Privacy Policy
Effective Date: April 9, 2026 ยท GlobalSync LLC d/b/a AuthForge
This Privacy Policy describes how GlobalSync LLC d/b/a AuthForge ("we," "us," "our") collects, uses, and handles information when you use the AuthForge platform at authforge.cc.
1. Information We Collect
Account Information
When you register, we collect your email address. Passwords are managed by AWS Cognito and are stored in hashed form; we never have access to your plaintext password.
Usage and API Data
We collect logs of API requests made through your applications, including timestamps, application identifiers, license key identifiers, authentication outcomes, and IP addresses. These logs are retained for 90 days and used for abuse prevention, debugging, and service integrity.
Hardware Fingerprints (HWIDs)
AuthForge stores hardware fingerprint data (HWIDs) submitted by SDKs integrated into your end users' software. This data is submitted by you (the developer/Customer) as part of your application's authentication flow. AuthForge processes this data on your behalf. You are responsible for ensuring your end users are appropriately informed about HWID collection in your own software's privacy disclosures.
Payment Information
Payments are processed by Stripe, a PCI DSS Level 1 certified payment processor. AuthForge never receives or stores your credit card number, CVV, expiration date, or other raw payment card data. When you add a card, that information is sent from your browser directly to Stripe and does not pass through AuthForge's servers. Card details are entered in Stripe's secure hosted fields (Stripe Elements) and never touch our systems as payment card data.
To enable features such as auto-refill, we store references provided by Stripe: a Stripe customer identifier and, when you save a card, a Stripe payment method identifier. These identifiers allow Stripe to charge your saved payment method on our behalf when your credit balance drops below your configured threshold. They cannot be used by themselves to recover your full card number. You can remove your saved payment method at any time from Settings, in the Auto-refill section, by choosing Remove. We detach the payment method in Stripe and clear the payment method identifier from our database. A Stripe customer identifier may remain on your account so you can add a new card later; it does not contain your card number.
We also store transaction records (amount, date, credit pack purchased, and Stripe session or payment intent identifiers) for billing history, support, and dispute resolution purposes.
Cookies and Session Data
We use session tokens issued by AWS Cognito to keep you signed in. These are essential cookies required for the Service to function.
If you arrive via an affiliate referral link, we store a first-party cookie named
authforge_referral_code for up to 30 days so we can attribute your account signup to
the referring partner. The cookie is scoped to .authforge.cc (our marketing site and app subdomain) and
is used only for affiliate commission bookkeeping. It is not used for advertising, cross-site tracking, or analytics.
On your first visit to authforge.cc or app.authforge.cc, we store a first-party cookie named
authforge_first_touch for up to 90 days. It records the external website that linked
you to us (its address without any query string), the page you first landed on, any utm_ campaign tags
on that link, and when that first visit happened. Later visits never overwrite it. The cookie is scoped to
.authforge.cc. When you sign in, the app sends these values to us once, and we save them to your account
only if it was created within the last 7 days, so we can see which channels bring developers to AuthForge. It is not
used for advertising or cross-site tracking. If you never sign up, it simply expires.
Apart from the first-party cookies described above, we do not use tracking, analytics, or advertising cookies, and we do not use any third-party cookies. The website analytics described below do not use cookies.
Website Analytics
On our marketing site (authforge.cc), we use Umami Cloud, a privacy-focused analytics service
operated by Umami Software, Inc., to count visits and see which pages and links are used. For each page view, your
browser sends Umami the page address and the address of the website that linked you to us (both without any query
string), the page title, your screen size, and your browser language. We also record clicks on sign-up buttons, the
SDK install button, and links to the dashboard, labeled only with where the button sits on the page, the pricing pack
it belongs to, or the install command shown. Umami uses your IP address and browser user agent at the time of the
request to work out your approximate location (country, region, and city), browser, operating system, and device
type, and to compute an anonymous session identifier; it does not store your IP address or user agent. Umami does not
use cookies or track you across websites, and it is not used on app.authforge.cc or portal.authforge.cc. We look at
this data only in aggregate, and we do not use it for advertising. You can opt out by blocking
cloud.umami.is in your browser or content blocker.
Acquisition Survey
After you create your first application, the dashboard may ask how you heard about AuthForge. Answering is optional and you can dismiss it permanently. If you answer, we store your selected option, any text you enter in the "Other" and "Anything else?" fields, and when you answered. When a credit reward is offered, we also record a credit transaction for the reward; that transaction does not contain your answers.
2. How We Use Your Information
- To provide, operate, and maintain the AuthForge Service
- To process payments and manage your credit balance
- To detect and prevent abuse, fraud, and AUP violations
- To respond to support requests
- To send transactional emails (purchase receipts, account notices)
- To attribute signups to affiliate partners when you arrived via a referral link
- To understand which websites, campaigns, and channels lead developers to sign up, using the first-touch cookie and survey answers described above
- To understand, in aggregate, how visitors use our marketing site, using the website analytics described above
We do not sell your personal data. We do not use your data for advertising.
