Back to sign in

Legal

Privacy Policy

Last updated August 22, 2026. This policy covers Arveniq Forge web and mobile services.

Account and organization information

Forge processes account contact details, authentication identifiers, organization and workspace memberships, roles, preferences, and access requests needed to provide and secure the service.

Workspace content and AI work

Forge collects the content an authorized user chooses to provide for work: chat prompts, chat responses, photos, videos, voice recordings, uploaded or shared files, memory requests, approvals, schedules, evidence, and permitted connected-tool results. It also processes the selected agent, project, workspace context, and applicable saved memory needed to perform the requested work. Organization administrators control access, integrations, policies, and retention for their workspace.

AI processing and your choice

Before Forge sends a mobile AI request to an external AI processor, it identifies the processor, explains the categories of content that will be sent, and asks the user to allow the transfer. A user may decline; Forge then does not send that request. Consent is requested again when the applicable processor, disclosed data scope, or disclosure version changes. Users can review the Privacy Policy from the app Settings before making that choice.

Third-party AI processors

Depending on the AI model enabled by an organization and the selected agent, Forge may send the disclosed content to OpenAI, Anthropic, Google, Meta, Amazon Web Services (AWS Bedrock), Microsoft Azure AI Foundry, xAI, Groq, Together AI, Fireworks AI, DeepSeek, or an organization-configured AI service. Forge identifies the processor or processor set applicable to the individual request in the app before content is transmitted. A self-hosted model operated solely within an organization’s controlled environment is identified as such and is not treated as an external processor.

How AI processors use disclosed content

Forge uses disclosed content to generate a requested response, analyze documents or media, transcribe audio or video when enabled, generate requested media, retrieve permitted workspace context, and operate safety and reliability controls. Forge does not sell mobile application data or use it for third-party advertising. Forge requires processors it engages to protect data under contractual terms that are no less protective than Forge’s applicable obligations; organization administrators remain responsible for reviewing and approving their chosen model providers.

Mobile device and diagnostic data

The mobile app processes an installation identifier, push token, app version, operating system, canonical screen routes, connectivity state, performance information, and privacy-filtered crash diagnostics. Push payloads do not contain prompt, file, or chat content. Biometric templates remain with the operating system; Forge receives only the result of the device authentication check.

Connected services and wallets

When a user or organization connects an approved provider, Forge exchanges the minimum data needed for the authorized action under that provider and workspace policy. Wallet linking may process a public address and signed ownership message. Forge never requests or stores a wallet recovery phrase.

How information is used

Information is used to authenticate users, provide AI and workflow features, enforce permissions and approvals, deliver notifications, prevent abuse, troubleshoot failures, measure reliability, and maintain security, billing, and audit records. Forge does not use mobile application data for third-party advertising.

Service providers and disclosure

Information may be processed by infrastructure, AI, authentication, notification, monitoring, and organization-approved integration providers needed to operate Forge. Data is not disclosed outside authorized users, organization administrators, the processors identified above or in the applicable in-app disclosure, configured providers, or a valid legal requirement.

Retention and deletion

Account and workspace data is retained according to the applicable organization policy, contract, security requirements, and legal obligations. A user can start an account-deletion request from the public account-deletion page. The response identifies data scheduled for deletion and records that must be retained for an applicable audit, billing, security, or legal period.

Security

Forge uses encrypted transport, signed sessions, scoped authorization, secure mobile storage, tenant isolation, audit records, and governed approval boundaries. No security measure eliminates all risk, so suspected unauthorized access should be reported promptly.

Contact and choices

Users can review profile, notification, memory, company-tool, and wallet controls in the application. Privacy or deletion questions can be sent to support@arveniq.xyz. Organization-managed users may also need to contact their organization owner.

Visit mobile support or request account deletion.