Security and Data Practices

What we do with your data. What we don't. What's still being built.

This page is the long version of a short commitment: we collect the minimum we need, we store it in one place we can point at, and we don't sell it. Below is the specific list, with the limitations of being a small operation stated where they exist.

What data we collect

What we don't collect

Where your data lives

Primary VPS with OVH in the France region, IP 15.204.8.77. We disclose the provider and IP because transparency is easier than vagueness.

Forge specifically

Forge IDE runs on your machine. This is not a cloud IDE. No code, no data, no variables, no project files are sent to any Commons server.

The only network traffic Forge IDE makes is:

  1. License validation on startup. Sends your license key, receives yes or no.
  2. Update checks. Sends your current version, receives "newer exists: yes/no" and a download URL if yes.
  3. PyPI package index fetch. Only when you explicitly run pip install. This goes to PyPI, not to us.

Telemetry. We send anonymous counters for installation events and feature usage frequencies. No personal data, no code, no data from your projects. You can disable this with forge --no-telemetry or by setting FORGE_TELEMETRY=off in your environment.

What we don't have (yet)

If you want to leave

Every product exports to standard formats. You're never locked in.

You are never locked in. The code is open. The data is portable.

Incident response

Contact

Commons Infrastructure LLC is a Delaware-registered company with a sole founder and no employees. That shapes what we can and can't do. Everything on this page reflects the current state of a small operation that prefers honest limits to marketing copy.