Privacy Policy
Last updated August 5, 2026. This is a plain-language, best-effort policy prepared without a retained attorney; it is not a substitute for individualized legal advice. © 2026 Haven Command LLC.
ScriptForge AI is operated by Haven Command LLC, a California limited liability company, doing business as Script Forge AI. This policy explains what we collect, why, and how it's protected.
Information We Collect
Account email, username, and password (hashed, never stored in plain text); waitlist signup email and name if you join the waitlist; encrypted model provider API keys if you add your own; project content you create, upload, edit, or export; billing and subscription status (payment card details are never stored by us — see Payments below); usage records such as request counts, token usage, and feature access; and technical logs such as IP address, browser type, and error diagnostics.
How We Use It
To run your account and authenticate sign-in, to generate and store your writing projects, to process billing and enforce plan limits, to send transactional email (verification codes, receipts, cancellation notices), to notify waitlist members at launch, to moderate the community forum, and to diagnose and fix bugs.
We do not sell your personal information, and we do not use your project content to train our own AI models.
Encryption And Storage
Account emails, usernames, waitlist emails, and stored model API keys are encrypted at rest. Lookup hashes are keyed with server secrets so raw contact details are not stored as plain text for normal lookup paths. Data is stored on our hosting provider's infrastructure in the United States.
AI Providers
When you use AI features, relevant project context and prompts are sent to the configured model provider — by default a shared DeepSeek key, or a provider you configure yourself (for example Anthropic) if your plan supports custom API keys. Provider-side retention and training policies are governed by that provider's own terms; see our AI Disclosure for details. Do not submit material you are not authorized to process with a third-party AI service.
Other Service Providers
We use a small set of third-party processors to run ScriptForge: a hosting provider to run the application and database, a payment processor (Stripe) to handle billing when enabled, and a transactional email provider to send verification codes and account notices. Each only receives the information needed to perform its function.
Payments
When billing is enabled, payment details are handled entirely by Stripe. ScriptForge never sees or stores your full card number.
Waitlist
Pre-launch signups are stored on the waitlist so we can notify users when public access opens and apply launch offers. You can ask us to remove your waitlist entry at any time through the chat support experience.
Cookies And Local Storage
ScriptForge uses essential cookies and browser local storage to keep you signed in and to save your workspace preferences. We do not use third-party advertising trackers.
Your Rights
You can request a copy of your account data, ask us to correct inaccurate information, or request deletion of your account and associated data through the ScriptForge chat support experience. We will fulfill verifiable requests within a reasonable time, subject to records we're required to keep for billing, tax, or fraud-prevention purposes.
Data Retention
We retain account and project data for as long as your account is active, and for a limited period after account deletion or subscription cancellation as needed for billing records, fraud prevention, and legal compliance.
Children's Privacy
ScriptForge is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.
International Users
ScriptForge is operated from the United States. If you use ScriptForge from outside the United States, your information will be processed in the United States, which may have different data protection laws than your country.
Security
No system is perfectly secure. We use encryption at rest for sensitive fields and standard access controls, but you should also use a strong, unique password, keep your own backups of important work, and rotate any API key you believe may have been exposed.
Changes To This Policy
We may update this policy as the product evolves. We will update the "Last updated" date above when we do.
Contact
For privacy questions or data requests, use the ScriptForge chat support experience. Transactional or moderation messages may come from noreply@scriptforgeai.studio.