ForgeAI · Legal
Privacy Policy
Last updated: 26 July 2026 · This Privacy Policy explains how the operator of the ForgeAI / Porticus platform (“we”, “us”, or “ForgeAI”) collects, uses, stores, discloses, and protects information in connection with websites, web apps, APIs, workers, exports, share links, and related services (together, the “Platform”).
Using the Platform is acceptance of this Policy
By accessing, browsing, signing in to, uploading to, viewing, sharing, exporting from, or otherwise using the Platform, you acknowledge that you have read and understood this Privacy Policy and agree to the processing of information as described here and in our Terms and Conditions. If you do not agree, do not use the Platform. If you use the Platform on behalf of an organisation, you represent that you are authorised to accept this Policy on its behalf.
1. Who we are and how to contact us
This Policy is issued by the business operating under the ForgeAI and Porticus brands (the controller of personal information for Platform operations, unless a signed enterprise agreement states otherwise). For privacy requests, questions, or complaints, contact us via the support channel provided for your pilot or subscription, or email privacy@porticusai.com.
If your organisation has a separate written data processing or enterprise agreement with us, that agreement prevails over this Policy only to the extent of an express conflict.
2. Scope
This Policy applies to:
- Visitors to our marketing sites and public pages
- Account holders, invited users, and pilot participants
- Recipients of share links or other limited public views
- Personal information and customer content processed when you use the Platform
It does not govern third-party websites or services that we do not control (for example a Microsoft or Google sign-in page, or a client portal outside ForgeAI).
3. Information we collect
3.1 Account and identity
Name, email address, authentication identifiers, organisation / company name, role, profile settings, and similar account data — including data received from our authentication provider (Clerk) and from identity providers you choose (for example Google or Microsoft).
3.2 Customer content (project data)
Documents and data you or your organisation upload or generate, which may include drawings, PDFs, schedules, specifications, markups, BOQ lines, rates, notes, RFIs, activity logs, exports, proposals, and related project metadata. This material may contain personal information (for example names on drawings or in notes) and commercially sensitive information. You are responsible for ensuring you have the right to upload and process that content.
3.3 Usage, device, and technical data
Log data, IP address, browser type, device identifiers, timestamps, pages or API routes accessed, feature usage, error diagnostics, performance metrics, and similar technical information needed to secure and operate the Platform.
3.4 Communications
Messages you send us (support, early-access requests, feedback), and operational emails we send you (security, product, billing, or pilot communications).
3.5 Cookies and similar technologies
We and our providers use cookies, local storage, and similar technologies for authentication, session security, preferences, and (where enabled) analytics or fraud prevention. You can control cookies through your browser; disabling essential cookies may prevent sign-in or core features from working.
4. How we use information
We use information to:
- Provide, host, secure, and improve the Platform
- Authenticate users, enforce roles, tenancy, and access controls
- Run takeoff, detection, estimation, review, export, share, and related workflows you request
- Process content with automated systems and third-party AI / infrastructure providers solely as needed to deliver the service
- Communicate with you about the Platform, pilots, and security
- Monitor abuse, debug incidents, and protect rights and safety
- Comply with law and enforce our Terms
- Create aggregated or de-identified statistics that do not reasonably identify you or your projects, for product and business purposes
We do not sell your personal information. We do not use your project drawings or BOQ content to train public foundation models for unrelated third parties, except where you have given a separate written authorisation or a product setting you control explicitly permits improvement use for your organisation.
5. Legal bases (where applicable)
Where data-protection laws require a legal basis (including the GDPR for individuals in the EEA/UK), we rely on one or more of: performance of a contract with you or your organisation; legitimate interests in operating a secure B2B product (balanced against your rights); consent where we ask for it; and legal obligation.
For Australian Privacy Principles (APPs), we collect and handle personal information only by fair and lawful means and for purposes that a reasonable person would expect from an estimating platform, or as otherwise permitted by the Privacy Act 1988 (Cth) and related rules.
6. Where data is hosted and processed
Primary infrastructure. Application servers, databases, workers, and related Platform services are hosted on Railway.com (Railway Corporation and its infrastructure partners). Our production stack is hosted in Railway's US East region (Virginia, United States) — the same US East / Northern Virginia market commonly associated with facilities around Ashburn, Virginia. Railway may operate additional regions (for example US West or EU West); we may change, add, or rebalance regions for reliability, latency, or operational reasons. We will update this Policy when primary hosting locations materially change.
Object storage and databases used by the Platform run on Railway-managed infrastructure and volumes associated with those services. Uploaded files and derived artefacts are stored as part of delivering the product to your organisation.
Subprocessors and cross-border processing. Authentication, email, AI model inference, content delivery, and other components may process data in the United States, European Union, Australia, or other countries where those providers operate. By using the Platform you instruct and authorise us to transfer and process information in those locations as needed to provide the service. Where required, we rely on appropriate safeguards (including contractual protections with providers).
Exact physical data-centre addresses are controlled by Railway and its suppliers and may change without notice to end users. References to Virginia / Ashburn describe the US East region, not a guarantee of a single named facility.
