Privacy & Security Statement.
Effective: 11 July 2026
1. We never train AI models on your data
Your uploads, your Digital Twin and your generated outputs are never used to train, fine-tune, or improve any AI model — ours or anyone else's. We use AI providers (Anthropic, and, if you select them, OpenAI and Google) exclusively through their commercial APIs, under terms that contractually prohibit training on content submitted through the API. If you select a provider whose terms we cannot back with this guarantee, we require you to use your own API key and tell you so in the product.
2. Three kinds of data — and how long each one lives
TwinForge handles your content in three deliberately different ways, and it is worth understanding the difference:
- Voice-training uploads (the writing you upload to build or update your Twin) are ephemeral. The raw file exists only long enough to be distilled into your Twin — typically minutes, never more than 24 hours — then it is automatically and irreversibly deleted. Deletion is enforced by our infrastructure at the end of every processing job (including failed jobs), with a scheduled sweep as a backstop. What remains is your Twin: a structured profile of how you think and write, not a copy of your source documents.
- Knowledge base content (documents you deliberately add as reference material, SOPs, or facts your Twin should look up) is retained, by design and with your consent, so it can be searched and cited when you generate. This is the intentional opposite of the ephemeral path above. The original uploaded file is still deleted immediately after processing; the extracted text chunks are the retained copy. You can view and delete any knowledge source at any time from the Knowledge page, which removes its stored content permanently.
- Data tables (structured business records you add — price lists, rate cards, catalogs) are retained like knowledge, for the same reason: your Twin quotes them exactly when you generate. They are commercially sensitive by nature, so note: rows relevant to a request are sent to your AI provider as part of that generation (see section 5), they are editable and deletable cell-by-cell or table-by-table from the Data page, and they are never used to train any model. The original uploaded file (PDF, spreadsheet) is deleted after the table is extracted; the table is the retained copy.
- Outbound action drafts and approvals (emails and calendar events your Twin drafts for a connected Google account, per section 10) are retained indefinitely as your record of what was proposed and what was actually sent or created — this is a permanent audit trail, not subject to automatic deletion, and it is not redacted the way automatically-ingested content is (see below), because it is content youchose to send. It can include personal information of people other than you — a recipient's email address, meeting attendees, or names and details you or your Twin included in the message — and by approving a send or calendar event you confirm you are authorised to disclose that information to those recipients. You can review this history at any time in Approvals, and it is deleted with your account.
Two smaller categories, for completeness: voice interview answers (the optional questionnaire) are retained so you can review and edit them at any time — they are folded into your Twin and deleted with your account; and automatically ingested content from connected accounts follows section 10 (relevance-filtered, PII-redacted before storage, deletable per connection).
We do not log the content of your uploads, chats, or generated outputs. For voice uploads we retain only filenames, cryptographic checksums, sizes and timestamps as a processing record.
3. Your Twin lives in a vault only you can open
Your Twin and your knowledge base are stored as isolated records protected by database-level row security: our own application code cannot read one customer's data while serving another. You can export your Twin as JSON, or permanently delete your account and everything in it, instantly, from Settings.
4. Bring your own key — inference under your agreement
If you supply your own AI provider API key, your Twin's requests go directly to that provider under your agreement with them. We store your key encrypted with AES-256-GCM, never display it again after entry, and use it solely to perform generations you initiate.
5. Where your data is processed (overseas disclosure)
TwinForge is operated from Australia, and we host our database and file storage in an Australian region. However, when you generate, chat, or build your Twin, the specific content needed for that request is sent to our AI processing providers — principally Anthropic, and OpenAI or Google if you select them — whose inference infrastructure is located outside Australia, primarily in the United States. By using the Service you consent to this overseas disclosure of your content for the sole purpose of producing the output you request. We disclose only what a request requires, under commercial API terms that prohibit training, and never sell or share your content for advertising or any unrelated purpose. If your organisation requires all processing to remain onshore, contact us before uploading regulated or client-confidential material.
