BloxForge AI

Privacy Policy

Last updated 30 July 2026. Written to be read: what we collect, why, who else sees it, and how to have it deleted.

01

Who we are

The controller

Georgii Mishchenko, Dubai, United Arab Emirates, operating BloxForge AI. Contact for any privacy question or request: mishchenko.george@gmail.com.

Scope

This policy covers bloxforge.ai and kintechs.org (the same service under its former address), the dashboard, and the BloxForge AI plugin for Roblox Studio.

02

What we collect

Account data

Your email address, a hashed password (we never store the password itself), the invitation code used, the date you accepted the terms, and your account status.

What you type

Your project names, the messages in your design conversations, the plans produced from them, and the scripts generated for you.

Usage and billing records

What you generated and when, the model cost and credits charged or refunded, and your credit ledger. Payment records come from Stripe; card numbers never reach our server.

Technical data

Your license token for the plugin, server logs of requests needed to run and secure the service, and errors.

Visit counts

Our own server counts page visits: which page was opened, which website you arrived from, and the date. Nothing about you personally is stored with it — no cookie, no IP address, no identifier — so these counts can never be traced back to a person.

What we do not collect

No advertising trackers, no third-party analytics, no Roblox password. We do not ask for your address, phone number or any government ID.

03

Why we use it

To run the service

To sign you in, keep your projects, generate what you ask for, and show your history.

To charge fairly

To quote work, spend and refund credits, and keep an auditable ledger.

To keep it safe

To enforce rate limits, detect abuse, and screen generated and third-party code.

To support you

To answer your emails and investigate a problem in your account.

Legal basis

We process this data to perform our contract with you, to meet legal obligations, and for the legitimate interest of keeping the service secure. We do not use your data to train our own AI models.

04

Who else sees it

AI providers

Your prompts and plans are sent to our AI providers (Anthropic and OpenAI) to produce output. They process it under their own API terms and, under those terms, do not use API content to train their models.

Infrastructure

The service runs on Railway (United States) with Cloudflare in front of the domain. They host and route the data needed to serve the site.

Payments

Stripe processes payments and holds the payment details; we receive only whether the payment succeeded.

Roblox

When a build looks up or inserts a catalog asset, the request goes to Roblox's public services. Your account data is not sent to Roblox.

Nobody else

We do not sell your data, rent it, or share it for advertising.

05

Where it lives and for how long

Location

Our database and files are stored in the United States (Railway, US West). By using the service you accept this transfer.

Retention

Account data, projects and scripts are kept while your account is open. Billing and credit records are kept as long as the law requires for accounts. Server logs are short-lived.

Deletion

Ask us to delete your account and we remove your account, projects, conversations and scripts, keeping only the minimum billing record we are legally required to hold.

06

Your rights

Access and a copy

Ask us what we hold about you and we will send it.

Correction and deletion

Ask us to fix or delete your data.

Objection and complaint

You can object to how we process your data, and complain to your local data protection authority.

How to ask

Write to mishchenko.george@gmail.com from your account email. We answer within 30 days.

07

Cookies

What we use

One cookie: the session cookie that keeps you signed in. It is required for the site to work and is removed when you sign out.

What we do not use

No advertising cookies, no tracking pixels, no third-party analytics. We do count page visits, but we do it on our own server without storing a cookie, an IP address or any identifier — which is why you are not being asked to click a consent banner.

Blocking it

If you block the session cookie you cannot sign in.

08

Children

Age 13 and over

Accounts are for people aged 13 and over. If you are under 18, a parent or guardian must agree to the terms and be the payer.

If a younger child registered

Write to us and we will delete the account and its data.

Want your data, or want it gone?

One email is enough — a person reads it.