3. Third-Party Services
We use the following third-party processors as part of providing the Service:
- Amazon Web Services (AWS): cloud hosting, database, authentication (Cognito), and email (SES). Data is processed in the US.
- Stripe: payment processing. Stripe's privacy policy applies to payment data: stripe.com/privacy.
- Umami Software, Inc. (Umami Cloud): cookieless website analytics for authforge.cc. Umami Cloud servers are located in the US and EU: umami.is/privacy.
We do not share your personal information with third parties except as necessary to provide the Service or as required by law.
4. Data Retention
- Auth logs: 90 days
- Account data: Retained while your account is active. Deleted upon confirmed account deletion request.
- Referral attribution cookie: Up to 30 days, or until signup attribution is recorded and the cookie is cleared
- First-touch cookie: Up to 90 days in your browser. Once saved to your account, the acquisition details and any survey answers are part of your account data and are deleted with your account.
- Website analytics: Visit and click records in Umami Cloud contain no IP addresses, names, or email addresses, and are kept for as long as our Umami Cloud plan retains them.
- Transaction records: Retained for 7 years for legal and tax compliance.
- Stripe references: The payment method identifier is removed from our database when you remove your saved card. A Stripe customer identifier may remain on your account for future card setup. Stripe may retain records per their own privacy policy.
5. Your Rights
You may request the following at any time by contacting us at support@authforge.cc:
- Account deletion: we will delete your account and associated personal data, subject to retention requirements above
- Data export: we will provide a copy of the personal data we hold about you
- Correction: we will correct inaccurate personal data upon request
6. Security
We implement industry-standard security practices including encrypted data transmission (HTTPS/TLS), hashed credential storage via AWS Cognito, and cryptographically signed API responses. However, no system is perfectly secure. We cannot guarantee absolute security of your data.
7. Children
The Service is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will delete it.
8. Companion App for Even Realities G2 Glasses
We publish a free companion app for Even Realities G2 smart glasses (optionally used with the R1 ring). It is an optional add-on for existing AuthForge customers. This section describes it in full.
What the app displays
The app is a read-first view of your own AuthForge account. Depending on the permissions you grant when you pair it, it can show:
- Your applications: name, whether each is paused, and its authentication counts for the last 24 hours and 7 days
- Recent failed authentications for your apps, grouped by license key and failure reason
- A summary of one license: its status, expiry, whether a device is bound, and when it was last seen
- Your credit balance, credits used today, average daily burn, and estimated days of runway
If you grant the optional action permissions, it can also reset a license's bound device, revoke or reactivate a license, extend a license's expiry, and pause or unpause an application. Pausing is a separate permission that is off by default and must be enabled deliberately.
The app displays data you already own. It does not collect anything about you, and it does not read anything from the glasses, the ring, or your phone: no contacts, no location, no microphone, no camera, no photos, no calendar, and no other apps' data.
How the app signs in, and where its key is stored
The companion app never receives your AuthForge password and never holds your dashboard session. It
signs in through a pairing flow: the glasses display an eight-character code, you open
app.authforge.cc/pair on a device where you are already signed in, confirm the code matches, choose what
the glasses may do and for how long, and approve. Only then do we issue the glasses a scoped API key limited
to exactly the permissions you selected.
That key is delivered to the glasses once and is then stored only on your own device - inside the Even Realities phone app's storage on your phone. We keep only a one-way hash of it, which is what lets us recognise the key without being able to reproduce it. We do not transmit the key anywhere else, and neither we nor Even Realities can read it back off your phone.
Pairing requests themselves are short-lived: an unapproved request is deleted automatically after ten minutes, and an approved one is deleted the moment the glasses collect their key.
Backend domains the app contacts
The companion app communicates with exactly one backend domain, which we operate:
api.authforge.cc- the AuthForge API, over HTTPS, hosted on AWS in the US
It contacts no other domain. There are no third-party SDKs, no advertising or attribution networks, no crash reporters, and no analytics providers in the app.
No tracking
The companion app contains no tracking of any kind: no analytics, no advertising identifiers, no device fingerprinting, no cookies, and no cross-app or cross-site tracking. The website analytics described in Section 1 apply only to our marketing site and are not present in the app. We do record ordinary server-side API request logs for the key the glasses use - the same abuse-prevention and debugging logs described in Section 1 - and an audit entry when a key is created or revoked.
How to revoke the app's access
You can cut the glasses off at any time, in any of these ways:
- From the dashboard: sign in at
app.authforge.cc, open API Keys, and choose Revoke glasses access. This removes every key paired with your glasses immediately. - From the glasses: signing out in the companion app makes it revoke its own key.
- By waiting: the key expires on its own after the period you chose when pairing (30, 90, 180, or 365 days, defaulting to 180).
Revoking takes effect at once - the key stops working on its next request. Revoking the key does not delete any of your AuthForge data; it only ends the glasses' access to it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or notice on the Service. Continued use of the Service after changes constitutes acceptance.
10. Contact
For privacy inquiries:GlobalSync LLC d/b/a AuthForge
732 South 6th Street #5253, Las Vegas, NV, US
support@authforge.cc
+1 (512) 843-3470