Legal
Privacy Policy
We collect only what AlleForge needs to run, and we protect what we collect. This page explains exactly what that means — what we collect, why, and how it’s kept secure. For how the platform itself may be used, see our Terms of Service.
What We Collect
Account details, usage data, and information you send us directly — nothing more than what's needed to run AlleForge.
Why We Collect It
To provide the platform, keep it secure, and understand which features to invest in next.
How We Protect It
Encryption in transit and at rest, strict access controls, and continuous monitoring.
Your Rights
You can access, export, correct, or delete your data whenever you'd like.
How To Contact Us
Reach our team directly through the Contact page for any privacy question.
This page is example policy content written for demonstration purposes. It has not been reviewed by legal counsel and should not be relied on as-is — have a lawyer review and adapt it before using it in production.
Introduction
AlleForge (“we,” “us,” or “our”) operates a browser-native API workspace that helps developers build, test, document, and collaborate on APIs. This Privacy Policy explains what information we collect when you use AlleForge, why we collect it, how we use and protect it, and the choices available to you.
By creating an account or using AlleForge, you agree to the practices described in this policy. If you don’t agree with any part of it, please don’t use the platform, and feel free to reach out with questions before you do.
Information We Collect
We collect a limited set of information, grouped into the following categories:
- Account Information — your name, email address, hashed password, and organization details you provide when creating a workspace.
- Usage Analytics — aggregated interaction data, such as which features are used and how often, to help us improve the product.
- Device Information — operating system, browser type, and device identifiers used to keep sessions secure and diagnose issues.
- Browser Information — browser version and locale settings, used to render the workspace correctly and support accessibility.
- Authentication Data — session tokens and login timestamps used to keep your account secure.
- Support Communications — messages you send us through the contact form, email, or chat, including any attachments you choose to share.
- API Usage Data — metadata about requests you send through AlleForge (method, endpoint, response time) used to power features like history and collaboration.
We do not read or store the contents of requests you send to third-party APIs beyond what’s needed to display them back to you inside your own workspace.
How We Use Information
- To provide, maintain, and improve the AlleForge platform.
- To authenticate your account and protect against unauthorized access.
- To respond to support requests and communicate important updates.
- To understand how features are used so we can prioritize what to build next.
- To detect, investigate, and prevent abuse, fraud, or security incidents.
We do not sell your personal information, and we do not use the contents of your API requests to train any models without your explicit, separate consent.
Third-Party Services
We rely on a limited set of third-party service providers to operate AlleForge — for example, infrastructure hosting, email delivery, and authentication support. Each provider only receives the minimum information necessary to perform its function, and is bound by contractual obligations to protect your data.
See the “Third-Party Services” section further down this page for details on each category.
Data Retention
We retain account information for as long as your account is active, and for a limited period afterward in case you choose to reactivate it. Usage analytics are retained in aggregated or anonymized form once they’re no longer needed individually.
You can request deletion of your account and associated data at any time — see “Your Rights” below for how.
Security
We apply industry-standard technical and organizational measures to protect your data, including encryption in transit and at rest, strict access controls, and continuous monitoring for unusual activity.
No system can be guaranteed 100% secure. We encourage you to use a strong, unique password and to enable any additional account protections we offer.
International Transfers
AlleForge’s infrastructure may process and store data in countries other than your own. Where this happens, we take steps designed to ensure your information receives a level of protection consistent with this policy, regardless of where it’s processed.
Your Rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. See “Your Privacy Rights” further down this page for a full breakdown of how to exercise these.
Children's Privacy
AlleForge is not directed at children, and we do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, please contact us so we can remove it.
Policy Updates
We may update this policy as AlleForge evolves. When we make material changes, we’ll update the “Last Updated” date at the top of this page and, where appropriate, notify you directly.
Contact
If you have questions about this policy or how your data is handled, reach out through our Contact page or email our privacy team directly.
How we protect your data
Security, by design
Encryption
Data is encrypted in transit with TLS and at rest wherever it's stored.
Secure Infrastructure
Hosted on infrastructure built for isolation, redundancy, and uptime.
Access Controls
Every internal system access is authenticated, authorized, and logged.
Least Privilege
Team members only get access to the data required for their role.
Monitoring
Continuous monitoring watches for unusual access or activity patterns.
Backups
Regular, encrypted backups protect against accidental data loss.
Your privacy rights
You stay in control
Access Your Data
Request a copy of the personal information we hold about you at any time.
Update Information
Correct inaccurate account details directly from your workspace settings.
Delete Account
Permanently delete your account and associated data whenever you choose.
Export Data
Download your requests, collections, and workspace data in a portable format.
Withdraw Consent
Opt out of optional analytics or communications without affecting core access.
Contact Support
Reach out any time with questions or requests about your personal data.
Cookies & tracking
What we set, and why
An illustrative look at the cookie categories AlleForge uses. Adjust your browser settings at any time to control non-essential cookies.
Essential
Always onRequired for login, security, and core functionality. These can't be turned off.
Functional
Remembers preferences like theme, layout, and recently used workspaces.
Analytics
Helps us understand which features are used, and how often.
Performance
Monitors load times and errors so we can improve reliability.
Future Preferences
Coming SoonReserved for upcoming personalization controls.
Third-party services
Who else touches your data
AlleForge relies on a small number of service categories to operate. Each one only receives what it needs to do its job.
Authentication
Purpose
Secure sign-in and session management for your account.
Information shared
Email address and authentication tokens.
Why it's required
Needed to verify your identity and keep your account secure.
Analytics
Purpose
Understand product usage so we can improve features.
Information shared
Aggregated, non-identifying usage events.
Why it's required
Helps us prioritize what to build without exposing personal data.
Payment Provider
Purpose
Process subscription billing for paid workspaces.
Information shared
Billing details are handled directly by the provider — AlleForge never stores full card numbers.
Why it's required
Only used for customers on a paid plan.
Infrastructure
Purpose
Hosting, storage, and delivery of the AlleForge platform.
Information shared
Encrypted application data required to run the service.
Why it's required
The platform can't run reliably without hosting infrastructure.
Email Services
Purpose
Deliver account, security, and product emails.
Information shared
Your email address and the content of transactional messages.
Why it's required
Needed to reach you for login verification and important updates.
Questions about privacy?
Our team is happy to walk through anything in this policy — reach out any time.