Privacy Policy
ForgeRelay relays review activity from forges you connect into chat channels you choose. This policy explains what we collect to run that service, and what we do not.
Last updated 8 August 2026 Security and permissions
Overview
Who this covers, and the product in one line.
This policy applies to the ForgeRelay website, control panel, webhooks and related early-access services. ForgeRelay is operated as an early-access product; contact details below are the route for privacy questions while the service matures.
We process personal data to authenticate you, run your workspace, verify inbound webhooks, deliver messages to destinations you configure, and bill paid plans when they are available. We do not sell personal data. We do not use forge or chat content to train third-party models.
Collection
What we collect.
Most of what we store comes from you or from providers you authorise. Categories expand only when a new connection type or product feature needs them.
- Account and profile Name, email address, and identity details from sign-in providers you use (Google, GitHub, GitLab or Discord).
- Workspace configuration Organisation or workspace name, members, routes, feature toggles, reminder settings and identity mappings between forge accounts and chat users.
- Connection credentials OAuth tokens, bot tokens, webhook secrets and related metadata for forges and chat destinations you connect. Tokens are encrypted at rest and are not shown again in the UI.
- Event and delivery data Webhook payloads needed to relay and replay activity, delivery attempts, status, destination identifiers and error details. When a Commits route matches, this can include push and commit metadata such as messages, authors, SHAs and path lists when the forge includes them.
- Billing When paid plans are active: customer and subscription identifiers via our payment processor (Stripe). We do not store full card numbers.
- Technical logs IP address, user agent, timestamps and similar request metadata used for security, debugging and abuse prevention.
Use
Why we process that data.
- Provide, operate and improve the relay service you configure
- Authenticate users, manage membership and enforce workspace permissions
- Verify webhook signatures, queue events and post to channels you select
- Support delivery history, replay and troubleshooting
- Process payments and manage subscriptions when billing is enabled
- Communicate about the service, security issues and material policy changes
- Detect abuse, protect the service and comply with law
Connections
Third-party services you connect.
ForgeRelay only receives data from providers after you authorise a connection. Permissions are described on the security page; future forges or chat destinations will follow the same least-privilege approach.
- Sign-in Google, GitHub, GitLab and Discord for authentication and profile email.
- Forges GitHub and GitLab for repository metadata, pull or merge request activity, checks or pipelines, reviewer identity signals, and push and commit metadata from webhooks when a Commits route matches.
- Chat Slack and Discord to list destinations you can route to, post messages and threads, and resolve mapped users.
- Payments Stripe (via Laravel Cashier) for organisation Team subscriptions.
Those providers process data under their own terms and policies. ForgeRelay does not control their practices. Disconnecting a connection removes its stored token and stops further processing for that link.
Retention
How long things stick around.
We keep data only as long as needed for the purposes above, subject to plan limits and legal obligations.
- Account and workspace Until you delete the workspace or close the account, then removed or anonymised within a reasonable period.
- Connection tokens Until you disconnect the connection or delete the workspace.
- Operational data Free workspaces retain 30 days. Paid and complimentary Team workspaces may select 30, 60, or 90 days.
- Downgrades A paid retention preference is saved, but only 30 days is effective once paid access actually ends. The next daily pruning run removes older operational data; deleted history is not restored after upgrading again.
- Stripe billing records Billing records required for accounting, tax, chargebacks or disputes follow those legal requirements, separately from ForgeRelay operational retention.
- Security logs For a limited period needed to investigate incidents and abuse.
Choices
Access, correction, deletion and related rights.
Depending on where you live, you may have rights to access, correct, export or delete personal data, object to certain processing, or withdraw consent where processing is consent-based.
- Update profile details in the control panel where available
- Disconnect forge or chat connections to stop further data flow from that provider
- Delete a workspace to remove its routes, mappings and delivery history
- Contact us to request access, correction, export or deletion we cannot complete in-product yet
ForgeRelay makes no claim of GDPR or similar certification. We still aim to honour reasonable requests. We may need to verify identity before acting, and some records may be retained where law or legitimate security needs require it.
Children. The service is aimed at professional software teams. It is not directed at children under 16, and we do not knowingly collect their personal data.
International transfers. Data may be processed in the United Kingdom, European Economic Area, United States or other locations where we or our processors operate. Where required, we use appropriate safeguards offered by those processors.
Cookies. We use cookies and similar technologies needed for sessions, authentication and security. We do not run third-party advertising cookies on the marketing site.
Changes. We may update this policy as the product grows (including new connection types). Material changes will be reflected on this page with an updated date; continued use after the effective date constitutes acceptance of the revised policy.
Contact
Privacy questions and requests.
The same ForgeRelay address handles privacy, support, legal and security enquiries.
- Privacy contact
- hello@forgerelay.dev
- Security reports
- Security page
- Related
- Terms of Service
Clear about what we keep.
Permissions, encryption and retention are spelled out on the security page too.