Last updated
Privacy Policy
How Community Inviter, Inc. collects, uses, shares, and retains information for OGForge at ogforge.co.
This Privacy Policy describes how Community Inviter, Inc., a corporation organized under the laws of Wyoming, United States (“Company,” “we,” “us,” or “our”), processes information in connection with the OGForge website at ogforge.co, the web editor, HTTP API, MCP server, x402 agent lane, and related services (the “Service”). Community Inviter, Inc. is the controller of personal data processed through the Service.
Community Inviter, Inc. also operates inviter.co. This policy applies only to ogforge.co and the Service. inviter.co is a separate offering with its own notices. We may share limited information with our affiliates as described in Section 5.
By using the Service, you acknowledge this policy. Where consent is required (for example, optional analytics or advertising cookies), we will ask as described in the Cookie Policy. Use of the Service is also subject to our Terms of Use. Disputes relating to privacy are subject to the informal-resolution, arbitration, and class-action waiver in those Terms to the fullest extent permitted by law.
Questions: [email protected] or the contact form.
1. Information we collect
We collect information you provide, information generated by your use of the Service, and information from third parties who help us operate it.
1.1 Account and communications
- Email address, password hash (argon2id — we do not store plaintext passwords),
email-verification status, and optional Google account identifier (OAuth
sub) if you use Sign in with Google. - Entitlement tier (Free, Pro, or Enterprise) and related account flags.
- Messages you send via contact or enterprise forms (name, email, optional company, and message).
- Support correspondence you send to our inboxes.
1.2 Session, security, and device
- An httpOnly
ogf_sessioncookie (JWT, 7-day sliding expiry) and a short-livedogf_oauth_statecookie during Google sign-in. - Cloudflare Turnstile tokens on register, login, and password-reset forms, and related bot-detection signals.
- IP address, user agent, approximate location derived from IP, timestamps, request paths, and similar log and rate-limit data. Render analytics store a hashed client IP that is not designed to be reversed to an address.
1.3 Uploads, renders, and keys
- Images and parameters you submit as template inputs. Anonymous and Free uploads are stored ephemerally and deleted after 24 hours. Pro and Enterprise uploads persist until you delete them or the account is closed, subject to residual backups and legal holds.
- Render records for paid accounts (template id, preset, format, URL, timestamp) and operational metrics (template, timing).
- API keys stored hashed, with a redacted prefix and last-used time so you can recognize them.
1.4 Billing and agent payments
- Stripe customer and subscription identifiers and status. Stripe processes card details; we do not store full card numbers.
- For x402: transaction hash, network, payer address, and resource URL, used to prevent replay and to deliver the paid render.
1.5 Cookies, analytics, and advertising
Essential cookies run the session and security flows. If you allow optional cookies, Google
Analytics 4 and, for anonymous and Free visitors, Google AdSense may collect device and usage
data as described in the Cookie Policy and Google’s own policies. We
store your cookie choice in localStorage (ogf_cookie_consent).
1.6 Sources
We collect information directly from you, automatically from browsers and clients that call the Service, from payment and identity providers (Stripe, Google, Cloudflare, blockchain networks), and from our processors listed in Section 5.
2. How we use information
We use information to:
- provide, operate, maintain, and improve the Service, accounts, quotas, and support;
- authenticate users, issue and verify sessions and API keys, and prevent abuse, fraud, and security incidents;
- process payments, prevent replay of x402 payments, and manage subscriptions;
- send transactional email (verification, password reset, and similar service messages);
- respond to inquiries and enterprise sales requests;
- measure traffic and show advertising — only if you allow optional cookies, and ads only for anonymous and Free visitors;
- comply with law, enforce our Terms of Use, and protect our rights, users, and the public;
- transfer or integrate systems in a corporate transaction (financing, merger, acquisition, or sale of assets).
We do not use your render content to train foundation models. We do not sell personal information for money. See Section 8 regarding advertising “sharing” under some U.S. state laws.
3. Legal bases (EEA, UK, and similar)
Where a legal basis is required, we rely on:
- Contract — to provide the Service you request (accounts, renders, billing, support).
- Legitimate interests — to secure the Service, prevent fraud and abuse, understand aggregate usage, improve the product, and defend legal claims, provided those interests are not overridden by your rights.
- Consent — optional analytics and advertising cookies, and other processing we specifically ask you to agree to. You may withdraw consent as described in the Cookie Policy, without affecting prior lawful processing.
- Legal obligation — tax, accounting, law-enforcement, and similar duties.
4. Retention
- Account and billing identifiers: while the account exists, then as needed for tax, fraud, dispute, and legal retention.
- Free and anonymous uploads: 24 hours, then deleted from primary storage.
- Paid uploads and render history: until you delete them or the account is closed, then residual copies as above.
- Email verification and reset tokens: hours, then expired.
- Hashed render analytics and rate-limit rows: short operational windows.
- x402 payment hashes: retained as needed to block replay.
- Security and server logs: a limited operational period unless needed longer for an incident or claim.
We may retain information longer if we reasonably believe it is required for a legal hold, investigation, or dispute. When we delete, residual copies may remain in encrypted backups until they cycle out.
5. How we share information
We do not sell your personal information for monetary consideration. We share information as follows:
- Processors that host or help run the Service, including infrastructure and object storage we operate or contract (including Cloudflare R2 for paid files); Plunk (transactional email); Stripe (checkout and subscriptions); Cloudflare (including Turnstile); Google (optional Sign in with Google; optional Analytics and AdSense after consent).
