Skip to content
Dark ForgeAutomation
HomePricingTermsPrivacyPayments
Privacy questions

Privacy policy

Clear data practices.
Respect for people.

Effective Date: August 21, 2026 · Last Updated: August 21, 2026

The short version

Dark Forge Automation uses information needed to provide, secure, support, and operate requested websites, dashboards, Discord bots, Custom Development Services, and community-safety workflows. We do not sell personal information. Privacy questions and requests may be sent to DarkForgeAutomation@protonmail.com.

Who and what this policy covers

This policy applies to Dark Forge Automation websites, dashboards, portals, downloads, Discord applications and bots—including Foundry and StormVault—Custom Development Services, support, hosting, and related services that link to this policy. Discord and other providers are separate services with their own policies. Customers and Discord server owners may also have responsibilities for information they direct Dark Forge to process.

Information we process

  • Discord and account data: Discord user IDs, usernames, display names, server IDs, channel and role IDs, permissions, server settings, authorization records, and interaction records.
  • Submitted content: support tickets, feedback, applications, reviews, project inquiries, safety reports, case notes, messages, uploaded files, and evidence.
  • Safety and moderation data: reported account IDs, case references, evidence, review decisions, appeals, moderation actions, reasons, timestamps, assignments, threat indicators, Network Incident history, containment history, and audit records.
  • Custom Development data: approved scope, Orders, acceptance records, Customer Materials, project working files, build artifacts, configuration, deployment information, repositories, and project communications.
  • Credentials and delegated access: OAuth grants, scoped API keys, bot tokens, application secrets, service accounts, temporary credentials, repository access, hosting access, and other delegated permissions supplied when reasonably needed for a project or Service.
  • Website inquiries: name, email address, optional Discord username, community size, service interest, and project details submitted through contact forms.
  • Operational data: security events, access logs, errors, health information, entitlement status, backup metadata, and limited technical information needed to protect and operate Services.
  • Business records: Orders, invoices, payments, accepted scopes, project acceptance, material scope changes, and other records reasonably needed for contracts, accounting, disputes, and legal obligations.

Do not submit personal-account passwords, payment-card numbers, government identifiers, medical records, illegal material, or information unnecessary for the requested workflow. Do not upload sensitive evidence to a public Discord channel. Customers must have authority to provide credentials, Customer Materials, and other data submitted for a project.

Why we use information

We use information to provide requested features and Custom Development, authenticate and authorize access, configure and deploy projects, route support, process applications and reviews, investigate safety reports, maintain auditability, coordinate authorized security activity, detect and prevent abuse, troubleshoot failures, process plan entitlements, communicate with users, maintain business records, comply with legal obligations, and protect Services and communities.

We do not use Discord data for unrelated behavioral advertising or sell personal information.

Custom Development access and credentials

Dark Forge requests only credentials and access reasonably necessary for agreed work. Where reasonably available, official OAuth, scoped API keys, service accounts, delegated or team access, temporary credentials, provider-supported collaborator access, and limited repository or hosting permissions are preferred over shared passwords.

Dark Forge uses Customer-provided access only as reasonably needed for the project or Service, restricts it to people who need it, avoids unnecessary duplication, and does not intentionally commit secrets to public repositories. Temporary local copies and access no longer reasonably needed are removed or revoked where practical, subject to security, dispute, backup, contractual, and legal requirements.

Customers should remove unnecessary collaborator access and rotate temporary or shared credentials after handoff or suspected exposure where appropriate. Customer credentials are separate from Dark Forge master infrastructure credentials and credentials belonging to other customers.

Customer choices and privacy requests

Where a workflow requests optional or sensitive information, the Service may ask for acknowledgement before submission. A person may decline optional information, although the related feature may not work. A private review does not authorize public testimonial publication without separate confirmation.

