Version 1 This document is under legal review and may change.
Privacy Policy
BlackForge is a browser-based workshop for building and playing guitar tone devices. This policy explains what we collect when you use it, why, who processes it for us, and the choices you have. We wrote it to be read, not skimmed past: there is no analytics tracking in BlackForge, there is one cookie, and we do not sell anything you give us.
Contents
1. Who we are
BlackForge ("BlackForge", "we", "us") operates the BlackForge application at blackforge.io. BlackForge is currently a private beta: access is by request and approval. We are the controller of the personal data described here. You can reach us about anything in this policy at privacy@blackforge.io.
2. What we collect and why
We collect only what the product needs to work. Here is the full list.
Requesting access
- Your email address and a password. The password is stored only as a hash by our authentication provider; we never see it.
- Optional answers to a few questions (your name, what you play or do, how experienced you are, what you are hoping to find, what you make music with today). These help us decide who to let in first and what to build. Every one of them is optional.
- The time you accepted the Terms and this policy, and confirmed you are 16 or older.
Signing in
- Email and password, as above; or
- Google or GitHub sign-in. If you choose one of these, the provider sends us your email address, your name, and an identifier for your account with them. We do not receive your password for that service, and we do not post or read anything on your behalf there.
- A display name and handle you choose. These are shown next to things you publish.
What you make
- Devices, rigs, presets, and their names and descriptions. These are yours; we store them so they follow you between browsers and devices. They are private unless you publish them.
- Captures and impulse responses you upload (for example a
.namor.wavfile), with the credit and license you attach to them. - Images you upload as device artwork or as a reference for AI image generation, and images the Forge generates for you. Photos are downscaled in your browser before upload, which also strips camera metadata.
- Recordings. BlackForge asks for your microphone only when you choose an input that needs it. Audio is processed live inside your browser. A recording is kept only when you record a take and press Save or Use; it then lives in your account until you delete it. Raw audio is never sent to an AI service.
- Your TONE3000 connection. If you connect your TONE3000 account, an access token for that account is kept in your browser and used to fetch captures on your behalf, under TONE3000's own terms. We do not copy the TONE3000 catalog.
Technical data
- One session cookie that keeps you signed in (see Cookies).
- Your IP address, held briefly in memory to limit abusive request rates (for example repeated sign-in attempts). These tables are purged automatically and are not written to disk or used for anything else.
- Operational logs. Our server logs request errors so we can fix them. Prompts, audio, and the content you create are not logged. Some logs may include an account identifier next to an error; we are reducing this.
3. Feedback you send
The in-app feedback panel is how the beta gets better, so we want to be exact about what it sends when you press Send feedback:
- the message you type and the category you pick (bug, idea, and so on);
- where you were in the app (the screen or panel, detected automatically or set by you);
- screenshots or images you attach, and the on-screen elements you point at with "Pick element", described by their label and position;
- details that help us reproduce what you saw: your browser type (the "user agent"), the page address, the app build number, and the name of the rig or device you had open;
- your account, if you are signed in, so we can reply. Feedback can also be sent without an account.
Feedback is read by the BlackForge team, may be turned into an item on our roadmap, and is kept for as long as the beta runs. Attached images are stored privately and are not published. Please do not include other people's personal information in feedback.
4. AI features
When you ask the Forge to build a device, compose a sound, or generate or restyle an image, the text you typed and any reference image you attached are sent to an AI provider to produce the result. We send the prompt and the image only; no account identifier, email, or other personal data travels with the request. We do not use your recordings, captures, devices, or prompts to train AI models. The providers we use are named in section 6. We are putting data-processing agreements and no-retention settings in place with them, and this policy will be updated when that is complete.
5. What we do not do
- We do not run analytics or advertising trackers, pixels, session replay, or error-reporting services in the app.
- We do not sell, rent, or trade personal data, ever.
- We do not read your microphone unless you have chosen an input that needs it, and nothing is recorded until you press record.
- We do not send your audio, captures, or devices to AI services.
- We do not show ads.
6. Who processes data for us
We use a small number of service providers. Each one processes data only to provide its service to us, and only the data listed here.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, authentication, and file storage | Your account, what you make, recordings, uploaded and generated images, feedback and its attachments |
| Fly.io | Hosting for the BlackForge server | Requests to the app, including your IP address in transit |
| Anthropic | AI generation of device designs and sounds, and checking generated artwork | Your prompt text and, for artwork checks, the generated image. No account identifier |
| fal.ai | AI image generation and background removal | Your prompt text and any reference image you attach. No account identifier |
| Sign-in, only if you choose "Google" | Handled by Google under its own policy; we receive your email, name, and an account identifier | |
| GitHub | Sign-in, only if you choose "GitHub" | Handled by GitHub under its own policy; we receive your email, name, and an account identifier |
| TONE3000 | Capture library, only if you connect your TONE3000 account | Your authorization to act on your TONE3000 account; requests for captures you choose |
We do not load third-party analytics, fonts, or scripts on the sign-in page or these legal pages. If we add or change a provider, we will update this table.
7. Cookies and browser storage
BlackForge sets one cookie, which holds a signed session so that you stay signed in for up to 30 days. It is strictly necessary for the service to work, contains no tracking identifier, and is not read by anyone else. Because it is the only cookie and it is essential, no cookie consent banner is required, and we do not show one.
The app also keeps a working copy of your rigs, devices, and recent recordings in your browser's own storage so it loads fast and works offline. That copy is scoped to your account, hidden when you sign out, and can be removed by clearing site data in your browser.
8. How long we keep things
- Account data (email, sign-in identity, display name, request-access answers): until you delete your account.
- Recordings, captures, devices, rigs, and images: until you delete them, or until you delete your account.
- Feedback and its attachments: while the beta runs, then deleted or fully anonymized.
- Rate-limit records (IP address): minutes, in memory only.
- Operational logs: a short rolling window.
Things you have published under a license that allows reuse may already have been copied by others under that license; deleting the original does not undo those copies.
9. Your rights and choices
Wherever you live, you can ask us to:
- access the personal data we hold about you;
- correct it;
- delete it, including your whole account;
- export a copy of what you have made, in a portable format;
- object to or restrict a use of your data.
Until in-app account deletion and export ship, email privacy@blackforge.io from the address on your account and we will handle the request by hand, normally within 30 days. If you are in the EU, UK, or another place with a data protection authority, you also have the right to complain to that authority. If we rely on your consent for something, you can withdraw it at any time.
10. Children
BlackForge is for people aged 16 or older. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has an account, tell us at privacy@blackforge.io and we will delete it.
11. Where data is stored
BlackForge is hosted in the United States and our providers process data there. If you use BlackForge from outside the US, your data is transferred to and stored in the US. Where the law requires it, we rely on standard contractual safeguards with our providers for those transfers.
12. Security
Data is encrypted in transit. Sessions are signed and cannot be forged without the server's secret. Storage is private by default and only becomes public when you publish something. No system is perfectly secure; if we learn of a breach affecting your data, we will tell you.
13. Changes to this policy
This is version 1. We will change it as the product changes and as legal review completes. When we do, the version and effective date at the top change, and for anything that matters to you we will tell you in the app or by email before it takes effect.
14. Contact
Privacy questions, requests, and complaints: privacy@blackforge.io.