# Privacy policy

What information Forecall collects, why, who receives it, how long it is kept, and how to have it shown, corrected or deleted.

This policy explains how 株式会社みらいスタジオ (Mirai Studio, Inc.; "we") handles information in
Forecall: the website at forecall.dev, the dashboard at app.forecall.dev, the API at
api.forecall.dev, the Failure KB at mcp.forecall.dev and the `forecall` command-line tool. We handle personal information under Japan's
Act on the Protection of Personal Information.

## What we collect

- **Your account**: your email address, your name and GitHub login when you sign in with GitHub,
  and the language you choose. We do not keep your GitHub avatar. Signing in with GitHub asks only
  for your public profile and email address.
- **Your organization**: its name, its members and their roles.
- **Sign-in sessions**: the IP address and browser of each signed-in session, kept with the
  session.
- **What you submit**: the tool definitions you paste or register, your servers' details, their
  scores, and for evaluations the test utterances written from your tools and each model's answers.
- **What your agents send to the Failure KB** (mcp.forecall.dev, with an Agents key): reports of
  failures (the server's and the tool's names, the error text, the workaround and notes, the names,
  types and lengths of the call's arguments but never their values, and the model, client and
  server version), confirmations and disputes of workarounds, and lookups (kept as a hash of what
  was looked up, with the records returned). Before anything is stored, secrets, email addresses,
  file paths, IP addresses and identifiers are replaced by placeholders such as `<SECRET>`.
  Redaction recognizes known forms only, so agents are asked not to send raw data.
- **The sensor**, only if you add it with `forecall setup --sensor`: after each call of another MCP
  server's tool in Claude Code, the result's text, redacted on your computer and again by us and
  cut to 2,000 characters, with the server's and the tool's names, the arguments' names, types and
  lengths, and the client's name.
- **API keys**: only a hash of each key and its first eight characters, to tell keys apart. The key
  itself is shown once and never stored.
- **Usage**: the units your organization uses, what each evaluation cost us, and a log of API keys
  created and revoked (without IP addresses).
- **Payments** (on the paid plans): Stripe's identifiers for your organization and its payments.
  Card details go to Stripe, never to us.
- **Visits**: for each request to the website, categories only (the kind of page, the language,
  whether the visitor is a person or a bot, the kind of site it came from, the response's status).
  We do not record IP addresses, the full address of the page, or cookies in these statistics.

`forecall lint` scores tool definitions on your computer and sends nothing to us, and
`forecall dump` connects only to the server you name. The command-line tool sends us something
only through the sensor, and only once you add it.

## How we use it

We use this information to provide the service: to sign you in, to score and evaluate your tools,
to show your results to your organization, to count usage against your plan, to bill paid plans,
to answer your questions, to run the Failure KB (to judge whether a report or an observation is
a failure, a duplicate or spam, or may still hold a secret; to publish the records that agents of
two other organizations reproduced, without saying who reported them; and to show anonymous counts
of observed failures by public server), to keep the service secure and stop abuse (for instance
by counting requests per IP address for rate limits), and to understand, in aggregate, how the service is used
so we can improve it. We do not sell personal information, and we do not use your content to train
models.

## Who receives it

We share information only with the companies that help us provide the service, for that purpose:

| Company | What it does for us | What it receives |
|---|---|---|
| Cloudflare, Inc. (United States) | Runs the website, dashboard and API, sends sign-in emails, stores backups, and relays requests to AI models | Everything the service handles, while it runs on Cloudflare |
| Neon, Inc. (United States) | Hosts the database, in Singapore | Everything stored in the database |
| GitHub, Inc. (United States) | Signs you in when you choose GitHub | The sign-in request |
| Anthropic, PBC and OpenAI, L.L.C. (United States) | Run the AI models of an evaluation, and write its test utterances. For the Failure KB, OpenAI turns error texts into embeddings to find similar failures, and Anthropic translates published records between English and Japanese | Your tool definitions, the tools of any distractor servers you choose, and the test utterances; the redacted error texts of reports; the workarounds and notes of published records |
| TypeSafe AI, Inc. (United States) | Judges the Failure KB's reports, confirmations and sensor observations, and predicts a known failure before a call (its model jev) | The redacted reports, confirmations and observations, the records they are compared with, and for a prediction the tool's definition and the arguments' shape |
| Stripe, Inc. (United States) | Takes payments for the paid plans | Your email address, your organization's name and your payment details |
| Google LLC (United States) | Measures visits to the public website (Google Analytics) | What the [page on external transmission](https://forecall.dev/en/external-transmission) lists |
| Product Hunt, Inc. and Ory Group LLC (Orynth) | Show their badges on the public website | What the [page on external transmission](https://forecall.dev/en/external-transmission) lists |

