Privacy Policy

What we collect, why, and your rights.

Effective date: 2026-04-27 · Last updated: 2026-04-27

1. Data we collect

CategoryExamplesWhy
AccountEmail, Google profile name, picture URL, Firebase UIDSign-in and identity (Firebase Auth)
UsagePages visited, endpoint calls, credits consumed, idempotency keysBilling, abuse detection, product analytics
Research inputsIP Radar briefs, polymer screening drugs, FTO proposed_product textRun the analysis you requested. Confidential — per-uid scope only
Research outputsGenerated reports, drug briefs, FTO verdicts, polymer compatibility scoresSaved to your job history; downloadable as ZIP; not shared with other users
TelemetryHTTP latency, error codes, Cloud Run revision IDs, request IDsReliability monitoring (Cloud Logging, retained 30 days)

2. Where it's stored

3. What we do not do

4. Data shared with third parties

5. Your rights (GDPR / CCPA)

You can:

6. Cookies

MolForge uses minimal cookies: a session token (Firebase Auth), a theme preference (molforge-theme), and a Google Analytics tracking cookie (_ga) with anonymized IP. No advertising cookies. No cross-site tracking.

7. Children

MolForge is not directed at children under 16. We do not knowingly collect data from minors. If you believe a minor has registered, contact us and we will delete the account.

8. Security

All traffic is HTTPS-only with HSTS enabled. CSP, X-Frame-Options, and X-Content-Type-Options headers are set. API authentication uses Firebase JWT (>1024-bit RSA signed by Google). Database access is VPC-private (no public IP). Service accounts follow least-privilege.

9. Changes

Material privacy changes will be announced by email and posted on the blog 30 days in advance.

10. Contact

Privacy questions or data requests: [email protected]
Data Protection Officer: Gauthier Bros ([email protected])