1. Who we are
Microforge is an independent microSaaS operation run by Roberto (Brazil), the party responsible for your data. Contact: roberto@microforge.app.
2. Data we collect
We collect only what's needed to run the services. This list is exhaustive — if it's not here, we don't collect it. Practice mode runs on fictitious money; an account is needed to use the product.
| Category | Data | When |
|---|---|---|
| Identification | Email address (and an optional display name) | When you create an account for paid features |
| Authentication | A unique user ID and a cryptographic password hash — we never see your plaintext password | Sign-up / sign-in |
| Usage | Bot settings, order and cycle history generated by using the product; preferences; last-access timestamps | While using a signed-in feature |
| Technical | IP address and browser user-agent, in server logs | Each request |
| Payment | Transaction metadata from Stripe (IDs, amount, date). Card number, CVV and expiry are handled entirely inside Stripe — never by us | When you purchase |
| Identification | Email address | When you request an invite (form on the home and Theta pages) |
| Profile | Approximate capital range and which exchange you use — multiple-choice answers, never an exact figure. Used to prioritise invite batches and size support | When you request an invite |
| Technical | A truncated hash of your IP (not the IP itself), only to rate-limit repeated requests and block bots. It does not identify you and is not cross-referenced with anything | When you request an invite |
| Analytics | Anonymous usage events. Google Analytics 4 (IP anonymized) and Microsoft Clarity (sensitive fields auto-masked). Both honor Do-Not-Track | Each visit |
Invite request — where that data lives
Since 22 Sep 2026 access to Theta is invite-only. What you type into that form (email, capital range, exchange) is written to a file on our own server in São Paulo, outside the public folder — it never goes through Formspree, Typeform, Mailchimp or any third-party tool, and it does not leave Brazil. It is not cross-referenced with analytics, does not feed a profile and is never sold. We use it for one thing: sending you the invite when the next batch opens.
Legal basis: consent — you chose to fill it in. To leave the list, just ask by email and we delete the record; there is no account or password involved.
3. How we use it
To run and authenticate your account, deliver paid features, send transactional email (receipts, account notices), provide support, prevent fraud and abuse, and meet legal/tax obligations. We do not use your data for third-party advertising or profiling.
4. We do not sell your data
Microforge does not sell or "share" your personal information (as those terms are used under the CCPA/CPRA), and never has. There is no opt-out to perform because there is no sale.
5. Sub-processors
Providers that process data on our behalf. Full, named list:
Hostinger (São Paulo, Brazil)
Hosting, database, and file storage. Data is stored in Brazil.
Stripe Payments
Payment processing and receipts. Card data is handled inside Stripe's PCI-DSS Level 1 environment; we have no access to it.
Google Workspace
Corporate email and transactional messages (account & receipt notifications) sent from the microforge.app domain.
Google Analytics 4
Aggregate, anonymized usage metrics. IP anonymized; no personal identifiers shared.
Microsoft Clarity
Heatmaps + session replay with sensitive fields auto-masked. Honors Do-Not-Track.
We never sell, rent, or share personal data with third parties for their own marketing.
6. Your rights
Wherever you are — and including the rights granted to California residents under the CCPA/CPRA — you may request:
- Know / access — what we hold about you.
- Delete — your personal data (legal/tax records excepted).
- Correct — inaccurate data.
- Portability — export your saved data.
- Opt out of “sale/share” — not applicable: we do not sell or share your data.
- Non-discrimination — exercising a right never degrades your service.
7. Retention, security & cookies
- Retention: while your account is active; personal data removed within ~30 days of deletion (minimal billing records kept as legally required).
- Security: TLS in transit, encryption at rest, cryptographic password hashing (bcrypt), optional MFA, least-privilege admin access.
- Cookies: strictly-necessary (preferences in
localStorage; auth/session where you use an account) and analytics —_gaand_ga_FYV5CZR3CH, set by Google Analytics 4 with IP anonymization and 14-month data retention. No third-party advertising cookies, no fingerprinting. Nothing loads before you accept: on your first visit a notice offers Decline and Accept as equally sized buttons, and until you choose, no third-party script runs and no analytics cookie is created. Browsing without choosing does not count as consent. Declining deletes any analytics cookies already set — it does not merely ignore them — and you can reopen the choice at any time from the Portuguese policy page. - International: data is hosted in Brazil (Hostinger, São Paulo) and processed by the sub-processors above; payments are processed by Stripe.
8. Changes & contact
We may update this policy; material changes get reasonable notice. Questions or requests: