Clear about data. Clear about limits.
This is the shared privacy page for SendForge products. Use the product links below to jump to the policy section that applies to the product you are using.
July 18, 2026
Contact: privacy@sendforge.app • support@sendforge.app
Our products
SendForge is the umbrella brand. Different products may handle different categories of data depending on what the product does.
SendForge Messaging
The following section explains how SendForge Messaging handles account, delivery, consent, and service data.
Information we collect
- Account details such as name, email, and company.
- Billing metadata from payment processors.
- Messaging data required to deliver messages and track status.
- Technical usage data such as IP, browser, and device analytics.
How we use it
- Operate and improve the service.
- Deliver SMS and email messages.
- Enforce usage limits and prevent abuse.
- Comply with telecom, provider, and legal requirements.
Compliance safeguards
We may monitor complaint rates, opt-out activity, unusual sending behavior, and carrier requirements to protect the platform. We do not sell message content or use it for advertising.
Retention and sharing
We retain data only as long as necessary for service delivery and compliance. We may share data with hosting, telecom, email, payment, and legal service providers as needed to operate the platform.
TabForge
This section applies specifically to the TabForge browser extension and related TabForge product surfaces.
What TabForge stores
- Shortcut layout, pages, packs, and the current workspace are stored locally in the browser.
- When Private Sync is active, layouts, shortcuts, notes, and note images are automatically synchronized through a private Cloudflare Worker and private R2 storage so supported signed-in devices stay aligned.
- Shortcut and note deletions made through active Private Sync are retained in a private cloud trash for 30 days. “Restore all deleted items” adds missing items without removing newer local work.
- Permanent Pro without active Private Sync may keep infrequent latest, one-day, and seven-day layout recovery points. Previously synced notes remain read-only; new cloud note writes require active Private Sync. This is not a general file-storage feature.
- Authentication state, a local access token, and a random device identifier/name are stored locally when the user signs in.
- While Recent, Favorites, or sorting shortcuts by frequency is turned on, TabForge records the websites visited in this browser (address, page title, number of visits, and first and latest visit time) so those lists show where the user actually goes, including sites never saved in TabForge. Incognito windows are never recorded. The record stays in
chrome.storage.localin this browser; it is never synced, backed up, or sent to SendForge or Cloudflare. Turning those options off stops the recording. - SendForge stores account, billing, entitlement, and referral metadata, but TabForge workspace content is not written to the Render-hosted SendForge database.
How TabForge uses it
- Persist the user’s new-tab workspace across browser sessions.
- Restore shortcut pages, layouts, purchased access, and eligible notes/images. Historical recovery is additive; current cross-device sync still honors intentional deletions.
- Verify account access and entitlements through the SendForge backend when the user signs in.
- Enforce device, request, file-type, daily-write, and account safety limits intended to prevent TabForge from being used as a general transfer service.
What TabForge does not do
- Does not send browsing activity to SendForge or Cloudflare. Trail Mode keeps a bounded navigation breadcrumb history only in this browser.
- Does not read page content from arbitrary websites.
- Does not track keystrokes.
- Does not sell user data.
- Does not load or execute remote hosted code.
Extension-specific handling
TabForge uses chrome.storage.local to store the current workspace configuration locally. If a user signs in,
login credentials are sent securely to the SendForge backend and a token is stored locally so the extension can
verify account access and purchased features. Automatic Private Sync content requests go to a Cloudflare Worker;
content objects are kept in a private Cloudflare R2 bucket and per-account coordination metadata is kept in a
Cloudflare Durable Object. The bucket has no public sharing URL.
Trail Mode is enabled by default and records local URL, page-title, favicon, transition, and branch information
so browser navigation and recently closed trails can be restored. It is bounded to 80 tracked tabs, 180 trail
nodes per tab, and 40 closed trails. Users can disable Trail Mode or clear its log from Hotkeys & Trail Mode.
Trail data stays in chrome.storage.local; it is excluded from layout backups, Private Sync, analytics,
advertising, and SendForge account storage.
