Privacy Policy
Last updated 30 July 2026. Written to be read: what we collect, why, who else sees it, and how to have it deleted.
Who we are
Georgii Mishchenko, Dubai, United Arab Emirates, operating BloxForge AI. Contact for any privacy question or request: mishchenko.george@gmail.com.
This policy covers bloxforge.ai and kintechs.org (the same service under its former address), the dashboard, and the BloxForge AI plugin for Roblox Studio.
What we collect
Your email address, a hashed password (we never store the password itself), the invitation code used, the date you accepted the terms, and your account status.
Your project names, the messages in your design conversations, the plans produced from them, and the scripts generated for you.
What you generated and when, the model cost and credits charged or refunded, and your credit ledger. Payment records come from Stripe; card numbers never reach our server.
Your license token for the plugin, server logs of requests needed to run and secure the service, and errors.
Our own server counts page visits: which page was opened, which website you arrived from, and the date. Nothing about you personally is stored with it — no cookie, no IP address, no identifier — so these counts can never be traced back to a person.
No advertising trackers, no third-party analytics, no Roblox password. We do not ask for your address, phone number or any government ID.
Why we use it
To sign you in, keep your projects, generate what you ask for, and show your history.
To quote work, spend and refund credits, and keep an auditable ledger.
To enforce rate limits, detect abuse, and screen generated and third-party code.
To answer your emails and investigate a problem in your account.
We process this data to perform our contract with you, to meet legal obligations, and for the legitimate interest of keeping the service secure. We do not use your data to train our own AI models.
Who else sees it
Your prompts and plans are sent to our AI providers (Anthropic and OpenAI) to produce output. They process it under their own API terms and, under those terms, do not use API content to train their models.
The service runs on Railway (United States) with Cloudflare in front of the domain. They host and route the data needed to serve the site.
Stripe processes payments and holds the payment details; we receive only whether the payment succeeded.
When a build looks up or inserts a catalog asset, the request goes to Roblox's public services. Your account data is not sent to Roblox.
We do not sell your data, rent it, or share it for advertising.
Where it lives and for how long
Our database and files are stored in the United States (Railway, US West). By using the service you accept this transfer.
Account data, projects and scripts are kept while your account is open. Billing and credit records are kept as long as the law requires for accounts. Server logs are short-lived.
Ask us to delete your account and we remove your account, projects, conversations and scripts, keeping only the minimum billing record we are legally required to hold.
Your rights
Ask us what we hold about you and we will send it.
Ask us to fix or delete your data.
You can object to how we process your data, and complain to your local data protection authority.
Write to mishchenko.george@gmail.com from your account email. We answer within 30 days.
Cookies
One cookie: the session cookie that keeps you signed in. It is required for the site to work and is removed when you sign out.
No advertising cookies, no tracking pixels, no third-party analytics. We do count page visits, but we do it on our own server without storing a cookie, an IP address or any identifier — which is why you are not being asked to click a consent banner.
If you block the session cookie you cannot sign in.
Children
Accounts are for people aged 13 and over. If you are under 18, a parent or guardian must agree to the terms and be the payer.
Write to us and we will delete the account and its data.