Skip to main content
ForgeMeshPrivacy policy · updated 2026-08-28

Privacy Policy

This policy covers forgemesh.io and its subdomains, The Brief newsletter, the open-source MCP servers and AI Skills published by ForgeMesh Labs, and our x402-paid API services (“Services”). It is written to be read, not skimmed past. Questions: [email protected].

1. What we collect

  • Website analytics. forgemesh.io uses self-hosted, first-party Umami analytics. It is cookie-less, does not fingerprint devices, and records page views, referrers, country, browser and device class. You can exclude your browser at /no-track.
  • Newsletter. If you subscribe to The Brief we store your email address and the date you subscribed. Mail is sent through Amazon SES. Every issue carries an unsubscribe link; unsubscribing removes you from the list.
  • Contact. Email you send to us is kept for as long as needed to answer it and keep a record of the conversation.
  • Paid API calls (x402). Our paid endpoints settle in USDC on public blockchains (Base, Solana). A payment leaves a public, permanent on-chain record: paying wallet address, amount, timestamp, and our receiving address. We log the request path, timestamp, response status and the paying address for accounting, abuse prevention and service analytics. We do not link wallet addresses to names or emails unless you give us both.
  • Service inputs. Requests you send to our APIs (for example a URL to scan or a query to expand) are processed to produce the response and are retained in short-lived logs for debugging, then discarded.

2. MCP servers and AI Skills

Our open-source MCP servers (published under @forgemeshlabs on npm) run on your machine inside your own agent. Free scanners such as the Agent Readiness scanner make ordinary HTTP requests from your machine to the sites you ask them to check; nothing is sent to ForgeMesh. Servers that call a paid ForgeMesh API do so only when you invoke a paid tool, and only with the inputs for that call.

Our AI Skills (including those listed on third-party marketplaces such as the TikTok for Business Agentic Hub) are instruction files. They contain no code that contacts ForgeMesh. Data your agent reads from a third-party platform (for example ad, campaign or spend data from TikTok for Business MCP Server) stays inside your agent session and is never transmitted to us. Skills that can perform write actions require your explicit confirmation in chat before each change.

3. What we do not do

  • We do not sell, rent or trade personal data.
  • We do not run third-party advertising trackers or ad pixels on forgemesh.io.
  • We do not use your newsletter address for anything other than The Brief and direct replies.
  • We do not train models on your API inputs.

4. Processors we rely on

Cloudflare (DNS, CDN, DDoS protection), Amazon Web Services (hosting, SES email), Vercel (some static properties), GitHub and npm (source and package distribution), Umami (self-hosted analytics on our own infrastructure), and public blockchain networks and x402 facilitators for settlement. Each processes data only as needed to provide its function.

5. Retention

Analytics are kept in aggregate indefinitely. Request logs are rotated within 90 days. Newsletter addresses are kept until you unsubscribe. On-chain records are permanent by design and outside our control.

6. Your rights

You can ask what we hold about you, ask us to correct or delete it, or object to processing, by emailing [email protected]. We answer within 30 days. Residents of the EU/EEA, UK, California and other jurisdictions with data-protection laws have the rights those laws provide; we honour them regardless of where you live.

7. Children

The Services are not directed to anyone under 16 and we do not knowingly collect their data.

8. Changes

We will update the date at the top of this page when the policy changes. Material changes are announced in The Brief.

9. Contact

ForgeMesh Labs · [email protected] · forgemesh.io. See also our Terms & Disclaimer.