Privacy Policy
Last updated June 12, 2026
What Audit Forge collects, why, and who it is shared with. The short version: as little as possible — and your pasted code is not stored unless you publish it.
1. Overview
This policy explains what Audit Forge collects when you use auditforge.org, why, and who it is shared with. We aim to collect as little as possible.
2. What we collect
- Submitted content — the Solidity source you paste, the contract address you enter, or the GitHub repository/path you link, plus scan options.
- Network/technical data — your IP address and basic request metadata, used for rate-limiting, abuse prevention, and operational logging.
- Account data (only if you sign in) — your GitHub username, avatar, and email, via GitHub OAuth, plus a session cookie to keep you signed in.
- Cookies — a single session cookie when signed in. We do not use advertising or cross-site tracking cookies.
3. How we use it
- To run the requested analysis and produce your report;
- To generate the AI brief (see section 4);
- To enforce rate limits and protect the Service from abuse;
- To operate, debug, and improve the Service.
4. Third-party processors
To deliver the Service we share the minimum necessary data with:
- AI brief provider (Groq) — your reconciled findings and a portion of the submitted source are sent to generate the plain-English brief. If you consider your source sensitive, audit it privately rather than through this hosted Service.
- Block explorers (Etherscan, BscScan and equivalents) — only the contract address, when you audit by address, to fetch verified source.
- GitHub — only the repository and path, when you audit a repo, to fetch source; and for OAuth login if you sign in.
- Hosting — the Service runs on a dedicated server (Hetzner); data is processed there.
5. Data retention & publication
- Signed-in audits are published to the public registry by default. Before each scan you can switch off the "Publish to registry" toggle to keep that report private to your account. Published reports are stored so they remain accessible at their share link and in the registry.
- Anonymous audits are never auto-published, and pasted source from an anonymous scan is not retained beyond delivering your result.
- Operational logs containing IP/request metadata are short-lived and used only for security and debugging.
6. Security
Each analysis engine runs in an isolated, network-disabled, resource-capped sandbox. Traffic is served over TLS. No system is perfectly secure, but we apply industry-standard safeguards.
7. Your choices
You can use the Service anonymously (no account). If you sign in, you can sign out at any time. To request removal of a published report, contact us via the repository linked in the footer.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect their data.
9. Changes
We may update this policy; the "Last updated" date above reflects the latest version.
10. Contact
Privacy questions can be raised through the public source repository linked in the site footer.