Privacy Policy
Last updated: September 30, 2026
Overview
Forjari is operated by VSBD.iT OÜ as a small, operator-run product. This policy explains what data we collect when you use Forjari, why we collect it, who can see it, which providers process it and on what terms, and how long it is kept. It covers both roles on the platform: clients who talk to an expert's AI clone, and experts who configure one. We don't collect data we don't need and we don't sell your data.
What we collect
When you create an account, we collect:
- Your email address and, if you sign in with Google, your Google account name and profile picture (via Google OAuth / Supabase Auth)
- The conversations you have with a clone, including all messages
- A distilled "user model" - a structured summary Forjari builds across your sessions with one expert to maintain continuity (one model per expert you work with, never merged across experts)
- Session summaries and action items generated at the end of each session
- Optional wellbeing inputs you add on your dashboard - mood check-ins before and after sessions, and key insights you write down
- If you enable notifications, a web-push subscription token for your browser (used only to deliver the reminders you opted into)
- Basic subscription data (plan tier, billing status) via Stripe
- If you file a bug report: the title, steps and optional screenshot you submit, plus technical diagnostics (page, language, browser, operating system, viewport, deployed version, last request id)
If you are an expert, we additionally collect what you author in the studio:
- Your clone configuration - identity, methodology, voice anchor, materials you paste or attach, openers, empty-chat hint and call instructions - and the translations Forjari generates from the opener and hint
- Your public profile (photo, headline, bio, specialties, credentials, links) if you fill it in
- The voice recording you make or upload to clone your voice, and the identifier of the synthetic voice created from it
- The photo or short video you submit for a video avatar, and the animated avatar bundle generated from it
- Payout details, described under Data storage and security
We do not collect your name, phone number, physical address, or any demographic data beyond what you voluntarily provide in conversation, in your expert profile, or at checkout (see billing below).
How your data is used
Your conversation data is used to:
- Generate the clone's replies during sessions and the summary at the end of a session (sent to an AI model - see AI processing below)
- Build and maintain your user model for the expert you are working with
- Display your session history and open commitments in the dashboard
- Send the reminders and emails you opted into, or that are needed to run your account
An expert's clone configuration is used for exactly one thing: powering that expert's own clone in sessions with that expert's clients. It is never shared with other experts, never shown to clients as a document, and never used to train any model.
AI processing and model training
Every session reply and every end-of-session summary is generated by a large language model. Requests are routed through Vercel AI Gateway to Anthropic's Claude models by default, or to another provider the operator selects from the gateway's catalogue. Two constraints are attached to every request we send: zero data retention and no training on prompts. The gateway then routes only to providers with which Vercel holds a written zero-retention and no-training agreement, and refuses the request rather than fall back to a provider that retains data. The gateway itself does not retain prompts or outputs. See Vercel's zero data retention and disallow prompt training documentation, and Anthropic's API data retention page and commercial terms, which state that API inputs and outputs are never used to train Anthropic's models.
If the gateway is unavailable, a request may be sent directly to Anthropic's API under our commercial agreement. That path is covered by the same no-training commitment and by Anthropic's standard commercial retention policy (short-term retention for abuse monitoring, then deletion) instead of zero retention.
A clone never learns from clients. Nothing a client says is used to train a model, and nothing a client says is written into the expert's clone configuration. What a client shares is stored only in that client's own conversation, summary and user model for that specific client-expert relationship; it is never surfaced to other clients of the same expert and never reaches another expert's clone. Ideas a client brings to a session stay the client's.
The engine instructs every clone not to reveal its instructions or materials and to treat conversation content as data rather than commands. These are technical safeguards, not guarantees: any AI system can be probed, and an expert's method is observable to a client in the ordinary course of using the clone. The Terms of Service prohibit clients from extracting, reconstructing or reusing an expert's methodology, and experts control what they put into the materials field.
Voice, video calls and avatars
Optional dictation and read-aloud in normal chat run on your browser's built-in speech services - audio is processed by your browser or OS vendor (for example, Chrome performs dictation via Google's speech service) and Forjari never records or stores that audio. In video calls your microphone audio is likewise transcribed by your browser and never stored by us.
Cloned voice (experts). If you enable voice cloning, your recording is sent to ElevenLabs to create a synthetic voice, and each spoken sentence in a video call is generated by ElevenLabs from that voice. ElevenLabs processes the recording under its own privacy policy, which describes retention of voice-derived data for up to three years after the last interaction unless deleted. In our ElevenLabs account the "improve the models" data-use setting is switched off and public sharing is opted out, so recordings and generated speech are not used to train ElevenLabs' models. We delete the synthetic voice at ElevenLabs when you remove the voice in the studio or delete your account (unless another clone of yours still uses it). We also keep your original recording in a private storage bucket that is served to nobody - its only purpose is to re-create the same voice with a different provider without asking you to re-record - and delete it at the same moments.
