LAST UPDATED · 31 JULY 2026

Privacy Policy

This policy explains what personal data LLM Forge collects, why, and what your rights are. The controller is Strix Technology (Pty) Ltd, 581 Opstal Street, Pretoria, 0184, South Africa. Contact: hello@llmforge.io.

The short version. Prompts and responses exchanged with a model you deploy travel directly between your client and your own infrastructure. They never pass through our systems, so we cannot read, store, log, or train on them. What we hold is your account data and an audit trail of the infrastructure actions we performed for you.

1. What we collect

2. What we do not collect

If we host a shared sandbox playground (a small demo model run by us), prompts you type into it are processed transiently on our infrastructure to produce the reply, are rate-limited, and are not used to train anything. The sandbox is the only place where prompt text can reach systems we operate, and it is clearly labeled.

3. Why we process it

We do not sell personal data, and we do not use it for advertising. We send no marketing email unless you explicitly opt in.

4. Who we share it with

We use a small number of processors, chosen with EU hosting where the data is EU-resident:

Your cloud provider (for example AWS or RunPod) is your provider, under your own agreement — we act on your account at your instruction and are not a party to that relationship. Beyond the above: only if required by law.

5. Where data lives

Platform data is stored in the European Union (Germany). Strix Technology operates from South Africa, so our staff access EU-hosted data from there under appropriate contractual safeguards; South Africa's POPIA provides data protection comparable in structure to the GDPR. Deployment infrastructure itself is created in the regions you choose — the EU-only option pins it to EU member-state regions.

6. How long we keep it

7. Security

Credentials are protected with envelope encryption and are unloggable by construction; all traffic is encrypted in transit; every state-changing action is audit-logged; access to your cloud account uses the narrowest mechanism your provider offers (on AWS, a short-lived assumed role scoped to resources we tagged, revocable by you at any time).

8. Your rights

Under the GDPR (where it applies to you) and South Africa's POPIA, you can request access to, correction of, deletion of, or a copy of your personal data, and object to or restrict certain processing. Most of this is self-service: your data is visible in the dashboard, and organization deletion is available at any time, on any plan, regardless of billing state. For anything else, email hello@llmforge.io — we respond within 30 days. You can also lodge a complaint with the South African Information Regulator or, in the EU, with your local supervisory authority.

9. Children

The service is for adults and businesses; it is not directed at children under 18, and we do not knowingly collect their data.

10. Changes

We will update this policy as the service evolves (for example, when new features process new data) and will note material changes in the dashboard or by email. The date above always reflects the current version.