Requests to Anthropic's and OpenAI's models go through Cloudflare's AI Gateway with its logs
turned off, so the gateway keeps no copy of your tool definitions; requests to jev go to TypeSafe
directly. Each provider handles the data under its terms for API customers:
[Anthropic](https://www.anthropic.com/legal/privacy),
[OpenAI](https://openai.com/policies/privacy-policy/),
[TypeSafe](https://typesafe.ai/legal/privacy-policy). We disclose information to others only when
the law requires it or with your consent.

## Outside Japan

These companies are outside Japan, most of them in the United States, and the database is in
Singapore. Before relying on a
company outside Japan, we check that its terms commit it to protect personal information to a
standard equivalent to Japanese law. The Personal Information Protection Commission publishes
[information on the laws of other countries](https://www.ppc.go.jp/personalinfo/legal/kaiseihogohou/#gaikoku).
You can ask us for more detail on these measures.

## Cookies

- On the dashboard, a session cookie keeps you signed in, and a cookie protects forms against
  cross-site requests. Both are used only by app.forecall.dev.
- On the website, a cookie lets the browser that made a linter result delete it, for 30 days, and a
  cookie protects forms.
- On the public website only, Google Analytics and the badges set their own cookies, as the
  [page on external transmission](https://forecall.dev/en/external-transmission) describes. The dashboard and the
  result pages load nothing from them.

## How long we keep it

| Information | Kept |
|---|---|
| A linter result made without signing in | 30 days, or until the browser that made it deletes it |
| Your account, your organization and what it registered | Until you delete them, or ask us to |
| Sign-in sessions | 7 days from the last use |
| What your agents sent to the Failure KB | As long as the KB holds the records it concerns |
| Sensor observations | 30 days; one we make into a record lives on as that record |
| Visit statistics | 3 months |
| Database backups | Up to 7 days in the database's history, and up to 56 days in encrypted weekly backups |

When you ask us to delete your account, we delete it and the organizations you are the only member
of, with everything they registered, within 30 days. Copies in the backups disappear as the backups
expire, within 56 days. What your agents sent to the Failure KB stays, without any link to you or
your organization: records are knowledge shared with every agent, with secrets and identifiers
removed. Ask us to remove a record that should not be there. Records of the sign-in emails sent to you are kept by Cloudflare under its
own policy. To remove Forecall's access to your GitHub account, revoke it in GitHub's settings.

## Your rights

You can ask us to show you the personal information we hold about you, to correct it, to stop
using it or to delete it, and to show you the records of its provision to others. Write to
[support@forecall.dev](mailto:support@forecall.dev) from the address you sign in with; we will
answer without delay, as the law requires.

## Security

All connections are encrypted. API keys and one-time tokens are stored as hashes, sign-in tokens
from GitHub are encrypted, backups are encrypted with a key only we hold, and copies of the data
used for testing have personal information replaced first. Access to the production systems is
limited to the people who run the service.

## Children

The service is meant for developers and is not directed at children under 16.

## Changes

We will publish any change to this policy on this page with the date it takes effect, and tell you
in advance of a change that affects how we use your information.

## Contact

株式会社みらいスタジオ (Mirai Studio, Inc.), person responsible: Hiroki Nomura (野村弘樹).
Our address is disclosed on request.
[support@forecall.dev](mailto:support@forecall.dev)
