Privacy
Forge stores the minimum state needed to connect your GitHub account, prepare reviewable changes and carry out decisions you approve.
Last updated 19 September 2026.
What Forge stores
Account and GitHub access
Your GitHub numeric user id, current login and Forge GitHub App installation id. Forge also keeps one GitHub user credential encrypted at rest. It is used only to create a personal repository and when you explicitly ask Forge to search public GitHub. Ordinary repository work uses your repository-scoped App installation instead.
OAuth connection
Registered client names and redirect addresses, hashes of short-lived authorization codes, and the user id they belong to. Forge access tokens are signed. Refresh tokens are opaque, client-bound, rotate on every use and are stored only as hashes; inactive refresh tokens expire after 30 days. Used and expired token records are removed with the Forge account and may remain until then so replay can be detected.
Changes and approvals
GitHub remains the only copy of repository files. For a requested merge or discard, Forge stores the repository name, change branch, expected commit, changed-file evidence, expiry, decision and outcome. An approval link can act for seven days; its record currently remains until the Forge account is deleted.
Public-page captures
Forge renders public pages on demand and returns screenshots in the tool response. It stores only your daily capture count; it does not keep a screenshot gallery or persistent copy of captured pages.
Usage and analytics
Forge stores one daily capture count per user. When PostHog analytics is enabled, it receives only product shape: tool name, success or failure, duration, file or viewport counts, action and outcome. It never receives repository names, file contents, patches, intents, captured URLs or tokens.
What Forge does not keep
- Chat transcripts.
- A mirror, checkout or workspace copy of your repositories.
- Repository secrets or environment variables.
- Private-page captures; Forge accepts only public HTTP or HTTPS URLs.
Who processes data
GitHub provides identity and repository operations. Cloudflare hosts the Worker, database and Browser Rendering. PostHog receives the limited analytics described above only when its optional key is configured. Forge does not sell personal data.
Your controls
- Revoke or narrow the Forge GitHub App installation from GitHub at any time.
- Disconnect Forge from your chat client to stop that client using it.
- Ask for the Forge account and its stored Forge metadata to be deleted.
For support or deletion, use one of the public contact links at timcoy.uk and ask for a private response route. Do not send tokens, private repository details or captured-page contents.
Security and changes
Forge uses repository-scoped GitHub App access, encrypted storage for the one user credential, signed approval links, and explicit approval before Forge merges or discards a proposed change. This notice will be updated when the stored data, processors or retention behaviour changes.