Skip to content
ModeForge
StudioProjectsPricing
Credits简体中文Sign in

ModeForge legal

Privacy Policy

This policy explains what ModeForge processes, why it is needed, where private media goes, and what remains after deletion.

Effective
2026-09-22
Operator
ModeForge Demo (no production operator configured)
Contact
support@getmodeforge.com
Privacy PolicyTerms of ServiceCookie PolicyAcceptable Use Policy

Data we process

We process account and authentication details, project and asset metadata, generation settings, portrait-rights consent, credit-ledger events, billing references, security rate-limit keys, and audit events. Raw prompts and provider response bodies are excluded from audit metadata.

Uploaded portraits and garment or source images are inspected for MIME type, file magic, dimensions, and size before storage. Private objects are stored with an S3-compatible operator and exposed only through short-lived signed URLs.

Google Analytics and optional ModeForge measurement

Google Analytics 4 runs by default to understand conversion and page usage. ModeForge's separate first-party measurement starts only after explicit consent and uses a random first-party anonymous identifier for up to 30 days; it is not a fingerprint, is not a cross-site identifier, and is never stitched to an account identity.

ModeForge-controlled measurement attributes are a closed allowlist. They never contain a raw prompt, email, name, IP address, file name, object key, signed URL, media content, provider response, Stripe payload or secret, authentication token, or arbitrary free text. Server-owned account, Checkout, purchase, refund, and generation facts can be recorded only by their authoritative service boundary.

Google Analytics 4 runs by default and may receive the page URL and title, referrer, interaction and session data, and browser and device information. Google may use an IP address transiently to derive approximate location, but Google states that Analytics does not log or store individual IP addresses. This integration does not intentionally send prompts, uploaded media, contact details, or payment payloads to Google Analytics.

Processors and transfers

Stripe processes hosted Checkout, payment, subscription, refund, and dispute data. ModeForge does not collect full card details.

In production generation, OpenAI processes image and prompt requests, FASHN processes authorized portrait and garment inputs for try-on, and MiniMax processes a source image and motion prompt for video. Provider output is copied into ModeForge private storage before a job succeeds.

ModeForge gives FASHN 300-second signed input URLs and requests base64 output, which FASHN makes available for up to 60 minutes; FASHN request metadata may remain in its account history. OpenAI may retain API abuse-monitoring logs for up to 30 days unless approved retention controls apply. MiniMax and other processors apply their own provider retention terms; ModeForge deletion timers do not erase separate provider records.

Google processes Google Analytics 4 data under the deployment operator's Google Analytics configuration and Google data-processing terms. Analytics data may be processed outside the user's country subject to Google's transfer safeguards.

Retention and deletion

Original portrait media expires after 24 hours. Generated results expire after 30 days. Uploads and provider results are registered for owner-scoped staged cleanup before object storage is written; successful asset adoption removes that record atomically. Unadopted objects remain in a durable cleanup queue. Scheduled maintenance physically deletes expired or unadopted objects before recording success, and retries failures until deletion is confirmed.

Account deletion first closes new project, asset, generation, and Checkout writes, waits for in-flight staged writes holding the account lock, then attempts to delete all owned asset and staged private objects. If storage deletion fails, the account remains deletion-in-progress and deletion must be retried; authentication and business rows are not anonymized until object deletion succeeds. Legally required billing records, security audit records, and the immutable credit ledger may remain; retained identity is anonymized and generation content is cleared.

Measurement events are retained for up to 90 days. The anonymous identifier expires after 30 days, the essential consent-preference cookie expires after 180 days, and a separate HttpOnly withdrawal capability expires after 120 days. The withdrawal capability is not used for tracking or event attribution; it exists only so retained events can still be deleted after the shorter anonymous identifier expires. These periods do not extend the separate media or provider retention periods above.

Google Analytics event retention is controlled in the linked GA4 property. Google Analytics identifiers such as _ga can remain in the browser for up to two years after their last update unless they expire sooner, are removed by the user, or are deleted by browser controls.

Your choices

You can reject optional ModeForge measurement, change that preference, or withdraw its consent. Withdrawal stops later ModeForge browser measurement, clears ModeForge's anonymous identifier, and deletes ModeForge measurement events associated with the current anonymous identifier and signed-in account. It does not disable Google Analytics, which runs by default, or erase data already received by Google. A Google Analytics rejection recorded before this policy version remains honored in that browser for 180 days. Authenticated users can export their account data, including associated safe ModeForge measurement records, delete individual assets, or request account deletion from the Credits page. Contact the configured service operator for privacy requests that cannot be completed in-product.

ModeForge
Prompt LibraryBlog
Privacy PolicyTerms of ServiceCookie PolicyAcceptable Use Policy