The short version: Forge never stores your source code or the contents of your tickets, documents, or messages — that stays in your own AI coding tool, not on our servers. We collect workflow and usage metadata to run the analytics dashboard — things like task types, work-item titles and links, timing, and AI token usage. You own your work. We help you measure it.
1. Who we are
ShipToday, Inc. ("ShipToday", "we", "us", or "our") operates the Forge product and the ShipToday website at shiptoday.ai. If you have questions about this policy, contact us at privacy@shiptoday.ai.
2. What information we collect
We collect information in two ways — information you give us directly, and information generated automatically when you use Forge.
Information you provide:
- Account information — name and work email address, collected when you sign up for Forge (free or paid).
- Payment information — billing details collected and processed by our payment provider. We do not store full card numbers.
- Communications — any messages you send us by email or through our contact form.
Information generated automatically:
- Workflow metadata — the task types and workflows you run, the SDLC stage, timing, cycle counts, and outcome signals (e.g., whether a PR was approved), the connected tools and local skills a step used, and the key, title, and link of the work item a session relates to. We record this per session — including AI coding sessions that weren't explicitly started as a Forge workflow — to power the analytics dashboard.
- AI token usage — per-session token counts (input, cached, and output) and the AI model used, so the dashboard can show what your AI tooling costs. We read these from the usage your tools already record; Forge does not sit between your tools and the AI model.
- Operational data — error and performance logs from our hosting, used to keep the product running, diagnose issues, and improve it.
- Device and connection data — IP address, client type (e.g., Claude Code, Codex, Cursor), and operating system, collected for security and diagnostic purposes.
What we do not collect:
- Your source code or codebase contents. Code stays in your AI coding tool; it is never sent to or stored by Forge.
- The body or description of your tickets, PRDs, documents, or internal communications. (We do store a work item's key, title, and link — see above.)
- Anything else from your connected tools (Jira, Linear, Notion, GitHub, etc.) beyond what a workflow step needs to run. Apart from the work-item identifiers noted above, that content is used in the moment and not retained after the step completes.
3. How we use your information
- To provide, operate, and improve the Forge product.
- To generate and display the analytics dashboard available to your team.
- To process payments and manage your subscription.
- To send product updates, security notices, and support communications.
- To diagnose and fix technical issues.
- To comply with legal obligations.
We do not sell your personal information. We do not use your data to train AI models.
4. How we share your information
We share information only as follows:
- Service providers — third parties who help us run the product: our cloud hosting provider, and our authentication and billing provider, which holds your account name, email, organization membership, and subscription status and processes payments (we store no card data). They are contractually bound to use your data only to provide their service to us.
- Feedback delivery — when you send feedback through Forge, your message — with any secrets or credentials automatically stripped out — is delivered to our team through our internal messaging tool. We don't store the feedback content.
- Your organization — on paid team add-ons (when available), your workspace administrators can see your team's Forge activity and the names and emails of the members who generated it. Individual members see only their own activity.
- Legal requirements — if required by law, court order, or to protect the rights and safety of ShipToday or others.
- Business transfers — if ShipToday is acquired or merges with another entity, your information may be transferred as part of that transaction. We will notify you before this happens.
5. Data retention
We retain account information for as long as your account is active, plus a reasonable period after closure to meet legal obligations. Workflow and usage metadata is retained for the life of your account so your dashboard can show long-term trends; we do not currently apply a fixed deletion window to it. You can request deletion of your data at any time — see Section 8.
6. Security
We implement industry-standard security controls to protect your information, including encryption in transit (TLS) and at rest, access controls, and regular security reviews. However, no system is completely secure, and we cannot guarantee the absolute security of your information.
7. Compliance and certifications
Forge's free Individual and Team plans run on the secure infrastructure described in Section 6. Our Business plan runs on compliance-certified infrastructure for organizations with regulatory requirements. Compliance is inherited from the certified providers Forge is built on — here is what each layer covers:
- Application hosting & data — hosted on Render, which is SOC 2 Type II and ISO 27001 certified. HIPAA is supported through a HIPAA-enabled workspace under a signed Business Associate Agreement (BAA), available to Business-plan accounts.
- Authentication & identity — handled by Clerk, which is SOC 2 Type II certified. Clerk stores account data in ISO 27001-certified cloud infrastructure (Google Cloud and Cloudflare).
Because HIPAA coverage depends on a signed BAA and applies to the hosting and data layer, it is offered on selected Business-plan services rather than across the entire product. The SOC 2 Type II and ISO 27001 certifications above are maintained by our infrastructure providers; your data is protected by their audited controls.
To request a HIPAA Business Associate Agreement (BAA) for your use of the Business plan, contact privacy@shiptoday.ai. SOC 2 Type II reports and ISO 27001 certificates are issued by Render and Clerk rather than ShipToday; we can help you obtain the relevant provider documentation, subject to their terms.
8. Your rights
Depending on your location, you may have rights under applicable privacy law including:
- The right to access the personal data we hold about you.
- The right to correct inaccurate data.
- The right to request deletion of your data.
- The right to object to or restrict certain processing.
- The right to data portability.
- The right to withdraw consent where processing is based on consent.
To exercise any of these rights, email privacy@shiptoday.ai. We will respond within 30 days.
9. Cookies
We use essential cookies required to keep you signed in and to make the product work. The dashboard includes a cookie-consent control that governs any non-essential cookies (such as product analytics); these are not set unless you allow them. We do not use advertising cookies or share cookie data with ad networks.
10. Children
Forge is a professional tool intended for use by individuals 18 years of age or older. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
11. International transfers
ShipToday operates globally. Your information may be processed in countries outside your own. Where we transfer data internationally, we use appropriate safeguards such as Standard Contractual Clauses to ensure your data is protected to the same standard as in your home jurisdiction.
12. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by email (if you have an account) or by posting a prominent notice on our website at least 14 days before the change takes effect. Your continued use of Forge after that date constitutes acceptance of the updated policy.
13. Contact us
For any privacy-related questions or requests, contact our Privacy Team:
ShipToday, Inc.
Privacy Team
privacy@shiptoday.ai