Legal

Privacy Policy

Last updated August 5, 2026

Your data stays yours. ForgeWatch reads only read-only OAuth metadata about the apps connected to your environment — never your files, messages, or credentials.

01Scope of this policy

This Privacy Policy explains what information ForgeWatch (“ForgeWatch,” “we,” “us”) collects, how we use it, and the choices you have. It covers our marketing website and the ForgeWatch shadow-AI detection service.

ForgeWatch is an agentless, read-only service. It connects to a customer’s cloud identity environment to inventory the third-party applications that have been granted access to that environment, and to produce compliance evidence about them.

02What we access in your environment

With a single administrator authorization, ForgeWatch reads OAuth grant metadata from your identity provider (such as Google Workspace or Microsoft 365 / Entra ID). This is limited to information about which applications hold access and the permissions they were granted.

  • Third-party application and service-principal names and identifiers
  • The permission scopes each application was granted
  • The user or account that granted access, and consent/audit event timestamps

03What we never access

ForgeWatch requests read-only permissions only — never a write or mutate scope. We are designed so that we cannot change, delete, or exfiltrate the underlying data an application can reach.

  • The contents of your emails, files, documents, or calendars
  • Your users’ passwords, API keys, or secrets
  • Any ability to modify, delete, or send data in your environment

04How we use information

We use the metadata we read to generate your inventory, assess the risk of each grant, produce audit-ready evidence, and deliver reports to the recipients you designate. We use marketing-site information (such as details you submit through the contact page) solely to respond to your inquiry and provide the service you requested.

05Storage, retention, and security

The per-customer value ForgeWatch stores is your directory (tenant) identifier — a non-secret value — together with the read-only scan results keyed to your organization. We do not store your credentials. Data is transmitted over encrypted connections. See our Security page for a fuller description of our posture.

We retain scan results for as long as your engagement is active and as needed to provide historical comparison and compliance evidence. You may request deletion of your data as described below.

06Sharing and service providers

We do not sell your information. We may share data with service providers who process it on our behalf (for example, infrastructure and email delivery) under confidentiality obligations, and where required by law. Risk reasoning may be performed using a third-party AI provider on de-identified application metadata.

07Your choices and revocation

You are always in control. Because access is granted by consent in your own environment, you can revoke ForgeWatch’s access at any time from your identity provider — no action on our side is required for revocation to take effect. You may also contact us to access, correct, or delete information we hold about your organization.

08Cookies

Our marketing website uses only the cookies necessary for it to function. We do not use it to build advertising profiles.

09Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above, and where appropriate we will notify active customers.

Questions about this policy? Reach us at forgewatch@outlook.com or through the contact page.