Privacy Policy
Last updated 6 October 2026
1. Who we are
This website (avakode.com), the Forge Suite plugins (Lang Forge, Rank Forge, Form Forge, Field Forge, Guard Forge, Velocity Forge, Draft Forge, Flow Forge, Clearway Forge, Profit Forge, Inclusive Forge and Renew Forge) and their product websites are operated by:
Tigran Avakov, a self-employed individual, Mirzo-Ulugbek 45A, 100007 Tashkent, Uzbekistan
Contact: [email protected]
Throughout this document, “Avakode”, “we”, “us”, and “our” refer to the above entity.
2. Scope of this policy
This policy describes how we collect, use, store, and share personal data when you:
- Visit avakode.com or any plugin-specific website we operate
- Create an Avakode account
- Purchase a Forge Suite license
- Use any Forge Suite plugin on your WordPress site
- Contact us for support or any other reason
It does not cover the data your own WordPress site collects from its visitors — that’s governed by your own privacy policy, since the plugins store that data in your own database, not ours. (Inclusive Forge, a hosted service, keeps its scan results on our infrastructure; its own page says what it stores.)
3. What data we collect
3.1 Account data
When you create an account, we collect: your name, email address, hashed password, and (optionally) your company name and billing country.
3.2 Payment data
Payments are processed by our merchant of record, Paddle: Paddle.com Inc. for buyers in the United States, Paddle.com (Canada) Ltd. in Canada and Paddle.com Market Limited in all other countries. We do not store your full card number, CVV, or bank account details on our servers. Paddle sends us a transaction ID, the amount, the billing country, your email address and the products purchased. Purchases made before September 2026 were processed by Freemius Inc., which shared the same fields. Paddle is an independent controller of the data it collects to take your payment; Paddle’s privacy notice applies to it.
3.3 License and site data
When you activate a Forge Suite plugin on a WordPress site, we record: the site’s domain, the plugin version, the WordPress version, and the license key used. This is a standard license-verification handshake and runs once per day per site.
3.4 AI request data
When you use an AI feature in any Forge Suite plugin, the request is sent to our backend (api.avakode.com) which then forwards it to the underlying AI provider. We log: the type of AI operation (e.g., “translate post”, “generate meta”), the number of credits consumed, and a timestamp. We do not log the content of your prompts or the AI’s responses.
3.5 Integration tokens
When you connect a third-party service (Mailchimp, Google Sheets, Google Calendar, HubSpot), the OAuth tokens or API keys are stored in our backend (Cloudflare D1 database) rather than in your WordPress installation. This keeps sensitive credentials off your server. Tokens are stored encrypted at rest.
3.6 Support and communication data
When you write to [email protected] or submit a contact form, we store the full content of your message, your email address, and any attachments — so we can respond, resolve the issue, and reference the history on follow-ups.
3.7 Technical data
Standard web-server logs: IP address, browser user-agent, pages visited, timestamps. Used for security, debugging, and abuse detection.
Logs of our API. Our API runs on Cloudflare Workers. We have switched off the log of each request that Cloudflare Workers can keep for us. What is logged is the lines our own code writes about events in the API and the exceptions of the Worker. Each line has a time, a level, an event name, a request identifier and a few facts, such as an HTTP status, a product name or a numeric account or license number; a line about an unexpected failure also holds the method and the path of the request, without its query string, and the technical error text. The logs are kept for 7 days in Cloudflare’s dashboard and 30 days in a copy in our own storage (Cloudflare R2). Some of the lines hold personal data:
- Phone numbers. The lines about WhatsApp messages (a message accepted, its delivery reported or failed, a number connected or refused) hold the phone number of the recipient or the sender, and the address of the customer’s website.
- IP addresses. The lines about a failed human check (Cloudflare Turnstile), a rejected trial token (with the website domain the plugin reported), a failed administrator sign-in, or a call to our Telegram webhook with a wrong secret (with the first 100 characters of the caller’s User-Agent) hold the caller’s IP address.