Depending on applicable law and the nature of the record, a person may request access, correction, deletion, restriction, objection, withdrawal of consent, or a copy of personal information by emailing DarkForgeAutomation@protonmail.com. Dark Forge may need to verify the requester and coordinate with a Discord server owner or Customer that controls community data.

A request does not automatically require immediate deletion of every record. Some records may involve other people or communities, shared security history, active investigations, audit integrity, fraud prevention, contractual obligations, or legal requirements. Dark Forge will evaluate requests under applicable law and will not rely on this policy to deny a right that cannot lawfully be denied. No general downloadable evidence or security-record export feature is promised.

Retention guidelines

Dark Forge aims to keep information long enough for the purpose for which it was collected, support, safety review, appeals, security, abuse prevention, accountability, contracts, and legal obligations without retaining it indefinitely. A documented hold, active investigation, unresolved safety matter, fraud review, dispute, backup lifecycle, contractual requirement, or law may require longer retention.

Record typeDefault retentionAfter the period
Custom Development working materialsUp to 90 days after project completion or formal inactive archivalMay be deleted unless still needed for an approved purpose, dispute, security, backup, contract, or law
Customer credentials and temporary accessOnly while reasonably needed for the project or ServiceRemove or revoke where practical; rotate Customer-controlled credentials where appropriate
StormVault reports and case recordsWhile active; then 24 months after closure or archivalDelete or de-identify unless a documented hold or another lawful need applies
StormVault evidence filesWhile the case is active; then 12 months after closureSecure deletion, subject to safety, dispute, or legal hold
Foundry support tickets and transcripts180 days after closureDelete attachments and transcript content; retain minimal operational records if reasonably needed
StormVault support and security communicationsWhile needed for support, cases, security, audit, or dispute handlingDelete, de-identify, or retain only a limited record under the applicable security and legal basis
Staff applications12 months after the final decisionDelete answers and attachments unless an ongoing documented relationship or lawful need applies
Feedback and private reviews12 months after submission or moderationDelete or anonymize unused submissions; approved public reviews remain until withdrawn or removed
Audit, security, threat, and access logs24 monthsDelete or aggregate when no longer needed for security, fraud prevention, audit, or accountability
Orders, invoices, acceptance, and business recordsAs reasonably needed for contracts, accounting, taxes, disputes, and legal obligationsDelete or minimize when no longer lawfully needed
BackupsUntil the applicable backup rotation completes, targeted at 90 daysDeleted active data may remain in protected backup copies until rotation

These are operating guidelines, not promises of exact deletion on a particular day. Custom Development retention does not require deletion of reusable Provider Materials or create permanent project backup. Business records, credentials, StormVault security data, and managed-product data have separate purposes and lifecycles.

StormVault downgrade and cancellation

An ordinary plan downgrade or paid-plan cancellation does not automatically erase legitimate cases, evidence, appeals, audit history, support messages, threat detections, containment history, authorized Network Incident history, or other security records. Existing evidence is not automatically deleted because a lower plan limits new evidence.

Premium configuration may be preserved where safe while premium execution becomes disabled or read-only. During an applicable seven-calendar-day downgrade grace period, historical records and excess ordinary snapshots are not immediately purged solely because the lower plan has a smaller limit. After grace, eligible ordinary snapshots may be reduced through normal retention while protected, incident, pre-restore, active-recovery, security-required, or audit-required snapshots may follow a separate lifecycle.

Downgrade retention remains limited by the retention schedule, authorization, lawful deletion obligations, security and audit needs, disputes, and applicable law. It is not a promise of permanent storage.

Server deregistration, account or organization deletion

Server deregistration may disable monitoring, protection, Safety Network participation, new snapshots and recovery, notifications, and operational access after a safe technical transition. It does not automatically erase cases, evidence, appeals, audit history, detections, Network Incident history, support records, snapshots, or recovery history. Those records enter their applicable retention and deletion lifecycle.

