Privacy policy
0. Summary
Last updated: October 8, 2026
The privacy of your data, and it is your data, not ours, matters to us. This policy sets out what we collect and why, how we handle it, and your rights. We never sell your data.
In this policy, "Frog Joe", "we", "our" and "us" mean Klaviersoft Ltd, of Nova Scotia, Canada, which operates Frog Joe at frogjoe.com. "You" means visitors to our website and the people who hold or use a Frog Joe account.
1. Your forge content
Each Frog Joe customer organization gets its own Forgejo server (a "forge"). The repositories, issues, pull requests, CI jobs and other content in a forge belong to the customer organization. We store and process that content only to run the forge for the organization, under its instructions. If you use a forge as a member of an organization, that organization decides what is kept in it; please contact the organization about that content.
2. What we collect and why
We collect only what we need to run Frog Joe.
2.1 Account and sign-in
When you get a Frog Joe account, we store your email address, a hash of your password (never the password itself), the organizations you belong to and your role in each. If you sign in with Google or Microsoft, or with your organization's own identity provider, we store the email address and the account identifier that provider gives us, so we can recognise you next time. We use your email address to send you messages about your account, such as confirmations, invitations and password resets. We do not send newsletters or marketing email.
2.2 Billing
Payments are handled by Stripe. Your card details go directly to Stripe and never reach our servers. Stripe also collects your billing address to calculate sales tax. We store the Stripe identifiers for your organization's customer record and subscription, your plan, its billing period and its payment state, so we can provide the service you paid for.
2.3 Service records
To run your forge and its CI runners, we record what we create for you: the forge's name and address, its server and storage, runner start and stop times, and the runner minutes used, which we use to apply your plan's allowance.
2.4 Security and abuse prevention
We use your IP address and the email address you enter to limit repeated sign-in and password-reset attempts. Our servers keep technical logs (for example, the address and time of a request) to keep the service secure and working, and we send error reports to our monitoring provider so we can fix problems. We keep these records for up to 12 months, because we need them to run and secure the service (for example, to investigate a security incident or abuse), and then delete them.
2.5 Cookies
We use only the cookies Frog Joe needs to work: a session cookie that keeps you signed in, and, if you choose "Remember me" when signing in, a cookie that keeps you signed in for 14 days. We do not use analytics, advertising or tracking cookies, and our pages load no third-party scripts.
2.6 Email to us
If you write to us, we keep the correspondence so we can refer to it later.
3. When we access or share your information
To provide the service. We use the following providers to run Frog Joe. Each receives only what it needs for its task.
| Provider | Purpose | Location |
|---|---|---|
| Fly.io | Hosting for our application, your forge and your CI runners | Canada (Toronto) for our application; your forge and its runners in the region your organization uses (see section 7) |
| Backblaze | Encrypted backups of your forge (from general availability) | Canada (Toronto) |
| Stripe | Payments, invoices and sales tax | United States |
| Mailgun | Sending account email | United States |
| AppSignal | Error reports and application monitoring | Netherlands (European Union) |
| Google, Microsoft | Sign-in, when you choose it | United States |
| Fastmail | Receiving email sent to us | United States |
| DNSimple | DNS records for frogjoe.com and your forge's address (no personal data beyond the forge name) | United States |
Looking at your content. Nobody at Frog Joe looks at the content of your forge except with your permission (for example, to help with a support request), when an error needs manual repair and cannot be fixed otherwise, to investigate a report that the service is being used in breach of our terms, or when the law requires it.
When the law requires it. We disclose information only when compelled by a valid legal order, and we tell the affected customer first unless the law or an emergency prevents it. If a tax authority audits us, we disclose only the minimum billing information needed.
If the business changes hands. If Frog Joe is sold or merges with another company, we will tell you before your information is transferred or becomes subject to a different privacy policy.
4. Your rights
You have the right to:
- know what personal information we hold about you and how we use it;
- get a copy of it;
- have it corrected;
- have it deleted, unless we must keep it by law (deleting some information may mean closing your account);
- withdraw consent where we rely on it; and
- complain to us, and to the Office of the Privacy Commissioner of Canada or the data-protection authority where you live.
To use any of these rights, email privacy@frogjoe.com. We may need to confirm your identity before we act on a request.
5. How we protect your data
All traffic between your browser or Git client and Frog Joe or your forge is encrypted (HTTPS and SSH). Disks are encrypted at rest. Each forge runs on its own server and storage, and each CI job runs on a new machine that is destroyed when the job ends. Secrets we hold for your forge are encrypted in our database.
6. Deletion and retention
Today, our hosting provider takes a daily snapshot of each forge's storage and keeps it for five days. Before general availability, we will add encrypted backups in Canada: once a day on the Starter plan, and continuously, with point-in-time recovery, on the Team and Scale plans.
When a forge is deleted, we delete its server and its storage; any remaining snapshots expire within five days, and its backups are deleted with it. When an organization's subscription ends, we keep its forge and backups so you can come back or export your data, until you ask us to delete them. Billing records are kept for as long as Canadian tax law requires (currently six years). Other information is kept while your account exists; when you ask us to close your account, we delete it, except what the law requires us to keep.
7. Where your data is stored
Frog Joe is operated from Canada. Our application and its database run in Canada (Toronto). Each forge and its CI runners run in one region: Ashburn, Virginia, United States, unless your organization chooses another region we offer. From general availability, backups of every forge are stored in Canada (Toronto), whichever region the forge runs in. Our other providers store data in the locations listed in Table 1. When your data is stored outside your country, the laws of that country may allow its authorities to access it.
8. Changes and questions
We may update this policy to reflect new practices or legal requirements. When we make a significant change, we update the date at the top and tell account holders by email.
Questions about this policy or your data go to our privacy officer at privacy@frogjoe.com.
Adapted from the 37signals privacy policy, licensed under CC BY 4.0. Changes were made.