Legal
Privacy Policy.
We built KnownForge for Salesforce teams that care about security. This policy explains exactly what data we collect, why, and how we protect it.
Last updated: October 2026.
01 / Policy
What we collect
| Account | Name, work email, and company name when you sign up. We store no passwords — authentication runs through AWS Cognito. |
|---|---|
| Salesforce org | When you connect an org: the OAuth tokens needed to pull metadata, and the metadata itself (objects, fields, flows, Apex classes, permission sets, and 75+ other component types), stored in S3, logically separated per tenant. |
| Usage events | Pages visited, pipeline stages triggered, and deploy outcomes — used to operate and improve the product. No third-party analytics SDKs that phone home to ad networks. |
02 / Policy
How we use your data
- Exclusively for pipeline automation, metadata intelligence, and AI-assisted development.
- We do not sell, rent, or share personal data for advertising or marketing.
- Metadata powers dependency analysis, org health scoring, package building, and TDD generation. It is never used to train AI models.
- Transactional emails only — invitations, password resets, deployment notifications. No marketing emails without your explicit opt-in.
03 / Policy
AI processing
- Anthropic's Claude API generates technical design documents, code reviews, and tech-debt narratives.
- Only the minimum necessary context is sent: the story description and relevant metadata summaries. Full raw metadata is never transmitted.
- Structural summarization reduces metadata to the relevant signal before any AI call, cutting token cost and data exposure.
Anthropic's API data-handling policies apply — see anthropic.com/privacy.
04 / Policy
Data storage & security
| Region | AWS us-east-1 (N. Virginia). |
|---|---|
| Isolation | Metadata is stored in S3, logically separated per tenant — no tenant can access another tenant's data. |
| Encryption | AES-256 at rest, TLS 1.2+ in transit. |
| Secrets | OAuth tokens and API keys encrypted with industry-standard key management. |
| Access | Production access restricted to engineers with a legitimate need. |
| Audit | Audit log of all deployments and pipeline actions. |
05 / Policy
Data retention
| Active accounts | Account and metadata data are retained while your account is active. |
|---|---|
| Account closure | Personal data and Salesforce metadata are purged within 30 days. |
| Pipeline audit logs | Deploy records and validation results — component names and operation outcomes only, no record data — retained for up to 1 year. |
06 / Policy
Third-party integrations
| Salesforce · GitHub · Jira · Linear | Connected via customer-provided OAuth tokens — stored encrypted, used only for actions you trigger. |
|---|---|
| AWS SES | Email delivery. |
| AWS Secrets Manager | Credential storage. |
| hCaptcha | Bot prevention. |
Each service operates under its own privacy policy. No Facebook Pixel, Google Analytics, Mixpanel, or behavioral tracking SDKs on app.knownforge.com.
07 / Policy
Your rights
- Access, correct, or delete your personal data by emailing privacy@knownforge.com — we respond within 30 days.
- Disconnect any integration from your org Settings at any time; disconnecting revokes the stored token.
- EU and UK residents have GDPR rights, including data portability and the right to lodge a complaint with a supervisory authority.
08 / Policy
Contact
| Privacy | privacy@knownforge.com |
|---|---|
| Security disclosures | security@knownforge.com |
| Legal | legal@knownstandard.ai |
KnownForge is operated by Known Standard LLC.