ForgeForSocials
← Back to home Wersja polska

Privacy Policy

Last updated: 2026-08-03

This policy explains what personal data ForgeForSocials (the "Service") processes, for what purpose, on what legal basis, and who we share it with. It is written to comply with Regulation (EU) 2016/679 (GDPR).

1. Data controller

The controller of your personal data is 21 Mateusz Matejko (owner: Mateusz Matejko), NIP 5833512979, REGON 529056732, ul. Tadeusza Bramińskiego 12/39, 80-180 Gdańsk, Poland.

For any data protection matter, contact: kuzniasocialmedia@gmail.com.

2. What data we process

2.1. Account data

  • email address,
  • password — stored only as an irreversible bcrypt hash, never in plain text,
  • interface language, selected plan, notification preferences,
  • marketing (newsletter) consent and the date it was confirmed, if given,
  • account creation date.

2.2. Business profile data

  • name, website, industry, location,
  • description, logo, brand colours, tone of voice,
  • an AI-generated brand profile derived from the above.

2.3. Connected social account data

Once you connect an account (Facebook, Instagram, Google Business Profile, LinkedIn, X, TikTok, YouTube) we store:

  • the account or Page ID on that platform and its display name,
  • the OAuth access token (plus refresh token and expiry where the platform issues them),
  • aggregate statistics: reach, engagement and new followers over the last 7 days.

We do not retrieve or store your friend list, private messages, comments, or any personal data about the people who follow your Page. We request only the permissions technically required to publish content and read Page-level aggregate insights.

2.4. Content data

  • AI-generated topic proposals and their rationales,
  • post text (AI-generated or written by you) and attached images,
  • publication schedule, publication status, and the resulting post ID on each platform.

3. Purposes and legal bases

PurposeLegal basis
Providing the service — planning, generating and publishing content Art. 6(1)(b) GDPR (performance of a contract)
Account management, login, password reset Art. 6(1)(b) GDPR (performance of a contract)
Notifications about new post proposals and publishing failures Art. 6(1)(b) GDPR (performance of a contract)
Marketing newsletter Art. 6(1)(a) GDPR (consent — optional, withdrawable at any time)
Billing and tax obligations Art. 6(1)(c) GDPR (legal obligation)
Service security and defence of legal claims Art. 6(1)(f) GDPR (legitimate interest)

4. Recipients

We share data only with processors necessary to operate the Service:

ProcessorData sharedPurpose
Meta Platforms Ireland Ltd. post content, images, access tokens publishing to Facebook and Instagram, reading Page insights
Google Ireland Ltd. post content, access tokens publishing to Google Business Profile and YouTube
LinkedIn, X (Twitter), TikTok post content, access tokens publishing to those platforms — only after you explicitly connect them
OpenAI, L.L.C. brand profile and post topic content and image generation. We never send your email address or any access token to OpenAI
Resend, Inc. email address and message content transactional email and newsletter delivery
Fly.io, Inc. all Service data application and database hosting (region: Frankfurt, European Union)

Some of these processors are established outside the European Economic Area. Such transfers rely on Standard Contractual Clauses approved by the European Commission. We do not sell your data and we do not share it with data brokers or advertising networks.

5. Retention

  • Account, business, content and connected-account data — for as long as your account exists.
  • After account deletion — data is erased immediately and permanently, see section 7.
  • Billing records — for the period required by tax law (5 years from the end of the tax year).
  • Newsletter consent — until withdrawn.

6. Your rights

You have the right to:

  • access your data and receive a copy of it,
  • rectify inaccurate data,
  • erasure ("right to be forgotten"),
  • restriction of processing,
  • data portability,
  • object to processing based on legitimate interest,
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal,
  • lodge a complaint with the Polish supervisory authority (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland).

7. Data deletion

You can delete your account yourself at any time: Settings → Delete account. The operation is immediate and irreversible — it erases the account, all businesses, posts, content proposals, generated images, statistics, and every stored access token for connected social platforms.

Full instructions, including the procedure for people who no longer have access to their account, are on the Data Deletion page.

8. Cookies

The Service uses a single strictly necessary session cookie (sync_session) that keeps you logged in. We use no marketing, tracking or analytics cookies, and we do not profile users for advertising purposes.

9. Security

All traffic is served over HTTPS. Passwords are stored as bcrypt hashes. Access tokens for social platforms are stored solely to publish on your behalf, are never shared with third parties, and are never displayed in the interface.

10. Changes to this policy

We will notify you of material changes by email to the address on your account at least 14 days in advance. The date of the last update is shown at the top of this page.

Privacy Policy Terms of Service Data Deletion