CardForge trust center
Privacy Policy
Last updated September 3, 2026
CardForge Studio is a software product created and operated by Cameron Locke, an independent sole proprietor based in Oregon.
CardForge is designed as a local-first card creation tool. Card projects, imported data, generated previews, personal uploads, export settings, and browser preferences are stored in browser IndexedDB. Portable exports and backups are downloaded project files that remain on the devices and storage locations you choose. This browser-local project data is not automatically uploaded to CardForge; it leaves your browser when you download, share, or intentionally submit it. Clearing site data, changing browsers or devices, or deleting downloaded files can remove copies that CardForge cannot recover.
Clerk provides authentication, account identity, session management, and trusted access metadata. Stripe processes billing and maintains payment, checkout, customer, refund, and subscription records. Supabase stores operational records used for shared platform features, including entitlement status, billing events, roadmap suggestions and votes, Contributor profiles, Contributor submissions and votes, asset registry records, contact requests, abuse-prevention records, legal publications, and owner settings. Resend sends communications for contact workflows and other transactional messages. Vercel hosts the site and server routes and may process standard request, device, network, and deployment log information needed to deliver and operate them. Each provider processes information for its role under its own terms and retention practices.
Signed-in users may connect CardForge to ChatGPT, Codex, or another compatible Model Context Protocol client. That client and its provider separately process conversation and tool-call data under their own terms. CardForge receives the tool inputs the client sends and returns the requested tool results. To support continued editing, Supabase stores private assistant working documents tied to the CardForge account. Those documents may contain editable Templates, cards and card sets, production plans, revisions, and artwork intentionally attached through the assistant workflow. They are separate from ordinary browser-local CardForge projects and are not published unless the user later chooses a separate review or publication workflow.
CardForge also records aggregate MCP usage tied to the account and tool name, including attempts, success or failure, assisted-action units, request and response byte counts, tool duration, and private assistant document counts and storage size. The aggregate usage table does not store prompts, card content, artwork, or document payloads. Those totals support reliability review, capacity planning, plan presentation, abuse prevention, and future usage-policy decisions; the displayed capacity values are measurement targets and are not currently enforced quotas or overage charges.
CardForge and Clerk use cookies and similar authentication technologies to keep users signed in, maintain sessions, protect account workflows, and remember necessary authentication state. Blocking those technologies may prevent sign-in or other account features from working.
CardForge may also offer optional, privacy-minimized measurement through Google Analytics and PostHog to understand website acquisition and how visitors interact with core creation activities. This measurement is off until you choose "Accept" or "Accept once," and you may decline or turn it off later through the Analytics settings shown by CardForge. If allowed, Google Analytics uses a randomly generated client identifier in a first-party cookie. Google may receive basic session, browser, device, language, and approximate-location information alongside a sanitized page path and title, limited referrer context, approved campaign parameters, and explicit CardForge activity events. PostHog uses an anonymous identifier kept only in browser session storage and receives a sanitized path, basic browser and device context, and allow-listed events such as navigation, card-format choices, card creation, and export outcomes. Approximate-location enrichment is disabled for PostHog events. CardForge does not identify visitors to PostHog or create PostHog person profiles.
CardForge does not use PostHog session replay. PostHog receives only the allow-listed event properties described above; it does not receive recordings of page content, text, form inputs, card content, project or design names, account names, email addresses, uploaded files, non-campaign query values, or raw private workspace content. CardForge does not enable Google advertising storage, Google Signals, ad personalization, or Enhanced Measurement. Google and PostHog control the resulting analytics records under their own processing and retention practices; CardForge reads owner-only reports but does not copy raw visitor events into Supabase. Learn more in Google's privacy policy at https://policies.google.com/privacy and PostHog's privacy information at https://posthog.com/privacy.
Choosing "Accept" or "Decline" stores the analytics choice in a first-party cookie for up to 180 days so CardForge can remember it. Choosing "Accept once" stores permission only for the current browser-tab session. PostHog's anonymous browser state is session-only regardless of which acceptance option you choose. Declining or turning analytics off prevents future Google Analytics and PostHog collection from that browser and clears provider browser state that CardForge can identify, but it does not retroactively delete aggregated or previously processed provider records. You can also block or clear cookies and site storage in your browser. Google Search Console separately provides CardForge with aggregated information about how pages appear and perform in Google Search; it does not depend on the optional CardForge analytics choice.
Information you choose to provide may include an account identifier, email address, optional name, contact requests and their contents, roadmap suggestions and votes, Contributor profile details, Contributor submissions, source files, and Contributor votes. Contributor submissions, public source files, and published library assets are intentionally shared with the review Pipeline and may become visible to other users. Do not upload confidential files, private client work, or content you do not have permission to share.
Browser IndexedDB data remains until you clear it or the browser removes it, and downloaded project files remain until you delete them from the places where you saved them. Private assistant working documents use an inactivity window tied to the current account plan: 12 hours for Free, 24 hours for Creator Pass, and 48 hours for Designer Pass and Contributor and owner accounts by default. Opening or updating a document restarts its window; merely listing documents on the Account page does not. The CardForge owner may adjust these plan windows in the protected Profile utility. An expired or manually deleted assistant document remains in recoverable trash for 24 hours, then CardForge permanently removes its stored document and private artwork. Aggregate MCP usage may remain for operational, security, abuse-prevention, legal, or record-integrity needs. Other platform and provider records are retained for periods that vary by record, operational need, legal obligation, and provider setting. Some billing, legal, voting, attribution, published-asset, aggregate usage, and security records may need to remain after an account is disabled or deleted to preserve accurate platform history and system integrity.
For a privacy question or an access or deletion inquiry, including a request concerning private assistant working documents, contact pyraliscameron@gmail.com. CardForge may need to verify the requester and may be unable to alter records that must remain for security, record-integrity, provider, or legal reasons. Account deletion does not delete browser IndexedDB or downloaded project files under your control.
CardForge uses operational safeguards, but no method of transmission or storage is completely secure. Keep control of your devices, account credentials, and downloaded backups. CardForge does not sell user project files.
CardForge is not directed to children under 13 and does not knowingly collect their personal information. A parent or guardian who believes a child provided information can use the privacy contact above.
Policy changes may be made as CardForge and its data practices develop. An updated publication will identify its version and effective date, so review the current policy when you use the service.
Business contact
CardForge Studio is a software product created and operated by Cameron Locke, an independent sole proprietor based in Oregon.
Legal operator: Cameron Locke
Jurisdiction: Oregon, United States
Support email: pyraliscameron@gmail.com
Legal and privacy email: pyraliscameron@gmail.com