BLACKFORGE
private beta

Version 1 This document is under legal review and may change.

Privacy Policy

Effective September 3, 2026 · Version 1

BlackForge is a browser-based workshop for building and playing guitar tone devices. This policy explains what we collect when you use it, why, who processes it for us, and the choices you have. We wrote it to be read, not skimmed past: there is no analytics tracking in BlackForge, there is one cookie, and we do not sell anything you give us.

Contents

  1. Who we are
  2. What we collect and why
  3. Feedback you send
  4. AI features
  5. What we do not do
  6. Who processes data for us
  7. Cookies and browser storage
  8. How long we keep things
  9. Your rights and choices
  10. Children
  11. Where data is stored
  12. Security
  13. Changes to this policy
  14. Contact

1. Who we are

BlackForge ("BlackForge", "we", "us") operates the BlackForge application at blackforge.io. BlackForge is currently a private beta: access is by request and approval. We are the controller of the personal data described here. You can reach us about anything in this policy at privacy@blackforge.io.

2. What we collect and why

We collect only what the product needs to work. Here is the full list.

Requesting access

Signing in

What you make

Technical data

3. Feedback you send

The in-app feedback panel is how the beta gets better, so we want to be exact about what it sends when you press Send feedback:

Feedback is read by the BlackForge team, may be turned into an item on our roadmap, and is kept for as long as the beta runs. Attached images are stored privately and are not published. Please do not include other people's personal information in feedback.

4. AI features

When you ask the Forge to build a device, compose a sound, or generate or restyle an image, the text you typed and any reference image you attached are sent to an AI provider to produce the result. We send the prompt and the image only; no account identifier, email, or other personal data travels with the request. We do not use your recordings, captures, devices, or prompts to train AI models. The providers we use are named in section 6. We are putting data-processing agreements and no-retention settings in place with them, and this policy will be updated when that is complete.

5. What we do not do

6. Who processes data for us

We use a small number of service providers. Each one processes data only to provide its service to us, and only the data listed here.

ProviderWhat it doesWhat it receives
SupabaseDatabase, authentication, and file storageYour account, what you make, recordings, uploaded and generated images, feedback and its attachments
Fly.ioHosting for the BlackForge serverRequests to the app, including your IP address in transit
AnthropicAI generation of device designs and sounds, and checking generated artworkYour prompt text and, for artwork checks, the generated image. No account identifier
fal.aiAI image generation and background removalYour prompt text and any reference image you attach. No account identifier
GoogleSign-in, only if you choose "Google"Handled by Google under its own policy; we receive your email, name, and an account identifier
GitHubSign-in, only if you choose "GitHub"Handled by GitHub under its own policy; we receive your email, name, and an account identifier
TONE3000Capture library, only if you connect your TONE3000 accountYour authorization to act on your TONE3000 account; requests for captures you choose

We do not load third-party analytics, fonts, or scripts on the sign-in page or these legal pages. If we add or change a provider, we will update this table.

7. Cookies and browser storage

BlackForge sets one cookie, which holds a signed session so that you stay signed in for up to 30 days. It is strictly necessary for the service to work, contains no tracking identifier, and is not read by anyone else. Because it is the only cookie and it is essential, no cookie consent banner is required, and we do not show one.

The app also keeps a working copy of your rigs, devices, and recent recordings in your browser's own storage so it loads fast and works offline. That copy is scoped to your account, hidden when you sign out, and can be removed by clearing site data in your browser.

8. How long we keep things

Things you have published under a license that allows reuse may already have been copied by others under that license; deleting the original does not undo those copies.

9. Your rights and choices

Wherever you live, you can ask us to:

Until in-app account deletion and export ship, email privacy@blackforge.io from the address on your account and we will handle the request by hand, normally within 30 days. If you are in the EU, UK, or another place with a data protection authority, you also have the right to complain to that authority. If we rely on your consent for something, you can withdraw it at any time.

10. Children

BlackForge is for people aged 16 or older. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has an account, tell us at privacy@blackforge.io and we will delete it.

11. Where data is stored

BlackForge is hosted in the United States and our providers process data there. If you use BlackForge from outside the US, your data is transferred to and stored in the US. Where the law requires it, we rely on standard contractual safeguards with our providers for those transfers.

12. Security

Data is encrypted in transit. Sessions are signed and cannot be forged without the server's secret. Storage is private by default and only becomes public when you publish something. No system is perfectly secure; if we learn of a breach affecting your data, we will tell you.

13. Changes to this policy

This is version 1. We will change it as the product changes and as legal review completes. When we do, the version and effective date at the top change, and for anything that matters to you we will tell you in the app or by email before it takes effect.

14. Contact

Privacy questions, requests, and complaints: privacy@blackforge.io.