Legal
Privacy Policy
Last updated: July 14, 2026
1. Who we are
Supraforge ("we", "us") operates the SEO automation platform at supraforge.one. The data controller for Supraforge is Alan Cope (sole proprietor), 11500 Jollyville Rd #913, Austin, TX 78759, USA. Privacy questions and requests: support@supraforge.one or by mail at the address above.
2. What we collect
- Account data: email, name, avatar, password hash (via our auth provider), OAuth identity (Google).
- Site data: URLs you add, public HTML/metadata fetched during scans, AI-generated optimizations, repair history.
- Integration tokens: OAuth tokens you grant for Google Search Console, Google Analytics, Google Business Profile, GitHub, Cloudflare, WordPress, Shopify, LinkedIn, TikTok. Tokens are encrypted at rest and used only to perform the actions you authorize.
- Community data: posts, replies, chat-room messages, direct messages, moderation reports, and blocks you create.
- Marketplace data: job listings, quotes, contract state, and reviews.
- Brain memories: the notes and embeddings you save into your AI workspace.
- Billing data: handled by Stripe. We never see your full card number; we store the subscription ID, price ID, and last-4 metadata Stripe returns.
- Usage telemetry: page views, feature usage, AI-router logs (model, latency, credit cost), and error logs to operate and improve the product.
- Cookies & pixels: see Section 9.
3. How we use it
To run scans, generate fixes, push approved changes to your CMS, run the community and marketplace, send reports and transactional email, provide support, prevent abuse, and bill you. We do not sell personal data.
4. AI processing
Optimization suggestions and content are produced by third-party large language models routed through providers including OpenRouter, Groq, Google Gemini, and (for voice) ElevenLabs. Page content, metadata, and prompts you submit are sent to those providers solely to generate the requested output. We do not use your data to train external models, and we do not sell your prompts.
5. Subprocessors
Supabase (auth + database + storage), Stripe (payments), Cloudflare (delivery), Firecrawl / ScrapingBee (crawling), OpenRouter / Groq / Google Gemini / ElevenLabs (AI inference and voice), Semrush (SEO data), Resend (email delivery), Google (Search Console, Analytics, Business Profile), Meta / TikTok / LinkedIn (only if you connect a social account). Each operates under its own terms; we maintain DPAs where applicable.
6. Data retention
Scan results, repair logs, generated content, and community messages are retained while your account is active and for 90 days after deletion, then permanently erased. Billing records are retained for 7 years to meet tax and accounting obligations. You can request earlier deletion of eligible data at any time by emailing support.
7. Your rights
Access, correction, export, and deletion. Email support@supraforge.one and we will respond within 30 days. GDPR, UK GDPR, CCPA/CPRA, and similar laws apply where relevant, including the right to object to processing and to lodge a complaint with your local data-protection authority.
8. Security
TLS in transit, encryption at rest, row-level access control on all customer data, audit logging on repair actions, service-role isolation for privileged writes. No system is perfectly secure; report vulnerabilities to security@supraforge.one.
9. Cookies, analytics, and ad measurement
We use strictly-necessary cookies for authentication and session state (always on). With your consent (via the cookie banner) we also use analytics cookies (Google Analytics 4) and ad-measurement pixels (Google Ads, Meta, TikTok) to understand traffic and measure campaign performance. Consent is enforced through Google Consent Mode v2 — if you reject non-essential cookies, ad and analytics storage stay denied and pixels do not receive personally identifying data. You can change your choice any time by clearing site data or by revisiting the banner from a private window.
10. Community content visibility
Posts, replies, and public chat-room messages are visible to all signed-in members. Direct messages are private to the participants but may be reviewed by Supraforge staff when reported for abuse. Do not share information in the community that you consider confidential.
11. International transfers
Data may be processed in the United States and other countries where our subprocessors operate. Where required, transfers rely on Standard Contractual Clauses or equivalent safeguards.
12. Children
Supraforge is not intended for children under 16 (or the digital-consent age in your country, whichever is higher). See Section 2 of the Terms.
13. Changes
We will post material changes here and notify active customers by email at least 14 days before they take effect.