6. Your rights under Australian privacy law
We handle personal information in line with the Australian Privacy Principles (APPs). You may request access to, or correction of, the personal information we hold about you; export your Twin and knowledge base in machine-readable form at any time; and delete your account and all associated data immediately from Settings, with residual backups purged within 30 days. If you have a privacy concern we cannot resolve, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
7. Minimal collection
We collect your account email, subscription status (via Stripe — we never see card numbers), and anonymous usage counts (token totals, not content). We use only essential cookies for authentication — no advertising trackers, no third-party analytics scripts, no tracking pixels in our emails. The full list of services that process data on our behalf is in section 12.
8. A draft tool, with you in the loop
TwinForge produces drafts for you to review, edit, and send. It does not make automated decisions with legal or similarly significant effects about you or anyone else, and it never sends, books, orders, or otherwise acts on your behalf without your explicit approval: every outbound action is drafted and held in an approval queue until a human releases it. You remain the author and decision-maker for every output. The full record of what was proposed and decided is retained as an audit trail — see section 2.
For completeness: routine service administration is automated — enforcing plan usage limits, screening sign-ups against disposable-email abuse, and sending you billing and lifecycle notifications. These are ordinary operational safeguards, not decisions made by profiling your content.
9. Teams and shared workspaces
If you join or create an organization, content you explicitly share with that organization (knowledge sources, data tables, skills) becomes visible to its members under that organization's administrators. Your personal Twin, and anything you do not share, remain private to you. Organization administrators can see an audit log of actions taken within the organization (who ran what, and what grounded it) for security and accountability. Removing yourself from an organization, or deleting it, reverts shared content to the uploader's personal space rather than destroying it.
10. Connected accounts (Gmail, Outlook, Google Drive, OneDrive)
Connecting an email or file account for ingestion (keeping your twin's knowledge current) is opt-in and uses read-only access — this connection can never send, modify, or delete anything in the connected account. When you connect one, we collect: encrypted access tokens (AES-256-GCM, revoked and deleted on disconnect), a decision record for every item scanned (title, source date, relevance verdict — visible to you in the decision log), and the content of items judged relevant, which is stored in your private knowledge base after personal identifiers are automatically redacted (email addresses, phone numbers, card and account numbers, TFNs, Medicare numbers are replaced with placeholders before storage — a redaction audit trail is kept). Items judged irrelevant are not stored; their content is processed transiently and discarded.
Separately, you may connect a Google account for actions — sending email or creating calendar events on your behalf. This is a distinct, separately consented connection (its own OAuth grant, its own encrypted tokens) that can send or create, but every send and every new event is queued in your Approvals inbox and only actually reaches Google after you review it and click Approve — nothing fires automatically, and this connection never reads or scans your mailbox or calendar beyond what you ask it to look up. Disconnecting revokes and deletes these tokens immediately, same as the read-only path.
AI processing on this path (relevance scoring, extraction) runs on the model API key you supply, under your agreement with that provider — see section 5. Your mailbox naturally contains information about other people; the redaction step exists to minimise what of theirs is retained, and by connecting an account you confirm you are authorised to grant that access. Disconnect any time in Train → Connected sources: tokens are deleted immediately (and revoked with Google), and you choose whether imported material is kept or purged.
TwinForge's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: Google user data is used only to provide the connected-ingestion feature you requested, is never used for advertising, and is never transferred except as necessary to provide the feature (to your own chosen AI model provider), for security, or to comply with law. Data received from Microsoft services is handled to the same standard.
11. Emails we send
We send service emails required to operate your account — billing, security, approvals you requested. Reminder emails (like a nudge to finish your voice interview) are optional and sent in line with the Spam Act 2003 (Cth): every one identifies us as the sender and carries a one-click unsubscribe that works without logging in and takes effect immediately. You can also manage reminder emails in Settings → Account. We use no tracking pixels.
12. Subprocessors & DPA
Our current subprocessors — the services that process personal information on our behalf — are: Vercel (application hosting), Supabase (database and file storage, Australian region), Stripe (payments), Resend (transactional and inbound email), and Anthropic (AI inference) — plus OpenAI and/or Google only where you select those models or where OpenAI embeddings index your knowledge base. Providers you connect with your own API key or your own MCP servers are governed by your agreement with them, not ours. Businesses that require a signed Data Processing Agreement can request one via the address below before uploading regulated or client-confidential material.
13. Contact
Privacy questions, DPA requests, or data-access/deletion requests: reply to any email from us or use the support address in your account.