Privacy Policy
What SignalForge processes, why it is needed, and the controls available to you.
The operator name, address, jurisdiction, registration details, and governing law are intentionally not invented. They must be configured before paid public access.
Effective date · 2026-08-14Who controls your data
The legal operator and controller identity will be published before paid public access begins. SignalForge is the current trading name.
Data we process
- Account data such as email, verification state, and authentication identifiers.
- Profile data such as display name and organization.
- Research questions, scopes, projects, evidence selections, notes, comments, analyses, opportunities, Validation Plans, Watchlists, and exports.
- Security and operational logs needed to protect and operate the service.
- Encrypted provider credentials, plus a non-secret key hint and connection status.
Why we process it
We process data to create and secure accounts, provide requested research features, preserve projects and Watchlists, connect user-selected providers, prevent abuse, diagnose failures, communicate service information, and meet legal obligations. Depending on the context and jurisdiction, legal bases may include contract performance, legitimate interests, consent, and legal obligation.
Authentication and credential handling
Supabase provides authentication and cloud persistence. OpenAI and YouTube credentials are encrypted for server-side storage and are not intentionally returned to the browser. They are decrypted in server memory immediately before an authenticated provider request.
Service providers
Supabase supports authentication and database persistence. OpenAI processes selected research inputs and evidence when you request analysis. Google/YouTube APIs provide video metadata and optional comments for live research. The production hosting provider and any future Merchant of Record will be identified before those services are used for paid public access.
Retention
Account and research data are retained while needed to provide the service or until deletion is requested, subject to legal and security requirements. Non-authorized YouTube API metadata follows the applicable 30-day refresh-or-delete lifecycle in strict compliance mode. Provider credentials are removed when you disconnect them.
Security and international processing
SignalForge uses authenticated access, Row Level Security, server-side provider calls, and encrypted credential storage. No internet service can promise absolute security. Providers may process data in countries outside yours under their own safeguards and contractual arrangements.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing. You may disconnect provider credentials and delete projects or Watchlists in the product. Contact details for formal privacy requests will be published before paid public launch.
Updates
This notice is effective 2026-08-14. Material changes will be reflected on this page.