Clear about data. Clear about limits.
This is the shared privacy page for SendForge products. Use the product links below to jump to the policy section that applies to the product you are using.
July 18, 2026
Contact: [email protected] • [email protected]
Our products
SendForge is the umbrella brand. Different products may handle different categories of data depending on what the product does.
SendForge Messaging
The following section explains how SendForge Messaging handles account, delivery, consent, and service data.
Information we collect
- Account details such as name, email, and company.
- Billing metadata from payment processors.
- Messaging data required to deliver messages and track status.
- Technical usage data such as IP, browser, and device analytics.
How we use it
- Operate and improve the service.
- Deliver SMS and email messages.
- Enforce usage limits and prevent abuse.
- Comply with telecom, provider, and legal requirements.
Compliance safeguards
We may monitor complaint rates, opt-out activity, unusual sending behavior, and carrier requirements to protect the platform. We do not sell message content or use it for advertising.
Retention and sharing
We retain data only as long as necessary for service delivery and compliance. We may share data with hosting, telecom, email, payment, and legal service providers as needed to operate the platform.
TabForge
This section applies specifically to the TabForge browser extension and related TabForge product surfaces.
What TabForge stores
- Shortcut layout, pages, packs, and the current workspace are stored locally in the browser.
- When Private Sync is active, layouts, shortcuts, notes, and note images are automatically synchronized through a private Cloudflare Worker and private R2 storage so supported signed-in devices stay aligned.
- Permanent Pro without active Private Sync may keep one infrequent, overwrite-only layout recovery backup. It is not a general file-storage feature.
- Authentication state, a local access token, and a random device identifier/name are stored locally when the user signs in.
- SendForge stores account, billing, entitlement, and referral metadata, but TabForge workspace content is not written to the Render-hosted SendForge database.
How TabForge uses it
- Persist the user’s new-tab workspace across browser sessions.
- Restore shortcut pages, layouts, purchased access, and—while Private Sync is active—notes and images on supported devices.
- Verify account access and entitlements through the SendForge backend when the user signs in.
- Enforce device, request, file-type, daily-write, and account safety limits intended to prevent TabForge from being used as a general transfer service.
What TabForge does not do
- Does not send browsing activity to SendForge or Cloudflare. Trail Mode keeps a bounded navigation breadcrumb history only in this browser.
- Does not read page content from arbitrary websites.
- Does not track keystrokes.
- Does not sell user data.
- Does not load or execute remote hosted code.
Extension-specific handling
TabForge uses chrome.storage.local to store the current workspace configuration locally. If a user signs in,
login credentials are sent securely to the SendForge backend and a token is stored locally so the extension can
verify account access and purchased features. Automatic Private Sync content requests go to a Cloudflare Worker;
content objects are kept in a private Cloudflare R2 bucket and per-account coordination metadata is kept in a
Cloudflare Durable Object. The bucket has no public sharing URL.
Trail Mode is enabled by default and records local URL, page-title, favicon, transition, and branch information
so browser navigation and recently closed trails can be restored. It is bounded to 80 tracked tabs, 180 trail
nodes per tab, and 40 closed trails. Users can disable Trail Mode or clear its log from Hotkeys & Trail Mode.
Trail data stays in chrome.storage.local; it is excluded from layout backups, Private Sync, analytics,
advertising, and SendForge account storage.
Remote code and permissions
TabForge does not download and execute remote code. Executable extension logic is packaged with the extension. Network requests are used for account authentication, entitlement verification, billing/account actions, and—when eligible—automatic background recovery backup or Private Sync. Local saves continue even when the network is unavailable.
Sharing and retention
TabForge workspace data is primarily stored locally. Cloudflare processes eligible synchronized or recovery data only to operate TabForge; SendForge does not sell it or provide public sharing links. Canceling Private Sync stops live multi-device sync but does not delete permanent Pro or automatically erase retained sync data, so a later re-subscription can resume. A verified account-deletion request removes the account’s TabForge R2 objects and per-account coordination metadata within the deletion period stated on our Delete Account page, except records we must retain for billing, tax, fraud prevention, or legal compliance.