Legal
Privacy Policy
Last updated: August 2026
Version 2026-08-19
1. Who we are
DebtForge is operated by OP Solutions Ltd, a company registered in England and Wales (company number 17199394), registered office 1a Heartburn Walk, Newcastle NE3 3YU, United Kingdom. We provide an educational debt payoff toolkit to help individuals understand and manage their personal debt. Our registered contact is debtforge@opsols.net.
2. What data we collect
We collect only the data you provide directly:
- Account data: email address and password (stored via Supabase Auth).
- Financial data: income, outgoings, debt balances, APRs, and monthly payment entries you enter into the toolkit. This data is stored in our database and is associated with your account.
- Usage data: standard server logs (IP address, browser type, pages visited). Our public pages also load an advertising pixel — see §8. We use no third-party analytics or advertising code inside the toolkit itself.
We do not collect payment card details. Payments are processed by Stripe, who have their own Privacy Policy.
3. How we use your data
- To provide and operate the DebtForge toolkit.
- To send transactional emails (account confirmation, password reset, magic link sign-in).
- To send product updates if you opted in during signup (you can unsubscribe at any time).
- To comply with legal obligations.
We do not sell your data for money, and we never share your financial toolkit data with advertisers under any definition. We do not share your financial data with third parties except as described in Section 5.
One thing worth stating plainly: under some US state privacy laws, including California's, running an advertising pixel counts as "sharing" personal information for cross-context behavioural advertising, even though no money changes hands. We do run such a pixel on our public pages. Section 8 sets out exactly what it collects, where it runs, and how to switch it off.
4. Data storage and security
Your data is stored in a Supabase-managed PostgreSQL database hosted on AWS infrastructure in the United States. Data is encrypted at rest and in transit (TLS 1.2+). Access to your financial data is restricted to your account via Row-Level Security policies — no other user can read your data.
We implement reasonable technical and organisational measures to protect your data. No system is 100% secure; if you believe your account has been compromised, contact us immediately at debtforge@opsols.net.
5. Third-party services
We use the following sub-processors:
- Supabase — database and authentication hosting.
- Vercel — application hosting and edge delivery.
- Stripe — payment processing. Stripe does not receive your financial toolkit data.
- Resend — transactional email delivery.
- OpenAI — large-language-model inference for our optional AI-assisted features (see §6). We have OpenAI's training opt-out enabled, so your inputs are not used to train their models.
- Cloudflare — bot protection on our sign-in, signup and password-reset forms.
- Sentry — error monitoring, so we find out when something breaks. Data is stored in the European Union. Request bodies and cookies are stripped before an error report leaves our servers, and we do not attach your identity to reports, so error data does not include your debts, balances or account details.
- Upstash — a rate-limit counter that stops our AI features being abused. It holds only a usage count against your account identifier or IP address, and no other data.
- Madgicx — relays our advertising events (see §8) to Meta on our behalf. It handles no account or financial data.
- PostHog — product analytics and session recording on our public pages only (see §8). Data is stored in the United States. It handles no account or financial data.
Each sub-processor is contractually bound to process your data only as instructed and to maintain appropriate security standards.
Meta (Facebook and Instagram) is listed separately because it is not a sub-processor. We run the Meta Pixel on our public pages for advertising measurement (see §8), and Meta decides independently how it uses what the pixel collects — it does not act on our instructions. Meta receives no toolkit data: not your debts, balances, payments, or anything you enter while signed in.
6. AI-assisted features and bank statement uploads
DebtForge offers optional AI-assisted features (debt-entry suggestions, dashboard insights, spending audit extraction, and bank-statement auto-fill). These features call OpenAI on your behalf when you choose to use them. They are entirely optional — every tool also has a manual entry path.
Bank statement upload — two modes, your choice. When you upload a statement, you pick the processing mode:
- Smart scan (default). The PDF is processed in memory on our server. Account numbers, card numbers, routing numbers, names, addresses, phone numbers, email addresses, and tax IDs are stripped from the text by an automated redaction step. Only the redacted transactional content is sent to OpenAI for categorisation. We never send your full PDF or your identifying details to any third party in this mode.
- AI scan (opt-in).If Smart scan can't read your PDF (e.g. it's a scanned image), you can choose AI scan. In this mode your full PDF — including any name, address, or account number printed on it — is sent to OpenAI under their training opt-out, analysed by a vision-capable model, and then deleted from OpenAI immediately after processing. OpenAI may retain API inputs for up to 30 days for trust-and-safety review under their standard terms. AI scan is never the default; you have to actively switch to it, and a clear notice describes this trade-off before you upload.
No retention of uploaded files on our side. In both modes, the bank statement you upload is held in our server memory only for the duration of a single request. We do not save it to disk, to our database, or to any storage bucket. Once the request returns, the file is discarded. The structured numbers extracted from it are written to your account only after you review and click Save.
