Privacy
EngineForge is operated by A & Y, licensed dealer no. 558553418, Nahshol 4, Rosh HaAyin, Israel. A & Y is the controller of the personal data described below, and privacy questions go to support@engineforge.ai.
Last updated 28 August 2026.
Who controls this data
A & Y is the data controller for everything described in this notice: account, service, telemetry, diagnostic and billing-record data. Paddle is the merchant of record for every EngineForge purchase and is a separate, independent controller for the payment data it collects at its checkout. That payment data is covered by Paddle's own privacy notice, not by this one.
Payments and the merchant of record
EngineForge plans and top-ups are sold through Paddle as merchant of record. Paddle is the legal seller of the purchase, issues the invoice, and is responsible for sales tax and VAT on it. Payment details, including card numbers, are entered on Paddle's checkout and go to Paddle. They never reach our systems and we never store them. When a checkout is opened, we send Paddle the email address on your account plus enough detail to attribute the resulting payment to the right account: your EngineForge user identifier, and with it the plan on a subscription, or, for a top-up, the fact that it is a top-up and how much usage it grants.
Billing records EngineForge keeps
We store what Paddle returns to us so that your account receives what you paid for. That is a billing customer identifier and the provider that issued it, your current plan, its status and its billing period, the usage allowance for the current month and how much of it has been spent, and, for each top-up you buy, the amount paid and the usage it granted.
Billing notifications are stored exactly as received
We keep an unaltered copy of every billing notification Paddle sends us, so that a payment can be reconstructed and audited if it is ever questioned. Those records carry the subscription, transaction, plan and amounts, the identifiers described above, and whatever else Paddle includes, which can include your email address and the country and postcode Paddle used to calculate tax. They do not carry card numbers.
Website analytics
The public website uses Vercel Analytics, which records page views and the pages visited so that we can measure how the site is used. We do not send it any custom events, and it is not used to profile you or to target advertising.
Account and authentication
We use Supabase for account sessions and authenticated service requests. Sign-in is OAuth only: choosing Continue with GitHub or Continue with Google sends you through that provider's OAuth flow and back to the EngineForge authentication callback, so we never receive or store a password. We read the resulting user identifier, email address, and any profile details the provider returns, such as your display name and avatar, to show your account and to check your access.
Cookies
The website sets Supabase authentication cookies, which are what keep you signed in between requests. There are no advertising cookies and no cross-site tracking cookies, and Vercel Analytics measures page views without setting one. Clearing the authentication cookies signs you out.
Local development data
Your project files, the local search index, Code Graph source data, ignore-rule processing, and Unity and Godot bridge operations all run on your own machine. We never copy your project wholesale to our servers. What leaves your machine is the working context you send with a model request, the service, usage and telemetry records described under Service and usage records and Automatic platform telemetry, and anything you choose to attach to a diagnostic report.
Model requests
When you ask the Crew to use a model, we send the prompt, the conversation, the available tools and the working context you selected through our gateway to the provider that serves the model you chose. The providers in use today are Anthropic, OpenAI and DeepSeek, and which one receives a given request follows the model you picked for it, and nothing else.
Service and usage records
We record the request and usage information needed to operate the gateway, meter your plan, and diagnose faults. For each model call that includes the model used, token counts by billing class, the cost of the call, timing, tool and error activity, session and conversation identifiers, and the application version and platform the call came from.
Automatic platform telemetry
The application sends us the outcome of editor bridge commands, search quality data including search queries and result scores, and aggregate metrics about the health of your local index. This is used to keep the product working correctly and is not used to profile you.
Feedback and diagnostics
Feedback about a session is sent to us only when you submit it. Diagnostic reports are also sent only when you choose to send one, and can contain conversation content, logs, a timeline of the tools that ran, agent state, system and version details, and any note you add. Please remove anything confidential from a report before you send it.
Who this data is shared with
Supabase hosts our database and account sessions. Vercel hosts the website and the gateway and provides the website analytics. Axiom receives our server-side logs. Anthropic, OpenAI and DeepSeek are the configured model providers, and the one serving the model you chose receives the prompt and working context of that request at the moment you make it. Paddle receives the checkout data described above and holds it as its own controller. Personal data is not sold, and it is not shared for advertising.
Why this processing is allowed
Account, gateway, model-request and billing data are processed to perform the contract between you and A & Y. Service records, telemetry and error data are processed on the legitimate interest of keeping the platform working, correct, and correctly paid for. Session feedback and diagnostic reports are processed on your consent, because each is sent only when you choose to send it. Billing and accounting records are also processed to meet the record-keeping obligations that apply to a licensed dealer in Israel.
How long it is kept
Account and profile data are kept while your account exists and are deleted when the account is deleted. Billing and accounting records outlive the account: they are kept for as long as Israeli accounting and tax rules require a licensed dealer to keep them, and the usage periods and top-up records that justify a charge are kept with them. Service logs, telemetry, and diagnostic reports are kept on rolling operational retention and are not used to build a profile of you.
Your rights
You can ask for a copy of the personal data held about you, ask for it to be corrected or deleted, ask for it in a portable form, object to the processing that rests on legitimate interests, and withdraw consent for anything that rests on consent. Write to support@engineforge.ai and we will respond within one month. If you are in the UK or the EEA you may also complain to your national supervisory authority. Requests about payments, invoices, or the card on file belong to Paddle, which holds that data as its own controller; the billing portal linked from your account settings opens Paddle directly.
Where data is processed
We operate from Israel. Our hosting, database, logging and model providers operate in the United States and the European Union, and DeepSeek operates from China, so personal data is transferred internationally and a request you send to a DeepSeek model is processed in China. Israel is recognised by the European Commission as providing an adequate level of protection, and transfers onward to providers rely on the data protection terms in those providers' own agreements.
Security
Requests are authenticated before account data is returned, and an account is served only its own records. The website and the gateway are served over TLS. Provider credentials are held server side and are never sent to the browser. Billing notifications are accepted only when they carry a valid signature from the payment provider, so a forged payment event cannot change what an account is owed. No system can be completely secure, and we do not claim otherwise. If a breach affects your personal data and the law requires us to tell you, we will do so without undue delay.
Children
EngineForge is a professional development tool and is not directed at children. It is not intended for anyone under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to support@engineforge.ai and we will delete it.
If you are in the United States
We do not sell personal data and we do not share it for cross-context behavioural advertising, in the sense those terms are given by California law, and we have not done so in the past twelve months. Residents of California and of other states with comparable laws can exercise their rights of access, correction, deletion and portability using the same address below, and we will not treat you differently for doing so.
Changes to this notice
We update this notice when the way we handle personal data changes. The current version always lives at this address, and the date it last changed is shown at the top of the page. Where a change materially affects you, we will give notice by email or in the application before it takes effect.
What this notice does not cover
It does not cover the payment details you enter at Paddle checkout. Paddle collects those as its own controller and describes them in its own privacy notice. It also does not cover third-party services you choose to use alongside EngineForge, which are governed by their own notices.
Questions or requests
Contact support@engineforge.ai. See the technical Privacy & Data guide for payload-level detail, or use the Contact page for support and policy requests.
Purchases are sold by Paddle as merchant of record, under the Paddle buyer terms you accept at checkout.
Read the EngineForge Terms.