Privacy

What Forge Daughter stores, where, and which services handle it. This describes how the app is built today.

Your account

You sign in with Google, GitHub, or an email address and password, through Better Auth. With Google or GitHub, the app receives your name, email address, and profile picture from that account. Your name, email, profile picture, a hash of your password if you set one, and your sessions (with the IP address and browser they came from) are stored in the database. A cookie keeps you signed in. Better Auth's hosted dashboard also receives sign-up and sign-in events, including your email address.

Account emails, such as the link that confirms your address or resets your password, are sent through Resend, which receives your email address and the message. When you choose a password, the first five characters of its SHA-1 hash are checked against Have I Been Pwned's list of breached passwords; the password itself is not sent.

Your chats

Chats, projects, messages, tool calls, file records, and search queries are stored in a Turso database, tied to your account. The app shows them only to you.

Models and tools

To answer, your messages and the chat so far are sent to the provider of the model you choose: OpenAI, Anthropic, Google, xAI, Zhipu (GLM), Cerebras, or MiniMax. Small background tasks, such as naming a chat, also go to one of them. Image generation uses OpenAI, and web searches are sent to Brave Search.

Code the agent runs, and the files it works on, live in a Vercel Sandbox for that chat. A snapshot is kept so the sandbox can be resumed later.

Search

So you can search your past work, finished chat turns and the text files the agent edits are indexed in Vespa Cloud on AWS in the US East (us-east-1) region. Vespa computes the search embeddings itself; the index is only queried on your behalf, within your own chats.

Hosting and analytics

The app runs on Vercel. On the production site, Vercel Web Analytics and Speed Insights measure page views and loading performance.

Deleting

Deleting a chat removes it from your history and its entries from the search index; the database keeps it marked as deleted. Rewinding a chat removes the rewound turns from the index. When an account is deleted, its data is removed from the database and the search index.

Home