⌗ Legal
Privacy Policy
Last updated: July 19, 2026
1. Who we are and what this Policy covers
This Privacy Policy explains how Holocron Forge LLC, a Texas limited liability company ("Holocron Forge," "we," "us") collects, uses, discloses, and protects personal information in connection with the holocronforge.com website and its subdomains (including app.holocronforge.com), the ForgeMetrics application, and related services (together, the "Service").
Holocron Forge is the controller of (that is, the business responsible for) personal information processed through the Service. Where we provide consulting or professional services to a client under a separate written agreement, that agreement — including any confidentiality or data-handling terms in it — governs information exchanged in that engagement, and this Policy applies only to the extent it does not conflict.
By using the Service, you acknowledge this Policy. If you do not agree with it, please do not use the Service.
2. Summary of how we operate
A few commitments up front, in plain terms — the sections below give the detail:
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- We do not use third-party advertising trackers, and we serve no ads.
- Analytics is off by default. Google Analytics runs only if you accept it in our cookie banner, and never for advertising. You can decline, or switch it off entirely at /ga-optout.
- We do not store your password (sign-in is handled by our identity provider) and we never receive your full payment-card number (payments are handled by our payment processor).
- You own your modeling data, and you can ask us to delete your account and content.
3. Information we collect
(a) Account information. When you create an account, our identity provider collects your email address and, optionally, your name, and provides us with a unique account identifier. We do not store your password.
(b) Content you create. The economic and site-development data you save in ForgeMetrics — mining scenarios, forecasts, sites and their layouts, interconnection and treasury records, alert and control rules, saved assumptions, and any API keys you generate — is stored so you can retrieve and use it. This content may include business information; whether it includes personal information is up to what you put in it.
(c) Billing information. For paid tiers, our billing and payment providers collect the information needed to process your subscription, such as your name, email, billing address, payment-method details, and transaction history. We never receive or store full payment-card numbers; we receive limited records such as tier, status, and the last digits and brand of your card for support and accounting.
(d) Beta acceptance records. During our private beta, if you accept the ForgeMetrics Beta Evaluation & Confidentiality Agreement, we record your acceptance together with your email, the name you type, the agreement version you saw, and the IP address and browser at the time, as a durable record of consent.
(e) Communications. If you contact us — by email, a contact form, or otherwise — we collect the contact details you provide and the contents of the communication, and we keep records of our correspondence.
(f) Technical and log data. Our hosting and security infrastructure processes standard request data — such as IP address, browser type and version, device and operating-system information, referring pages, pages viewed, and timestamps — to deliver, secure, debug, and defend the Service (including bot and abuse protection and rate limiting).
(g) Waitlist and marketing sign-ups. If you join a product waitlist or subscribe to updates, we collect your email address (and any details you choose to add, such as name or company) to send you the updates you requested. Every marketing email includes an unsubscribe link.
(h) Cookies and local storage. We use a small set of cookies and browser local storage as described in Section 7 and, in full detail, in our Cookie Policy. Interface preferences (such as theme and working state) are stored in your browser's local storage on your device.
(i) Sharing features. If you choose to create a public share link for a scenario or results snapshot, that specific content becomes viewable by anyone with the link until you remove the link. Sharing is off unless you enable it.
We do not seek to collect, and ask that you not submit, sensitive personal information (such as government identifiers, health information, or precise geolocation) through the Service.
4. How we use information
We use the information above to:
- provide, operate, maintain, and improve the Service, including saving and returning your content and generating the outputs you request;
- create and administer your account and authenticate you;
- process subscriptions, payments, invoices, and renewals, and prevent payment fraud;
- secure the Service — including detecting, investigating, and preventing abuse, automated attacks, unauthorized access, and violations of our Terms of Service;
- communicate with you about the Service, including transactional messages (receipts, renewal and security notices, material changes to terms) that you cannot opt out of while you have an account;
- send product news and marketing you have signed up for, which you can opt out of at any time;
- understand aggregate usage so we can improve the Service — via consent-gated analytics (Section 7) and via aggregated or de-identified data that does not identify you;
- comply with law, respond to lawful requests, and establish, exercise, or defend legal claims; and
- enforce our agreements and protect the rights, safety, and property of Holocron Forge, our users, and others.
We do not use your content or personal information to train third-party artificial-intelligence models, and we do not make decisions producing legal or similarly significant effects about you by solely automated means.
5. Legal bases (where GDPR or UK GDPR applies)
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with an equivalent framework, we process personal information on these bases: performance of a contract (providing the Service you signed up for, billing, support); legitimate interests (securing and improving the Service, preventing abuse, communicating with business contacts, establishing or defending legal claims) — balanced against your rights; consent (analytics cookies, marketing emails), which you may withdraw at any time without affecting prior processing; and legal obligation (tax, accounting, and lawful-request compliance).
6. How we share information
We do not sell personal information and we do not share it for cross-context behavioral advertising. We disclose personal information only:
- (a) To service providers (processors) who process it on our behalf, under contracts that restrict their use of it to providing services to us. Our core providers are: Clerk (Identity and sign-in; billing orchestration for Account email, name, authentication data, session records; subscription status), Stripe (via Clerk Billing) (Payment processing for Billing details and payment-method data, card numbers go to Stripe, not to us), Neon (Database hosting for Your saved content and account records), Vercel (Hosting, delivery, and security infrastructure to Request and log data such as IP address and browser metadata), Google (Google Analytics 4) (Usage analytics — only after you consent for Usage events and device/browser data as described in the Cookie Policy), Resend (Waitlist and marketing email delivery to Email address and sign-up details, delivery and engagement records)
We may engage additional providers of the same kinds (for example, error monitoring, support tooling, or accounting) under equivalent restrictions; material additions — including naming our email delivery provider once engaged — will be reflected in updates to this Policy.
(b) Professional advisers — lawyers, accountants, insurers, and auditors — under duties of confidentiality, where reasonably necessary.
(c) For legal reasons — to comply with applicable law, regulation, legal process, or enforceable governmental request; to enforce our terms and agreements; or to protect the rights, property, safety, or security of Holocron Forge, our users, or the public.
(d) In a business transfer — in connection with, or during negotiations of, a merger, acquisition, financing, reorganization, or sale of assets, in which case the successor will be bound by this Policy or one at least as protective, and we will notify you of material changes.
(e) At your direction — for example, when you create a public share link (Section 3(i)) or ask us to send something to a third party.
(f) Within a workspace — if your account belongs to an organization workspace, workspace administrators and members can access content and activity within that workspace according to its settings.
7. Cookies, local storage, and analytics
We use a deliberately small set of cookies: strictly-necessary cookies that keep you signed in, remember your cookie choice, and secure the Service; and — only with your consent — Google Analytics cookies. Analytics is denied by default for everyone (Google Consent Mode v2) and begins only if you click Accept in the consent banner; your choice is remembered for one year and honored across holocronforge.com and its subdomains. We configure analytics without advertising features, and advertising-storage signals remain denied at all times. You can decline in the banner, change your mind later, or disable Google Analytics for your browser entirely at /ga-optout. We do not use advertising cookies or third-party advertising trackers.
The complete list of cookies, their purposes, and their lifetimes — plus how to manage them — is in our Cookie Policy.
8. Data retention
We keep personal information only as long as needed for the purposes above, and then delete or de-identify it. In general:
- Account and content data — for as long as your account is active, and deleted within a reasonable period after you delete your account or request deletion, except for limited records we must keep (below) and residual copies that clear from backups on our normal backup cycle.
- Billing records — for as long as required for tax, accounting, and audit purposes (typically at least seven years).
- Beta acceptance and consent records — for as long as needed to evidence the agreement and consent, including for the duration of any surviving confidentiality obligations and applicable limitation periods.
- Communications — for as long as needed to resolve the matter and for a reasonable period afterward to maintain business records and handle any related claims.
- Technical logs — for a short rolling period appropriate to security, debugging, and abuse prevention.
- Marketing lists — until you unsubscribe, plus a suppression record so we don't email you again.
We may retain information longer where required by law, to resolve disputes, or to enforce agreements.
9. Security
We use administrative, technical, and organizational measures designed to protect personal information — including encryption in transit, access controls and least-privilege practices, segregation of production credentials, and vendor security review. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security; you play a part too, by protecting your account credentials and API keys. If we learn of a breach affecting your personal information, we will notify you and regulators as required by applicable law.
10. Your rights and choices
For everyone. Regardless of where you live, you may: access the personal information we hold about you; correct it; delete your account and associated content; export a copy of your saved content in a portable form; and opt out of marketing at any time (use the unsubscribe link or contact us). To exercise any of these, email contact@holocronforge.com from the address associated with your account (or provide equivalent verification). We will respond within the time required by applicable law — and in any case aim to respond within 30 days. We will not discriminate against you for exercising your rights. You may use an authorized agent where applicable law provides for one; we may take reasonable steps to verify the request and the agent's authority.
If you are in the EEA, UK, or Switzerland, you also have the rights to restrict or object to certain processing (including any processing based on legitimate interests, and direct marketing), to withdraw consent at any time (without affecting prior processing), to data portability, and to lodge a complaint with your local supervisory authority — although we would welcome the chance to address your concern first.
If you are a U.S. state resident with rights under a state privacy law (for example, Texas, California, Colorado, Connecticut, or Virginia), those laws may give you specific statutory rights to access, correct, delete, and obtain a portable copy of your personal information, and to opt out of "sales," "sharing"/targeted advertising, and certain profiling. We do not sell personal information, share it for targeted advertising, or conduct such profiling, so there is nothing to opt out of on those fronts; your access, correction, deletion, and portability rights are honored through the process above. If we decline a rights request, you may appeal by replying to our decision with "Appeal" in the subject line; we will respond as applicable law requires, and if the appeal is denied you may contact your state attorney general.
Do Not Track and Global Privacy Control. Because we do not sell personal information or share it for targeted advertising, and analytics only runs with your affirmative consent, browser DNT and GPC signals do not change how the Service treats you — there is no sale or sharing for them to opt out of.
11. International data transfers
We are based in the United States, and the Service is operated and hosted there; information we collect is processed in the U.S. (and in other countries where our service providers operate), which may have data-protection laws different from those of your jurisdiction. Where we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (with the UK addendum where applicable) and/or our providers' participation in the EU–U.S. Data Privacy Framework, together with supplementary measures where appropriate.
12. Children
The Service is intended for business and professional use and is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18; if you believe a minor has provided us personal information, contact us and we will delete it.
13. Third-party sites and services
The Service may link to third-party sites and services (for example, data sources, documentation, or social platforms). Their privacy practices are their own; this Policy does not apply to them, and we encourage you to review their policies.
14. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date above shows the current version's effective date, and material changes will be announced by reasonable means — such as posting on the Site, in-app notice, or email — before they take effect. Your continued use of the Service after the effective date constitutes acknowledgment of the updated Policy.
15. Contact us
Questions, concerns, or rights requests may be sent to:
Holocron Forge LLC 4902 Big Elm Cir, Missouri City, TX 77459, USA contact@holocronforge.com