Legal

Privacy Policy

Last updated: June 28, 2026

1. Who we are

Supraforge ("we", "us") operates the SEO automation platform at supraforge.one. Questions: support@supraforge.one.

2. What we collect

  • Account data: email, name, password hash (via our auth provider).
  • Site data: URLs you add, public HTML/metadata fetched during scans, AI-generated optimizations, repair history.
  • Integration tokens: OAuth tokens you grant for Google Search Console, Google Analytics, Google Business Profile, GitHub, Cloudflare, WordPress, Shopify. Tokens are encrypted at rest and used only to perform the actions you authorize.
  • Billing data: handled by Stripe. We never see your full card number.
  • Usage telemetry: page views, feature usage, error logs to operate and improve the product.

3. How we use it

To run scans, generate fixes, push approved changes to your CMS, send reports, provide support, and bill you. We do not sell personal data.

4. AI processing

Optimization suggestions are produced by third-party large language models (OpenAI, Anthropic, Google). Page content and metadata are sent to those providers solely to generate the requested output. We do not use your data to train external models.

5. Subprocessors

Supabase (auth + database), Stripe (payments), Cloudflare (delivery), Firecrawl (crawling), OpenAI / Anthropic / Google (AI inference), Resend (email). Each operates under its own terms; we maintain DPAs where applicable.

6. Data retention

Scan results, repair logs and generated content are retained while your account is active and for 90 days after deletion, then permanently erased. You can request earlier deletion at any time.

7. Your rights

Access, correction, export and deletion. Email support@supraforge.one and we will respond within 30 days. GDPR / CCPA / UK GDPR applies where relevant.

8. Security

TLS in transit, encryption at rest, row-level access control on all customer data, audit logging on repair actions. No system is perfectly secure; report vulnerabilities to security@supraforge.one.

9. Cookies

Strictly-necessary session cookies for authentication. No third-party advertising cookies.

10. Changes

We will post material changes here and notify active customers by email.