Privacy policy
Effective 2026-08-11
Overview
AngleForge ("we", "us") operates the service at angleforge.click — an angle-first ad creative platform. This policy explains what personal data we collect, why, who processes it on our behalf, and the choices you have. It applies to the website, the app, and related services. Questions go to privacy@angleforge.click.
Short version: we collect what the product needs to work — your account details, the content you put in, and billing handled by Stripe. We run no advertising trackers and no third-party analytics, we do not sell data, and we do not train AI models on your content.
Data we collect
- Account data — your name, email address, and password (stored only as a salted hash — we never see or store the plaintext), plus your organization memberships and roles.
- Content you provide — briefs, offers, brand kits and brand voice, product and asset images, competitor URLs you ask us to fetch, imported ad performance files, and the creatives generated from them. This content belongs to your organization.
- Billing data — payments are processed by Stripe. Card numbers never touch our servers; we keep only the subscription state and invoice references Stripe gives us.
- Technical data — server logs (IP address, user agent, request timing) kept for security and debugging, error reports with sensitive fields redacted, and an audit trail of account and organization actions.
- Acceptance records — which version of the terms and this policy your account has accepted, and when.
Cookies
We set essential cookies only: a session cookie that keeps you signed in and a token that protects forms against cross-site request forgery. There are no advertising cookies, no cross-site trackers, and no third-party analytics scripts. Because every cookie is strictly necessary, there is no cookie consent banner to click through.
How we use your data
- To provide the service: generate angle matrices, render creatives, run compliance lint, and produce exports.
- To operate your account: authentication, organization membership, invitations, and role-based access.
- To bill you, through Stripe, for paid plans.
- To send transactional email — invitations, digests, and account notices. We send no marketing email without separate consent.
- To secure the service: audit logging, abuse prevention, and debugging from redacted error reports.
- To meet legal obligations, such as tax and accounting records.
We do not sell personal data, and we do not share it with anyone for advertising.
AI processing
Generating angles, copy, and images is the product, and it runs on third-party AI providers: Anthropic, OpenAI, NVIDIA, and fal.ai. When you generate, the relevant parts of your brief and brand content are sent to a provider via its API strictly to produce the output you asked for, under that provider's API terms. We do not use your content to train models, and we use API tiers whose terms do not grant the provider training rights over your content.
When you paste a URL to auto-fill a brief, that publicly accessible page is fetched on your behalf through Firecrawl.
Sub-processors
These providers process data on our behalf, each limited to the purpose listed:
- Stripe — payment processing and subscription billing.
- Resend — transactional email delivery.
- Cloudflare R2 — storage of generated images, uploaded assets, and database backups.
- Anthropic, OpenAI, NVIDIA, fal.ai — AI generation of angles, copy, and images.
- Firecrawl — fetching public web pages from URLs you submit.
- Meta, Taboola — only if you connect an ad account or publish: we store the access token you grant and exchange campaign data with that platform at your direction.
- Hosting provider — the servers the application and its database run on.
Some providers process data in the United States or other countries outside your own. Where required, transfers rely on the providers' standard contractual clauses or equivalent safeguards.
Retention and deletion
We keep your account and organization data for as long as the account is active. When an account or organization is deleted, its data is removed from the live database, and copies in backups expire on a rolling schedule. Billing records are retained as long as tax and accounting law requires. You can request an export of your organization's data, or its deletion, at any time via the contact below.
Security
All traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes. Tenant data is isolated per organization with database row-level security, access inside an organization is scoped by role, and sensitive actions are audit-logged. No system is perfectly secure; if a breach affects your personal data, we will notify you as the law requires.
Your rights
You can access and correct your account data in the app. For anything else — a copy of your data, a full export, correction, deletion, or an objection to processing — email privacy@angleforge.click and we will respond within 30 days. If you are in the EEA, the UK, or a jurisdiction with similar law (including US state privacy laws), these are your statutory rights, and you may also lodge a complaint with your local supervisory authority.
Children
AngleForge is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16; if you believe we have, contact us and we will delete it.
Changes to this policy
We may update this policy as the product evolves. The version date at the top always reflects the current text, and material changes are announced with an acceptance prompt in the app before they take effect. This version is effective as of 2026-08-11.
Contact
Privacy questions, rights requests, and anything unclear above: privacy@angleforge.click.