Effective 27 August 2026
Privacy
The CLI
forge-sync has no telemetry. It reads credentials from environment variables and uses them only to contact the GitHub and target forge endpoints you configure. Credentials are not written to configuration, SQLite state, audit logs, or archives.
The website
This static site does not receive repository data or access tokens. The config builder runs entirely in your browser. If you restore or purchase the Migration Kit, a license token and daily verification result are stored in your browser’s local storage. The token is sent only to the Sociobot verification API.
Your archive
The local archive contains repository metadata and public or private discussion content selected by your GitHub token. You control its location, retention, and access. Deleting the state and archive directories removes forge-sync’s local copy.
Payments
Sociobot/Dodo is the merchant of record and processes checkout details under its own privacy terms. forge-sync never receives card details.
Contact
Privacy questions may be sent to privacy@sociobot.in.