Overview
Forkbench ("we," "our," or "us") is the controller of the personal data described here. This Policy explains what we collect when you use the Forkbench application, website, and related services (the "Service"), why, and the rights you have. Where the General Data Protection Regulation (GDPR) of the EU/EEA or the UK applies, we process your data as a controller on the legal bases set out below. For any privacy question or request, contact us at [email protected].
Information we collect
Account data
When you create an account, we collect:
- Your email address.
- A name, if you choose to provide one.
- A password hash (we never store plain-text passwords), or an identifier from Google or Apple if you sign in with one of those providers.
- Timestamps for account creation, email verification, and sign-in.
- Session metadata so you can review and manage your sessions.
Payment data
When you subscribe, payments are processed by Polar as merchant of record; it receives your billing details (such as name, email, payment method, and billing address) and processes the charge. We receive a purchase record (transaction id, product id, status, renewal date) and a customer id so we can grant your subscription and show your purchase history. We never receive your full card number or security code. See the processor's own privacy policy for how it handles billing data.
Notebooks content
We store the notes, notebooks, and notes you create so we can synchronize them across your branches, devices, and the teammates you share them with. This content is whatever you choose to write; please don't include secrets or credentials you don't want stored.
Fork Lab data
To connect the web to the agents on your paired Macs, we process:
- Device and pairing data — a device name, platform, app version, online status, and last-seen time for each Mac you pair, so you can identify and manage your devices.
- Conversation and message data — the messages, instructions, and commands you send, and the agent replies and status your Macs relay back, plus related metadata such as project names and paths. This content passes through and is stored on our servers so we can deliver it and queue it while a Mac is offline.
The AI coding agents you run are third-party tools. The code and prompts those agents process on your machines are handled by the agents and their AI providers under their own policies; we relay the messages you choose to send to and from them, and we do not control the agents' own processing. We do not use your notes or messages to train AI models.
Transactional email
We use Resend to send account email (verification, password resets, receipts, and billing notices). Resend receives the recipient address and the content needed to deliver the message, and does not use it for marketing.
Error tracking
If error tracking is enabled, we use Sentry to record application errors and the minimum note needed to diagnose them (such as app or browser version, error stack, and a request id). We scrub identifiable information from these reports where practical.
App usage data (optional)
The Forkbench desktop application can share anonymous usage data with us — only if you choose to turn it on. The app asks once on first launch, sends nothing until you agree, and you can change your mind at any time in the app's Settings → Privacy; turning it off also deletes the app's local telemetry identifier and queue.
If you enable it, the app sends:
- A random installation identifier generated on your device. It is not derived from your hardware, account, or network, and it is not linked to your account — usage data is analyzed separately from who you are.
- The app version, macOS version, device architecture, and language setting.
- A coarse country code derived from the connection at our edge when an event arrives. We never store your IP address with usage data.
- Content-free usage counters — for example that the app was launched, that a feature was used, how long a session lasted, or that a connection dropped and recovered.
The app never sends the content you work with. No code, prompts, commands, transcripts, file names, file paths, project or workspace names, error message text, or keystrokes are ever included in usage data.
We use this data solely to understand which versions are in use, how features are adopted, and where reliability needs work. Raw usage events are kept for at most 90 days, after which they are reduced to aggregate statistics (counts per day) that no longer contain the installation identifier, and the raw events are deleted.
Logs and usage data
We keep server-side request logs (such as IP address, timestamp, and route) for operational and security purposes. These are retained for a limited period and are not used for marketing.
Legal bases for processing
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — to create and run your account, provide the Service (including synchronizing your notes and relaying your Fork Lab messages to and from your paired Macs), and handle subscriptions and billing.
- Our legitimate interests — to secure the Service and your account, prevent and investigate abuse, debug, and keep the Service reliable, balanced against your rights and freedoms.
- Your consent — where we ask for it, such as when you choose to sign in with Google or Apple, or when you enable optional app usage data sharing; you can withdraw consent at any time without affecting earlier processing.
- Legal obligations — to meet accounting, tax, and other legal requirements.
How we use information
We use the information we collect to:
- Authenticate you and protect your account, devices, and the Service from abuse.
- Provide the Service — including synchronizing your notes and relaying your Fork Lab messages to and from your paired Macs.
- Provide Paid Features to subscribers and manage billing.
- Send transactional email about your account and purchases.
- Diagnose and fix problems and improve reliability and security.
- Comply with legal obligations and enforce our Terms.
We do not sell your personal information.
How we share information
We share information only with the service providers needed to run the Service, acting as our processors, and only as needed:
- Polar — payment processing and billing.
- Resend — transactional email delivery.
- Cloudflare — application download hosting and content delivery.
- Sentry — error tracking, where enabled.
- Google and Apple — only if you choose to sign in with them.
We may also disclose information when required by law or to protect the rights, property, safety, or security of Forkbench, our users, or others. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction.
International data transfers
Some of our service providers process data in countries outside your own, which may include countries outside the EEA or UK. Where we transfer personal data outside the EEA or UK, we rely on appropriate safeguards — such as a European Comscope (or UK) adequacy decision, or Standard Contractual Clauses — so that your data keeps an equivalent level of protection.
Your rights
Subject to applicable law, you have the right to access, correct, delete, or receive a portable copy of your personal data, to restrict or object to certain processing, and to withdraw consent where processing is based on it. You can exercise many of these directly from your account page, or by emailing [email protected]; we respond as required by law. If you are in the EU/EEA or the UK, you also have the right to lodge a complaint with your local data protection supervisory authority.
Data retention and deletion
You can delete your account at any time from your account page. Deletion is permanent: your email, name, sign-in links, notes, and conversation content are removed or disconnected, while purchase records may be retained in anonymized form for accounting and dispute-resolution purposes. We keep personal data only as long as needed for the purposes described here or as required by law.
Security
We use industry-standard safeguards, including encrypted transport (HTTPS), hashed passwords, signed webhooks, and least-privilege access to infrastructure. No system is perfectly secure. Because sessions use signed tokens, signing out and changes such as a password reset apply going forward and to new sign-ins; an already-issued session may remain valid until it expires (within 7 days). Report security concerns to [email protected].
Children
The Service is not directed to children, and we do not knowingly collect personal data from children below the age of digital consent that applies to them. If you believe a child has provided us personal data, contact [email protected].
Changes
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email.
Contact
Questions about this Privacy Policy, or want to exercise your rights? Email [email protected].