Video avatar (experts). If you generate a video avatar, the photo or short video you submit is processed on GPU servers that Forjari rents from Scaleway in the EU (Paris and Warsaw) and operates itself; no third-party avatar company receives your likeness. The source clip and the generated avatar bundle are stored in private buckets and on those servers, and are used only to render your clone in video calls with your own clients.
Clients always interact with an AI clone and the interface presents it as such. The likeness features change how the clone looks and sounds, not what it is.
What your expert can see
By default, your expert sees your session summaries, commitments, and session counts - and, under the same sharing switch, your mood check-ins and the key insights you record - never raw transcripts - so they can follow your progress between sessions. You stay in control: turn sharing off account-wide in settings (your expert then sees nothing about your sessions, mood, or insights), hide any single session, or share a specific session in full - including its raw transcript. If you joined through an expert's invite, they also see your name, email, plan tier, and join date (their client roster). Your distilled user model always stays private to you.
Everything above is a view for the expert, not an input to their clone: what your expert can read about you is never fed back into the clone's configuration (see AI processing above).
Who at Forjari can see your data
Forjari is run by its founder. There is no support team with routine access to user data. The operator holds administrative credentials to the database and uses them only for: support you ask for, investigating security incidents or abuse, resolving billing disputes, and complying with legal obligations. Conversations are not read to improve the product, for marketing, or out of curiosity.
The admin console shows account details, session summaries and commitments - not raw transcripts. Reading a raw transcript requires direct database access and is limited to the purposes above. Privileged administrative actions are recorded in an audit log. Error reports (Sentry) and operational logs (Axiom) contain technical fields only, never conversation content.
Data storage and security
All account data is stored in Supabase (PostgreSQL) in the EU (Ireland). Row-level security (RLS) is enforced at the database level - your data is scoped to your user ID and inaccessible to other users, and a client's data is scoped to the specific client-expert relationship it belongs to, so one expert's clone can never read another expert's client data. Supabase encrypts data at rest. Connections are encrypted in transit via TLS. Application servers run on Vercel in the EU (Dublin); avatar rendering runs on Forjari-operated servers in the EU (Paris, Warsaw).
Billing is handled by Stripe. At checkout, Stripe collects your billing address and uses it to calculate and collect any applicable VAT or sales tax (Stripe Tax); we receive your country/region and the tax amounts as part of billing records - never your card details. We store only your subscription tier and Stripe customer/subscription IDs. Stripe's privacy policy governs their handling of payment data.
For experts who enable payouts: with Stripe, we store only your Stripe connected-account ID - your banking and identity data live with Stripe under its own terms. With Wise, we store the payout details you submit (legal name, IBAN or account number, SWIFT/BIC, currency, country, contact email) and use them solely to pay your earnings; they are removed when your account is deleted.
Data retention and deletion
Your account data (conversations, user model, session summaries, mood check-ins, insights) is retained as long as your account is active. You can permanently delete any single session from your dashboard, your insights individually, or your entire session history from account settings, at any time; these deletions take effect in the live database immediately.
When you delete your account, every row belonging to you is removed from the live database at that moment (all tables cascade from your user record). At the same time we delete the likeness data held outside the database: the synthetic voice at ElevenLabs (unless shared by another clone you own), your stored voice recording, and your likeness photos; avatar bundles and source clips no clone references any more are removed from storage and from the rendering servers by a scheduled cleanup within hours. Payout details and the Stripe customer record are deleted as part of the same step, except billing records we must keep for tax and accounting law.
Copies can outlive a deletion for a bounded time: daily database backups age out after 7 days; error reports and operational logs are kept for a limited rolling window (weeks, not years) and contain no conversation content; AI providers reached through the gateway retain nothing (see AI processing); the direct-Anthropic fallback path follows Anthropic's short-term commercial retention. ElevenLabs deletes the synthetic voice when we delete it; its own policy governs any residual voice-derived data.
If you are an expert, deleting a clone in the studio removes its configuration, materials, translations, voice and avatar in the same way; removing just the voice or avatar removes that asset. Deleting your account also ends your relationships with clients, but takes nothing from them: each client keeps their conversations, session summaries, the user model built during your work together, and their mood check-ins and insights (that data is theirs); they lose access to your clone, any subscription to you is cancelled at the end of its billing period, and they continue with another of their experts or the built-in Forjari clone. The relationship record itself is kept in an archived, inert state so that data stays attributable to them; it is never used by any other clone.
To request account deletion or a copy of your data, email contact@forjari.com.
