Security & data handling
This page is maintained by ForgeMetric to answer the security and privacy questions merchants and agencies ask before connecting an ad account. It describes how we operate today — it is not a certification, an audit report, or an independent assessment.
Last updated August 2, 2026.
Accounts and authentication
Accounts are created with email and password or Google sign-in. Sessions are issued as short-lived tokens and refreshed automatically; passwords are never stored by us in readable form.
Every database table that holds customer data is protected by row-level security so a signed-in account can only read and write its own records. Administrative capabilities are gated by a separate roles table, never by anything the browser can set.
Connected ad and store accounts
Meta and Shopify are connected through their official OAuth flows. We never ask you to paste an API key or create your own app.
Meta permissions we request, and what each one is used for:
- ads_read — read your ad sets and creatives so they can be scored.
- ads_management — create the rewritten ad in a paused state when you click “Send to Meta”.
- pages_manage_posts / instagram_content_publish — publish an approved social post to the page or account you select.
- business_management — list the ad accounts you are allowed to choose from.
Shopify access is limited to read scopes for products and orders, used for catalog and brand context. Access tokens are encrypted at rest with AES-256-GCM and are only decrypted server-side at the moment a request is made on your behalf. Disconnecting a store or ad account deletes the stored token.
What we store, and for how long
We store your account details, the ads and copy you submit, generated rewrites and creative, connection metadata for the accounts you link, and usage counters for plan limits. We do not store card numbers — payments are handled by Stripe.
Audits, drafts and generated media stay in your workspace until you delete them. Deleting your account removes your workspace data; backups age out on the platform's standard rotation. To request deletion, email hello@forge-metric.com from the address on the account.
Subprocessors and platform
The application runs on Lovable Cloud, which provides the managed Postgres database, authentication and file storage, served over HTTPS. Model access runs through the Lovable AI Gateway. Payments run through Stripe. Meta, Shopify, X and LinkedIn receive only the content you explicitly approve for publishing.
Content you submit is sent to the model provider to produce the audit or rewrite. We do not sell your data, and we do not use your ad copy to train models.
The full subprocessor list is maintained in our privacy policy.
Shared responsibility
Lovable Cloud is responsible for the underlying hosting, database and platform infrastructure. ForgeMetric is responsible for application access control, OAuth scope usage, encryption of stored tokens and the retention practices above. You are responsible for keeping your own credentials safe, choosing which ad accounts to connect, and reviewing any ad or post before it is published.
Reporting a vulnerability
Email hello@forge-metric.com with “Security” in the subject. Include steps to reproduce and any affected URL. We aim to acknowledge reports within two business days. Please do not run automated scans against production or access data that is not yours.
Contact
ForgeMetric is operated by Joe Resha, Founder & CEO. For security, privacy or data processing questions, write to hello@forge-metric.com or use the contact page. Live uptime is published on our status page.
