Privacy
Updated 27 August 2026
Documents
Uploaded PDF, DOCX and TXT files are read by code in your browser. Raw files, full extracted text and pages are not sent to OskForge or stored in its database. After a completed paid check, a sanitized report—passport fields, findings, quotes, warnings and file metadata without document contents—is kept for up to 24 hours in the current tab’s sessionStorage. A reload may restore it; closing the tab, clearing browser data, expiry or selecting Reset removes the copy.
Account data
The identity service provides OskForge with a verified email address, a technical account identifier and, when available, a profile name. OskForge stores these details to connect the account with access and purchases. OskForge does not receive passwords or full payment-card details.
Search and company analysis
Search terms, opportunity types and supported country filters are sent to official sources to run a search. If AI web discovery is enabled, the company description, keywords, selected markets, opportunity types and any optional budget filters are sent to OpenAI to search public pages. Those results remain suggestions linked to sources for the user to verify. When separate company-profile analysis is started, the URL and optional description are sent to the server; if OpenAI is enabled, they are used to create a draft profile, otherwise the server reads metadata from one public page. The profile remains a draft for the user to verify.
Search cache and infrastructure logs
For reliability, the server briefly stores normalized public-source results and a SHA-256 hash of normalized search parameters. A fresh result may be reused for up to 30 minutes; during a temporary source failure, a result no older than 24 hours may be shown; physical deletion occurs during the next cache-maintenance cycle. The CDN and hosting provider may keep operational IP-address and security logs under their policies; OskForge does not use them for advertising.
Cookies and campaign tags
Necessary authentication cookies may be used for sign-in. The osk_locale cookie keeps your selected language for up to one year. An infrastructure country header may suggest a language and starting settings. The current tab’s sessionStorage may keep the company profile you entered, filters and the latest shortlist for up to 6 hours so work can be restored after a reload; they are removed on explicit sign-out, tab close, browser-data clearing or expiry. To improve the product, OskForge records first-party events for page views, signup, checkout, search and document preflight; UTM tags are temporarily held in sessionStorage and may be sent with an event. Account and browser-session identifiers are HMAC-pseudonymized. Analytics does not store raw email addresses, IP addresses, full URLs, search text, company descriptions or document contents. The product reads and uses events for up to 90 days and short-lived request-rate counters for up to 2 days. To enforce plan limits and one-time entitlements, the technical account identifier and search-use count may remain while the account or relevant entitlement exists. Older records are excluded from analytics and product decisions; physical database cleanup runs during normal database activity and maintenance and may finish later. OskForge sets no advertising or analytics cookies, does not sell this data and does not share it for targeted advertising.
Support requests
When you send a support request, OskForge stores your account email or the reply address you provide, the selected topic, subject and message so the issue can be reviewed and answered. Support can view and use this data for up to 180 days. Older requests are hidden from the working inbox and no longer used; physical database cleanup runs during normal database activity and maintenance and may finish later. Do not send passwords, full card details or confidential tender documents.
Billing and payment data
When you pay through the hosted Dodo Payments checkout, Dodo Payments acts as Merchant of Record and processes the payment method, billing address and information required for taxes and billing documents. OskForge does not receive the full card number; it receives only identifiers and statuses needed to grant access, manage the plan and process a refund.