- Email addresses. The lines about email that our API sends through Resend (sent, failed, or held back as a repeat) hold the address of the recipient; the line about a repeat also holds the subject.
- Website addresses. When a customer’s website exchanges a one-time connection token with our API, the line holds the website address and the first ten characters of the token.
- Answers of outside services. When an outside service (email, payments, messaging, a license or an AI provider) reports an error, the line holds up to a few hundred characters of its answer; for an AI provider, the answer can repeat words of the request.
Error monitoring (Sentry). We use Sentry, a service of Functional Software, Inc. in the United States, where our Sentry data is stored, to find and fix faults in our API. An error record is sent when a scheduled job fails or a request fails in a way our own error handling does not catch; it holds the error message and its technical stack trace, and either the name and schedule of the job or the method, the address and four headers (Content-Type, Content-Length, Accept and Origin) of the request. A performance trace is sent for about one request or scheduled job in ten; it holds the method (or the schedule), the address, the response status, the timing, the outside services called and the same four headers. Before anything is sent, our API removes the query string from every address and replaces with “[redacted]” any part of an address that looks like a UUID, an IP address, an email address or a long random token, the identifier of a purchase session, and the identifiers of customers’ calendars, sites and spreadsheets in the addresses of the outside services it calls; it does the same with web addresses, email addresses, IP addresses, UUIDs, bot tokens and product keys found in an error message. Our API does not send Sentry query strings, request bodies, cookies, credentials, your IP address, your browser identification (User-Agent), your country, time zone or language, user accounts or the lines of our API’s logs. Sentry itself may add an approximate place to a record, derived from the address of the Cloudflare server that ran our API, not from yours; Sentry is set not to store that address.
3.8 Cookies, analytics and advertising measurement
We use strictly-necessary cookies for authentication and security, and a small set of first-party cookies for remembering your preferences — including your cookie choice, kept in a cookie called forge_consent for about six months. Our websites also load these third-party tags and scripts:
- Meta Pixel (every Avakode and Forge Suite website): records page views and, when you click a link to download a free plugin, a
PluginDownloadevent that names the plugin and the page you were on. Meta receives your IP address, browser details and its own cookies (_fbp,_fbc). - Google Tag Manager with Google Analytics and Google Ads (langforgewp.com): traffic and advertising measurement.
- Cloudflare Web Analytics (langforgewp.com): counts page views and measures how fast our pages load, without cookies and without building a profile of you; Cloudflare does not use your IP address or browser details to identify you for this. Cloudflare adds this script to our pages itself.
When they load. If your browser reports a European time zone, or one we cannot place, such as UTC, the Meta and Google tags are not loaded and no analytics or advertising cookie is set until you choose “Accept all” in the cookie banner; if you choose “Reject”, they stay unloaded. Elsewhere the Meta and Google tags load when a page opens, and you can switch them off at any time with “Cookie settings” in the footer of every page. Cloudflare Web Analytics does not wait for your choice: it sets no cookie and builds no profile of you. The plugins themselves set no advertising cookies on your own WordPress site.
Meta Conversions API. When marketing cookies are allowed and you download a free plugin, our servers also send that same download event to Meta directly (server to server), with your IP address, browser user-agent, the page address and Meta’s cookie identifiers, so the event still counts if your browser blocks the pixel. Meta receives the browser event and the server event with the same event ID and counts them once. We send no name, email address or anything you typed.
3.9 Google API Services and Data Usage
Avakode (specifically the Rank Forge and Form Forge plugins) requests access to certain Google APIs to provide core application functionality directly within your WordPress dashboard.
Rank Forge: Accesses Google Search Console (webmasters.readonly) and Google Analytics (analytics.readonly) to display SEO performance metrics. It also uses the Google Indexing API (indexing) to submit URL update requests to search engines on your behalf.
Form Forge: Accesses Google Drive/Sheets (drive.file) to append your form submissions to specific spreadsheets you select, and Google Calendar (calendar.events, calendar.readonly) to manage booking availability and create event invitations.
