Privacy Policy
Last updated: July 17, 2026
This Privacy Policy explains how KeyForge ("we," "us") collects, uses, stores, and shares information when you use keyforge.win, our dashboard, loader runtime, Discord integrations, and related APIs. It should be read together with our Terms of Service.
1. Information we collect
Account and profile
When you register, we collect your email address, display name, and a bcrypt-hashed password. If you enable two-factor authentication, we store the settings and secrets needed to verify codes (for example, a TOTP secret for an authenticator app, or your phone number if you enable SMS). We record when you accept these Terms and our Privacy Policy.
Optional sign-in with Google provides basic profile information (such as email and name) according to the permissions you approve. We do not receive or store your Google password.
Discord
If you link Discord or add our bot to a server, we may store your Discord user ID, username, display name, email (if shared by Discord), guild IDs, and configuration for panels, roles, slash commands, and key redemption flows you enable.
Projects, scripts, and keys
We store projects, scripts, obfuscated outputs, license keys, key metadata (status, expiration, execution counts, type), HWID hashes you bind to keys, and settings you configure (including anti-bypass policies, webhooks, and ad gates).
Loader and runtime activity
When end users run your loader, we process technical data needed to authenticate and deliver scripts, including:
- Hashed IP address (HMAC-SHA256 binding identifier — raw IPs are not stored in execution logs or analytics)
- Country (ISO 3166-1 alpha-2 code inferred from our hosting edge, such as Cloudflare or Vercel — city or precise location is not stored)
- Hashed hardware identifiers (HWID) where your configuration uses them
- Executor name reported by the client
- Roblox place or game identifiers when provided by the loader
- Session nonces, heartbeat timestamps, and delivery telemetry
- Security and tamper signals (for example, loadstring hook reports or late heartbeats) when your anti-bypass settings are enabled
This data appears in your dashboard analytics and execution logs. Country-level audience breakdown is available on the Scale plan only.
Ad-link gates
If you use ad gates, we store gate configuration, claim records, creator-provider and KeyForge-provider verification state, completion timestamps, one-way completion-proof digests, and technical metadata such as hashed IP addresses, browser identifiers, and session identifiers. We use this data to prevent abuse, stop replayed receipts, and issue keys after the required checkpoints.
Creator-selected providers are configured by the reward-link owner. On ad-network reward links, KeyForge also selects and operates one Work.ink checkpoint and may receive revenue from it. When you follow that outbound Work.ink link, Work.ink independently collects and processes data under its own privacy policy and terms, including its cookie and advertising practices.
Billing
Payments are processed by Stripe. We store Stripe customer and subscription identifiers and plan status. We do not store full payment card numbers on our servers.
Signup abuse prevention
To limit fraudulent account creation, we may store hashed device fingerprints, hashed IP addresses, and hashed user-agent strings associated with new registrations.
Logs
We maintain operational, security, and interaction logs (including authentication events, rate-limit triggers, and dashboard actions) to secure the platform and help you debug issues. Security logs store hashed IP identifiers and short fingerprints for correlation; raw IP addresses are not written to application logs.
2. How we use information
We use collected information to:
- Provide, maintain, and improve the service
- Authenticate users and deliver protected scripts to licensed end users
- Enforce plan limits, rate limits, and security policies you configure
- Process payments and manage subscriptions
- Send transactional email (verification, password reset, security notices)
- Operate Discord bot features you enable
- Detect abuse, fraud, and violations of our Terms
- Comply with legal obligations
We do not sell your scripts or use them to train third-party AI models. We do not sell personal information to advertisers.
3. How we share information
We share information only as needed to operate the service:
- Infrastructure: hosting and database providers (for example, Vercel, Cloudflare, Turso)
- Payments: Stripe
- Email: transactional email providers (for example, Brevo or SMTP relays you configure for platform mail)
- Obfuscation: Luraph, MoonVeil, or similar providers when you request protection
- Ad providers: services creators connect and providers KeyForge selects for free-plan reward checkpoints (including Linkvertise)
- Discord: when you use bot or OAuth features
- Webhooks: endpoints you configure to receive events from your projects
- Legal: when required by law or to protect rights, safety, and security
Team members you invite may access project data according to the permissions you grant.
4. Cookies and local storage
Essential cookies (session, login, security) are required for the product to work and are always on. Optional on-site cookies and third-party scripts (for example display advertising) stay off by defaultuntil you choose "Allow optional" in the cookie banner. This preference does not disable required outbound provider checkpoints or the provider's independent cookies after you choose to leave KeyForge.
We use cookies and similar technologies for:
- Session cookie: keeps you signed in to the dashboard (essential)
- Two-factor and OAuth cookies: short-lived state during login (essential)
- Device fingerprint cookie (
kf_device): signup abuse prevention when enabled (essential security) - Ad-gate cookies: verify ad completion on reward pages you publish (essential to that feature)
- Theme preferences: accent and appearance in local storage (preference)
- Optional advertising: only if you allow optional cookies
We do not sell personal information. Project Discord webhooks you configure send only minimal event alerts (masked key, executor name, short IP hash) — not raw IPs or HWIDs.
5. Data retention
We retain account and project data while your account is active. You may delete projects, scripts, keys, and ad gates from your dashboard. When you delete content or close your account, we remove or anonymize data within a reasonable period, except where retention is required for security, fraud prevention, billing records, or legal compliance.
Loader sessions, execution logs, and security events may be retained for a limited period for analytics and abuse investigation, then purged or aggregated.
6. Security
We use industry-standard measures including HTTPS encryption, hashed passwords, hashed API keys, and access controls. No method of transmission or storage is completely secure; you use the service at your own risk and should protect your credentials.
7. Your choices and rights
You can update your profile, turn integrations on or off, and control what your projects collect from end users (within the features we provide). If you're in the EEA/UK or another region with similar laws, you may have rights to access, correct, delete, export, or restrict processing of personal data, and to object to certain processing. Contact us to submit a request — we may need to verify your identity.
Cookie preferences: use the on-site banner (Essential only / Allow optional). Essential cookies cannot be disabled while you use the service.
8. Children
KeyForge is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
9. International users
KeyForge is operated from the United States. If you access the service from other regions, your information may be processed in the United States and other countries where our providers operate, which may have different data-protection laws than your jurisdiction.
10. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the bottom of this page will change when we do. Material changes will be posted here; continued use after updates constitutes acceptance.
11. Contact
Privacy questions and data requests can be sent through our Discord server.