Who operates Forge
N&R Tech Labs, LLC operates Forge, a private work cockpit for organizing tasks, reviewing results, and using connected services. This policy covers the Forge website and the Forge features we operate. It also explains the Google integrations used by the morning brief and, where enabled, the connected assistant.
For privacy questions, access or deletion requests, contact robipop@norsoft.dev. Please identify the account or workspace involved without sending passwords, access tokens, or unnecessary private documents.
Information we handle
- Account and connection information, such as account identifiers, account labels, authentication information, permissions, and the credentials needed to maintain integrations you authorize.
- Work you place in Forge, including tasks, notes, project information, articles, files, review decisions, and outputs from features you choose to use.
- Information retrieved from connected services to carry out an enabled feature or a request you make. The Google examples below describe the different access involved.
- Operational records needed to run and troubleshoot the service, such as job identifiers, timestamps, delivery status, error categories, and request or access logs. Hosting and authentication services may also process technical connection information.
Google data in the morning brief
The morning brief retrieves an estimate of unread inbox messages from each configured Gmail account. For Google Calendar, it retrieves event start and end values from the primary calendar for the day and produces event counts and time blocks. Gmail estimates are approximate, not guaranteed exact counts.
This brief does not retrieve email subjects, senders, bodies, snippets, or attachments, or calendar event titles, descriptions, or attendees. It combines the resulting account aliases, estimates, and time blocks with your Forge priorities and sends the brief to your configured private Telegram chat.
The morning brief is assembled without an AI model call. These limits describe the brief feature; other explicitly used assistant features can access additional information as explained below. The permissions shown by Google may be broader than the fields used by an individual feature.
Google data in connected assistant features
Where enabled, the connected assistant can search Gmail, read selected messages and supported attachments, read calendar event details, and search or read selected Google Drive files in response to your requests. Selected content returned to the assistant may be sent to its configured AI provider so it can answer or complete the requested work.
Separately enabled filing features can create new files in a designated Google Drive folder when requested, including copying selected email attachments or filing invoices. Connecting an account does not authorize every possible action. The actions available depend on the enabled integration, its permissions, and your request.
Information contained in an email, event, or file is treated as source material, not permission from you to take additional actions. Review generated answers and proposed work before relying on them.
Why we use information and who receives it
We use information to authenticate access, operate the features you choose, maintain your workspace, deliver results, respond to support requests, and protect and troubleshoot the service.
The Google connection service, Executor, runs on infrastructure operated for Forge. Google supplies the connected account data. Convex processes Forge backend and delivery records, and Telegram receives briefs or other messages delivered to your configured chat. Hosting providers process information needed to operate that infrastructure. When you use an assistant or generation feature, its configured AI provider may process the inputs needed for that feature.
We may disclose information to comply with a legal obligation or protect the service and its users where permitted by law. We do not sell personal information or use connected Google data for advertising. Third-party services also handle information under their own terms and privacy policies.
Google API Services Limited Use
Forge's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
We use Google user data to provide or improve the visible, user-facing features you choose. We do not use or transfer that data for advertising, data brokerage, sale, or training or improving generalized AI or machine-learning models. Any transfer to an assistant provider must support the specific feature you request and comply with these restrictions.
Human access to Google user data is limited to circumstances permitted by that policy, such as your consent to review specific data for support, a necessary security investigation, or a legal obligation. This policy does not authorize routine human reading of your connected email or files.
How long information is kept
For the morning brief, the backend temporarily holds the Google-derived aggregate while delivering it. It removes that aggregate when delivery is recorded as successful or failed. An hourly maintenance process clears stranded delivery data. Operational records of completed or failed brief jobs are scheduled for deletion after 30 days; cleanup is periodic and may be delayed by a service interruption. The schedule and configured delivery target are maintained separately while the feature is configured.
There is no single fixed retention period for all other Forge workspace records, connected-service credentials, assistant histories, or operational logs. Retention depends on the feature, the operator's configuration, deletion actions, and any applicable legal requirements. Disconnecting Google access does not automatically erase records already created in Forge or other services.
Messages already delivered to Telegram remain subject to Telegram's storage and deletion controls. Copies in service logs, backups, or third-party systems may remain after an active record is deleted and follow those systems' retention processes. We do not promise immediate deletion of every copy.
Your choices and privacy requests
You choose which accounts to connect and which optional features to use. You can revoke Google's authorization in your Google Account's third-party connections settings. This stops future authorized access but does not delete existing Forge records or Telegram messages. You can also ask the operator to disable an integration or a scheduled brief.
Contact robipop@norsoft.dev to request access to, correction of, or deletion of information we control, or to ask about other rights available under the law that applies to you. We may need to verify your authority over the account or workspace before acting. We will explain any information we need to retain and any third-party deletion steps that remain under your control.
Security and policy changes
Forge uses access controls and separates integration credentials from ordinary task execution. No system can guarantee complete security. Protect your accounts, review the permissions you grant, and contact us if you suspect unauthorized access.
We may update this policy as features or data practices change. The date shown on this page identifies the current version. Material changes to how connected Google data is used require appropriate disclosure and, where required, renewed consent before the new use begins.
Contact Forge
N&R Tech Labs, LLC
robipop@norsoft.dev
Manage your Google connections · Google API Services User Data Policy