Legal

Privacy Policy

Effective 7 June 2026 -- SoClose Pte. Ltd.

This policy explains what AdsForge collects, why, and your choices. AdsForge is built to be self-hosted: when you run it on your own infrastructure or the offline desktop app, your briefs, brand kits, and generated creatives stay on your own systems.

1. Who we are

AdsForge is operated by SoClose Pte. Ltd., a company incorporated in Singapore. This policy covers the hosted service at ads.soclose.co and the AdsForge marketing site. When you self-host AdsForge or run the desktop app, SoClose Pte. Ltd. does not receive your generation data: you are the data controller for that deployment.

2. What we collect

On the hosted service and marketing site we may collect:

  • Account data: your email, hashed password, and role. Passwords are stored as bcrypt hashes, never in plain text.
  • Content you create: clients, brands, briefs, and the creatives generated from them. This is stored so you can return to your work.
  • Provider keys you enter: API keys for AI providers are encrypted at rest (Fernet) and used only to call the providers you choose.
  • Operational logs: request metadata and error logs used to keep the service running and secure.
  • Access requests: if you ask for access, the contact details you submit.

We do not sell your data, and we do not use your briefs or creatives to train our own models.

3. Third-party AI providers

To generate copy, images, and video, AdsForge sends the relevant parts of your brief to the providers you configure (for example Anthropic, fal.ai, OpenAI, or a local Ollama or ComfyUI instance). Each provider processes that data under its own terms and privacy policy. You choose which providers to enable, and you can run fully offline with the built-in free engines so no data leaves your machine.

Platform integrations (Meta, Google, TikTok, X, LinkedIn) are draft-only and advisory. AdsForge never activates ad spend on your behalf: every action stops at a paused or draft state behind an explicit human confirmation.

4. How we use data

  • To provide and operate the service: authenticate you, run generations, store your work.
  • To secure the service: rate-limiting, abuse prevention, and debugging.
  • To communicate with you about access, support, and material changes to the service.

5. Security

We use JWT access tokens with rotating refresh tokens, bcrypt password hashing, and Fernet encryption for provider keys and sensitive settings. Security headers and an SSRF guard protect user-supplied URLs. No method is perfectly secure, but we apply industry-standard safeguards and keep secrets out of source code.

6. Data retention and deletion

We keep your account and content for as long as your account is active. You can request deletion of your account and associated content at any time. See How to delete your data for step-by-step instructions, what gets removed, and how long it takes. On a self-hosted or desktop deployment, retention is fully under your control.

7. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To delete your data, follow How to delete your data. For any other request, contact us at legal@soclose.co. We will respond within a reasonable time.

8. International transfers

The hosted service may process data on infrastructure located outside your country. Where required, we rely on appropriate safeguards for such transfers. Self-hosted deployments process data wherever you run them.

9. Changes to this policy

We may update this policy as the service evolves. We will revise the effective date above and, for material changes, provide notice through the service.

10. Contact

Questions or requests: legal@soclose.co. SoClose Pte. Ltd., Singapore.


Questions about this document? Contact legal@soclose.co. See also our Privacy Policy and Terms of Service.