Avakode’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Explicit Limitations on Google Data:
- We strictly use this data only for providing or improving our application’s direct user-facing features.
- We do not use Google Workspace or Google API data to develop, improve, or train generalized AI and/or machine learning models.
- We do not sell, rent, or transfer this data to third parties.
- We do not use or share this data for advertising purposes.
3.10 The site assistant
When you use the site assistant (“Ask AI”), the question you type goes to our API with the name of the website you are on and a reference to the earlier part of the conversation. Our API passes it on, through Cloudflare’s AI Gateway, to OpenAI, L.L.C. in the United States, whose model writes the answer from our documentation. OpenAI keeps the conversation (your questions and its answers) for 30 days, as it does by default, so that the next question can build on it, and keeps its abuse-monitoring logs for up to 30 days, longer only where the law requires it or where OpenAI needs it to protect its services. Our API does not keep your questions or the answers: it counts the requests from your IP address for about a minute, to limit abuse, and keeps a count of all questions per day for two days. Our API’s own code writes neither your question nor the answer to its logs: it writes, for an error from OpenAI, its status, type and code and, for another failure, a technical error text of up to 200 characters, from which we remove your question if the text repeats it; your IP address is written there only if the check that you are not a bot fails. These logs are kept for 7 days in Cloudflare’s dashboard and 30 days in a copy in our own storage (Cloudflare R2). The conversation is also kept in your browser, in the local storage of the website you are on: it is deleted when you open a page of that website more than an hour after your last message, and you can delete it at any time by clearing that website’s data in your browser. Please do not write personal or sensitive data in the assistant. On every page that has the assistant, whether or not you open it and whatever you chose in the cookie banner, Cloudflare Turnstile runs invisibly when the page loads and receives your IP address and technical details of your browser to check that you are not a bot. We offer the assistant, and protect it with that check, on the basis of our legitimate interest in answering questions about our products.
4. Why we collect it (legal basis)
Depending on your jurisdiction, we rely on the following legal bases:
- Performance of a contractto deliver the plugins, process payments, provide support, verify licenses.
- Legitimate interestto secure our infrastructure, detect abuse, improve the product.
- Consentfor optional communications (product announcements, newsletters). You can withdraw consent at any time.
- Legal obligationtax records, accounting, fraud prevention.
5. Who we share data with
We share personal data only with the following categories of recipients, strictly to deliver the service:
| Recipient | Purpose | Location |
|---|---|---|
| Paddle (Paddle.com Market Limited; Paddle.com Inc. in the United States; Paddle.com (Canada) Ltd. in Canada) | Merchant of record and independent controller (not a sub-processor): sells our products to you, takes payment, charges tax, issues invoices and refunds | United Kingdom / United States / Canada |
| Freemius Inc. | Payment processing and license management for purchases made before September 2026 | United States / EU |
| Cloudflare, Inc. | API hosting (Workers, D1, KV, CDN); AI Gateway (passes requests to OpenAI); Web Analytics on our websites (page views and page load speed, no cookies) | Global edge network |
| Hostinger International Ltd. | Marketing-site hosting | EU |
| OpenAI, L.L.C. | AI text generation (translations, form generation, answers in the site assistant) | United States |
| Anthropic, PBC | AI text generation (SEO analysis, content optimization) | United States |
| Google LLC | Google Tag Manager, Google Analytics and Google Ads on our websites (subject to your cookie choice); OAuth for Google Sheets / Google Calendar integrations | United States / EU |
| Meta Platforms Ireland Ltd. / Meta Platforms, Inc. | Meta Pixel and Conversions API: advertising measurement and plugin-download events (subject to your cookie choice) | Ireland / United States |
| Resend, Inc. | Sending our transactional email (license keys, account and credit notices) | United States |
| Functional Software, Inc. (Sentry) | Error monitoring of our API (error records and performance traces) | United States |
All sub-processors are bound by data processing agreements. We do not sell or rent personal data to anyone, ever.
