CIAG QUANTUM FORGE
// LEGAL

Privacy Policy

Effective date: October 6, 2026 · Service: CIAG Quantum Forge (hosted trial)
This Policy has not been reviewed by outside counsel. We publish it because the Service needs it to operate, and we'll update it as the Service and our legal review mature.

This Privacy Policy describes how CIAG Global, LLC, a Minnesota limited liability company ("Company," "we," "us"), collects, uses, and shares information in connection with the CIAG Quantum Forge hosted automation service (the "Service"). It supplements, and should be read together with, our Terms of Service. By using the Service, you agree to the collection and use of information as described here.

In short: unlike a simple extraction tool, Forge is designed to let you resume work — so your SOPs, in-progress drafts, and compiled automation scripts are stored, encrypted, in our database. Credentials you enter into the Vault during a session are held only in that session's temporary, isolated execution environment, never in our database, and are discarded when the session ends. The AI provider we use to synthesize scripts (OpenAI) briefly retains what it processes, under its own policy, for abuse-monitoring purposes only — not to train its models. Details below.

1. Information We Collect

Account & Signup Information

When you create an account, we collect your email address, a password (which we store only as a one-way hash — we never store or transmit your actual password), and the IP address you signed up from. We also record the fact and timestamp that you accepted our Terms of Service, tied to your account, so that acceptance is a verifiable record rather than just a client-side assumption.

SOPs, Drafts, and Compiled Scripts

When you submit an SOP, work on a draft, or compile an automation, we store that content — encrypted at rest with a key generated for your account — so you can return to it in a later session. Compiled manifests and in-progress drafts are kept in separate database tables from your account identity, referenced only by an internal, opaque identifier rather than a direct link to your email or password; this is a deliberate internal safeguard, though it does not change the fact that the content itself is retained. We do not use the content of your SOPs, drafts, or compiled scripts to train our own models or any third party's model.

Vault Secrets

Credentials or other secrets you enter for use during a session (the "Secrets" scope) are held only in an encrypted credential store scoped to that session's temporary, isolated execution environment. We do not write Secrets to our database. That store is destroyed when your session ends.

Live Execution Telemetry

While an agent is running, the Service streams a live visual feed (screenshots or DOM snapshots of the interface being automated) to your browser so you can watch and intervene, and logs execution events (such as step progress, faults, and timing) for the duration of the session. This telemetry is transmitted to you live and is not separately retained by us once your session ends, except for the compliance and security logging described below.

AI Synthesis & Compliance Logging

SOP text and related prompts sent to our AI provider, and the structured responses it returns, are logged to a secure, append-only audit log on our own infrastructure, retained for recordkeeping and abuse-investigation purposes. This log exists so we can audit how an automation was synthesized if a dispute or incident arises; it is not used for any other purpose and is not shared except as described in Section 3.

Payment Information

The Service does not currently have a mechanism to purchase additional Quanta, so we do not currently collect payment card or billing information. If we introduce one, this Policy will be updated to describe it before it goes live.

Usage & Billing Data

For every session you run, we record the execution time used and the resulting Quanta cost, tied to your account. This is our usage ledger — it reflects what was debited from your balance, not the content of what you automated.

Technical & Log Data

We log basic request metadata (such as IP address and timestamps) for security and anti-abuse purposes — for example, limiting how many accounts can be created from one IP address per day, and blocking known disposable-email signups. These operational logs are separate from the AI compliance log described above.

2. How We Use This Information

  1. To provide and operate the Service — authenticating you, synthesizing and running your automations, and billing Quanta against your balance;
  2. To let you save and resume SOPs, drafts, and compiled automations across sessions;
  3. To verify your email address and process password-reset requests;
  4. To detect and prevent fraud and abuse of the Service, including free-trial abuse, automated signups, and rate-limit circumvention;
  5. To maintain a record of your acceptance of our Terms of Service and to enforce those Terms; and
  6. To maintain, secure, and improve the Service.

3. How Information Is Shared

We do not sell your personal information. We share information only with the service providers below, each acting on our behalf to help operate the Service, or as required by law.

ProviderPurposeWhat it receives
OpenAIAI-based synthesis of automation scripts from your SOPsThe SOP text and related prompts you submit, and the resulting output. Processed under OpenAI's API terms: not used to train OpenAI's models, but retained by OpenAI for a limited period for abuse-monitoring purposes under its own data usage policy. We do not currently have a zero- or reduced-retention agreement in place with OpenAI.
SendGrid (Twilio)Sending account-verification and password-reset emailsYour email address and the content of those transactional emails only — we do not send marketing email through this channel.
Microsoft AzureApplication hosting and per-session execution environments (Azure App Service and Azure Container Apps Jobs)All data described in Section 1, as our infrastructure and compute provider. Each hosted session runs inside its own temporary Azure Container Apps job instance, destroyed when the session ends.
NeonDatabase hostingAccount, SOP, draft, compiled-script, and usage-ledger data described in Section 1. Located in the United States.

We may also disclose information if required by law, subpoena, or other legal process, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of the Company, our users, or others.

4. Data Retention

  1. SOPs, drafts, and compiled automation scripts are retained until you delete them or close your account, so you can resume work across sessions — see Section 1.
  2. Vault Secrets entered for a session are not retained by us at all once that session's temporary execution environment is destroyed.
  3. Live execution telemetry (the visual stream and step-by-step execution log) is not separately retained once your session ends, other than the AI compliance log described above.
  4. Account information is retained for as long as your account is active, and for a reasonable period afterward as needed for accounting, fraud-prevention, and legal-compliance purposes.
  5. The AI compliance audit log and the usage ledger are retained as ongoing records of how automations were synthesized and what was billed, consistent with standard recordkeeping practice.

5. Data Security

Passwords are stored only as salted, one-way hashes — never in plain text, and never logged. SOPs, drafts, and compiled automation scripts are encrypted at rest using a key generated for your account. Vault Secrets are held only in an encrypted, session-scoped credential store, never in our database. Email-verification and password-reset links are single-use and stored server-side only as a one-way hash of the token. All traffic to the Service is encrypted in transit. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

6. Cookies & Local Storage

The Service does not use advertising or analytics trackers. Your sign-in session is kept in your browser's local storage, solely to keep you logged in between visits — clearing it will sign you out.

7. Your Choices and Rights

  1. You can review and update your account information by logging in, or by emailing us at will@ciag-global.com.
  2. You may delete an individual SOP, draft, or compiled script yourself, or request deletion of your entire account and associated data by emailing will@ciag-global.com. Some records — such as the usage ledger, the AI compliance audit log, and the record of your Terms acceptance — may need to be retained even after account closure for legitimate accounting, fraud-prevention, or legal-compliance purposes.
  3. We do not currently send marketing email; the only emails the Service sends are transactional (signup verification, password reset, and similar account notices).

8. Children's Privacy

The Service is not directed to, and we do not knowingly collect personal information from, anyone under 18 years old, consistent with the eligibility requirement in our Terms of Service. If you believe a minor has provided us with personal information, contact us at will@ciag-global.com and we will take appropriate steps to delete it.

9. International Users

The Service and the infrastructure it runs on are located in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those of your jurisdiction.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice — such as by posting an updated effective date on this page, or emailing the address on your account. Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.

11. Contact

CIAG Global, LLC, a Minnesota limited liability company
Contact: will@ciag-global.com
Address: 330 S Second Ave, Suite 200 1900, Minneapolis, MN 55401