Privacy Policy

MarketPilot AI is owned and operated by Forge Group. This policy describes the data the application actually collects and processes.

1. Who is responsible

Forge Group
Operator of MarketPilot AI
Website: forgegroup.world
Contact: admin@forgegroup.world

Formal business registration details and the responsible party will be published here before public launch.

2. What personal data we collect

Account information

  • Email address (email/password sign-up, or the address from your Google account).
  • Your name, if you enter one in Settings.
  • Preferred interface language.
  • An internal account identifier and account creation/update timestamps.

Passwords are handled by the authentication service and are stored hashed. We never see your password in plain text. Payment card data is entered on Paddle's hosted checkout and is never stored in this application.

Business information you enter

  • Business name, website, industry, location and description.
  • Products and services, target audience, unique selling points and tone of voice.
  • Marketing goals and preferred content language (your “business memory”).

Brand information

  • Brand colors, fonts, brand description, keywords and words to avoid.
  • Any logo you upload.

Uploaded files and images

  • Logo files you upload to your brand kit.
  • Images generated for your campaigns.
  • Business photos, product photos and other images you upload yourself.

These are kept in private storage. They are never public: the app issues short-lived signed links so only your signed-in session can view them.

Generated content

  • Campaign briefs, goals, offers, calls to action and creative direction settings.
  • Generated posts, hooks, captions, hashtags, keywords and visual concepts.
  • Content status and any scheduled publication dates you set in the calendar.

Usage and generation statistics

  • The number of generations used per calendar month, to enforce plan and trial limits.
  • Your subscription status and trial start/end dates.

Technical information

Our hosting and authentication providers process standard technical data such as your IP address, browser user agent and requested URLs in order to deliver the service and protect it against abuse. Forge Group does not build behavioural profiles from this data and does not operate any advertising or tracking technology in the application.

3. Cookies and local storage

The application uses strictly necessary storage only — your sign-in session and your language preference. There are no analytics, advertising or tracking cookies. Full details are in the Cookie Policy.

4. Why we process your data (purposes)

  • To create and secure your account and keep you signed in.
  • To store your business memory and brand kit so campaigns are on-brand.
  • To generate, refine and store marketing content you request.
  • To count generations and apply trial and plan limits.
  • To respond to support, privacy and security requests you send us.

Where data protection law requires a legal basis, processing is generally based on the performance of our contract with you (providing the service), our legitimate interest in keeping the service secure and functional, and your consent where you voluntarily submit optional information. The precise legal framework will be confirmed before public launch.

5. AI processing

When you generate a campaign, a title, a refinement or an image, the following is sent to the AI provider: your business profile, your brand kit details, the campaign brief and the creative direction you selected. Results are returned to the app and stored in your account so you can edit, reuse and export them.

Do not enter personal data about third parties, customer lists or confidential information into campaign briefs — that content is transmitted to the AI provider for processing. AI output can be inaccurate; review it before publishing.

6. Third-party services actually used

These are the only external services the application is configured to use. Each processes data on our behalf to deliver a specific part of the service.

  • Lovable Cloud (Supabase) — authentication Creating and securing your account, sign-in sessions and password resets. Data sent: Email address, hashed password or Google account identifier, sign-in timestamps, IP address and browser user agent captured by the auth service. Processing: Managed cloud infrastructure operated by the platform provider. (essential to run the service)
  • Lovable Cloud (Supabase) — database Storing your profile, business memory, brand kit, campaigns, generated content, schedule and usage counters. Data sent: All account and business content you enter or generate in the app. Processing: Managed cloud database with row-level security scoped to your user id. (essential to run the service)
  • Lovable Cloud (Supabase) — file storage Storing logo uploads and AI-generated campaign images. Data sent: Files you upload and images generated for your campaigns. Processing: Private storage buckets; files are served only through short-lived signed links. (essential to run the service)
  • Google Sign-In (OAuth) Optional alternative to email/password sign-in. Data sent: Your Google account email and basic profile identifier — only if you choose this option. Processing: Google, under Google's own privacy terms. (optional — only if you use it)
  • Lovable AI Gateway (Google Gemini models) Generating campaign text, campaign titles, refinements and images. Data sent: Your business profile, brand kit details and the campaign brief you submit for each generation. Processing: AI gateway operated by the platform provider, routed to the model provider. (essential to run the service)
  • Paddle (payments and billing) Processing subscription payments, invoicing and taxes when you purchase a paid plan. Paddle acts as the seller (merchant of record) for your purchase. Data sent: Your email address, billing details and payment method — entered on Paddle's hosted checkout. Card details go directly to Paddle and are never stored in this application. Processing: Paddle.com Market Ltd and its affiliates, under Paddle's own privacy terms. (optional — only if you use it)
  • Application hosting Serving the website and running server-side application logic. Data sent: Standard technical request data such as IP address, user agent and requested URL. Processing: Managed hosting provider. (essential to run the service)

International transfers may occur where a provider operates infrastructure outside your country. The applicable transfer framework will be confirmed before public launch.

7. What we do not use

The application currently has none of the following configured:

  • Analytics or tracking tools
  • Advertising or marketing pixels
  • Social-media publishing integrations
  • Third-party email marketing tools

If any of the above is added later, this policy and the Cookie Policy will be updated before it goes live.

8. Data retention

  • Account, business, brand, campaign and content data is kept while your account exists.
  • Anything you delete in the app (content, campaigns, images, logo) is removed immediately.
  • When you delete your account, your profile, business memory, brand kit, campaigns, generated content, scheduled entries, usage records, subscription record, uploaded files and login are deleted.
  • Provider-side technical logs (for example server or authentication logs) expire on the providers’ own short retention schedules.

9. Data deletion

You can delete your account yourself at any time under Settings → Privacy & Data. The deletion is immediate and cannot be undone. You can also request deletion by writing to admin@forgegroup.world.

10. Your rights

  • Access — see what is stored about you, directly in the app or via a full export.
  • Correction — edit your profile, business memory, brand kit and content at any time.
  • Export / portability — download all your data as structured JSON from Settings → Privacy & Data.
  • Erasure — delete individual items, or your entire account.
  • Withdraw consent — where processing rests on consent, stop providing the optional information and delete what you already entered; withdrawal does not affect processing carried out beforehand.
  • Object / restrict — where applicable law grants it, you may object to or ask us to restrict processing by contacting us.
  • Complaint — you may lodge a complaint with the competent supervisory authority, which will be named here before public launch.

11. Security

Data is stored per account and protected by database row-level security, so one account cannot read or modify another account’s business memory, brand kit, campaigns, content, images, calendar, usage or subscription records. Uploaded files live in private buckets accessible only through signed links tied to your session. Server-side operations verify your identity on every request.

12. Contact and data protection contact

All privacy, data protection and security enquiries: admin@forgegroup.world.

This page is provided by Forge Group as operator of MarketPilot AI. The information describes how the application actually works and is pending final legal review where noted.