside the application, for the account that authorised it.
- Calendar data shows the day, finds free gaps, and lets a task be scheduled into one.
- Health data is displayed as recent trends alongside the user's own training log.
- Both may be summarised into the text sent to a language model when the user asks the application a question. That is described in the next section.
Forge's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never transferred to others except as required by law, never used for advertising, and never used to train, retrain or improve any generalised machine learning or artificial intelligence model.
Language models
Some features send text to Anthropic or OpenAI to generate a reply: a morning summary, a tutor answering a question, a draft being rewritten. Those requests can include the relevant parts of what the user has written, and where relevant a summary of the day's calendar or recent health figures.
This happens only when the user asks for it or when a summary they have scheduled runs. It is processing on the user's behalf, under those providers' API terms, which do not use API content to train their models. No Google user data is used to train any model by Forge or on its behalf.
Where it is stored, and for how long
On one server rented by Clickstarter from a hosting provider, located in Australia, in a PostgreSQL database that is not reachable from the public internet. Traffic to the application is encrypted with TLS.
- What the user types
- Kept until the user deletes it.
- Calendar cache
- A rolling window of about seven weeks. Older events fall out of the cache on each sync.
- Health days
- Kept until the user deletes them or the application is shut down.
- Backups
- Nightly, to the same server. Thirty days of the personal records, seven days of the full database.
- On disconnection
- Disconnecting Google Calendar clears the cached events. Disconnecting Google Health revokes further access and stops all syncing; days already pulled are kept unless deleted, since they are the user's own record.
Who else sees it
Nobody. The data is not sold, rented, shared or published. The only third parties involved are the hosting provider that runs the server, Google for the APIs the user connects, and the language model providers described above, each acting only to deliver a feature the user asked for.
Rights and control
The user can export everything the application holds as a single file from the settings screen, at any time, and can delete any record from the screen it appears on. To have all data erased, or to ask any question about it, write to dante@clickstarter.com.au.
Access granted to Forge can also be revoked directly from the Google account permissions page, which stops all further access immediately without needing to ask anyone.
Children
Forge is not intended for and not made available to anyone under 18.
Changes
If this policy changes in a way that affects how data is handled, the updated date at the bottom of this page changes with it. The overview page always describes the application as it currently stands.