6. International data transfers
Because our sub-processors operate globally, your data may be transferred to and processed in countries outside your own, including the United States and the European Union. When we transfer personal data from the EU/UK, we rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism.
7. How long we keep data
- Account data — for as long as your account is active, plus 3 years after closure (for tax and dispute-resolution purposes)
- Payment records — 7 years (tax and accounting obligations)
- License and site verification logs — up to 2 years after the license expires
- Free trial records — We keep the email address, the website address and the IP address of a free trial, so that each website and each email address gets one trial per product and no more than three trials start from one IP address within 30 days. The IP address is erased 30 days after the trial starts, and the rest of the record is deleted 12 months after the trial ends. A copy of our database, made every day to restore it after a failure, is deleted by a rule of the storage after 90 days, so an address erased or a record deleted may remain in such a copy for up to 90 days longer.
- AI request metadata (credit usage) — 2 years
- The site assistant — The conversation stays in your browser, in the local storage of the website you are on, for an hour after your last message; it is deleted when you open a page of that website after that hour, and you can delete it sooner by clearing that website’s data in your browser. Our API does not keep your questions or the answers: it counts the requests from your IP address for about a minute, and keeps a count of all questions per day, without IP addresses, for two days. OpenAI keeps the conversation (your questions and its answers) for 30 days, as it does by default, and keeps its abuse-monitoring logs for up to 30 days, longer only where the law requires it or where OpenAI needs it to protect its services.
- Support tickets — 3 years after the ticket is closed
- Technical logs — up to 90 days
- Logs of our API — 7 days in Cloudflare’s dashboard and 30 days in a copy in our own storage (Cloudflare R2). They hold the lines our API writes about its own events (for example a message sent, a failed check or an error) and the exceptions of its Worker; some of these lines hold personal data, such as an IP address. Cloudflare’s own log of each request to our API is switched off.
- Error monitoring (Sentry) — 30 days, for error records and for performance traces alike.
- Advertising and analytics data — held by Google, Meta and Cloudflare under their own terms
- Integration tokens — until you disconnect the integration or close your account
You can request earlier deletion at any time (see Section 9).
8. How we protect your data
- All traffic to avakode.com and api.avakode.com is encrypted with TLS 1.3
- Passwords are hashed with bcrypt
- Integration tokens and API keys are encrypted at rest (AES-256)
- Access to production systems is limited to authorized team members
- We run automated security scans and dependency updates on a regular basis
No system is 100% secure, but we take reasonable technical and organizational measures aligned with industry best practice.
9. Your rights
Regardless of where you live, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data (subject to legal retention requirements — see Section 7)
- Port your data in a machine-readable format
- Object to processing based on legitimate interest
- Withdraw consent for optional communications
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email [email protected]. We respond within 30 days.
10. Children
Forge Suite is a professional tool for building and managing websites. It is not intended for users under the age of 16. We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, contact us and we will delete it.
11. Changes to this policy
We may update this policy occasionally. When we make material changes, we will notify active customers by email and post a notice on avakode.com at least 30 days before the changes take effect. The “Last updated” date at the top always reflects the most recent revision.
12. Contact
Questions about this policy, your data, or anything privacy-related:
Email: [email protected]
Postal: Tigran Avakov, a self-employed individual, Mirzo-Ulugbek 45A, 100007 Tashkent, Uzbekistan
Bot protection (Cloudflare Turnstile)
To protect our forms and AI assistant from automated abuse, we use Cloudflare Turnstile, a CAPTCHA alternative provided by Cloudflare, Inc. Turnstile runs invisibly in the background and processes client-side signals (such as your IP address, TLS fingerprint, User-Agent header, and the page you are on) to confirm that you are a human and not a bot, without showing you a puzzle. This processing is governed by Cloudflare’s Turnstile Privacy Policy / Addendum. Cloudflare does not use this information to track you across websites or for advertising.