Privacy Policy
Last updated: October 5, 2026
1. Overview
This policy covers two different kinds of data: information about you, as a person with a ForgeOps account, and the Event Data your applications submit through the ingestion API. They're handled differently, and it matters which one we're talking about (see section 3).
A third kind, separate from both: this marketing site (the pages you're on right now, not the signed-in product) records anonymous page views, which path was viewed and which domain referred it, to understand traffic. No cookie, no account, no IP address, and nothing else that identifies who visited is stored, and it's automatically deleted after 90 days.
A fourth kind: the public "Replay your own incident" page lets anyone upload or paste incident data without an account. That data is processed to produce the replay shown on the next page and is not stored (see section 3a).
2. Account information we collect
- Account details: name, email address, and password (stored hashed, never in plain text).
- SSO: if your organization enables SAML or OpenID Connect, the subject identifier your identity provider asserts, plus whatever name/email it sends: nothing beyond what's needed to sign you in.
- Usage and audit data: sign-in timestamps, IP addresses, and a record of sensitive actions taken in your organization (who invited whom, who resolved which issue, and so on), kept as an audit trail for your own organization's owners and admins to review, not shared outside it. We also keep the IP address an account was created from, used only by us to spot the same person starting repeated free trials, and deleted after 90 days.
- Bug reports: if you report a bug from inside the product and leave "Include diagnostic information" ticked, we store the page you were on, your browser, your organization and project, and, from an incident's or issue's page, which one it was and the likely cause it showed. Untick it to send only what you wrote.
3. Event Data: data your applications submit
When you configure an application to report into ForgeOps, whatever that application sends (exception messages, backtraces, and any request or user context you choose to attach) is stored so it can be shown back to you. We don't control what's in that payload. If your application's exceptions or context data include personal information about your own users (an email address in an error message, a user ID in a backtrace, and so on), that comes through to us as-is.
Before anything is stored, likely-sensitive content is automatically redacted: email
addresses, formatted SSNs/credit cards, known API key and token formats, and any field whose
name suggests it holds a secret (password, api_key, and similar);
you can add your own field names for this on a per-project basis in that project's settings.
This is a safety net, not a guarantee: pattern-based scrubbing of free text
can't catch everything, and you're still responsible for what your applications send.
Configure your error reporting to avoid including sensitive data in the first place where
your own compliance obligations require it. Per-project retention settings control how long
Event Data is kept before automatic deletion; deleting a project or organization removes it
immediately and permanently.
A backtrace can also include a short snippet of your application's own source code around the line an exception was raised on, if your reporting library captures it and your project hasn't turned that off. This is on by default, and it's a different kind of data than anything else described above: literal source code, not just data about an error. Every project has its own setting, in that project's settings page, that governs whether the server accepts and stores this; turning it off stops it immediately and permanently for that project, regardless of what any individual application reporting into it is separately configured to send.
If you connect a third-party tool to a project, the errors the Service reads from it are Event Data too: the same automatic redaction is applied before anything is stored, the same per-project retention applies, and you remain responsible for what that tool holds. The credentials you provide for the tool are stored encrypted, are used only to read from it, and are deleted when you disconnect it. We also keep a short-lived record of which errors have already been imported, so none is imported twice.
3a. Uploaded incident files
When you use the "Replay your own incident" page, the file or text you provide is processed on our servers for the duration of that one request, and the result is returned to you on the page. Neither the file nor the result is stored: we keep no copy to show you again later. Your IP address is used briefly, for a few minutes, to limit how often one visitor can run a replay. Because we don't control what's in the file, leave out or mask anything you'd rather not send.
4. How we use this information
To operate the Service: authenticating you, displaying your organizations' issues back to you, sending the alerts you've configured, and maintaining the audit log. We don't sell personal information, and we don't use Event Data for anything beyond providing the Service back to the organization that submitted it.
5. Sharing and third parties
Notification channels (Slack, Microsoft Teams, email, PagerDuty, Opsgenie, or a generic webhook) are configured by your organization's own admins, and issue data is sent to whatever destination they've set up when a rule fires; that's a disclosure your organization controls, not one we make on your behalf.
Beyond that, we share information only with the service providers ("subprocessors") that actually run the Service on our behalf, each only to the extent needed to provide it:
- DigitalOcean: hosts the application and its database, and stores its encrypted nightly database backups, all in New York, United States.
- Postmark: delivers transactional email (invites, password resets, and email notification rules).
- Stripe: handles payment processing for paid plans. Given billing contact details and payment information, never Event Data.
- Anthropic: provides the language model behind ForgeOps' optional AI features, and only receives anything once one of them is turned on. Each is off by default and turned on by your own admins: AI issue search sends the search text you type, AI ticket enrichment sends an issue's exception class, title, and backtrace (file names, line numbers, and method names, after the redaction described in section 3; never source code snippets or request and user context) when a ticket is filed, and AI report summaries send your report's numbers.
We don't sell personal information, and we don't share it with anyone else except as required by law.
6. Security
Passwords are hashed, never stored in plain text. SSO client secrets, two-factor authentication secrets, and the credentials for any connected third-party tool are encrypted at the column level. Production traffic is served over HTTPS. Two-factor authentication (TOTP) is available for any account to enable on its own account settings page. We don't currently hold a third-party security certification (e.g. SOC 2, ISO 27001); if that changes, this section will be updated to say so.
7. Your rights
You can review and remove your own account and organization data directly in the Service at any time, including permanent deletion of a project or organization. For your own account data specifically (not Event Data, which the organization that configured the Service is the controller of, per section 3 above), two self-service tools cover the rights GDPR/CCPA give you without needing to contact us at all:
- Access and portability: from your account settings, "Download your data" gives you a plain JSON file of everything ForgeOps holds about your account, on demand, immediately.
- Erasure: from the same page, "Erase your personal data" permanently scrubs your name, email address, and every other identifying field, in place, without needing to wait on us. Organizations and projects you're a member of, and existing audit log entries recording what happened, are unaffected: only who you were is removed, not the historical record of events themselves.
For anything those two tools don't cover, contact us using the details below.
8. Children's privacy
The Service isn't directed at, and isn't knowingly used by, children under 13.
9. Changes to this policy
We'll update the date above when this policy changes, and make a reasonable effort to notify account owners directly of material changes.
10. Contact
Questions about this policy, or a data subject request: , or use the support form.