Privacy Policy
At Astra Forge, we take your privacy seriously. This policy explains what data we collect, how we use it, and the choices you have. By using Astra Forge, you agree to the practices described below.
1. Information We Collect
We collect information to provide, improve, and protect Astra Forge. This includes:
Account Information – Name, email address, password (encrypted), and workspace details.
Usage Data – How you use Astra Forge (pages visited, actions taken, device/browser type).
Task & Project Data – Content you create, upload, or share inside Astra Forge.
Billing Information – Payment details processed securely by our payment provider (we don’t store credit card numbers).
Integrations – If you connect Slack, Google Drive, or other apps, we store access tokens securely to enable those integrations.
2. How We Use Information
We use your data to:
Provide and maintain Astra Forge services.
Improve features and performance.
Personalize your experience (e.g., AI prioritization).
Communicate important updates, security notices, and support responses.
Comply with legal obligations.
3. Sharing of Information
We never sell your personal data. We may share information with:
Service Providers – e.g., hosting, analytics, payment processors.
Integrations – When you connect third-party apps, data flows between Astra Forge and those apps.
Legal Requirements – If required by law, regulation, or valid legal process.
4. Data Security
We protect your data with industry standards:
Encryption at rest (AES-256) and in transit (TLS 1.2+)
Daily backups with 30-day retention
Role-based access control (RBAC)
Regular security audits and penetration testing
5. Your Rights
Depending on where you live, you may have rights to:
Access, update, or delete your data.
Export your data (in structured formats).
Object to certain uses of your data.
File a complaint with your local data authority.
6. Data Retention
We keep your data only as long as needed to provide services. If you delete your account, we delete or anonymize your data within 30 days (unless required by law to retain it).
7. International Data Transfers
We may process and store data in the US, EU, or other regions where we operate. For EU users, we comply with GDPR requirements, including standard contractual clauses for data transfers.
8. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are significant, we’ll notify you by email or in-app before they take effect.
