This Privacy Policy describes how CIAG Global, LLC, a Minnesota limited liability company ("Company," "we," "us"), collects, uses, and shares information in connection with the CIAG Quantum Forge hosted automation service (the "Service"). It supplements, and should be read together with, our Terms of Service. By using the Service, you agree to the collection and use of information as described here.
When you create an account, we collect your email address, a password (which we store only as a one-way hash — we never store or transmit your actual password), and the IP address you signed up from. We also record the fact and timestamp that you accepted our Terms of Service, tied to your account, so that acceptance is a verifiable record rather than just a client-side assumption.
When you submit an SOP, work on a draft, or compile an automation, we store that content — encrypted at rest with a key generated for your account — so you can return to it in a later session. Compiled manifests and in-progress drafts are kept in separate database tables from your account identity, referenced only by an internal, opaque identifier rather than a direct link to your email or password; this is a deliberate internal safeguard, though it does not change the fact that the content itself is retained. We do not use the content of your SOPs, drafts, or compiled scripts to train our own models or any third party's model.
Credentials or other secrets you enter for use during a session (the "Secrets" scope) are held only in an encrypted credential store scoped to that session's temporary, isolated execution environment. We do not write Secrets to our database. That store is destroyed when your session ends.
While an agent is running, the Service streams a live visual feed (screenshots or DOM snapshots of the interface being automated) to your browser so you can watch and intervene, and logs execution events (such as step progress, faults, and timing) for the duration of the session. This telemetry is transmitted to you live and is not separately retained by us once your session ends, except for the compliance and security logging described below.
SOP text and related prompts sent to our AI provider, and the structured responses it returns, are logged to a secure, append-only audit log on our own infrastructure, retained for recordkeeping and abuse-investigation purposes. This log exists so we can audit how an automation was synthesized if a dispute or incident arises; it is not used for any other purpose and is not shared except as described in Section 3.
The Service does not currently have a mechanism to purchase additional Quanta, so we do not currently collect payment card or billing information. If we introduce one, this Policy will be updated to describe it before it goes live.
For every session you run, we record the execution time used and the resulting Quanta cost, tied to your account. This is our usage ledger — it reflects what was debited from your balance, not the content of what you automated.
We log basic request metadata (such as IP address and timestamps) for security and anti-abuse purposes — for example, limiting how many accounts can be created from one IP address per day, and blocking known disposable-email signups. These operational logs are separate from the AI compliance log described above.
We do not sell your personal information. We share information only with the service providers below, each acting on our behalf to help operate the Service, or as required by law.
| Provider | Purpose | What it receives |
|---|---|---|
| OpenAI | AI-based synthesis of automation scripts from your SOPs | The SOP text and related prompts you submit, and the resulting output. Processed under OpenAI's API terms: not used to train OpenAI's models, but retained by OpenAI for a limited period for abuse-monitoring purposes under its own data usage policy. We do not currently have a zero- or reduced-retention agreement in place with OpenAI. |
| SendGrid (Twilio) | Sending account-verification and password-reset emails | Your email address and the content of those transactional emails only — we do not send marketing email through this channel. |
| Microsoft Azure | Application hosting and per-session execution environments (Azure App Service and Azure Container Apps Jobs) | All data described in Section 1, as our infrastructure and compute provider. Each hosted session runs inside its own temporary Azure Container Apps job instance, destroyed when the session ends. |
| Neon | Database hosting | Account, SOP, draft, compiled-script, and usage-ledger data described in Section 1. Located in the United States. |
We may also disclose information if required by law, subpoena, or other legal process, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of the Company, our users, or others.
Passwords are stored only as salted, one-way hashes — never in plain text, and never logged. SOPs, drafts, and compiled automation scripts are encrypted at rest using a key generated for your account. Vault Secrets are held only in an encrypted, session-scoped credential store, never in our database. Email-verification and password-reset links are single-use and stored server-side only as a one-way hash of the token. All traffic to the Service is encrypted in transit. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
The Service does not use advertising or analytics trackers. Your sign-in session is kept in your browser's local storage, solely to keep you logged in between visits — clearing it will sign you out.
The Service is not directed to, and we do not knowingly collect personal information from, anyone under 18 years old, consistent with the eligibility requirement in our Terms of Service. If you believe a minor has provided us with personal information, contact us at will@ciag-global.com and we will take appropriate steps to delete it.
The Service and the infrastructure it runs on are located in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those of your jurisdiction.
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice — such as by posting an updated effective date on this page, or emailing the address on your account. Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.
CIAG Global, LLC, a Minnesota limited liability company
Contact: will@ciag-global.com
Address: 330 S Second Ave, Suite 200 1900, Minneapolis, MN 55401