Legal
Privacy Policy
Last updated: July 14, 2026. This policy outlines how Demiforge handles data collection, processing, and security for our enterprise planning and architecture studio.
1. Information We Collect
Demiforge collects basic account credentials (email addresses, corporate identifiers), organization structures, project names, and project specifications necessary to instantiate your virtual engineering environment.
We collect core business ideas and responses to our AI discovery interviews to compile your Engineering Design Packages. We do not store or process payment card details directly; all billing transactions are routed through secure, PCI-compliant payment processors.
2. How We Use Information
Your data is used strictly to provide the platform services:
- Creating and maintaining your team workspaces and project graphs.
- Routing prompt payloads to secure Large Language Model (LLM) providers under strict confidentiality agreements.
- Compiling, formatting, and executing quality gates for your 32 deliverables.
- Auditing system executions, logging performance metrics, and managing credit transactions.
3. Data Isolation and Multi-Tenancy
Data security is integral to our architecture. We implement strict Row-Level Security (RLS) policies within our PostgreSQL databases. Under no circumstances is data from one organization exposed, indexed, or shared with other tenants or used to train public LLM models.
4. Compliance & AI Model Routing
We route reasoning workloads through enterprise partners under strict data-protection agreements. Input and output tokens sent to LLMs are not retained by providers for training purposes and are governed by zero-retention policies where available. Our systems conform to GDPR, SOC 2, and EU AI Act governance standards.
5. Your Rights and Data Deletion
Organizations have the right to inspect, export, or permanently delete their workspaces, team members, projects, and versioned artifacts. Deleting a project cascades down to erase all related database rows and stored files, leaving only anonymized audit events required for compliance.
6. Contact Us
If you have questions about this Privacy Policy, data handling, or data security compliance, please reach out to our privacy team at: