SUBFORGE / PRIVACY POLICY
Your account. Your data.
Updated 28 September 2026.
Operator and contact
Daniel Oosterom, trading as SubForge Studio, Willem de Goedestraat 11, 4431 BM, 's-Gravenpolder, Netherlands. Contact support@subforge.studio for privacy questions.
Website and local projects
The product website does not use advertising trackers or third-party analytics. Its interactive demo stores settings only in page memory. Demo exports are created locally. Desktop design files stay on your computer unless you choose to share them for support.
Accounts and licence verification
The account service processes your email, a password hash, verification status, licence purchases, update periods and session information to provide account access and verify software rights. The portal keeps its sign-in token in page memory rather than browser storage. Servers also receive technical request data such as IP address and requested URL for delivery and security.
Email and support
Verification and password-reset messages are sent through Hetzner-hosted email. Action links expire after 30 minutes. We process support messages and the information you choose to include to answer your request. Please avoid including passwords, payment card data or unnecessary personal information.
Payments
When you open checkout, Paddle processes payment and billing information under its own privacy notice. SubForge receives transaction identifiers, payment status and information needed to link your purchase to your account. We do not receive your full payment-card number. Paddle checkout may use its own cookies and technical storage.
Purpose and legal basis
Account delivery, licensing and support are necessary to provide the requested service or take steps before a contract. Security and abuse prevention are based on legitimate interests, subject to your rights. Records required by law are retained to meet legal obligations. Optional processing requiring consent will be identified separately.
Retention and recipients
Account and licence records are needed while your retained software rights remain available, and certain transaction records may need to be kept for legal obligations. Hetzner provides hosting and email; Paddle handles checkout. Access is restricted to those who need it to operate and support the service. Encrypted daily backups are retained for 35 days; old archives are removed only after a new backup passes integrity verification. Expired or used account-recovery message payloads are cleared by a maintenance job running every minute. Recovery metadata is removed 30 days after expiry. Support correspondence is kept for as long as needed to resolve your request, provide related support or establish and defend legal claims. Unneeded personal information can be removed on request, subject to legal obligations. The public web server does not keep a separate website-access log. Account-service diagnostic logs rotate by size (up to three 10 MB files per container), so their duration depends on activity. Security and operating-system logs are managed separately for service operation and incident investigation. Contact us for details about records relating to you.
Paddle processes purchase data as an independent controller and may transfer it internationally under the safeguards described in its privacy notice. Hosting and email are provided by Hetzner; see its privacy information. SubForge does not use advertising services or sell personal information.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or object to processing. Some records must be retained for legal obligations or to establish rights. Contact support to exercise your rights; you may also complain to your data-protection authority. We will not ask for your account password to handle a privacy request.
Launch status
This notice applies to the website and existing account service. Public registration and Live sales are not open. The payment section explains the planned Paddle checkout; visiting this website does not initiate a payment.
Try the demo