Privacy
Privacy Policy
Version 2026-09-02.2 — last updated September 2, 2026.
Scope of This Policy
This Privacy Policy describes how Kelt Agentic Systems, LLC ("Kelt Forge," "we," "us," or "our") collects, uses, and shares information in connection with the Kelt Forge platform. It applies to anyone who accesses Kelt Forge — as an invited user, an organization administrator, or a visitor to our public website.
Information We Collect
Account and profile information: your email address, display name, and organization membership and role.
Your prompts and conversations: the instructions you give Forge AI and the resulting conversation history, stored so you and your organization can see and continue past work.
Your projects and content: source code, project files, and assets you connect, upload, or that Forge AI generates on your behalf, including files stored in our project-asset storage.
Connected-service credentials: where you connect your own third-party accounts (for example GitHub or Vercel), we store the access tokens or credentials needed to act on your behalf, held server-side and never exposed to generated code or written into your project.
Billing information: if you subscribe to a paid plan, our payment processor Stripe collects and stores your payment method details; we receive and store billing status, plan, and Kelt Credit balance information, but not your full card number.
Usage and security metadata: sign-in timestamps, IP address, browser/user-agent information, and records of security- and approval-relevant actions (such as who approved a change, and when), kept for account security and audit purposes.
Support interactions: messages you send through our in-product support assistant or to our support team.
How We Use Information
We use the information described above to: operate and provide the Kelt Forge service, including running Forge AI against your prompts and repository; process payments and manage subscriptions and Kelt Credits; secure the platform, including detecting misuse and maintaining audit records of security-relevant actions; communicate with you about your account, changes to the Service, or these policies; and provide customer support.
We do not sell your personal information, and we do not use your prompts, code, or project content for advertising.
AI Model Providers and Your Prompts and Code
When you use Kelt Forge, your prompts and relevant portions of your project's code are sent to the AI model provider(s) configured for your deployment in order to generate a response — principally Anthropic's Claude models via Anthropic's commercial API, and, where a given deployment enables them, one or more additional OpenAI-compatible model providers. These providers act as our processors: they receive your content to generate a response to your request, not to independently use it for their own purposes.
Our understanding, based on the commercial (API) terms under which we use these providers, is that content submitted through a commercial API account is not used by the provider to train its underlying models unless separately agreed. We have not independently listed or confirmed the specific data-processing terms of every model provider a given deployment might enable, and provider terms can change; if you have questions about a specific provider's handling of your content, contact us using the details below.
Infrastructure Providers and Other Subprocessors
We rely on the following categories of infrastructure providers to operate Kelt Forge, each of which may process your information as our subprocessor, solely to help us provide the Service:
Supabase — our database, authentication, file storage, and real-time messaging provider; the great majority of the data described in "Information We Collect" is stored in Supabase-hosted infrastructure.
Vercel — hosts the Kelt Forge web application and, where applicable, the web builds of projects you deploy through Kelt Forge.
Amazon Web Services (AWS) — powers infrastructure supporting Kelt Forge's real-time preview features.
Stripe — processes payments and stores payment method and billing details on our behalf; see Stripe's own privacy policy for how it handles payment data directly.
GitHub — where you connect your own GitHub account, or where Kelt Forge provisions a repository on your behalf, your project's source code and commit history live in GitHub.
Appetize — where you use Kelt Forge's mobile app preview features, Appetize provides the in-browser device emulation used to preview your app; your app build and preview session data pass through Appetize's infrastructure for that purpose.
Where you connect an additional third-party integration to Kelt Forge, your use of it is also subject to that provider's own terms and privacy practices.
Cookies and Analytics
Kelt Forge uses only the cookies strictly necessary to keep you signed in and to secure your session (issued by our authentication provider, Supabase). As of this version of this Policy, we do not use third-party advertising cookies or third-party analytics/tracking cookies. If that changes, we will update this Policy accordingly.
Data Retention
We retain your account and project information for as long as your account or your organization's account remains active, or as needed to provide the Service to you. When a project is deleted, an automated process removes that project's data and associated secrets from active use.
Following a valid account or project deletion request, we target deletion or de-identification of the associated active customer content within 30 days. Residual copies may remain in backups for up to an additional 90 days through normal backup rotation, after which they are also purged. We may retain certain records longer where necessary for legitimate technical, security, contractual, fraud-prevention, legal, regulatory, audit, or dispute-resolution purposes — including billing and transaction records, records of your acceptance of these policies, and security/audit logs — for as long as required or permitted by law. We do not promise instantaneous deletion from every third-party system our infrastructure providers operate.
Security
Connected-service credentials and other secrets are stored server-side and are never exposed to a project's own generated code. Access to an organization's projects, secrets, and integrations is restricted to that organization's own members through database-enforced access controls, and security-relevant actions are recorded in an audit log. No method of storage or transmission is completely secure; we cannot guarantee absolute security. Kelt Forge does not currently hold a third-party security certification such as SOC 2 or ISO 27001.
Your Rights and Choices
You can review and update your account information from your account settings, and can ask an organization admin to remove your access.
Depending on where you are located, applicable privacy law may give you additional rights, which can include the right to know what personal information we hold about you, to correct inaccurate information, to request deletion, to receive a portable copy of your information where applicable, and other rights available under applicable law. You can exercise these rights by contacting us at legal@kelt.com. We may take reasonable steps to verify your identity before fulfilling a request, and may decline or limit a request to the extent permitted by law — for example, where we have a legitimate need to retain certain records, such as billing or security audit records.
We intend for a future authenticated in-product experience to supplement this email-based process with self-service tools such as downloading your data, correcting your information, deleting your account, and submitting a privacy request directly. Until then, email is the current formal channel for exercising these rights.
Children's Privacy
You must be at least 18 years old to use Kelt Forge. Kelt Forge is not directed at children, and we do not knowingly collect personal information from anyone under 18.
International Users
Kelt Forge's infrastructure providers may process and store information in the United States and other countries in which they operate. By using Kelt Forge, you understand that your information may be processed in a country other than your own.
Changes to This Policy
We may update this Privacy Policy from time to time. Each version is dated and recorded with its own content. If we make a material change to how we handle your information, you will be required to affirmatively accept the updated Policy again before continuing to use Kelt Forge; for a non-material change, continued use of the Service after the update takes effect constitutes acceptance.
Contact
Kelt Agentic Systems, LLC, 26060 Acero, Suite 203, Mission Viejo, CA 92691. For privacy questions or requests, contact legal@kelt.com.