Privacy Policy

Last updated: 7 August 2026

This policy describes the Forenta public beta as it works today. It covers the website, accounts, Forge, Flux, workspaces, organization projects, matching, billing preparation and optional avatar generation.

1. Who is responsible

Studio Northstar B.V., registered with the Dutch Chamber of Commerce under number 42094999 and based in The Hague, is the controller for Forenta. You can reach us at privacy@forenta.tech. We process personal data to provide the service, protect the platform, meet legal duties and, where required, on the basis of your consent.

2. Data we process

Account and profile data can include your name, email address, profile text, skills, location, availability, portfolio links and visibility settings. Supabase handles authentication; Forenta does not receive your plain-text password. We also process the content you choose to add to Forge, Flux, projects, workspaces, messages, feedback and support requests. Technical records can include IP address, request time, browser information, security events and rate-limit identifiers. If you use billing, we store subscription and transaction references, not full card details. If you use avatar generation, we process the source image, prompt and generated result.

3. Why we use it

We use this data to create and secure your account, run analyses, keep project workspaces available, match profiles, calculate credits and Signal Score, process support requests and prepare or administer subscriptions. The usual legal bases are performance of the agreement, our legitimate interest in operating and protecting Forenta, compliance with legal duties and consent where the law requires it. Signal Score and matching support discovery; they do not make a binding employment, credit or access decision.

4. Providers and international processing

Forenta uses Supabase for authentication, database and storage, Vercel for application hosting, Anthropic for Forge and Flux, fal.ai for optional avatar generation, Mollie when payments are enabled and email providers for service messages. Core application data is intended for an EU Supabase region. AI providers may process input in the United States. We use the provider terms and transfer safeguards that apply to the service and review these before production use. Do not submit passwords, API keys or special-category personal data to an AI feature. The voice input button is a separate route. It uses the speech recognition built into your browser (the Web Speech API), so your browser performs the recognition. Some browsers do this on the browser vendor's servers: Chrome sends the audio to Google. That processing takes place between you and your browser vendor, under their terms, and Forenta is not the controller for it and does not engage that vendor as a processor. Forenta receives no audio, only the text you keep in the field. If your browser does not support the API, the button does not appear and no alternative recording route runs.

5. AI input and output

Forenta sends the input needed for a requested Forge or Flux result to Anthropic's commercial API. Forenta does not train its own models on Forge, Flux or workspace content. Anthropic states that commercial API input and output are not used for model training by default and are normally deleted from its backend within 30 days, subject to its contractual, safety and legal exceptions. AI output can be wrong or incomplete. Review important conclusions before you act on them.

6. Visibility and access

Your profile visibility setting controls whether a profile is public, limited to members or private. Public profiles may appear in public discovery. Members-only information requires an account. Private organization and workspace data is limited through membership, roles and database access rules. Turning off public visibility removes the profile from public discovery, but content already shared with project participants remains available where collaboration requires it.

7. Your controls and rights

From Settings you can edit profile visibility, download a machine-readable export and request account deletion. You may also ask us for access, correction, deletion, restriction, portability or an objection to processing. Email privacy@forenta.tech. We normally respond within one month. A complex request can take longer where the GDPR allows this; we will tell you within the first month. You can complain to the Dutch Data Protection Authority.

8. Retention and deletion

We keep active account and project data while the account or collaboration is in use. Account deletion removes the account data covered by the deletion flow and attempts to remove authentication and stored avatar files. Some records may remain where another participant needs the shared project history, where a provider backup has not yet expired or where the law requires retention. Dutch financial administration is generally kept for seven years. Anthropic applies its own API retention rules. We do not promise immediate deletion from every provider backup.

9. Cookies and security

Forenta currently uses necessary authentication cookies and stores your cookie-notice choice. No external analytics service is connected in this release. We use measures including session-based identity checks, role-based and row-level access controls, encrypted transport, hashed invitation and rate-limit identifiers, request limits, private upload storage and security logging. These measures reduce risk; no online service can guarantee absolute security.

10. Contact and changes

Send privacy questions to privacy@forenta.tech and security reports to security@forenta.tech. Our postal location is The Hague, the Netherlands. We update this policy when the product, providers or legal requirements change. Material changes will be dated here and communicated in the product where appropriate.