Legal
Privacy Policy
Effective August 29, 2026
01Who we are
Sky Forge Compute is operated by Starskold Advertisement - FZCO, registered in the United Arab Emirates (“Sky Forge”, “we”, “us”). This policy covers skyforgecompute.com and the Sky Forge console, and explains what personal data we handle when you browse the site or run GPU instances. We are the data controller for that data.
02Information we collect
We collect only what the service needs to function and to bill:
- Account data — your email address and a hashed password. We never store your password in readable form.
- Billing data — your billing name and address, and card details entered at checkout. Card numbers go directly to Stripe and never touch our servers; we retain only Stripe’s identifiers plus the card brand and last four digits. Billing address is collected for address verification and fraud screening.
- Instance and access data — the SSH public keys you register, API keys we issue, and the configuration and lifecycle of the instances you launch (model, GPU type, region, timestamps).
- Usage and metering data — instance runtime measured per second, and request metadata such as timestamps and response status, used to calculate what you owe.
- Support and sales data — the email address and message content you send us through forms on this site or by email.
- Technical data — IP address, browser type, pages viewed, and referring URL, collected automatically when you visit.
- Playground data — if you use the free public playground without an account, we log the prompt you send, the model you chose, and its length — not the completion — together with your IP address and a signed anonymous identifier cookie, both used to enforce the free-prompt limit. If you use the playground signed in, your prompts, the completions returned, and per-message token counts are stored with your account as conversations. Playground activity is logged for abuse prevention; see “What we do not collect” for how this differs from your private endpoints.
03What we do not collect
Two points worth stating plainly, because they are the ones customers ask about most:
- We do not log the contents of your inference requests. Traffic to your private endpoint is proxied straight through to your instance. Prompts, completions, and request bodies are not written to our logs — only opaque identifiers (instance ID, API key ID, request ID) and the metadata needed for billing and debugging. The free public playground is the one exception: playground prompts are logged for abuse prevention (for signed-in users, completions and token counts are stored with the account too), so do not put anything sensitive in a playground message.
- We do not use your data or your inference traffic to train models, and we do not sell personal data or share it with advertisers for their own purposes.
Data you place on an instance — files, datasets, model weights — lives on that instance and is under your control. It is destroyed when the instance is terminated.
04How we use your information
We use personal data to:
- provide, operate, and secure the service and your instances;
- meter usage, take payment, prevent fraud, and meet tax and accounting obligations;
- send transactional email about your account and instance lifecycle (launches, failures, terminations, receipts);
- respond to support and sales enquiries;
- diagnose errors and understand which parts of the site and product are used, so we can improve them.
Our legal bases, where the GDPR applies, are performance of a contract (operating the service and billing you), legitimate interests (security, fraud prevention, product improvement), consent (advertising cookies, where required), and legal obligation (financial records).
05Analytics and advertising
We use a small number of measurement tools on our public marketing pages and signup and login pages:
- Meta Pixel — provided by Meta Platforms. It reports page views, clicks on primary calls to action, form submissions, and successful signups, so we can measure which campaigns bring people who actually use the product. It sets cookies and shares your IP address and browser information with Meta, who may use it to show you ads and to build audiences. The pixel is loaded on our marketing pages and signup and login pages only — it is not present inside the authenticated console, so your instance activity, billing pages, and account pages are never reported to Meta.
- Google Tag Manager and Google Analytics — provided by Google. Tag Manager is a container that loads and configures our measurement tags, including Google Analytics, and it receives the same page view, call-to-action, form submission, and signup events described above. Tags deployed through it may set cookies and share your IP address and browser information with Google. Like the Meta Pixel, they load on our marketing pages and signup and login pages only, and are not present inside the authenticated console.
- Vercel Analytics — privacy-oriented traffic measurement for our own reporting.
- Sentry — captures application errors so we can fix them. Error reports may include your IP address and the page you were on.
You can limit advertising tracking through your Meta ad preferences, through Google’s ad settings, through browser controls such as blocking third-party cookies, or with a content blocker. Blocking any of these tools does not affect your ability to use Sky Forge.
06Service providers
We share personal data with providers who process it on our behalf, under contract and only for the purposes below:
- Stripe — payment processing, card storage, and fraud screening.
- Shadeform — sourcing and operating the GPU capacity your instances run on.
- Vercel — hosting for the website and console, and traffic analytics.
- Resend — delivery of transactional and notification email.
- Sentry — error monitoring.
- Cloudflare — bot and abuse screening (Turnstile) on the free playground and public forms. The Turnstile widget is served by Cloudflare and shares your browser information with them for that purpose.
- Meta Platforms and Google — advertising and traffic measurement, as described above.
We may also disclose data where we are legally required to, or to protect our rights, users, or the security of the service. If the business is sold or reorganised, account data may transfer as part of that transaction.
07International transfers
We operate from the United Arab Emirates and our providers operate in the United States, the European Union, and elsewhere. Your data will therefore be processed outside your home country, including in countries whose data protection laws differ from your own. Where the GDPR or UK GDPR applies, transfers are made under Standard Contractual Clauses or another approved safeguard.
08Retention
We keep account data for as long as your account is open. Billing and transaction records are kept for as long as tax and accounting law requires after the relevant transaction. Instance configuration and metering records are kept while needed for billing, dispute resolution, and capacity planning. Operational logs, including playground prompt logs, are kept on a rolling short-term basis; the anonymous playground quota identifiers (your IP address and the signed playground cookie) expire after 30 days; playground conversations saved to a signed-in account are kept while the account is open. When you close your account we delete or anonymise personal data that we are not required to retain.
09Security
Passwords are hashed, API keys and instance credentials are encrypted at rest, traffic is served over TLS, and access to production systems is limited to staff who need it. We have not obtained a third-party security certification, and we would rather say so than imply otherwise. No system is perfectly secure; you are responsible for keeping your password, API keys, and SSH private keys confidential.
10Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. If you are in the EEA or UK you also have the right to complain to your local supervisory authority.
If you are a California resident, you have the right to know what personal information we collect and to request its deletion, and the right not to be discriminated against for exercising those rights. We do not sell personal information; sharing with Meta and Google for advertising measurement may qualify as “sharing” under the CCPA, and you can opt out using the controls described above.
To exercise any of these, email legal@skyforgecompute.com. We may need to verify your identity before we act on a request.
11Children
Sky Forge is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
12Changes to this policy
We will update this policy as the service changes. The effective date at the top always reflects the current version, and we will notify account holders by email before a material change takes effect. Continued use after a change means you accept the updated policy. See also our Terms of Service.
Questions about this document? Email legal@skyforgecompute.com.