Skip to content
MonkeyForge home
  • Workflow
  • Parallel agents
  • Local-first
  • Pricing
Open appGet MonkeyForge
Legal

Privacy Notice

What personal data the Operator processes when you use MonkeyForge, why, for how long, and what stays on your machine.

Effective 23 September 2026 · Version 1.2

1. Who is responsible

The controller of your personal data is the Operator named at the end of this notice. There is no data protection officer: the processing is small-scale, involves no special categories of data and no systematic monitoring. Questions and requests go to support@monkeyforge.dev.

2. What stays on your machine

MonkeyForge is a desktop app. Your projects, source code, prompts, agent conversations, terminal output, task board, ForgeContext memory, settings and the credentials of any agent or provider you use are stored on your computer and are not sent to us. The agents you run talk to their own providers (for example Anthropic or OpenAI) directly, under those providers' privacy terms, not through our servers. The only exceptions are the transient relay traffic described in section 3.4 and the optional crash reports in section 3.5.

3. What we process, why and for how long

3.1 Account

When you sign in with GitHub or Google we receive and store the e-mail address, display name, the provider's user id and whether the provider marked the e-mail as verified. We use this to create and secure your Account, to tie your License to it and to contact you about the Services. We also record which version of the Terms of Service and the Privacy Notice you accepted, and when, so that we can show it to you and prove it if we have to. Basis: performance of a contract (GDPR Art. 6(1)(b)). Kept while the Account exists and deleted within 30 days after you ask us to close it.

3.2 Sessions and security

For each sign-in we keep a session record with a device identifier, the browser or app user agent, the name, operating system and app version of the computer for desktop sign-ins, timestamps and the sign-in events that led to it. When you sign in, and again when a session is later used from a different IP address, we also record the approximate location of the IP address it came from — city, region and country — and a keyed hash of that address, which only tells us whether two requests came from the same address. The IP address itself is not stored in the session record. The location is looked up on our own server in the MaxMind GeoLite2 database; your IP address is not sent to MaxMind or anyone else for this. Such locations are approximate and are often wrong for mobile networks and VPNs. We use all this to keep you signed in, to detect stolen or reused tokens, and to show you where each of your sessions is so that you can recognise and revoke one that is not yours. Basis: legitimate interest in securing the Account (Art. 6(1)(f)). Expired and revoked sessions can no longer be used; session records and sign-in events are kept while the Account exists and are deleted or detached from you when the Account is closed.

3.3 Purchases and licenses

Purchases are processed by Paddle.com Market Ltd as Merchant of Record. Paddle collects your payment details, billing address and tax information and is the controller for that data under its own privacy policy. Card numbers never reach us. From Paddle we receive the transaction and customer identifiers, your e-mail and the outcome of the payment, which we store together with your License record and, later, subscription and invoice references. We also record in your account the time at which you accepted the Terms and the Refund Policy, which versions, and that you asked for immediate delivery; the time and the versions also travel on the payment transaction. Basis: performance of a contract (Art. 6(1)(b)) and our legal duty to keep accounting records (Art. 6(1)(c)). License and transaction records are kept for 10 years after the transaction, as Czech accounting and tax law requires.

3.4 Remote Mirroring

When you turn Remote Mirroring on, we store the names you give your machines and paired browsers, a public key for each paired browser and when each was last seen, so you can see and revoke them. Terminal output and keystrokes that you mirror pass through our relay in memory only, to move them from your desktop to your paired browser; they are not written to disk or logs. Basis: performance of a contract (Art. 6(1)(b)). Device records are deleted when you revoke the device or close the Account.

3.5 Crash reports (optional)

The App can send crash reports to Sentry (Functional Software, Inc., USA) so we can fix bugs. A report contains the stack trace, the App version, the operating system and a short trail of the App's own actions before the crash. It contains no IP address, no user identifier, no machine name, no prompts, no terminal output and no diffs; anything that looks like a secret or a path is removed before the report leaves your machine. Crash reports are on by default in release builds and you can turn them off in the App's settings at any time; the report is built to contain nothing that identifies you. Basis: legitimate interest in finding and fixing defects (Art. 6(1)(f)). Sentry keeps reports for 90 days. Transfers to the USA rely on the EU-US Data Privacy Framework.

3.6 Support

If you write to us we process what you send and your e-mail address to answer you. Basis: legitimate interest in handling your request (Art. 6(1)(f)). Kept for 3 years after the last message, in case the matter comes back.

3.7 Server logs

Our servers keep short request logs (path, status, timing, a request id and user agent, and the client address where it is needed for rate limiting and abuse prevention). Query strings, cookies and tokens are removed before logging. Basis: legitimate interest (Art. 6(1)(f)). Request logs are rotated and kept only as long as troubleshooting needs them; the log of downloads from the update feed is kept for 12 months for security purposes.

4. Cookies

The marketing site monkeyforge.dev sets no cookies and runs no analytics or tracking. The app at app.monkeyforge.dev sets two strictly necessary cookies, __Host-mb_refresh and __Host-mb_session, which keep you signed in. They are sent only to app.monkeyforge.dev itself, never to any other monkeyforge.dev address, and only over an encrypted connection; they need no consent under Article 5(3) of the ePrivacy Directive. The checkout page loads Paddle's checkout script, which may set Paddle's own cookies to run the payment; those are covered by Paddle's policy. There is no cookie banner because there is nothing to consent to.

5. Who else receives data

  • Hetzner Online GmbH, Germany — hosting of our servers and database (processor).
  • Paddle.com Market Ltd, United Kingdom — Merchant of Record for every purchase (independent controller).
  • GitHub, Inc. and Google Ireland Ltd — identity providers you choose to sign in with (independent controllers).
  • Functional Software, Inc. (Sentry), USA — crash reports, only if you keep them on (processor).
  • Our own mail server in the EU for support e-mail.

We do not sell personal data and we do not use it for advertising. We disclose data to authorities only where the law requires it.

6. Your rights

Under the GDPR you can ask for access to your data, for a copy in a machine-readable form, for correction, for deletion, for restriction of processing, and you can object to processing based on legitimate interest and withdraw consent at any time (which does not affect processing that happened before). Write to support@monkeyforge.dev; we answer within 30 days. Deleting your Account ends your License. You also have the right to complain to a supervisory authority; in the Czech Republic that is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, www.uoou.gov.cz).

7. Children

The Services are not directed at children. You must be at least 16 to create an Account.

8. Changes

We update this notice when the processing changes. Material changes are announced by e-mail or in the App before they take effect; the effective date at the top tells you which version you are reading.

Operator

MonkeyForge is operated by Adam Todt, a sole trader registered in the Czech Republic, IČO 19197438, with the registered address Drahy 1625, 696 42 Vracov, Czech Republic (the “Operator”, “we”). Not a VAT payer. Contact: support@monkeyforge.dev.

Also seeTerms of ServiceRefund Policy
MonkeyForge

Coding agents. Tasks. One local workspace.

© 2026 MonkeyForge
TermsPrivacyRefunds
Downloadsupport@monkeyforge.dev