Privacy Policy
Last updated 28 September 2026
This is a plain description of what Forgeboard collects, why, who sees it, how long it is kept and how to have it deleted. It applies to the web app, the iOS and Android apps, and the public pages a workspace publishes.
1. Who we are and what this covers
Forgeboard is a software project and delivery management workspace, operated by Sedin Technologies (“we”, “us”). This policy covers the Forgeboard web application, the Forgeboard apps for iOS and Android, and the public pages a workspace can publish from it. It applies to three kinds of people:
- Members — people with an account who use Forgeboard as part of a workspace their organisation runs.
- Requesters and visitors — people without an account who interact with a workspace through a public surface, such as a request form, an incident link or a survey.
- Workspace owners — the organisation that created the workspace and decides what it is used for.
For account data — your name, email address, credentials and devices — Sedin Technologies is the data controller. For the content a workspace holds about its own customers and users, the workspace owner is the controller and we process that content on their instructions. If your organisation runs its own installation of Forgeboard, that organisation operates it and this policy applies as far as it describes what the software does.
2. Data we collect
Account and profile
- Name, email address and, if you upload one, a profile picture.
- A password, stored only as a salted hash. If you sign in with Google or GitHub we receive your name, email address and an identifier from that provider, and never your password.
- If you turn on two-factor authentication: the secret that generates your codes (stored encrypted) and your backup codes (stored hashed).
- Your role and membership in each workspace, and which workspace you last used.
Workspace content
Everything members create inside a workspace. In Forgeboard that is:
- issues, epics, stories, tasks and bugs, and everything written on them
- comments, checklists, estimates and worklogs
- attachments, files and documents
- sprints, releases, roadmaps and objectives
- whiteboards, mind maps and retrospectives
- team chat messages and reactions
Content can contain personal data about other people — a customer’s name in a ticket, an email address in a comment. The workspace owner decides what is entered and is responsible for having a lawful basis to hold it.
Information from people who are not members
A workspace can publish surfaces that collect information from requesters and visitors:
- public forms, where a submitter gives a name, an email address and the details of their request
- shared documents and the public roadmap, which are read-only and collect nothing beyond ordinary server logs
Devices, sessions and technical data
- For each sign-in: a session record with the time, the IP address and the browser or app it came from, so you can see and revoke your sessions from your account settings.
- For each phone that turns on notifications: a push token, the platform (iOS or Android) and the app version, so we can deliver notifications and stop trying when a device is gone.
- An audit log of security-relevant actions in a workspace (sign-ins, permission changes, exports, deletions) with the actor, time, IP address and user agent. Workspace administrators can read it.
- Server logs and rate-limit counters keyed by IP address, kept briefly to keep the service running and secure.
What the mobile apps access on your phone
- Camera and photo library — only when you choose to attach a photo or set a profile picture. Nothing is read from your library otherwise.
- Notifications — to deliver the alerts you turn on.
- Face ID, Touch ID or fingerprint — to unlock the app. The check happens on the device; no biometric data leaves it or reaches us.
- Secure storage — your sign-in token is kept in the platform keychain or keystore and a cache of recently viewed work is kept on the device so the app works offline. Both are cleared when you sign out.
The apps do not access your location, contacts or calendar, and contain no advertising, analytics or tracking SDK. They talk only to your Forgeboard server.
3. How we use it
- To provide the service: authenticate you, show your workspace, route requests, send the notifications you enable.
- To run the plans a workspace sets up — sprint, release and objective progress is computed from issue data.
- To keep the service secure: detect abuse, rate-limit, investigate incidents, and let you review your sessions.
- To support you when you contact us, and to tell you about changes to the service or to this policy.
- To produce the reports and dashboards a workspace asks for, computed from its own content.
We do not sell personal data, use it for advertising, or build profiles of you across services. Where a legal basis is required (for example under the GDPR), we rely on the performance of our contract with you or your organisation, our legitimate interest in running a secure and reliable service, and your consent where we ask for it (such as for notifications on your phone).
4. AI features
A workspace may turn on assistance features — summaries, suggested replies, classification — powered by a language-model provider that the workspace administrator chooses and configures (currently Anthropic, OpenAI or OpenRouter). When you use one of these features, the text you are working on is sent to that provider to produce the result and is handled under that provider’s terms. Nothing is sent when the feature is off or not used, and we do not use your content to train models.
6. How long we keep it
- Account data is kept while your account exists and deleted when the account is deleted (see below).
- Workspace content is kept for as long as the workspace keeps it. Workspace administrators can set retention rules that archive or delete records after a chosen number of days, and can delete a workspace entirely.
- Sessions expire on their own and are removed when they do or when you revoke them.
- Push tokens are removed when you sign out on that device or when the platform reports the device is gone.
- Audit logs are kept for the life of the workspace, because they exist to answer later questions about what happened.
- Backups are kept for up to 30 days and then overwritten, so deleted data can persist in a backup for that long.
7. How we protect it
- All traffic between your browser or phone and the service is encrypted in transit.
- Passwords are salted and hashed; two-factor secrets and connected-service credentials are encrypted at rest.
- Access inside a workspace is governed by roles and permissions the workspace sets, and security-relevant actions are audited.
- Sessions can be listed and revoked by their owner; administrators can enforce two-factor authentication.
- Uploads are size-limited, stored outside the web root and served only to people the workspace allows.
No system is perfectly secure. If we learn of a breach affecting your personal data we will tell the affected workspaces and, where the law requires, you and the relevant authority, without undue delay.
8. Your rights and choices
Depending on where you live you may have the right to:
- Access the personal data we hold about you, and receive a copy in a portable form.
- Correct it — your name, email address and picture can be changed from your account settings.
- Delete it — see Delete your account.
- Object to or restrict processing, and withdraw consent where processing relies on it — notifications can be turned off in the app or on your phone at any time.
- Complain to your local data-protection authority.
To exercise a right, email support@sedintechnologies.com from the address on your account. We answer within 30 days. If your request concerns content held by a workspace about you as a customer or requester, we will pass it to the workspace owner, who controls that content, and help them respond.
9. Deleting your account
You can have your account and its personal data deleted at any time. The full procedure, what is removed and what a workspace keeps is on the Delete your account page. In short: email support@sedintechnologies.com from your account’s address, we confirm it is you, and the account is deleted within 30 days.
10. Children
Forgeboard is a workplace tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
11. International transfers
Your data is stored where the service is hosted and may be processed in other countries by the providers listed above. Where data leaves the jurisdiction it was collected in, we rely on the safeguards that jurisdiction recognises, such as standard contractual clauses, and on the providers’ own commitments.
12. Changes to this policy
When we change this policy we update the date at the top. For a change that affects your rights or what we collect, we also tell workspace administrators by email or a notice in the product before it takes effect.
13. Contact
Privacy questions and requests: support@sedintechnologies.com
Support: support@sedintechnologies.com
Sedin Technologies