ModeForge legal
Privacy Policy
This policy explains what ModeForge processes, why it is needed, where private media goes, and what remains after deletion.
- Effective
- 2026-08-09
- Operator
- ModeForge Demo (no production operator configured)
- Contact
- support@modeforge.invalid
Data we process
We process account and authentication details, project and asset metadata, generation settings, portrait-rights consent, credit-ledger events, billing references, security rate-limit keys, and audit events. Raw prompts and provider response bodies are excluded from audit metadata.
Uploaded portraits and garment or source images are inspected for MIME type, file magic, dimensions, and size before storage. Private objects are stored with an S3-compatible operator and exposed only through short-lived signed URLs.
Optional first-party measurement
ModeForge uses optional first-party measurement to understand conversion and generation quality. Browser measurement starts only after explicit consent. It uses a random first-party anonymous identifier for up to 30 days; it is not a fingerprint, is not a cross-site identifier, and is never stitched to an account identity.
Measurement attributes are a closed allowlist. They never contain a raw prompt, email, name, IP address, file name, object key, signed URL, media content, provider response, Stripe payload or secret, authentication token, or arbitrary free text. Server-owned account, Checkout, purchase, refund, and generation facts can be recorded only by their authoritative service boundary.
Processors and transfers
Stripe processes hosted Checkout, payment, subscription, refund, and dispute data. ModeForge does not collect full card details.
In production generation, OpenAI processes image and prompt requests, FASHN processes authorized portrait and garment inputs for try-on, and MiniMax processes a source image and motion prompt for video. Provider output is copied into ModeForge private storage before a job succeeds.
ModeForge gives FASHN 300-second signed input URLs and requests base64 output, which FASHN makes available for up to 60 minutes; FASHN request metadata may remain in its account history. OpenAI may retain API abuse-monitoring logs for up to 30 days unless approved retention controls apply. MiniMax and other processors apply their own provider retention terms; ModeForge deletion timers do not erase separate provider records.
Retention and deletion
Original portrait media expires after 24 hours. Generated results expire after 30 days. Uploads and provider results are registered for owner-scoped staged cleanup before object storage is written; successful asset adoption removes that record atomically. Unadopted objects remain in a durable cleanup queue. Scheduled maintenance physically deletes expired or unadopted objects before recording success, and retries failures until deletion is confirmed.
Account deletion first closes new project, asset, generation, and Checkout writes, waits for in-flight staged writes holding the account lock, then attempts to delete all owned asset and staged private objects. If storage deletion fails, the account remains deletion-in-progress and deletion must be retried; authentication and business rows are not anonymized until object deletion succeeds. Legally required billing records, security audit records, and the immutable credit ledger may remain; retained identity is anonymized and generation content is cleared.
Measurement events are retained for up to 90 days. The anonymous identifier expires after 30 days, the essential consent-preference cookie expires after 180 days, and a separate HttpOnly withdrawal capability expires after 120 days. The withdrawal capability is not used for tracking or event attribution; it exists only so retained events can still be deleted after the shorter anonymous identifier expires. These periods do not extend the separate media or provider retention periods above.
Your choices
You can reject optional measurement, change your preference, or withdraw consent. Withdrawal stops later browser measurement, clears the anonymous identifier, and deletes measurement events associated with the current anonymous identifier and signed-in account. Authenticated users can export their account data, including associated safe measurement records, delete individual assets, or request account deletion from the Credits page. Contact the configured service operator for privacy requests that cannot be completed in-product.