Privacy Policy
This policy explains what personal data LLM Forge collects, why, and what your rights are. The controller is Strix Technology (Pty) Ltd, 581 Opstal Street, Pretoria, 0184, South Africa. Contact: hello@llmforge.io.
The short version. Prompts and responses exchanged with a model you deploy travel directly between your client and your own infrastructure. They never pass through our systems, so we cannot read, store, log, or train on them. What we hold is your account data and an audit trail of the infrastructure actions we performed for you.
1. What we collect
- Account data. Your email address, organization name, and sign-in records. Authentication uses one-time codes sent to your email; we do not store passwords.
- Cloud access credentials. The role identifiers or API keys you grant us so we can manage infrastructure in your cloud account. These are stored encrypted (per-record keys, envelope encryption), are never written to logs, and are decrypted only at the moment an operation needs them.
- Deployment metadata and audit logs. What was deployed, where, when, by whom, its cost estimates, its lifecycle events, and every action we took in your cloud account. This is the product's audit trail.
- Billing data. Subscriptions are processed by Paddle, our merchant of record. Paddle collects your payment details under its own privacy policy; we receive subscription status and invoicing metadata, never your card number.
- Support and correspondence. Emails you send us.
- Website. Our marketing site is static and carries no advertising or analytics trackers. It is served via Cloudflare, and its fonts are currently loaded from Google Fonts, which means your IP address reaches those providers when the page loads. Cloudflare may set strictly-necessary security cookies.
2. What we do not collect
- Prompts and responses sent to your deployed endpoints — they do not transit our systems.
- Model weights or files on your instances — they live on your infrastructure.
- Your cloud provider invoices or payment details.
If we host a shared sandbox playground (a small demo model run by us), prompts you type into it are processed transiently on our infrastructure to produce the reply, are rate-limited, and are not used to train anything. The sandbox is the only place where prompt text can reach systems we operate, and it is clearly labeled.
3. Why we process it
- To provide the service (contract): accounts, deployments, cloud operations, emails such as sign-in codes, deployment-ready notices, and budget warnings — sent via Scaleway's Transactional Email service.
- Security and accountability (legitimate interest): the audit trail, abuse prevention, and rate limiting.
- Legal obligations: tax and accounting records via Paddle.
We do not sell personal data, and we do not use it for advertising. We send no marketing email unless you explicitly opt in.
4. Who we share it with
We use a small number of processors, chosen with EU hosting where the data is EU-resident:
- Hetzner (Germany) — hosts the platform and its database.
- Cloudflare — DNS, content delivery, and serving of the website and dashboard.
- Scaleway (France) — transactional email delivery.
- Paddle — merchant of record for payments; an independent controller for the payment data it collects.
Your cloud provider (for example AWS or RunPod) is your provider, under your own agreement — we act on your account at your instruction and are not a party to that relationship. Beyond the above: only if required by law.
5. Where data lives
Platform data is stored in the European Union (Germany). Strix Technology operates from South Africa, so our staff access EU-hosted data from there under appropriate contractual safeguards; South Africa's POPIA provides data protection comparable in structure to the GDPR. Deployment infrastructure itself is created in the regions you choose — the EU-only option pins it to EU member-state regions.
6. How long we keep it
- Account and deployment data: for the life of your account. Deployment history is retained per your plan's retention terms.
- Cloud credentials: until you disconnect the account or delete your organization, at which point they are destroyed.
- On organization deletion: your users, sessions, and personal data are deleted and the organization record is reduced to a non-identifying tombstone. We retain minimal, PII-reduced records of consents given and teardown verifications (what infrastructure was created and verifiably destroyed), as evidence in both your interest and ours.
- Billing records: as long as tax law requires.
7. Security
Credentials are protected with envelope encryption and are unloggable by construction; all traffic is encrypted in transit; every state-changing action is audit-logged; access to your cloud account uses the narrowest mechanism your provider offers (on AWS, a short-lived assumed role scoped to resources we tagged, revocable by you at any time).
8. Your rights
Under the GDPR (where it applies to you) and South Africa's POPIA, you can request access to, correction of, deletion of, or a copy of your personal data, and object to or restrict certain processing. Most of this is self-service: your data is visible in the dashboard, and organization deletion is available at any time, on any plan, regardless of billing state. For anything else, email hello@llmforge.io — we respond within 30 days. You can also lodge a complaint with the South African Information Regulator or, in the EU, with your local supervisory authority.
9. Children
The service is for adults and businesses; it is not directed at children under 18, and we do not knowingly collect their data.
10. Changes
We will update this policy as the service evolves (for example, when new features process new data) and will note material changes in the dashboard or by email. The date above always reflects the current version.