1. Scope and controller
This notice covers the public website at forgedesk.dev, installer and update requests made to that domain, and the ForgeDesk desktop application where this notice says so. “ForgeDesk,” “we,” and “us” mean the publisher of ForgeDesk.
For privacy questions or requests, email privacy@forgedesk.dev. A postal contact and the publisher’s complete legal identity will be added before commercial distribution or active targeting of jurisdictions that require those details.
2. At a glance
| Activity | What happens | Your control |
|---|---|---|
| Visit the website | Hosting providers process ordinary request and security data needed to deliver the site. | No account or form is required. |
| Optional website analytics | Google Analytics loads only after affirmative consent. Advertising features are disabled. | Accept, reject, or withdraw through “Privacy choices.” Global Privacy Control keeps analytics off. |
| Use local models | Core prompts, conversations, project context, and model output are processed on your PC when you use a local Ollama model. | You choose the project, files, model, and access mode. |
| Use an online feature | The selected provider receives the data needed to perform that request. | Connections are optional and configured or invoked by you. |
3. Website, downloads, and updates
Hosting and security data
ForgeDesk uses Firebase Hosting to deliver the website, installers, and signed update channel. Google and the content-delivery infrastructure may process IP address, request time, requested URL, browser or device information, referrer, and security diagnostics to deliver content, prevent abuse, and maintain reliability. ForgeDesk does not operate a separate website account database or public contact form.
Downloads and update checks
Downloading the installer creates an ordinary web request. Installed copies periodically request the signed update manifest from forgedesk.dev and, when an update is available, may download it. These requests reveal normal network metadata to the hosting provider. They do not include your prompts or project files.
Consent-gated Google Analytics
If you accept optional analytics, the site loads Google Analytics 4 (Measurement ID G-5MMW5BBS0Y) to measure page visits and ForgeDesk download-link interactions. The implementation:
- sends no Google Analytics request before consent;
- keeps Google Signals, advertising personalization, ads storage, user IDs, user-provided data, enhanced measurement, and granular location/device collection off;
- removes query strings from the page location sent to Analytics;
- uses a fixed 60-day analytics-cookie lifetime and two-month user/event retention; and
- does not intentionally send prompts, project names, file names, email addresses, or account identifiers.
Google receives IP address at collection and may derive coarse location before discarding the address from Analytics data. See Google’s Analytics privacy information and the ForgeDesk Cookie Notice.
4. Data stored by the desktop app
ForgeDesk stores settings, projects, conversations, drafts, task state, permissions, checkpoints, logs, previews, screenshots, generated images, and connector configuration on the Windows PC where it runs. Project files remain in the folders you select. Local-model prompts and responses are sent to the local or private model endpoint you configure.
ForgeDesk does not receive that device-local content merely because you use the app. The publisher cannot remotely access or erase data that never leaves your machine.
5. Optional online features and connections
When you deliberately use an online feature, information leaves the core local workspace as needed for that request:
- Remote model endpoints: prompts, attachments, context, and output are processed by the endpoint you configure.
- Web research and browser tools: search services and visited websites receive normal request data; pages may receive task inputs you authorize the browser to enter.
- Gmail: if connected, ForgeDesk requests Google’s Gmail modify scope so it can read, draft, send, label, and manage messages at your direction. OAuth credentials are stored locally. Gmail data is used only to provide user-requested features and is not used for advertising.
- GitHub, MCP servers, and other connectors: the configured service receives requests and content needed for the tool you invoke, under that service’s terms and privacy notice.
- Android remote access: paired devices connect to the PC-hosted ForgeDesk workspace through the private network configuration you establish. The PC remains the host.
If you combine an online connector with a remote model, content returned by the connector can become part of a prompt to that model. Review the task, provider, and permission settings before sending.
6. Purposes and legal bases
| Purpose | Data | Basis where GDPR/UK GDPR applies |
|---|---|---|
| Deliver and secure the website, installer, and updates | Request and security metadata | Legitimate interests in providing a secure service; performance of requested service where applicable |
| Optional audience and download measurement | Consent-gated GA4 device, page, and event data | Consent |
| Perform an optional connected task | Data you direct to the selected provider | Performance of your request; consent or another disclosed basis where required |
| Comply with law and protect rights | Relevant records | Legal obligation or legitimate interests |
7. Recipients and international transfers
Website data may be processed by Google as the Firebase Hosting and Google Analytics provider. Optional connected services receive data only when configured or used. We may also disclose information when legally required or necessary to protect users, the public, or the service.
Providers may process data in countries other than yours, including the United States. Where required, transfers should be covered by applicable contractual and legal safeguards, such as standard contractual clauses or an adequacy framework. The publisher must complete processor agreements and transfer assessments appropriate to its legal entity and markets before broad international distribution.
ForgeDesk does not sell personal information. Analytics is configured without advertising features, and no data is intentionally shared for cross-context behavioral advertising.
8. Retention, deletion, and security
- Consent preference: kept in browser local storage until you change it or clear site data.
- Analytics identifiers: configured to expire after 60 days without renewal; user and event data retention is set to two months. Aggregated reports may remain longer.
- Hosting records: retained under the hosting provider’s operational and security schedules; ForgeDesk does not keep a separate copy by default.
- Device-local app data: retained until you delete it. Project deletion keeps project files unless you explicitly choose to move the folder to the Recycle Bin. Backups or engine archives may remain.
- Connected-service data: retained according to the provider you chose and any local copy ForgeDesk created.
ForgeDesk uses HTTPS, restrictive browser security headers, signed update metadata, local credential protection, origin validation, and permission controls. No system is completely secure; keep Windows and ForgeDesk updated and protect access to your PC.
9. Your privacy rights
Depending on where you live, you may have rights to know, access, correct, delete, restrict, object, port, or appeal a decision about personal data, and to withdraw consent without affecting earlier lawful processing. You may also complain to your local data-protection authority.
Email privacy@forgedesk.dev with “Privacy request” in the subject. We may need enough information to verify and fulfill the request. We will not discriminate against you for exercising a privacy right. For data stored only on your device, we can provide instructions but cannot remotely access or erase it.
Use the “Privacy choices” control in the footer to withdraw analytics consent. The site also treats a supported Global Privacy Control signal as a direction to keep optional analytics off.
10. Children
ForgeDesk is a general-audience productivity and development tool, not directed to children under 13. Do not connect a child’s account or submit a child’s personal information through an optional service without the authorization required where you live. Contact us if you believe a child provided data to the publisher.
11. Changes and contact
We may update this notice as ForgeDesk, its providers, or applicable requirements change. The effective date will change, and material changes will be presented through the website or app where appropriate.
Privacy contact: privacy@forgedesk.dev
Security reports: security@forgedesk.dev
Website: https://forgedesk.dev/