TINPUL FORGE Privacy Policy Effective date: 28 September 2026 This Privacy Policy explains what data is processed when you use the TINPUL FORGE desktop application (“Application”, “Forge”), who processes it, and for what purposes. By using the Application, you confirm that you have read this Policy. Operator: Tinpul Website: https://tinpul.ru Support and privacy requests: support@tinpul.ru Full Tinpul service terms: https://tinpul.ru 1. What TINPUL FORGE is TINPUL FORGE is Tinpul’s desktop client for AI-assisted development. The Application runs on your computer, opens local projects, helps analyze code, propose edits, and run commands with your permission. For sign-in, model catalog, billing, and related cloud features, the Application connects to Tinpul services. 2. Data we process 2.1. Tinpul account data When you sign in via Tinpul Accounts (OAuth), we process data needed for authentication and session operation: user identifier, name/display name (if provided), email address (if provided), access and refresh tokens, selected organization/project information, and balance status. 2.2. Project and code data on your device Project files, repository contents, local workspace settings, agent chat history, proposed edits, checkpoints, and related artifacts are processed locally on your computer. Tinpul does not receive a full snapshot of your disk and does not use file contents for product telemetry. 2.3. Data sent to models and Tinpul services To fulfill an AI request, the Application may send to Tinpul services (or a compatible endpoint you configure) the context needed for a response: chat messages, selected files/code fragments, project metadata, and technical request parameters. The amount of context depends on your actions and session settings. 2.4. Local agent step log A local agent step log is kept on your device (step type, short summary, destination host, cost information when available). Secret keys and full file contents are not written to this log. Log files are rotated: entries older than 14 days are deleted automatically. 2.5. Technical and operational data For reliable operation we may process: Application and OS version, crash/error information without file contents, sandbox/isolation status, auto-update parameters, and network endpoints of Tinpul services the Application contacts. 2.6. Tinpul Todo and related modules If you connect Todo or other Tinpul modules, the Application may retrieve and display related account/project data (issues, chats, documents, etc.) at your request and within your authorization. Such data is processed to provide the corresponding feature. 3. Purposes of processing Data is processed to: - provide sign-in, session, and account security; - deliver AI agent features and related Tinpul modules; - account for model usage and charge your Tinpul balance; - store your local settings, chats, and app state; - update the Application; - respond to support requests; - comply with law and prevent abuse. 4. Legal bases Depending on applicable law, processing may rely on: - performance of a contract / providing Application features at your request; - your consent (where required); - Tinpul’s legitimate interests in security, stability, and service improvement, provided they do not override your rights; - compliance with legal obligations. 5. Where data is stored - Local Application data (settings, session secrets in the app data store, chats, step logs, local artifacts) is stored on your device in the OS user data directory. - Account, billing, and cloud model-request data is processed on Tinpul infrastructure and/or model providers engaged by Tinpul to deliver the service. - If you use your own compatible endpoint, you and that endpoint’s operator are responsible for its privacy practices. 6. Sharing with third parties Tinpul does not sell your personal data. Sharing may occur with: - model providers and infrastructure contractors engaged for Tinpul services — to the extent needed to fulfill a request; - payment and accounting services related to Tinpul balance; - public authorities — only where required by law; - successors in a reorganization, subject to continued data-protection obligations. Third-party MCP servers, Docker environments, Git hosts, and other tools you connect yourself receive data by your choice; Tinpul does not control their privacy policies. 7. Retention - Local agent step log: up to 14 days, then deleted automatically. - Local settings, chats, and artifacts: while you use the Application or until you delete app data / uninstall the Application. - Session tokens: until expiry, revocation, or sign-out. - Account and billing data on Tinpul’s side: for as long as needed to provide the service, keep records, and comply with law. 8. Security We apply organizational and technical measures appropriate to the data involved: encrypted channels to Tinpul services, restricted infrastructure access, local storage of secrets in application data, and a prohibition on writing keys and file contents to product telemetry. No method of transmission or storage is completely secure. You are responsible for protecting your device, credentials, and access to local projects. 9. Your rights Subject to applicable law, you may: - request information about processing of your personal data; - request correction of inaccurate data; - request deletion where applicable; - withdraw consent where processing is based on consent; - restrict or object to certain processing; - sign out in the Application and delete local app data using OS tools. To exercise these rights, email support@tinpul.ru. We will respond within a reasonable time as required by law. 10. Children The Application is not intended for persons under 16 (or the digital age of consent in your jurisdiction). We do not knowingly collect children’s data. If you believe a child has provided data to us, contact support@tinpul.ru. 11. International transfers Tinpul services may be processed on servers in different countries. By using Tinpul cloud features, you acknowledge that processing may occur outside your country of residence where lawful bases and reasonable safeguards apply. 12. Auto-updates The Application may check for and download updates from Tinpul’s update channel (including updates.tinpul.ru). Technical information about Application version and platform may be transmitted for that purpose. 13. Changes to this Policy We may update this Policy. The current version is published with the Application and/or on the Tinpul website. Material changes may also be communicated in the Application or via support channels. Continued use after changes take effect means acceptance of the updated Policy, unless applicable law requires otherwise. 14. Contact Privacy and personal data requests: Email: support@tinpul.ru Website: https://tinpul.ru TINPUL FORGE · Tinpul