SignalForge

Legal Infrastructure

Privacy Policy

Effective Date: February 9, 2026

Provider: Signal Forge (“Company”, “We”, “Us”)

Platform: ForgeOS (“Service”, “Platform”)

1. Information We Collect

We collect and process the following categories of information to operate, secure, and monitor our business operating intelligence platform:

  • Account Credentials: Full name, business email, encrypted login credentials, and phone numbers.
  • Tenancy Profiles: Organization names, company industries, number of locations, operational logs, and standard operating procedures (SOPs).
  • Website Scan Metadata (Blueprints & Reports): Submitted business URLs, crawled public website texts, department contacts, services, locations, and technology structures.
  • Job Applicant Submissions: Candidate full name, email, phone number, resume links/LinkedIn URLs, and cover letter introductions submitted via our careers page.
  • Payment Data: All financial and subscription checkout transactions are processed directly by our third-party merchant processor (Stripe). We do not store full credit card numbers or bank credentials on our servers.
  • Security, Telemetry & Bot Protection: Device IP addresses, browser types, session timings, Turnstile CAPTCHA log telemetry, and detailed application logs.

2. How We Use and Ground Your Data

We process your data strictly under the following lawful bases:

  • To provide, maintain, and configure your ForgeOS Workspace.
  • To execute automated website analyses, calculate baseline ForgeScore™ results, and compile your Business Blueprint.
  • To review candidate qualifications and manage recruitment communications for Signal Forge job openings.
  • To execute your 5-Step Exit Protocol and compile backup ZIP payload archives.
  • To route operational queries from the Playbook Studio to AI endpoints. **Important:** Your playbooks and SOPs are only passed to the AI models for real-time inference grounding. They are not stored, cached, or utilized by our AI partners (Google Cloud AI) for training underlying public LLM models.
  • To verify safety checklist compliance, log exception events, and alert designated operations managers.

3. Approved Sub-Processors

To deliver our Services, we contract with the following third-party infrastructure sub-processors:

  • Supabase Inc. (Database storage, session auth management, secure encryption protocols)
  • Stripe Inc. (Subscription licensing checkouts, invoice billing logs)
  • Resend Inc. (Transactional account validation emails, password recovery messaging)
  • Cloudflare Inc. (API Turnstile bot verification and secure network routing services)
  • Google Cloud Platform / Google AI (Gemini API operational parsing and media generation)

4. Data Deletion, Retention, & Grace Periods

Data Deletion Hold: If a Workspace Owner triggers account deletion, ForgeOS initiates a **30-day soft-delete grace period**. During this period, the workspace is locked and inactive, but all customer data, backups, and checklists are preserved.

Permanent Purge: Once the 30-day grace period expires, an automated background job executes a hard delete, permanently removing all entries, members, playbooks, procedures, and storage assets from our database.

Job Applicant Retention: Candidate submission profiles are retained for a reasonable period (not exceeding 365 days) for candidate evaluation, unless deletion is requested earlier.

Exceptions: Invoices, transaction histories, and legal audit logs are retained in accordance with federal tax codes and compliance mandates.

5. SMS & A2P 10DLC Communications Consent

For users who opt-in to SMS notifications (e.g., task dispatching alerts or system exceptions):

  • Consent is completely optional and must be explicitly checked on our application forms.
  • Opt-in credentials and mobile numbers are kept strictly confidential. **We do not sell, share, or lease SMS consent or phone records with third-party marketers or affiliates.**
  • Users may unsubscribe at any time by replying STOP to any text alert.

6. CCPA/CPRA, GDPR, and HIPAA Compliance

If your organization is located in the European Union (GDPR) or California (CCPA/CPRA), you have the right to request access to, correction of, porting of, or deletion of your personal data. You can perform these requests directly using the Data Ownership Center inside your settings console, or by contacting our Data Protection Officer.

7. Contact Data Protection Officer

For inquiries regarding data protection compliance, contact our privacy office:

Signal Forge Privacy Operations

Contact: Contact us here