Third-party services
We use the following processors. Each one handles data only to provide the named function, under its own privacy policy and, where offered, a data processing agreement we have accepted:
- Supabase - database, authentication and file storage (EU, Ireland). Privacy · DPA
- Vercel - application hosting (EU, Dublin) and the AI Gateway every model request passes through, with zero data retention and no-training routing enforced. Privacy · DPA · Gateway ZDR
- Anthropic - AI inference for session replies and summaries (Claude models, reached through the gateway; direct API only as a fallback). Inputs and outputs are never used to train its models. Commercial terms · API data retention
- Other AI providers - the operator may select a different catalogued model; the same zero-retention and no-training constraints apply to every request, and the selection is limited to providers that meet them.
- ElevenLabs - synthetic voice for experts who enable voice cloning (their recording and the generated speech); model-training data use is opted out in our account. Privacy · Terms
- Scaleway - GPU servers operated by Forjari that generate and stream video avatars (EU, Paris and Warsaw). Scaleway provides the hardware; it does not process your likeness as a service. Privacy · Contracts and DPA
- Stripe - payment processing, tax calculation (Stripe Tax, including your billing address), subscription management, and expert payouts (Stripe Connect). Privacy · DPA
- Wise - expert payouts to countries Stripe cannot reach. Privacy
- Resend - sends sign-in, account and (for experts, with one-click unsubscribe) product emails. Privacy · DPA
- GitHub - bug reports you submit in the app are filed as issues in a private repository, with the diagnostics listed above. Privacy
- Google - optional sign-in via Google OAuth 2.0 (email address, name, profile picture only; see Google Sign-In below).
- Sentry - error monitoring: when something breaks, a technical error report (error message, browser type, an internal request id) is captured so we can fix it - no conversation content, no advertising or behavioral tracking. Privacy · DPA
- Axiom - server-log storage for reliability and debugging (structured technical logs, not conversation content). Privacy · DPA
- Better Stack - uptime monitoring and the public status page; it probes our health endpoints and holds no user data. Privacy
- Cloudflare - domain registration and DNS only; traffic is not proxied.
We do not use any advertising network, analytics tracker, data broker, or AI provider other than those listed. If this list changes materially we update this page and, where the change affects existing data, notify you by email.
Cookies and tracking
Forjari uses a single session cookie to maintain your authenticated state (managed by Supabase), and your browser's localStorage for interface preferences (theme, language). We do not use advertising cookies, analytics trackers, or any third-party pixel tracking.
Your rights
You can request a copy of your data (for experts, this includes your clone configuration, materials and the assets you uploaded), request correction of inaccurate data, or request deletion of your account at any time. Email contact@forjari.com.
If you're in the EU/EEA, you have rights under GDPR. If you're in California, you have rights under CCPA. We will fulfill these requests within 30 days.
Changes to this policy
We'll update this page if our data practices change materially. If the changes affect how we use your existing data, we'll notify you by email. This policy is maintained in English only; translations, where offered, are courtesy aids and the English text controls.
Google Sign-In
You may optionally sign in to Forjari using your Google account. When you do, Google shares the following data with us: your email address, display name, and profile picture. This data is used solely to create and identify your Forjari account.
We do not share your Google account data with any third party except as necessary to operate the service (Supabase for auth storage). We do not use Google user data for advertising, profiling, or any purpose beyond providing Forjari to you.
Our use of data received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke Forjari's access to your Google account at any time via your Google account permissions. Revoking access does not delete your Forjari account - to delete your account and data, use the Danger zone in your profile or email contact@forjari.com.
Legal bases and roles
The data controller for account, billing, and platform data is VSBD.iT OÜ, registry code 17151720, Sepapaja tn 6, Tallinn 15551, Estonia - the company operating Forjari. We process personal data on these legal bases: performance of our contract with you (delivering sessions, memory, summaries, powering an expert's clone), legal obligations (tax calculation and records), legitimate interests (securing the service, preventing abuse, improving reliability), and consent where required (accepted at signup; recorded separately for voice and likeness cloning and for AI processing disclosure).
Your expert receives summaries, commitments, session counts, mood check-ins, and insights by default, and beyond that only what your settings allow - sharing can be switched off entirely, and a raw transcript is visible only for a session you individually share in full. Experts are independent providers and, under the Terms of Service, are bound to keep the client information they can see confidential and to use it only for their work with that client.
International data transfers
Your account data is stored in the EU. Some processors operate from the United States (Anthropic, ElevenLabs, Vercel's AI Gateway, Stripe, Sentry, Axiom, GitHub, Resend). Where data crosses borders, transfers are protected by the providers' standard contractual clauses, EU-US Data Privacy Framework certification where held, or equivalent safeguards under their DPAs linked above.
Age requirement and incidents
Forjari is for adults - you must be at least 18 to use it, and we do not knowingly collect data from minors. If we learn we hold a minor's data, we delete it.
If a data breach affects your personal data, we will notify you and the relevant supervisory authority without undue delay, and where the law sets a deadline, within it.
Contact
Questions about this policy: contact@forjari.com