Remote code and permissions
TabForge does not download and execute remote code. Executable extension logic is packaged with the extension. Network requests are used for account authentication, entitlement verification, billing/account actions, and—when eligible—automatic background recovery backup or Private Sync. Local saves continue even when the network is unavailable.
Sharing and retention
TabForge workspace data is primarily stored locally. Cloudflare processes eligible synchronized or recovery data only to operate TabForge; SendForge does not sell it or provide public sharing links. Canceling Private Sync stops live multi-device sync but does not delete permanent Pro or automatically erase retained sync data, so a later re-subscription can resume. A verified account-deletion request removes the account’s TabForge R2 objects and per-account coordination metadata within the deletion period stated on our Delete Account page, except records we must retain for billing, tax, fraud prevention, or legal compliance.
Google sign-in
Signing in with Google is optional. A SendForge account can always be created and used with an email address and password instead.
When you choose Google sign-in, Google sends SendForge a signed identity token containing your email address,
a Google account identifier, and whether Google has verified that email address. SendForge uses this only to
create or locate your SendForge account and to issue your normal SendForge session. We request only the
openid, email, and profile scopes.
SendForge does not receive your Google password, and does not request or receive access to Gmail, Google Drive, Google Contacts, or any other Google service. We do not sell data obtained through Google sign-in, do not use it for advertising, and do not transfer it to third parties except the hosting and infrastructure providers described above that are required to operate the service.
You can disconnect SendForge from your Google account at any time from your Google account permissions page. Removing that connection does not delete your SendForge account; use the account-deletion process for that.
SendForge's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the sign-in feature you requested, we do not transfer it to others except as necessary to provide and improve that feature, to comply with applicable law, or as part of a merger or acquisition, we do not use it for advertising, and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymized.
Security
- All traffic between your browser, the TabForge extension, and our services is encrypted in transit with HTTPS/TLS.
- Account passwords are never stored in readable form. They are hashed with bcrypt before storage and cannot be recovered by us.
- Sessions use short-lived signed access tokens that are refreshed automatically and revoked when you sign out or delete your account.
- Synchronized TabForge content is held in a private Cloudflare R2 bucket with no public sharing URL, and per-account coordination metadata is held in a Cloudflare Durable Object.
- Access to production systems is limited to the personnel who operate the service, and requests are rate limited to reduce abuse and credential-stuffing.
- No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your account credentials confidential.
Your rights and how to exercise them
You can exercise all of the following from your account, or by writing to privacy@sendforge.app. We respond to verified requests within 30 days.
- Access. Request a copy of the personal data associated with your account.
- Correction. Update your email address and account details from your account page.
- Deletion. Request deletion of your account and associated data through our account-deletion process. Some records are retained where we are legally required to keep them, such as billing and tax records.
- Portability. Request your account data in a portable, machine-readable format.
- Withdraw consent. Disconnect Google sign-in, cancel Private Sync, or disable Trail Mode at any time without losing access to the rest of the product.
- Object or restrict. Ask us to stop or limit a specific processing activity where applicable law provides that right.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not use your data to build advertising profiles, and we do not run third-party ad networks on our products.
Children's privacy
SendForge products are intended for adults and are not directed to children. You must be at least 16 years old to create a SendForge account. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16, we delete that information and close the account. A parent or guardian who believes a child has created an account may write to privacy@sendforge.app and we will remove it.
Security incidents
If we become aware of a breach affecting personal data we hold, we will investigate, take steps to contain and remediate it, and notify affected account holders by email at the address on file, along with any regulator required by applicable law, without undue delay. Notifications describe what happened, what data was involved, and what you can do in response.
Changes to this policy
We may update this policy as our products change. The effective date at the top of this page always reflects the current version. If a change materially affects how we handle personal data, we will notify account holders by email or with an in-product notice before it takes effect. Continuing to use the products after a change takes effect means you accept the updated policy.
Who we are and how to contact us
SendForge LLC is the controller responsible for the personal data described in this policy.
SendForge LLC
6749 Fulton St E, Ste A #2333
Ada, MI 49301, United States
Privacy enquiries: privacy@sendforge.app
Product support: support@sendforge.app