Privacy
KEYWORD FORGE runs 100% static. No cookies, no localStorage, no fingerprinting. The only script is sites/_theme/beacon.js — a first-party cookieless stub that stays dormant until a collect endpoint exists (it doesn't while staged).
What we collect while staged
Nothing. No analytics is live, no form posts to us, no account. If you email us a seed list or domain, we use it only to produce your scope and deliver the file. Working copies deleted within 7 days of handover.
Keys and files
BYOK keys (GSC_OAUTH_JSON, SEMRUSH_API_KEY) stay on your machine or your provider — never paste them on this static site. When you use the underlying MCP/CLI tools, those keys are read from your env (GOLD_LICENSE_KEY + BYOK) and never sent to us.
Your rights
You own every CSV/HTML we hand you. Ask for deletion of working copies and we confirm within 48h. Questions: see Disclosure for operator contact and scope.