ForgeOSby Medina19
Sign in Create account

Draft

Privacy policy

This is a working draft. It is not in force.

No lawyer has reviewed this document. It has no legal effect, creates no obligation on Medina19 and grants you no rights. It is published so that you, and the lawyer who will review it, can see what we intend to commit to before we commit to it.

Do not rely on it for a procurement decision, a security review or a regulatory assessment. For any of those, ask us directly and you will get an answer from a person.

Drafted 15 August 2026. Nothing here is binding until a reviewed policy replaces this page and says so on its face.

ForgeOS reads and changes software you own. That makes what we do with your code, your history and your data the most important thing on this site.

1. Who this covers

Medina19 is the company. ForgeOS is its product. This draft covers the ForgeOS product site, the ForgeOS product itself, and the support we provide with it. It covers people who ask for access and organisations that use ForgeOS.

2. What we hold

Categories, and why each exists
WhatWhy
Account and contact details — name, email, organisationTo give you access, reach you about your goals, and provide support.
Repository contents you connectForgeOS cannot plan or change software it cannot read.
Goals you write and the conversation about themThey are the instruction. They are shown back to you as the record of what was asked.
Work records — plans, changes, test and check results, failuresThey are the evidence behind every claim the product makes.
The coordination audit chainEvery state change and approval, append-only, so what happened can be proved.
Operational logs and errorsTo keep the service working and to answer you when it does not.
How each model performed — pooled across this instance, carrying no repository name and no workspace identifierSo a model that keeps failing is tried later, and one that works is tried sooner, for everybody. See section 4.
A daily count of calls your workspace made to the shared free modelsSo one workspace cannot use up the free capacity every customer on this instance draws from. A number and a date; nothing about the work.
A cached list of the models your connected providers offerSo new models are usable without waiting for us to write them down. Public catalogue data from your provider, not data about you.

Two things we intend never to hold. Secrets are referenced, never stored as values in source or evidence. And ForgeOS has no access to your customers' data unless you grant it as its own separate authority — which is off by default and shown as ungranted in Trust & control.

3. Model providers, and training

ForgeOS runs work through model providers you choose. Where you bring your own provider account, your content goes to that provider under your agreement with them, not ours.

We do not train on your code

Your repositories, goals, conversations and evidence are not used to train models for other customers, and are not sold.

Providers are yours to choose

Which providers may run work is a setting, per instance and per repository. No provider runs work until you configure one.

Zero-retention where a provider offers it

Where a provider supports zero data retention, we intend to use it by default and to say which providers do.

Attributed work

Every change records which model and agent produced it, so you can see where your content went.

4. Separation between customers

Your repositories, goals, conversations, artifacts, evidence, secrets and history belong to your workspace and are not pooled across customers.

One thing is deliberately shared, and it is not yours. When a model is asked to make a change, ForgeOS records how that attempt went — which model, on which class of work, whether the change applied, whether your repository’s own tests passed, and whether it needed repairing. Those records are pooled across every workspace on this instance, so the tenth person to try a model that failed nine times for other people does not have to find that out again.

What crosses is the model’s record. What never crosses is you: the repository name is replaced before the record is written, your workspace identifier is never written at all, and no part of your code, your goal or your conversation is included. A pooled record cannot be attributed back to a workspace, and it is deliberately built so that your own workspace’s experience always outranks the pooled one when ForgeOS chooses a model for you.

Stated as intent and evidence, not as a completed audit. As of 23 August 2026 there is an adversarial suite covering one workspace reaching another’s goals, conversations, exports, sessions, repositories and files, provider connections, spending limits and stored keys — including with a valid session of its own and the exact identifier of the thing it is asking for. That is evidence, not certification: no third party has audited it, and it is a suite we wrote about our own software. The tests live in the repository and the trust page reports what they cover.

5. Who else sees it

We intend to share your content only where the work requires it:

6. How long we keep it, and getting it back

While you use ForgeOS

Work records and the audit chain are retained so evidence for past work stays checkable.

Export

You can ask for your goals, work records and evidence in a machine-readable form.

Deletion

You can ask us to delete your content. Some audit records may be retained where deleting them would destroy the integrity of the append-only chain; we will tell you exactly which.

Backups

Deleted content persists in backups until those backups rotate out.

Deletion is now a real operation rather than a promise. Erasing a tenant refuses unless the tenant is closed and the request names it exactly, revokes sessions before removing anything, and writes a receipt recording what was destroyed. What it does not do is offer you a button: it is run by us, on request, and the receipt is what you get back. Export is still manual. Ask privacy@medina19.com and we will do it by hand. Saying that is more useful than showing you a button that does not work.

7. Your rights

Depending on where you are, you may have rights to access, correct, export, delete or restrict the processing of your personal data, and to object to it.

Not yet mapped to a specific regime. This draft does not name a lawful basis under the UK GDPR, EU GDPR, CCPA or any other regime, does not identify a data controller entity or representative, and does not list international transfer mechanisms. Those are exactly the parts that need a lawyer, and inventing them here would be the most misleading thing on this page. Write to privacy@medina19.com with a request and we will answer it directly in the meantime.

8. Security

Authority in ForgeOS is explicit and separately granted: reading a repository does not imply writing to it, writing does not imply deploying, and none of it implies access to customer data or spending. Every consequential decision is recorded with who made it and what they were shown. The controls the software actually enforces are described on the trust page and visible in the product.

To report a vulnerability, write to security@medina19.com.

9. Changes

When a reviewed policy replaces this draft, it will carry a date and say plainly that it is in force. We intend to tell customers before a material change takes effect rather than after.

Reviewing this?

If you are the lawyer, a customer's security team, or someone who has spotted something wrong, tell us. A draft that survives review unchanged was not read carefully enough.