Privacy Policy
Last updated: July 10, 2026
Overview
Forjari is operated as a solo product. This policy explains what data we collect when you use Forjari, why we collect it, and how it's handled. We don't collect data we don't need and we don't sell your data.
What we collect
When you create an account, we collect:
- Your email address and, if you sign in with Google, your Google account name and profile picture (via Google OAuth / Supabase Auth)
- The conversations you have with Forjari, including all messages
- A distilled "user model" - a structured JSON summary Forjari builds across sessions to maintain continuity
- Session summaries and action items generated at the end of each session
- Optional wellbeing inputs you add on your dashboard - mood check-ins before and after sessions, and key insights you write down
- If you enable notifications, a web-push subscription token for your browser (used only to deliver the reminders you opted into)
- Basic subscription data (plan tier, billing status) via Stripe
We do not collect your name, phone number, physical address, or any demographic data beyond what you voluntarily provide in conversation or at checkout (see billing below).
How your data is used
Your conversation data is used to:
- Generate Forjari's responses during sessions (sent to Anthropic's API)
- Build and maintain your user model across sessions
- Display your session history and open commitments in the dashboard
Optional voice features (dictation and read-aloud) run on your browser's built-in speech services - audio is processed by your browser or OS vendor (for example, Chrome performs dictation via Google's speech service) and Forjari never records or stores audio. In live sessions, your expert's clone may speak with a cloned voice and animated face - that generated speech and video come from ElevenLabs and Simli (see Third-party services); your own microphone audio is still transcribed by your browser and never stored by us. Your data is not used to train AI models. Anthropic's API is used in passthrough mode - Anthropic's own data retention policies apply to API calls, which you can review at anthropic.com.
What your expert can see
By default, your expert sees your session summaries, commitments, and session counts - and, under the same sharing switch, your mood check-ins and the key insights you record - never raw transcripts - so they can follow your progress between sessions. You stay in control: turn sharing off account-wide in settings (your expert then sees nothing about your sessions, mood, or insights), hide any single session, or share a specific session in full - including its raw transcript. If you joined through an expert's invite, they also see your name, email, plan tier, and join date (their client roster). Your distilled user model always stays private to you.
If you're an expert, the methodology, voice, and materials you configure are used only to power your own clone. They are never shared with other experts or used to train AI models.
Data storage and security
All data is stored in Supabase (PostgreSQL). Row-level security (RLS) is enforced at the database level - your data is scoped to your user ID and inaccessible to other users. Supabase encrypts data at rest. Connections are encrypted in transit via TLS.
Billing is handled by Stripe. At checkout, Stripe collects your billing address and uses it to calculate and collect any applicable VAT or sales tax (Stripe Tax); we receive your country/region and the tax amounts as part of billing records - never your card details. We store only your subscription tier and Stripe customer/subscription IDs. Stripe's privacy policy governs their handling of payment data.
For experts who enable payouts: with Stripe, we store only your Stripe connected-account ID - your banking and identity data live with Stripe under its own terms. With Wise, we store the payout details you submit (legal name, IBAN or account number, SWIFT/BIC, currency, country, contact email) and use them solely to pay your earnings; they are removed when your account is deleted.
Data retention
Your account data (conversations, user model, session summaries, mood check-ins, insights) is retained as long as your account is active. You can permanently delete any single session from your dashboard, your insights individually, or your entire session history from account settings, at any time. If you delete your account, your data is deleted from our database within 30 days.
To request account deletion, email contact@forjari.com.
Third-party services
We use the following third-party services:
- Supabase - database and authentication (including Google OAuth)
- Google - optional sign-in via Google OAuth 2.0. We request only your email address, name, and profile picture. We do not access any other Google account data, Google Drive, Gmail, or any other Google service.
- Anthropic - AI inference (your messages are sent to Anthropic's API)
- Stripe - payment processing, tax calculation (Stripe Tax, including your billing address), subscription management, and expert payouts (Stripe Connect)
- Wise - expert payouts to countries Stripe cannot reach
- ElevenLabs - synthetic voice for experts who enable voice cloning (their audio sample and generated speech)
- Simli - photoreal animated face for experts who enable the video avatar (the photo they submit for it is sent to Simli and also stored by Forjari as that AI clone's avatar image, shown in the app to the expert's clients)
- Vercel - application hosting and serverless infrastructure
- Cloudflare - DNS and CDN
- Sentry - error monitoring: when something breaks, a technical error report (error message, browser type, an internal request id) is captured so we can fix it - no advertising or behavioral tracking
- Axiom - server-log storage for reliability and debugging (structured technical logs, not conversation content)
Cookies and tracking
Forjari uses a single session cookie to maintain your authenticated state (managed by Supabase), and your browser's localStorage for interface preferences (theme, language). We do not use advertising cookies, analytics trackers, or any third-party pixel tracking.
Your rights
You can request a copy of your data, request correction of inaccurate data, or request deletion of your account at any time. Email contact@forjari.com.
If you're in the EU/EEA, you have rights under GDPR. If you're in California, you have rights under CCPA. We will fulfill these requests within 30 days.
Changes to this policy
We'll update this page if our data practices change materially. If the changes affect how we use your existing data, we'll notify you by email. This policy is maintained in English only; translations, where offered, are courtesy aids and the English text controls.
Google Sign-In
You may optionally sign in to Forjari using your Google account. When you do, Google shares the following data with us: your email address, display name, and profile picture. This data is used solely to create and identify your Forjari account.
We do not share your Google account data with any third party except as necessary to operate the service (Supabase for auth storage). We do not use Google user data for advertising, profiling, or any purpose beyond providing Forjari to you.
Our use of data received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke Forjari's access to your Google account at any time via your Google account permissions. Revoking access does not delete your Forjari account - to delete your account and data, email contact@forjari.com.
Legal bases and roles
The data controller for account, billing, and platform data is VSBD.iT OÜ, registry code 17151720, Sepapaja tn 6, Tallinn 15551, Estonia - the company operating Forjari. We process personal data on these legal bases: performance of our contract with you (delivering sessions, memory, summaries), legal obligations (tax calculation and records), legitimate interests (securing the service, preventing abuse, improving reliability), and consent where required (accepted at signup).
Your expert receives summaries, commitments, session counts, mood check-ins, and insights by default, and beyond that only what your settings allow - sharing can be switched off entirely, and a raw transcript is visible only for a session you individually share in full. Experts are independent providers and are responsible for how they handle the client information they can see.
International data transfers
Our infrastructure providers may store or process data outside your country, including in the United States and the European Union. Where data crosses borders, transfers are protected by the providers' standard contractual clauses or equivalent safeguards.
Age requirement and incidents
Forjari is for adults - you must be at least 18 to use it, and we do not knowingly collect data from minors. If we learn we hold a minor's data, we delete it.
If a data breach affects your personal data, we will notify you and the relevant supervisory authority without undue delay, and where the law sets a deadline, within it.
Contact
Questions about this policy: contact@forjari.com