Privacy Policy
Last updated: July 20, 2026
This Privacy Policy explains how PriorForge ("we," "us," or "our") collects, uses, and protects your information when you use priorforge.com and our products and services (the "Services"). PriorForge is operated as a sole proprietorship. We keep data collection deliberately minimal: we collect what we need to deliver briefs and subscriptions, and nothing more.
The Services are offered for business and professional use, including to law firms and other IP professionals. The information described below is, in the ordinary course, business contact and transaction information tied to your professional use of the Services — not sensitive personal information about you as a consumer. This Privacy Policy, and your and our respective rights and obligations under it, are governed by the same Terms of Service (including its dispute resolution, arbitration, and limitation of liability provisions) that govern your use of the Services generally; see Sections 11 and 13 below.
1. Information We Collect
- Email address — when you request a sample brief, make a purchase, subscribe to a feed, or contact us.
- Payment information — collected and processed by Stripe, our payment processor. Your full card details go directly to Stripe and never touch our servers. We receive only limited transaction metadata from Stripe (such as the amount, date, last four digits of the card, and payment status) needed to fulfill your order and handle refunds.
- Download token usage — when we issue a download link or access token for a brief or feed, we record when and whether it was used. This supports order fulfillment, fraud prevention, and our refund policy (which depends on whether a brief has been downloaded).
- Basic technical data — standard server logs may include IP address, browser type, and pages requested, used for security and to keep the Services running.
- Correspondence — if you email us, we keep the message so we can respond and maintain a record of the conversation.
We do not collect sensitive personal information, and we do not run third-party advertising or analytics trackers on the site.
2. How We Use Your Information
- To deliver purchased briefs and subscription feeds to you;
- To process payments, subscriptions, cancellations, and refunds (via Stripe);
- To send transactional emails about your orders, downloads, and account;
- To respond to your questions and support requests;
- To prevent fraud, abuse, and unauthorized sharing of paid content;
- To comply with legal obligations (such as tax and accounting records); and
- With your consent, to send occasional product updates — you can opt out at any time via the unsubscribe link or by emailing us.
3. Payment Processing (Stripe)
All payments are handled by Stripe, Inc. Stripe is a PCI-DSS-certified payment processor, and your card information is transmitted directly to Stripe over an encrypted connection. We never see or store your full card number. Stripe's handling of your data is described in the Stripe Privacy Policy.
4. Cookies
We keep cookies to a minimum. We do not use advertising or cross-site tracking cookies. Our infrastructure provider, Cloudflare, may set a small number of strictly functional cookies (for example, for security, bot protection, and load balancing) that are necessary for the site to operate. If we ever add cookies beyond what is strictly necessary, we will update this policy first.
5. How We Share Information
We do not sell your personal information. Ever. We share information only with:
- Service providers that help us operate — currently Stripe (payments), Cloudflare (hosting/security infrastructure), and our email delivery provider — each of which processes data only as needed to provide their service;
- Legal authorities, if required by law, subpoena, or to protect our rights or the safety of others; and
- A successor, if the business is sold or transferred, in which case this policy would continue to apply to your data.
6. Data Retention
We retain your information only as long as needed for the purposes described above:
- Transaction records — kept as long as required for tax, accounting, and legal purposes (typically 7 years);
- Email addresses and account data — kept while you have an active relationship with us (active subscription or recent purchases), and deleted upon verified request or after extended inactivity;
- Download token logs — kept for as long as relevant to fulfillment, refunds, and fraud prevention;
- Server logs — rotated and deleted on a short cycle.
7. Your Rights
You may at any time:
- Access — request a copy of the personal information we hold about you;
- Correction — ask us to correct inaccurate information;
- Deletion — ask us to delete your personal information (we may retain transaction records we are legally required to keep);
- Opt out — unsubscribe from non-transactional emails at any time.
To exercise any of these rights, email [email protected]. We will respond within 30 days and may need to verify your identity before acting on a request.
8. Data Security
We use industry-standard measures to protect your information, including TLS encryption for all traffic, minimal data collection, and reliance on established providers (Stripe, Cloudflare) for the most sensitive operations. By design, the most sensitive data — your payment details — never reaches our servers at all.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. To the maximum extent permitted by law, our liability for any unauthorized access to, or disclosure of, your information is subject to the same disclaimers, exclusions, and liability cap set out in Section 11 (Limitation of Liability) below and in our Terms of Service. We are not responsible for the independent acts or failures of third-party service providers (including Stripe and Cloudflare), each of which maintains its own security practices and policies.
9. Security Incident Notification
If we become aware of a security incident affecting your personal information in a way that triggers a legal notification obligation, we will notify affected individuals and any required regulators or authorities as required by applicable law, using the timeline and method that law prescribes.
10. State and International Privacy Rights
Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA/CPRA) or the EU/UK General Data Protection Regulation (GDPR) — for example, rights to access, delete, correct, or port your data, or to opt out of certain uses. We do not sell personal information and do not engage in cross-context behavioral advertising, which addresses the primary opt-out rights these laws provide. To exercise any right available to you under applicable law, contact us as described in Section 7; we will honor valid requests to the extent required by the law that applies to you and may decline or limit requests where an exemption applies.
11. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, AND REGARDLESS OF THE LEGAL THEORY ASSERTED — WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, STATUTE, OR OTHERWISE — PRIORFORGE'S LIABILITY ARISING OUT OF OR RELATING TO THIS PRIVACY POLICY OR OUR HANDLING OF YOUR INFORMATION IS SUBJECT TO THE SAME EXCLUSIONS OF INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, AND PUNITIVE DAMAGES, AND THE SAME AGGREGATE LIABILITY CAP, SET OUT IN THE LIMITATION OF LIABILITY SECTION OF OUR TERMS OF SERVICE, WHICH IS INCORPORATED HERE BY REFERENCE.
As in the Terms of Service, this does not limit liability for PriorForge's own gross negligence, willful misconduct, or fraud, or for any other liability that cannot be limited or excluded as a matter of law.
12. No Third-Party Beneficiaries
This Privacy Policy is for the benefit of you and PriorForge only. If you are a law firm or other professional whose own clients' information passes through or is referenced in your use of the Services, this policy does not create any right for those clients to bring a claim against PriorForge; any obligations you owe to your own clients regarding their information are yours alone to manage under your own client agreements and professional obligations.
13. Dispute Resolution
Any dispute arising out of or relating to this Privacy Policy or our handling of your information is a "Claim" for purposes of, and is subject to, the binding individual arbitration, class action waiver, and dispute resolution provisions of our Terms of Service, which are incorporated here by reference.
14. Children's Privacy
The Services are intended for business and professional use and are not directed to children under 13 (or the applicable age of digital consent). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, for material changes, make reasonable efforts to notify you (for example, by email to subscribers or a notice on the website). Continued use of the Services after changes take effect constitutes acceptance of the updated policy.
16. Governing Law
This policy is governed by the laws of the State of Georgia, United States, without regard to its conflict-of-laws principles, consistent with our Terms of Service.
17. Contact
For privacy questions or requests, email [email protected]. A mailing address is available on request.