Effective 27 August 2026

Privacy

The CLI

forge-sync has no telemetry. It reads credentials from environment variables and uses them only to contact the GitHub and target forge endpoints you configure. Credentials are not written to configuration, SQLite state, audit logs, or archives.

The website

This static site does not receive repository data or access tokens. The config builder runs entirely in your browser. If you restore or purchase the Migration Kit, a license token and daily verification result are stored in your browser’s local storage. The token is sent only to the Sociobot verification API.

Your archive

The local archive contains repository metadata and public or private discussion content selected by your GitHub token. You control its location, retention, and access. Deleting the state and archive directories removes forge-sync’s local copy.

Payments

Sociobot/Dodo is the merchant of record and processes checkout details under its own privacy terms. forge-sync never receives card details.

Contact

Privacy questions may be sent to privacy@sociobot.in.