Privacy Policy — Forge Companion Chrome Extension
Effective date: May 1, 2026
1. Introduction
This Privacy Policy applies to the Forge Companion Chrome extension ("Forge Companion," "the extension"), a free browser extension published by SellerForge ("we," "us," or "our") that provides an AI assistant for Amazon sellers on Amazon-owned websites.
This policy covers only the Forge Companion Chrome extension. The SellerForge web platform at sellerforge.ai is governed by a separate privacy policy, available at sellerforge.ai/privacy.
By installing and using Forge Companion, you agree to the practices described in this policy. If you do not agree, please uninstall the extension and contact us at privacy@sellerforge.ai to delete any stored data.
2. What the Extension Does
Forge Companion runs in the Google Chrome browser and provides AI-powered assistance via a side panel when you are on an Amazon page (amazon.com and other Amazon marketplaces, sellercentral.amazon.com, advertising.amazon.com). When you invoke the extension, it reads the contents of the page you are currently viewing, sends relevant context to our backend, and uses Anthropic's Claude API to generate AI responses to your questions.
The extension does not run on any non-Amazon website. It does not collect data in the background. It only processes page content in response to a user action (clicking the extension icon, opening the side panel, or sending a chat message).
3. Information We Collect
3.1 Account information
To use the extension, you provide an email address during signup. We use this email to authenticate you (via a one-time magic-link), sync your usage data across devices, and send transactional emails about your account. We do not collect passwords — the extension uses passwordless magic-link authentication only.
3.2 Authentication tokens
After email verification, our backend issues a JSON Web Token (JWT). The token is stored locally in chrome.storage.local, an isolated browser storage area available only to the extension. The JWT is sent to our backend with each request to authenticate you. We do not transmit JWTs to any third party.
3.3 Page content (Amazon pages only)
When you invoke Forge Companion on an Amazon page, the extension extracts structured information from that page and sends it to our backend so the AI can give a context-aware response. Examples by page type:
- Product detail pages: ASIN, brand, title, bullet points, description, price, rating, review count, BSR
- Search results pages: search query, top organic and sponsored ASINs with titles, brands, prices
- Seller Central — Account Health: health rating, policy violations, performance metrics
- Seller Central — Cases & Notifications: case content, deadlines, and references shown on screen
- Seller Central — Inventory & Listings: your SKUs, ASINs, prices, stock levels, listing fields you are actively editing
- Seller Central — Advertising: campaign names and aggregate metrics (spend, sales, ACoS, impressions, clicks)
Page content is sent over HTTPS to our backend, processed for the AI response, and discarded. We do not retain raw page content beyond the request lifetime.
3.4 User chat input
The questions you type into the chat are sent to our backend alongside page context, processed by Anthropic's Claude API, and the AI response is streamed back to your browser.
3.5 Usage metadata
We log non-content metadata per AI request to enforce usage limits and improve the service:
- Timestamp, account ID, page type (e.g., "product-detail")
- Amazon marketplace (e.g., amazon.com, amazon.co.uk)
- Token counts and model used (Haiku or Sonnet)
- Response latency
3.6 What we do NOT collect
- Your Amazon login credentials, passwords, MFA codes, or session cookies
- Buyer personally identifiable information (names, addresses, order details)
- Browser history outside the Amazon pages you actively invoke the extension on
- Data from any non-Amazon website
4. How We Use Your Information
- Authenticate you, route AI requests, deliver responses, and track usage against your plan's message limits
- Send page content and your chat input to Anthropic's Claude API to generate responses
- If you upgrade to Pro, share your email with Stripe to process subscription payments — we never see or store credit card numbers
- Detect abuse and diagnose technical issues
- Comply with applicable laws and respond to lawful requests
We do not sell, rent, or trade your personal data to any third party, ever.
5. Third-Party Service Providers
- Anthropic (Claude API) — page content and your chat messages are sent to Anthropic's API to generate AI responses. Anthropic's Privacy Policy.
- Supabase — cloud database and authentication used to store your account data and usage logs. Supabase's Privacy Policy.
- Stripe — payment processing for Pro subscriptions only. Stripe's Privacy Policy.
- Resend — transactional email delivery (magic links). Resend's Privacy Policy.
6. Data Retention
- Account data (email, plan): retained while your account is active
- Authentication tokens (JWTs): valid for 30 days; refreshed automatically; deleted on sign-out
- Magic-link tokens: one-time use; expire 15 minutes after issue; deleted immediately after use
- Usage metadata: retained for 90 days, then automatically deleted
- Page content and chat messages: not retained beyond the request lifetime
To request deletion of all your data, email privacy@sellerforge.ai with the subject "Data Deletion Request — Forge Companion." We will process requests within 30 days.
7. Data Security
- All data in transit is encrypted with TLS 1.2 or higher
- Data at rest in Supabase is encrypted with AES-256
- JWTs are signed with HS256 and stored in
chrome.storage.local(notlocalStorage) - Backend API access is restricted by row-level security policies in Supabase
- We do not store any payment card data on our infrastructure
No method of transmission or storage is 100% secure. While we take industry-standard precautions, we cannot guarantee absolute security.
8. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict certain processing activities
- Receive a portable copy of your data
- Withdraw consent at any time (including uninstalling the extension)
- Lodge a complaint with your local data protection authority
To exercise any of these rights, contact privacy@sellerforge.ai. We will respond within 30 days.
California residents (CCPA/CPRA): You have additional rights including the right to know what personal information we collect and the right to non-discrimination for exercising your rights. We do not sell personal information.
EEA, UK, and Swiss residents (GDPR/UK GDPR): Our legal basis for processing is (a) performance of contract for service operation, (b) legitimate interests for abuse prevention and service improvement.
9. Children's Privacy
Forge Companion is intended for adult Amazon sellers. We do not knowingly collect data from anyone under the age of 18. If we become aware we have collected data from a minor, we will delete it promptly.
10. International Data Transfers
Our backend is US-hosted. If you access the extension from outside the United States, your data may be transferred to and processed in the US. We rely on Standard Contractual Clauses (SCCs) where required for transfers from the EEA, UK, or Switzerland.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email at least 14 days before they take effect. Continued use of Forge Companion after the effective date constitutes acceptance of the updated policy.
12. Relationship to SellerForge Web Platform
Forge Companion is a free Chrome extension published by SellerForge. The SellerForge web platform at sellerforge.ai is a separate paid SaaS product with its own Privacy Policy. If you use both products, each policy governs the data collected by that product.
13. Not Affiliated With Amazon
Forge Companion is not affiliated with, endorsed by, or sponsored by Amazon.com, Inc. Amazon, Seller Central, FBA, Sponsored Products, and related marks are trademarks of Amazon.com, Inc. The extension only reads content from Amazon pages you are actively viewing in your own browser; it does not connect to any Amazon API or scrape Amazon data.
14. Contact
For privacy questions, data requests, or concerns:
SellerForge
privacy@sellerforge.ai
Forge Companion is not affiliated with, endorsed by, or sponsored by Amazon.com, Inc.