Privacy Policy
Effective and last updated:
This policy describes how SignalForge, operated by SignalForge Dev Team, handles information through its website, private research workspace, backend API, and Chrome extension.
1. Information we handle
- Workspace and access information: administrator sign-in email, session information, and extension token labels, prefixes, hashes, creation dates, last-used dates, and revocation status. Sign-in passwords are submitted to the backend for authentication; they are not research data.
- Research information: submitted keywords, country, language, network, keyword lists, requested domains, returned metrics, raw provider responses, and retrieval timestamps. Research and snapshots are saved in the workspace database.
- Technical information: our hosting and infrastructure providers may process IP addresses, request details, browser information, timestamps, and diagnostic logs to deliver and secure the service.
- Support communications: information you send when contacting the team. Do not email passwords, private keys, refresh tokens, or other credentials.
The current workspace is shared and administrator-managed, not a separate private account for every junior user. Administrators can view stored research and manage extension access. Avoid submitting confidential or personal information as keywords.
2. Chrome extension data and permissions
On supported Google search pages, the extension reads the search query and organic result URLs to identify domains and their observed order. It sends the query, selected country and language, and result domains to your configured SignalForge backend, with your extension access token. It does not send full page HTML or snippets as part of these research requests, and it does not request Chrome’s browsing-history permission.
The backend URL, extension token, country, and language are stored using Chrome’s synchronized extension storage. Depending on Chrome settings, these values may synchronize across browsers signed in to the same Google account. Treat the extension token as a credential and use only a trusted backend URL. The extension requests permission to contact that backend when you save the connection.
Disable or uninstall the extension to stop its page processing. Ask your administrator to revoke the token to stop backend access; uninstalling alone does not revoke a token.
3. Google Ads access and Google data
SignalForge uses server-side Google Ads API access to retrieve Keyword Planner historical metrics, resolve location and language targets, and identify relevant account settings such as reporting currency. Historical responses may include monthly search counts, average searches, Ads competition, bid ranges, keyword text, and grouped close variants.
Access uses an administrator-configured service account or OAuth authorization with the https://www.googleapis.com/auth/adwords scope. This scope permits broader Ads access, but SignalForge’s current research features use it for the read and keyword-planning operations described here, not to create campaigns, buy ads, or change budgets. The extension does not receive Google access tokens, refresh tokens, client secrets, or service-account private keys.
We use Google data only to provide and support the research features described in this policy. We do not sell Google user data, use it for advertising targeting, or use it to train generalized AI models. Access by the team is limited to service administration, security, support with permission, or legal requirements.
SignalForge’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements where applicable. This statement is not a claim of Google verification or endorsement.
4. Why we process information
We process information to authenticate access, return and display research, save lists and retrieval history, cache slow-changing metrics, respect provider quotas, investigate technical problems, prevent abuse, and respond to support or privacy requests. No advertising cookies or marketing analytics scripts are currently added by SignalForge.
5. Providers and disclosures
Vercel hosts the application, and the configured PostgreSQL database provider stores workspace records; the current database integration uses Neon. Google processes Google Ads API requests and, depending on browser settings, Chrome extension synchronization. Ahrefs receives requested domains to provide Domain Rating. RDAP services, DNS providers, and target websites receive domain or public sitemap requests for domain research. Support email is handled through Gmail.
These services may process information in countries other than yours under their own terms and privacy policies. We do not send your Google credentials to Ahrefs, RDAP services, or target websites. We may disclose information when legally required or necessary to protect the service and its users. We do not sell research or personal information.
6. Storage, retention, and security
Research records, raw responses, snapshots, and access records are retained while needed for the workspace, support, and security, or until an applicable deletion request is fulfilled. Cache refresh intervals determine when data is fetched again; they are not automatic deletion deadlines. Hosting logs and backups follow the configured providers’ retention and recovery policies, so removed data may remain in backups until they expire.
Google and Ahrefs credentials are kept in backend configuration rather than browser bundles. Backend extension tokens are stored as hashes; the token itself is stored in the user’s Chrome settings. Administrator sessions use an HTTP-only cookie. These controls reduce risk but cannot guarantee absolute security.
7. Your choices and privacy requests
Contact the support email below to request access, correction, export, or deletion of information you submitted, or to ask about its use. These requests are handled by the team, not an automated self-service deletion tool. We may need to verify your authority, particularly in a shared workspace, and may retain records required for security or legal obligations. Available rights depend on applicable law.
For OAuth access, an authorized Google account holder can revoke SignalForge’s grant in their Google Account connection settings. For service-account access, an Ads administrator can remove that account’s Ads access, and the Cloud administrator can disable its keys or identity. Revocation stops future access but does not automatically delete previously stored research; request deletion separately.
8. Changes to this policy
We will update this page and its effective date when practices change. Material changes to Google data access or use will be disclosed, with additional consent obtained where required, before that new use begins.
Contact SignalForge
For questions about this policy or the service, contact SignalForge Dev Team at devteam.zeen.au@gmail.com.