- Affiliates. Community Inviter, Inc. may share information with its officers, employees, and affiliated operations — including personnel who also work on inviter.co — for corporate administration, security, fraud prevention, customer support, and legal compliance. Using inviter.co is optional and covered by that site’s notices.
- Legal and safety. We may disclose information if we believe in good faith it is required by law, legal process, or government request, or to protect the rights, property, or safety of Community Inviter, Inc., our users, or the public, including to enforce our Terms of Use.
- Business transfers. Information may be transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets. Successors may process it as described in this policy or a successor notice.
- With your direction — for example, if you authorize a third-party integration or payment.
Public render URLs you create may be fetched by anyone who has the link, including social networks and crawlers. Do not put secrets in template parameters or public URLs.
6. International transfers
We are based in the United States. Processors may store or access data in the United States, the European Union, and other countries. Those countries may not provide the same legal protections as your home country. Where required, we rely on appropriate safeguards such as the processor’s Standard Contractual Clauses or other lawful transfer mechanisms. By using the Service from outside the United States, you understand that your information will be processed in the United States.
7. Security
We use reasonable administrative, technical, and organizational measures designed to protect personal data, including hashed passwords, hashed API keys, and httpOnly session cookies. No method of transmission or storage is 100% secure. You are responsible for safeguarding credentials and for activity on your account. We are not liable for unauthorized access that results from your failure to maintain the security of your devices, passwords, or keys, except where we cannot exclude that liability under mandatory law.
8. Cookies and U.S. “sale” / “sharing”
See the Cookie Policy for the cookies and similar technologies we use and how to change your choice.
We do not sell personal information for money. If you allow optional advertising cookies, Google may use identifiers for cross-context behavioral advertising. Under some U.S. state laws (including California), that may be “sharing” or a “sale.” You can refuse or withdraw that activity by choosing “Essential only” on the Cookie Policy page or the banner, and via Google’s ad settings linked there. We honor that mechanism as our opt-out of sale/sharing for the Service. We do not have actual knowledge of selling or sharing the personal information of consumers under 16.
We do not respond to browser “Do Not Track” signals because there is no consistent industry standard; the cookie banner and Cookie Policy controls are the method we support.
9. Your rights and how we handle requests
Depending on where you live, you may have rights to request access, correction, deletion, export (portability), restriction, or to object to certain processing, and to appeal a denial. You may also have the right to lodge a complaint with a supervisory authority (for example, in the EEA or UK).
Email [email protected] from the address on your account when possible. We may require reasonable verification (including that we can match you to an account) before acting. We may decline, limit, or charge a reasonable fee for requests that are unfounded, excessive, repetitive, legally privileged, or that would compromise the security, integrity, or rights of others, or that we are not required by law to grant. We will not discriminate against you for exercising rights the law provides.
Authorized agents (including California agents) must provide proof of authority. We may still require you to verify the request. We do not process requests that we cannot reasonably verify.
You may close your account through the product where that control exists, or by emailing us. Closing an account deletes or de-identifies personal data we are not required or permitted to keep.
10. Additional U.S. state disclosures
This section supplements the rest of this policy for residents of California and other states with consumer privacy laws (including, where applicable, Virginia, Colorado, Connecticut, Utah, and similar statutes). Categories we may collect, depending on how you use the Service:
- identifiers (email, account id, cookie ids, IP address, Google sub);
- customer records and commercial information (plan, Stripe identifiers, purchase history);
- internet or electronic activity (logs, renders, pages viewed if analytics is allowed);
- approximate geolocation derived from IP;
- inferences drawn from the above for security, fraud, and product operation;
- user content you upload (which may include photos or other information you choose to provide).
We do not collect government ID numbers, financial account numbers (Stripe may), precise geolocation, or biometric identifiers. Account credentials are stored hashed and are not used for cross-context advertising. We do not use sensitive personal information for purposes that require a right to limit under the CPRA beyond providing the Service.
Retention for each category follows Section 4. Business purposes of disclosure are those in Sections 2 and 5. We do not use personal information for legally significant solely automated decisions about you (for example, eligibility for credit or employment).
Nevada residents: we do not sell covered information as defined by Nevada law. You may email [email protected] with the subject “Nevada do not sell.”
11. Children
The Service is for users 18 years of age and older. We do not knowingly collect personal information from children under 18, or under 16 where a higher age is required for our processing. If you believe we have collected such information, email [email protected] and we will delete it except where we are required to retain a record of the request.
12. Automated processing
We use automated systems for rate limits, bot checks (Turnstile), quota enforcement, fraud and abuse detection, and (if you opt in) analytics and ads. These do not produce legal effects similar to a bank or employment decision. Human review of enterprise inquiries is manual.
13. Changes
We may update this policy by posting a new version on this page and changing the “Last updated” date. Material changes that affect an existing account may also be noted in-product or by email when we have an address on file. Continued use after the effective date constitutes acknowledgment of the updated policy. If you do not agree, stop using the Service and close your account.
14. Contact
Controller: Community Inviter, Inc., a corporation organized under the laws of Wyoming, United States. Privacy requests: [email protected]. Formal service of process must comply with Wyoming law, including service on our registered agent as then listed with the Wyoming Secretary of State.