PRIVACY POLICY

How ChatForge handles your data.

Effective date: [待确认 — 域名 DNS 配置和 Stripe 启用后填写] · Last updated: [待确认]

ChatForge ("we", "us") operates charforge.org (the "Service"). This page summarizes how we collect, use, retain, and disclose personal data. The full Privacy Policy below is the legally binding document; this overview is provided for quick reference.

What we collect

  • Account & auth — Google OAuth email, name, profile photo URL, and Pro / Lifetime status.
  • User content — your prompts, character bibles, Story Projects, characters, cast relations, edits, and export requests. We do not offer file uploads.
  • Billing — plan, order ID, payment status, and limited metadata. Card numbers are processed by Stripe and never stored on our servers.
  • Technical — IP, device / browser, timestamps, request and error logs, rate-limit counters, and anti-abuse signals.
  • Cookies / storage — see the Cookie Policy for the live vendor list.

How we use it

To operate, secure, and improve the Service; to authenticate you via Google; to generate drafts through our AI providers; to process payments through Stripe; to respond to support requests; to detect and prevent abuse; to comply with law. We do not sell personal information, and we do not use your content to train third-party AI models by default.

AI providers

Prompts and project content are sent to our AI providers only as needed to generate the drafts you request. The current stack is Cloudflare Workers AI (primary), with OpenRouter as an optional fallback. The exact training / retention settings for each provider are documented in the live Privacy Policy below and will be re-confirmed before launch.

Sharing

Cloudflare (hosting, Workers, D1 / R2), Google (OAuth), Stripe (payments), our AI providers, email / support tooling, security services, and (only with consent) analytics. Disclosures may also be made when required by law or in a corporate transaction.

Retention & deletion

Account, project, and log data are retained only as long as needed to provide the Service, maintain security, handle disputes, prevent fraud, support backups, and meet legal obligations. Specific periods are listed in the live policy. You may request access, correction, or deletion at privacy@charforge.org.

Your rights

Subject to applicable law, you can request access, correction, deletion, portability, restriction, or objection, and withdraw consent. EEA / UK users may complain to their supervisory authority; California users may have CCPA / CPRA rights including the right to know, delete, correct, and opt out of sale or sharing. We do not discriminate for exercising these rights.

Children

The Service is not directed to children under 13 (or the higher minimum age required locally). If you believe a child has submitted data, contact privacy@charforge.org and we will delete it.

Full Privacy Policy

The complete Privacy Policy with all clauses (controller identity, transfers, security, contact, changes) is published below and is the legally binding version of this notice.


Full Privacy Policy — binding version

1. Controller and contact

The Service is operated by [Operator / DBA — 待确认]. Privacy inquiries: privacy@charforge.org. Until the operator identity and contact channel are confirmed, this policy is a working draft and not a final published version.

2. Information we collect

(a) Account and authentication data: Google OAuth email, display name, profile photo URL, Google account identifier, account creation timestamp, Pro / Lifetime status.

(b) User content: prompts, character descriptions, generated bible drafts (Voice, Flaw, Motivation, Backstory Hook, 3-Beat Arc), Story Projects, Characters, Cast Relations, your edits, and export requests (JSON, Markdown, Scrivener .scrivx, Notion-compatible Markdown). We do not provide file-upload functionality.

(c) Transaction and billing data: plan, subscription status, order identifiers, payment status, limited billing metadata. Full card numbers are processed by Stripe and not stored by us.

(d) Technical and security data: IP, device / browser, timestamps, request and error logs, rate-limit counters, anti-abuse signals.

(e) Cookies, local storage, and analytics: only categories actually deployed.

3. How we use your information

To provide, operate, secure, and improve the Service; to authenticate users; to generate drafts through AI providers; to process payments; to handle support; to prevent abuse; to comply with law. For EEA / UK users, the GDPR / UK GDPR legal bases are performance of contract, legitimate interests, legal obligation, or consent. We do not sell personal information. We do not use your content as third-party training data unless you give separate, explicit, and verified consent.

4. AI processing and providers

Prompts and project content are sent to our AI providers only as needed to generate drafts. Current provider stack (subject to final DPA verification before launch): Cloudflare Workers AI (primary); OpenRouter (optional fallback). Before launch we verify, for each provider, the DPA, sub-processor list, training usage (default: no), retention period (default: not retained beyond request handling), and cross-border transfer mechanism (SCCs or adequacy). We do not claim "never stored", "never used for training", or "always private"until the provider contract and configuration confirm them.

5. Who we share data with

Cloudflare (Pages, Workers, D1 / R2, KV); Google (OAuth); Stripe (payments); AI providers (Cloudflare Workers AI, OpenRouter if enabled); email / support tooling; security and abuse-prevention services; analytics (only if enabled and, where required, only after consent); professional advisors. We do not rent or sell personal information. Legal-process disclosures and corporate transactions are permitted with appropriate safeguards.

6. Data retention and deletion

Account, project, and log data are retained only as long as needed to provide the Service, maintain security, handle disputes, prevent fraud, support backups, and meet legal obligations. Specific retention periods are confirmed before launch. You may request access, correction, or deletion at privacy@charforge.org. Deletion may be irreversible; content you have already exported remains under your control. We may retain certain records (transaction receipts, fraud-prevention logs, consent records) where required by law.

7. International transfers

Vendors may process data outside your country. Where required, we rely on adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or other legally recognized safeguards.

8. Your rights

Subject to applicable law: access, correction, deletion, portability, restriction, objection, and withdrawal of consent. EEA / UK users may complain to their supervisory authority. California users may have CCPA / CPRA rights (know, delete, correct, opt out of sale or sharing). We do not discriminate for exercising rights. Requests: privacy@charforge.org.

9. Children

Not directed to children under 13, or the higher minimum digital-consent age required locally. We do not knowingly collect children's data. Contact privacy@charforge.org if such data was submitted.

10. Security

We use reasonable administrative, technical, and organizational safeguards. No online service is completely secure. You are responsible for protecting your credentials and for not submitting confidential or sensitive information.

11. Changes

We may update this policy. Material changes will be communicated where required by law.

12. Contact

[Operator / DBA — 待确认]
privacy@charforge.org

Independent, unofficial tool. Not affiliated with, endorsed by, or sponsored by any writing software, AI provider, franchise, author, studio, or platform referenced in user content.