7. Who we share information with
We may share information with:
- Service providers / subprocessors that host, authenticate, process, analyse, or support the Platform. The main categories we use today include:
- Railway — application hosting, databases, workers, and related infrastructure (primary region: US East)
- Clerk — sign-in, sign-up, passwords, and session authentication
- Stripe — billing and payment methods when paid plans are enabled for your organisation
- Resend (or similar) — transactional and operational email (for example invites, password-reset instructions, early-access enquiries)
- AI / model providers — process drawing and document content only as needed to run takeoff, extraction, classification, and related features you request
- Observability vendors (for example error monitoring) — technical diagnostics, not used for marketing your project content
- Your organisation — administrators and other users in your tenant according to roles and share settings you control
- Share-link recipients — anyone you give a link to may see the project information exposed by that link for its lifetime
- Professional advisers and authorities where required by law, regulation, legal process, or to protect rights, safety, and security
- Successors in a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality
Providers are permitted to process data only as needed to perform services for us (or as required by law), not to use your project content for their own unrelated marketing. A current subprocessor summary can also be requested at privacy@porticusai.com.
8. Share links and public surfaces
If you create a share link or similar public view, you control who receives the link and what it exposes. Anyone with the link may access that content until the link expires or is revoked. Do not put sensitive personal information in shareable fields unless necessary. We are not responsible for onward disclosure by recipients you choose.
9. Retention
We retain account data and customer content for as long as your organisation maintains an account or as needed to provide the service, resolve disputes, enforce agreements, and meet legal, tax, and security requirements.
- Projects you delete. When you delete a project from your dashboard, it is removed from your normal view immediately and any in-progress processing for that project is stopped. We may retain the deleted project and associated files for up to 30 days so we can recover from mistakes or investigate abuse, then permanently purge it (database records and, on a best-effort basis, stored files). Backups may lag that purge for a short additional period.
- Closing a company / account. There is no self-serve “wipe our whole company” button today. Email privacy@porticusai.com from an authorised company contact. After we verify the request, we aim to delete or de-identify that organisation's Platform data within 30 days, subject to legal holds, billing records we must keep, and residual backup copies that are securely isolated until rotated out.
- Logs and security telemetry are typically kept up to 12–24 months unless an incident requires longer retention.
10. Security
We implement technical and organisational measures appropriate to a multi-tenant B2B application, including transport encryption (HTTPS/TLS), access controls, tenant isolation controls, and authentication via a specialist provider. No method of transmission or storage is completely secure. You are responsible for protecting credentials, configuring share links carefully, and maintaining your own copies of critical source documents and exports.
11. Your rights and choices
Depending on your location and applicable law, you may have rights to request access, correction, deletion, restriction, portability, or objection to certain processing, and to withdraw consent where processing is consent-based. Australian individuals may also request access and correction under the APPs. California residents may have additional rights under the CCPA/CPRA (we do not sell personal information). EEA/UK individuals may lodge a complaint with their supervisory authority.
How to contact us. Email privacy@porticusai.com with: your name, work email, company name (if any), and what you are asking for (access, correction, deletion, or a question). We may need to verify your identity and your authority to act for an organisation (for example a company admin). For pilot customers, you may also use the support channel named in your pilot agreement.
What happens next. We aim to acknowledge requests promptly and to complete straightforward requests within 30 days where the law requires that timeframe, or otherwise within a commercially reasonable period for pilot operations. Complex or company-wide deletions may take the full period described in §9. Some requests may be limited where we must retain data for legal, security, or contractual reasons, or where another organisation is the controller of the data (for example your employer's tenant admin).
Australian complaints that we cannot resolve may be taken to the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au.
12. Children
The Platform is a business estimating product and is not directed to children under 16 (or the higher age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have, contact us and we will take appropriate steps to delete it.
13. Automated processing and AI
The Platform uses automated processing and machine learning to extract quantities, attributes, confidence signals, and related Outputs. Those Outputs can be wrong. Human review remains your responsibility as described in the Terms. Automated processing is performed to deliver the product you request, not to make legal or similarly significant decisions about individuals without human involvement in a consumer context.
14. Changes to this Policy
We may update this Policy by posting a revised version on the Platform and updating the “Last updated” date. Material changes will be effective when posted, or on a later date we specify. Continued use of the Platform after the effective date constitutes acceptance of the updated Policy. If you do not agree, stop using the Platform and request account closure.
15. Relationship to the Terms
This Policy forms part of your agreement with us together with the Terms and Conditions. Limitation of liability, indemnity, disclaimer, and governing-law provisions in the Terms apply to privacy-related claims to the maximum extent permitted by law, except where mandatory privacy law provides non-excludable rights.
Summary (does not replace this Policy)
- We process account, project, and technical data to run ForgeAI.
- Hosting is on Railway.com in US East (Virginia, United States).
- Key subprocessors include Clerk (auth), AI model providers (takeoff features), email, and optionally Stripe (billing).
- We do not sell personal information.
- You control share links; treat them as public to the holder.
- Deleted projects: hidden immediately, purged within about 30 days.
- Contact privacy@porticusai.com for access, correction, or company-wide deletion (we aim to respond within 30 days).