Privacy Policy

Last updated:

This policy explains how the AI scoping and delivery service operated by Forsa AI Pty Ltd, ACN 699 383 778 (“we”, “us”, “our”) collects, uses, and protects your information. It expands on Section 6 of our Terms & Conditions, which remain the governing agreement.

1. What we collect

When you request access we collect your first and last name, your business email address, and the company name derived from it. During a session, the AI agent collects the information you voluntarily provide — your business challenges, processes, systems, and goals — plus any files you upload. If your organisation uses the Knowledge Base, we also hold the documents and notes you load into it, and a record of who viewed or changed them. We collect basic technical data needed to operate and secure the service.

2. How we use it

We use your data to generate your scoping documents, score session quality internally, improve our agent's performance, create anonymised case studies (per Section 3 of the Terms), and — if you proceed to a build — to plan and deliver the project. We do not sell your data to third parties.

Knowledge Base notes from your sessions. If your organisation uses the Knowledge Base, when a session finishes we prepare notes from it — the facts the agent recorded from what you told it about your business, such as your budget, costs and who signs off — along with any files you attached in the chat. A member of our team reviews each one, and only what they approve is kept. What is kept stays with the person whose session it came from: the agent can draw on it in that person's later sessions, not in their colleagues'. Anything it draws on appears in that session's conversation and documents, like anything else said there.

3. How we store it

Session data is stored in a Supabase Postgres database hosted in the Sydney region (ap-southeast-2). It is encrypted in transit (HTTPS/TLS) and encrypted at rest by our database provider. Files you upload are held inside that same encrypted database rather than a separate file store. Access is restricted to the session participant and authorised administrators.

4. AI processing

Your conversation is processed by Anthropic's Claude via their API. Under Anthropic's commercial terms, your data is not used to train their models. Anthropic's handling of data is governed by their own terms and privacy policy.

Files you upload are passed to Claude in full so it can read them. Knowledge Base text is additionally sent to Voyage AI, which turns it into a numerical index that makes it searchable. Neither provider uses your data to train models.

Voice input. If you use the microphone button, the speech-to-text is done by your own web browser, not by us. On Chrome and Edge this means your browser sends the captured audio to its vendor — Google or Microsoft — for transcription, under that vendor's privacy terms. We never receive the audio, only the text your browser returns. If you would rather nothing left your device, type instead.

5. Subprocessors

We use a small number of third-party providers to deliver the service (hosting, database, email, AI, product analytics). Each is listed with its role and region on our subprocessors page.

6. Sending information overseas

Some of the providers we rely on operate outside Australia. Your conversation, and any file you upload, is sent to Anthropic in the United States so Claude can read it. Knowledge Base text is sent to Voyage AI in the United States to be turned into a searchable index. Transactional email goes through Resend, also in the United States. None of these providers keep your data as a record of their own, and each is bound by its own contractual confidentiality and data-processing terms. Everything we retain about you and your sessions is stored in Sydney. The one exception is product-usage events (see Cookies & analytics below): Mixpanel keeps those in the United States. They record which steps of the service were used and when. They never contain what you wrote or uploaded, your name or your email address.

7. Cookies & analytics

We use only strictly-necessary cookies — to keep you signed in and to maintain your session. We do not use third-party advertising or cross-site tracking cookies, and we do not sell cookie data. For aggregate traffic measurement we use Vercel Web Analytics, a cookieless tool that records anonymised page views and coarse location (country/region) — no cookies, no personal data.

To learn which parts of the service help people and where they get stuck, we also send product-usage events to Mixpanel, in the United States. An event says that a step happened, such as a page viewed (never your scope page, see below), a session started, a message sent or a scope generated. A page is recorded by its type, such as “the knowledge base page”, never by its full address. It carries counts and categories, such as which message in the conversation it was. It never contains what you wrote or uploaded, your name, your email address or your organisation's name. Before you sign in, you are identified by a random number kept in your browser's local storage, not a cookie. Once you sign in, you are identified by an internal number from our own database. Mixpanel also records your browser and device type and your country, which our own servers work out from your internet address; Mixpanel never receives the address itself.

When you request access we also record how you found us — the referring site and any campaign tags in the link you first arrived on, and the same for the most recent tagged link you followed before requesting access — and your approximate location (country/region) as our infrastructure saw the request. Until you submit the form that note waits in your browser's local storage; once submitted it is kept with your request in Sydney and used to understand which channels bring people to Forsa. The referring site and campaign tags also travel with the product-usage events above, so we can see which channels lead to a finished scope.

When you first open the page holding your scoping documents, we record the date and time you did. We keep that one timestamp against your session in Sydney, and we use it for a single purpose: to know whether the scopes we produce are actually being opened. We do not track how long you spend on the page, how much of a document you read, or which parts you look at, and nothing about your reading leaves our own database. What you decide there — confirming the scope, reopening it, or asking us to build it — is recorded as a usage event like any other step.

8. Retention

We retain session data for as long as it is useful for service improvement and business operations. You can request deletion at any time; we will action a verified request within 30 days, except where retention is required by law.

You can also delete a scoping session yourself, from your account page, provided it has not yet produced scope documents. A session you delete stops appearing anywhere — including for colleagues it was shared with — and waits in your recycle bin for 30 days, where you can restore it. After that it and its conversation are permanently removed.

9. Your rights & deletion

You may request access to, correction of, or deletion of your data, and you may withdraw the marketing permissions described in the Terms. To exercise any of these, email [email protected].

10. Contact

Questions about this policy or your data? Email us at [email protected]. These terms are governed by the laws of Victoria, Australia.