Organization or account deletion must not indiscriminately delete another organization's private records, shared Network Incident history, records required for security or audit integrity, legally retained material, or information affecting another person's or community's rights. The requester may lose operational access while eligible organization-owned contributions may be corrected or withdrawn through an authorized process.

Re-registering a server does not guarantee restoration of every previous configuration, entitlement, snapshot, recovery record, or Safety Network state.

Safety Network and Network Incidents

Safety Network participation is opt-in for active participating communities. Network coordination may use authorized account or domain indicators, incident notices, participation records, and anonymous or attributed information according to settings and workflow. Private evidence, reporter identity, private cases, and internal staff notes are not automatically shared.

Free and Silver communities may receive privacy-safe safety warnings where current StormVault policy permits. Gold is required for active Safety Network participation. Ending Gold or leaving the Safety Network stops new participation and coordination actions after a safe transition but does not automatically erase authorized historical or audit records.

A participating community may raise a good-faith concern about inaccurate, outdated, misattributed, or improperly shared information. Dark Forge may review, correct, withdraw, or annotate eligible information and preserve an appropriate restricted audit history of the original event and later action. One community cannot use correction or deletion to rewrite another community's private records.

Security, fraud, and Service termination

Dark Forge may preserve limited records reasonably needed to investigate serious prohibited use, malicious reporting, fraud, credential compromise, unauthorized access, security-tool abuse, disputes, or threats to customers or systems. Suspension or termination does not authorize indiscriminate destruction of Customer Data or indefinite retention without a legitimate basis.

When a material credential or data-security incident is identified, Dark Forge will investigate, take reasonable containment and remediation steps, and provide notice where appropriate and required by applicable law. This policy does not promise a fixed notification deadline beyond requirements that apply by law.

Service discontinuation and business wind-down

If StormVault or another Service is permanently discontinued, active bots, dashboards, protection, Safety Network operations, snapshot creation, recovery, support, or hosting may cease. Where reasonably practical, Dark Forge will evaluate which data can lawfully and technically be made available, which records must remain for a limited lawful purpose, and what deletion or backup-rotation process applies. This does not promise a currently unsupported export system.

If Dark Forge ceases operations, similar data-minimization, security, lawful-retention, and deletion principles apply where legally and practically possible. No continuity or recovery beyond Dark Forge's lawful and practical ability is guaranteed.

Sharing and service providers

Information may be processed by Discord; hosting, infrastructure, database, backup, monitoring, repository, deployment, email, support, media, API, and payment providers; and professional advisers where reasonably needed to provide or protect a Service. Providers may process information in countries other than the user's own and operate under their own terms and privacy practices.

Dark Forge does not sell personal information. Information may be disclosed when authorized by the Customer or user, required by law, reasonably necessary to protect users or systems, or involved in a business transfer with appropriate safeguards.

Security

Dark Forge uses measures such as access controls, least-privilege permissions, protected dashboards, private staff areas, secret management, encrypted connections where supported, backups, monitoring, and audit records. No system is perfectly secure. Suspected exposure or abuse should be reported promptly to DarkForgeAutomation@protonmail.com.

Children

Services are not directed to children below the minimum age required by Discord or applicable law. Dark Forge does not knowingly solicit information from children in violation of applicable requirements. Contact us if you believe a child submitted personal information so it can be reviewed and deleted where appropriate.

International processing and legal rights

Depending on where a person lives, applicable law may provide rights to access, correct, delete, restrict, object to, or receive a copy of personal information and to complain to a data-protection regulator. Nothing in this policy limits rights that cannot lawfully be limited.

Changes and contact

Dark Forge may update this policy when Services, providers, practices, or legal requirements change. Material changes will receive notice appropriate to the change and applicable law and will be posted with updated effective-date information.

Privacy questions and requests may be sent to DarkForgeAutomation@protonmail.com.

© 2026 Dark Forge Automation.Home  ·  Terms  ·  Privacy  ·  Payments