Skip to content

Legal

Privacy Policy.

We built KnownForge for Salesforce teams that care about security. This policy explains exactly what data we collect, why, and how we protect it.

Last updated: October 2026.

01 / Policy

What we collect

What we collect
AccountName, work email, and company name when you sign up. We store no passwords — authentication runs through AWS Cognito.
Salesforce orgWhen you connect an org: the OAuth tokens needed to pull metadata, and the metadata itself (objects, fields, flows, Apex classes, permission sets, and 75+ other component types), stored in S3, logically separated per tenant.
Usage eventsPages visited, pipeline stages triggered, and deploy outcomes — used to operate and improve the product. No third-party analytics SDKs that phone home to ad networks.

02 / Policy

How we use your data

  • Exclusively for pipeline automation, metadata intelligence, and AI-assisted development.
  • We do not sell, rent, or share personal data for advertising or marketing.
  • Metadata powers dependency analysis, org health scoring, package building, and TDD generation. It is never used to train AI models.
  • Transactional emails only — invitations, password resets, deployment notifications. No marketing emails without your explicit opt-in.

03 / Policy

AI processing

  • Anthropic's Claude API generates technical design documents, code reviews, and tech-debt narratives.
  • Only the minimum necessary context is sent: the story description and relevant metadata summaries. Full raw metadata is never transmitted.
  • Structural summarization reduces metadata to the relevant signal before any AI call, cutting token cost and data exposure.

Anthropic's API data-handling policies apply — see anthropic.com/privacy.

04 / Policy

Data storage & security

Data storage & security
RegionAWS us-east-1 (N. Virginia).
IsolationMetadata is stored in S3, logically separated per tenant — no tenant can access another tenant's data.
EncryptionAES-256 at rest, TLS 1.2+ in transit.
SecretsOAuth tokens and API keys encrypted with industry-standard key management.
AccessProduction access restricted to engineers with a legitimate need.
AuditAudit log of all deployments and pipeline actions.

05 / Policy

Data retention

Data retention
Active accountsAccount and metadata data are retained while your account is active.
Account closurePersonal data and Salesforce metadata are purged within 30 days.
Pipeline audit logsDeploy records and validation results — component names and operation outcomes only, no record data — retained for up to 1 year.

06 / Policy

Third-party integrations

Third-party integrations
Salesforce · GitHub · Jira · LinearConnected via customer-provided OAuth tokens — stored encrypted, used only for actions you trigger.
AWS SESEmail delivery.
AWS Secrets ManagerCredential storage.
hCaptchaBot prevention.

Each service operates under its own privacy policy. No Facebook Pixel, Google Analytics, Mixpanel, or behavioral tracking SDKs on app.knownforge.com.

07 / Policy

Your rights

  • Access, correct, or delete your personal data by emailing privacy@knownforge.com — we respond within 30 days.
  • Disconnect any integration from your org Settings at any time; disconnecting revokes the stored token.
  • EU and UK residents have GDPR rights, including data portability and the right to lodge a complaint with a supervisory authority.

08 / Policy

Contact

Contact addresses
Privacyprivacy@knownforge.com
Security disclosuressecurity@knownforge.com
Legallegal@knownstandard.ai

KnownForge is operated by Known Standard LLC.