Privacy Policy
1. Overview
Oxytal Ltd ("we", "us", or "our") operates the Forge AI Platform. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our Service. We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We act as the data controller for personal data you provide directly to us (account information, usage data). For data processed through third-party AI models (Anthropic Claude), Anthropic acts as a separate data processor.
2. Data We Collect
We collect the following categories of personal data:
Account data
- Name and email address (required for registration)
- Hashed password (never stored in plain text)
- Avatar initials and colour preference
- Organisation/project membership and role
Usage data
- Pipeline run history (which pipelines ran, when, by whom)
- Agent outputs stored in our database for pipeline history
- Token usage and cost estimates per user per run
- Gate approval actions (who approved/rejected, when)
Integration data
- Encrypted API credentials you provide (Anthropic, GitHub, Jira, etc.)
- Integration configuration (repository names, project keys, base URLs)
Technical data
- Server-side logs (IP address, request timestamps, error messages) — retained for 30 days
- Session tokens (stored as httpOnly cookies)
Content data
- Confluence page content fetched by the Requirements Agent (processed transiently, not permanently stored)
- Code diffs from GitHub pull requests (processed transiently by Code Review Agent)
- Extracted user stories and architecture decision records (stored in pipeline run history)
3. AI Processing & Your Data
When you run a pipeline, the Service sends content to the Anthropic Claude API for processing. This is fundamental to how the Service works. You should be aware that:
- Content sent to Claude: Confluence page text, Jira story summaries, GitHub code diffs, and prompt configurations are transmitted to Anthropic's API. This content is processed according to Anthropic's Privacy Policy.
- No training on your data: We do not use your pipeline content to train AI models, and we have contractual assurances from Anthropic that they do not use API content to train their models by default.
- Data minimisation: We send only the content necessary for each agent to function. We do not send full database contents, user account information, or API keys to AI models.
- Your responsibility: Do not include highly sensitive personal data, classified information, or regulated data (such as medical records or payment card data) in Confluence pages or Jira stories that will be processed by Forge pipelines.
4. Credential Storage
API credentials (your Anthropic key, GitHub tokens, etc.) are sensitive. We handle them as follows:
- Credentials are stored encrypted in our database using AES-256 encryption
- Your Anthropic API key is tied to your individual user account and is never shared with other users, even within the same organisation
- Credentials are never written to application logs
- Credentials are never loaded from environment variables in production — they are always user-provided
- You can delete your credentials at any time from the Team & Access → My credentials page
- We recommend rotating credentials periodically, especially after team member departures
5. How We Use Your Data
We use your personal data for the following purposes and on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Providing and maintaining the Service | Contract (Art. 6(1)(b) UK GDPR) |
| Authentication and account management | Contract |
| Running AI pipeline agents on your behalf | Contract |
| Storing pipeline run history and outputs | Contract / Legitimate interest |
| Usage analytics to improve the Service | Legitimate interest (Art. 6(1)(f)) |
| Sending account and security notifications | Contract / Legal obligation |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
7. Data Retention
We retain personal data for as long as necessary to provide the Service and comply with our legal obligations:
- Account data: for the duration of your account plus 30 days after deletion
- Pipeline run history and outputs: 12 months from the date of the run, or until you delete them
- API credentials: until you remove them or delete your account
- Server logs: 30 days
- Billing records: 7 years (legal requirement)
8. Security
We implement appropriate technical and organisational measures to protect your data, including:
- Passwords hashed using bcrypt (minimum 12 rounds)
- API credentials encrypted at rest using AES-256
- Authentication tokens stored as httpOnly cookies to prevent XSS attacks
- All data transmitted over HTTPS/TLS
- Access controls limiting which staff can access production data
- Regular security reviews of our codebase and infrastructure
No system is completely secure. If you believe your account has been compromised, please contact us immediately at privacy@oxytal.com.
9. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate data (you can update most data directly in the app)
- Right to erasure: Request deletion of your data. Note that some data may be retained for legal compliance purposes
- Right to restrict processing: Request that we limit how we use your data in certain circumstances
- Right to data portability: Request your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests
- Rights related to automated decision-making: We do not make solely automated decisions that have legal or significant effects on you
To exercise any of these rights, contact us at privacy@oxytal.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
11. International Transfers
The Forge Platform may process data through services located outside the UK and EEA, including Anthropic (USA) and other infrastructure providers. Where such transfers occur, we ensure appropriate safeguards are in place in accordance with UK GDPR Chapter V, including Standard Contractual Clauses or adequacy decisions.
12. Children's Privacy
The Service is intended for use by businesses and professional developers. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected such data, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by updating the "Effective" date at the top of this page. For significant changes, we will provide at least 14 days notice before they take effect.
14. Contact & DPO
For privacy-related enquiries, data subject requests, or to contact our Data Protection Officer: