Privacy questions

Last updated September 1, 2026

Privacy, without the fog.

Powerplant makes your team’s coding-agent work visible inside your organization. This policy explains what Forestwalk Labs collects to provide that service, how we use it, and the choices you have.

1. Who we are

Powerplant is a product of Forestwalk Labs, Inc. (“Forestwalk,” “we,” “our,” or “us”), a company incorporated in British Columbia, Canada. This policy applies to people who visit powerplant.sh, ask us about Powerplant, or use the Powerplant service.

We are an early-stage company, but we take the principles behind major privacy laws seriously, including Canada’s PIPEDA, the EU GDPR, and California’s CCPA/CPRA where they apply. Questions can be sent to founders@forestwalk.ai.

2. The short version

  • We collect the information needed to run, secure, support, and improve Powerplant.
  • Powerplant is transparent inside your organization. Captured work is not public and is not shared across organizations.
  • We do not sell personal information or use third-party advertising technology.
  • We use a limited set of service providers to operate Powerplant; they are listed below.
  • You can ask to access, correct, export, or delete personal information associated with you.
  • Powerplant is intended for people aged 16 and older.

3. Information we collect

CategoryExamplesWhy we need it
Account and organizationName, email address, Google sign-in identifier, organization, role, and membershipCreate and secure accounts; keep access within your organization
Agent-session contentRedacted conversations, tool activity, and references to files or commands in allowlisted repositoriesProvide shared team context through Powerplant
Collaboration dataRooms, comments, decisions, instructions, and responsibility for durable actionsSupport collaboration and preserve team context
Connected-service dataInformation received from services your organization connects, such as coding agents or source-control providersImport the work your organization chooses to make available to Powerplant
Usage and derived dataFeature use, search excerpts, summaries, embeddings, measured usage, costs, and friction patternsOperate, improve, and understand the service
Diagnostics and securityScrubbed logs, error reports, audit events, device information, and redacted MCP query textKeep Powerplant reliable, investigate problems, and protect the service
Website and communicationsPages viewed, referral information, demo requests, support messages, and email preferencesUnderstand site use and respond to you

Sensitive information. Powerplant is not designed for regulated personal information such as health records, biometric identifiers, payment-card details, or government identification numbers. Do not intentionally include that information in agent sessions or other content you share with Powerplant unless your organization has confirmed it has the right safeguards and authority to do so.

4. How we use information

  1. Provide Powerplant – authenticate people, capture permitted sessions, answer requests, and make team context available inside the correct organization.
  2. Operate and improve the service – measure performance, understand feature use, debug problems, and develop better product experiences.
  3. Evaluate model quality and safety – assess relevant inputs and outputs to test, debug, and improve Powerplant. We do not use customer content to train our own general-purpose AI models.
  4. Communicate with you – respond to questions, arrange demos, provide service notices, and send product updates where permitted.
  5. Protect people and the service – prevent abuse, enforce our terms, maintain audit records, and respond to valid legal requests.

Where the GDPR applies, our legal bases may include performing a contract, pursuing legitimate interests in operating and securing Powerplant, complying with legal obligations, and consent where required.

5. Service providers and sharing

We use service providers to run Powerplant. They may process information only for the purpose of providing their services to us, subject to their agreements and applicable law.

ProviderPurposeInformation involved
RenderWeb, API, and pipeline hostingRequests and transient application processing
SupabaseDatabase, authentication, and realtime servicesAccounts, organization data, session metadata, and derived records
CloudflareRaw-data storageRedacted raw session objects
Anthropic and OpenAIModel and embedding processingRelevant excerpts, prompts, and derived inputs
BraintrustAI tracing and cost debuggingModel prompts and results
SentryError and performance monitoringScrubbed diagnostics
Better StackOperational logs and uptime monitoringScrubbed application and infrastructure telemetry
PostHogProduct analyticsIdentifiers and bounded product events; browser session replay is off
FathomWebsite analyticsWebsite visits and referral information
LinearProduct feedbackFeedback text, organization name, and sender email address
GoogleUser sign-inBasic account identity and profile information

Customer-selected integrations, such as coding-agent or source-control providers, remain under your organization’s relationship with those providers. We may also disclose information if required by law, to protect rights or safety, or as part of a corporate transaction with appropriate safeguards.

We do not sell personal information. We do not share captured work across Powerplant organizations.

6. International transfers

Forestwalk is based in Canada and many of our service providers operate in the United States or other countries. Your information may therefore be processed outside the place where you live, where privacy laws may differ. Where required, we rely on contractual protections or other lawful transfer mechanisms provided by our vendors.

7. Cookies and analytics

We use technologies needed to operate the site and service, along with limited website and product analytics. We do not use third-party advertising technology or sell browsing activity for targeted advertising.

8. Retention and deletion

We keep information for as long as needed to provide Powerplant, maintain shared organizational history, meet legal obligations, resolve disputes, and protect the service. Redacted MCP query text expires after 365 days. Other retention periods depend on the type of information and the status of your organization.

An organization owner can request deletion. Today, organization deletion is a verified, human-run process that removes live organization records, known raw transcript objects, derived snapshots, encrypted provider credentials, and organization-tagged AI traces. Content-free security audit records may remain with their organization link removed.

We are still verifying exact deletion-response and backup-expiry periods for launch. We will publish specific timelines once we can support them reliably.

9. Your rights

Depending on where you live, you may have the right to:

  • ask for access to or a copy of personal information associated with you;
  • correct inaccurate or incomplete personal information;
  • request deletion or restriction of certain processing;
  • object to certain uses or withdraw consent where processing relies on consent;
  • opt out of marketing communications; and
  • complain to a privacy regulator.

To make a request, email founders@forestwalk.ai. We may need to verify your identity and coordinate with your organization’s owner. Some rights are subject to legal exceptions.

10. Security

We use technical and organizational safeguards designed to protect personal information, including encryption in transit, encrypted connected-service credentials, organization-bounded access controls, source redaction, separated data stores, and restricted production access. No system is perfectly secure.

For more detail, including current limitations and our pre-launch posture, read the Powerplant security overview.

11. Age limit

Powerplant is intended for people aged 16 and older. We do not knowingly collect personal information from children under 16. If you believe a child has provided personal information, contact us so we can investigate and delete it where appropriate.

12. Changes to this policy

We may update this policy as Powerplant develops. We will change the date at the top of this page and, for material changes, provide additional notice where appropriate. Your continued use of Powerplant after a change is subject to the updated policy.

13. Contact

Questions, concerns, or privacy requests can be sent to founders@forestwalk.ai.