Other AI-assisted features. Debt-entry suggestions, dashboard insights, and spending-audit extraction call OpenAI on free-text input you provide. They never send your account email, profile data, or other debts to the model — only the text you type. They are entirely optional; every tool also has a manual entry path.
Usage logging.We record per-call metadata for each AI feature you use (timestamp, model, token counts, estimated cost) for rate-limiting and cost monitoring. We never log the prompt body or the AI's response — only the counts.
You can avoid AI features entirely by sticking to manual entry. Closing your account deletes the usage log along with the rest of your data.
7. Your rights
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what data we collect, the right to delete it, and the right to opt out of sale (we do not sell data). All users, regardless of location, may:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and all associated data (via Settings → Data → Delete my account, or by emailing us). At deletion, you may optionally tick a box to keep your email address on our marketing list for product updates; if you do not tick it, your email is permanently removed. You can unsubscribe at any time by emailing us.
- Export your data in a portable format (via Settings → Data → Export).
- Opt out of marketing emails at any time via the unsubscribe link in any email.
- Opt out of advertising — stop the pixel on our public pages from associating your visit with your Meta account. Section 8 explains how; it takes a browser setting or a content blocker, and the toolkit works normally without it.
To exercise any of these rights, email us at debtforge@opsols.net. We will respond within 30 days.
8. Cookies and advertising
Essential cookies. We set a session cookie required to keep you signed in. Our bot-protection provider may also set a short-lived cookie on the sign-in, signup and password-reset forms. Neither can be turned off — without them you cannot log in.
Advertising cookies, on public pages only. Our marketing pages, the quiz, and the login and signup pages load the Meta Pixel. It sets cookies including _fbp, and it tells Meta that a browser visited a particular page on our site. If that browser is also signed in to Facebook or Instagram, Meta can connect the visit to that account. We use this to measure whether our ads work and to reach people similar to those who find DebtForge useful.
Analytics and session recording, on public pages only. Those same public pages load PostHog, which we use to understand how people move through the site — which screens they reach, where they stop, and where something is confusing. PostHog sets cookies that let it recognise a returning browser. It also records a reconstruction of the visit: the pages you saw, how far you scrolled, and where you clicked, which we can play back like a video.
Recordings never contain anything you type. Every input field is masked in your browser before any data is sent, so your name, your email address and anything else you enter are not transmitted to PostHog and are not stored by it. We do not link recordings to your account, and we never ask PostHog to identify you — a recording is an anonymous session, not a named one.
None of this runs inside the toolkit. This is the part that matters most, so we want to be exact about it. Once you are signed in, your dashboard and every tool page — Snapshot, Priority Map, Payoff Sequence, Tracker, Cycle Breaker — load no advertising, analytics or session-recording code whatsoever. Nothing is recorded there. Meta and PostHog are never told that you have debts, how much you owe, what you pay, which tools you open, or that you signed in at all. That boundary is enforced in our application code, not by a setting we could forget to tick.
How to opt out. Block or clear cookies for this site in your browser settings, or use any content blocker — this stops both the pixel and the session recording, DebtForge works exactly the same either way, and we do not detect or penalise it. You can also limit how Meta uses this data from the ad preferences in your Facebook or Instagram account. If you would rather ask us directly, email debtforge@opsols.net.
Because we use advertising cookies, this page — not a pop-up banner — is where we disclose them. If we ever add cookies beyond those described here, we will update this section and the "Last updated" date above.
9. Children
DebtForge is not intended for users under the age of 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. How long we keep your data
We keep your data for as long as your account is open, and then delete it. We do not keep financial data indefinitely on the chance it might be useful later.
- Your account and toolkit data — kept while you use DebtForge. If you do not sign in for 24 months, your account and everything in it is permanently deleted. We email you 90 days beforehand, and signing in at any point resets the clock; nothing else is needed.
- Support tickets and their attachments — deleted 12 months after the ticket is closed.
- Bank statements you upload — never stored at all. See §6.
- If you delete your account yourself — everything goes immediately, without waiting for any of the above. See §7.
Two exceptions, both narrow. Stripe keeps the payment records it is legally required to keep, which we cannot delete on your behalf. And if you tick the optional box at deletion, we keep your email address alone for product updates until you ask us to remove it.
11. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of DebtForge after a change constitutes acceptance of the updated policy.
12. Governing law
This Privacy Policy is governed by the laws of England and Wales. By using DebtForge, you consent to the collection and use of your information as described in this policy. If you use DebtForge as a consumer, nothing in this policy limits any mandatory privacy or consumer protections you are entitled to under the laws of the country or state where you live.
13. Contact
Questions about this policy? Email us at debtforge@opsols.net.
