Security

Last updated

Jobbot Inc operates the directory at forage.bot and the products it lists. This is a portfolio overview, not a data processing agreement, security certification, or service-level agreement. Product-specific notices and any separately agreed contract describe the relevant service. Questions can be sent to hello@forage.bot.

Different products have different data flows

The directory handles browsing, feedback, and contact messages; it has no checkout. Individual products include one-time purchases, subscriptions, developer accounts, and usage-based services. Some return a file, others maintain a hosted workspace or scheduled service. There is no single account, authentication, or retention model that describes all of them.

Product inputs can include text, URLs, documents, repository metadata, and personal or business details. Some products process sensitive or confidential information as part of their stated purpose. Read the product-specific input rules and privacy notice rather than assuming that all inputs are public or that a form's acceptance proves lawful processing. Do not send unnecessary sensitive records through the directory's feedback or support channels.

Hosting, storage, and access

The directory and product websites use hosted infrastructure. Many product records and generated files use Vercel Blob; API account and usage records use a Neon database. Email and support issues are held by the relevant providers below. Storage, access controls, and deletion behaviour must be checked for the particular product and data type. A hosted record should not be assumed private merely because it is absent from a search engine.

Many order and download links contain an access token or an identifier that grants access to whoever holds it. Other services use API keys or account authentication. Keep private links and keys confidential. Contact the product's support address if a link needs revocation; removing a link does not recall downloaded copies or establish that all underlying records have been deleted.

Hosted encryption and transport protection are not end-to-end encryption that prevents service operators or providers from accessing data. The directory's mail poll is configured to use TLS for IMAP, and its issue-filing integration uses HTTPS. We do not present this as an audit of every deployed connection, storage configuration, or HTTP security header. Provider capabilities do not by themselves prove that a particular application is configured safely.

Payment information

Product sites using Stripe Checkout direct card entry to Stripe's hosted fields. Our applications use payment identifiers and payment events rather than collecting raw card details in their own forms. Some products also place intake details in payment metadata, which can remain in payment and event records after generation. Read the relevant product notice before providing personal or confidential input.

A marketplace-billed or machine-payment service can have a different payment flow. Its billing terms must describe that arrangement. A payment provider's certification does not certify Jobbot Inc or establish that all our applications satisfy a security standard.

AI processing and model-provider practices

Some products use AI models through OpenRouter; others generate their output without a model. Support work can also involve AI-assisted tools. A request may include submitted content, selected extracts, or derived facts, depending on the product. AI processing can occur in a free preview before payment, not just after an order.

OpenRouter's privacy policy, reviewed on September 13, 2026, states that OpenRouter does not use inputs or outputs for its own model training and that some upstream model providers may use them for training or improvement. This is a statement about that provider's policy, not proof of our account configuration or a particular request's routing, retention, or contractual terms.

We make no verified portfolio-wide no-training or zero-retention assurance for all providers that may process customer content. A general provider-policy link is not a configured restriction or a customer-specific agreement. If your use requires such restrictions, confirm that they are supported and agreed before sending that data. A warning to minimise input does not replace our applicable privacy obligations.

Providers and subprocessors

This shared inventory describes providers used across the portfolio; not every provider receives every customer's information. Usage counts and assurance references in the inventory are historical implementation notes and may require re-verification. The date of this wording review is not a fresh audit of every entry, provider contract, or certification.

The word subprocessor does not assign every provider the same legal role. Depending on the activity, a provider may act as a processor, subprocessor, or independent controller. For example, the Stripe data processing agreement distinguishes its processor activities from its own controller activities. Our responsibilities for our processing remain with us.

Vercel

Hosts the directory and product websites, runs request handlers and order processing, and stores product records and generated files in Blob where used.

Data described in the inventory

  • Information sent to our hosted request handlers, including product inputs, feedback, and support-email content handled by mailbox polling
  • Stored order records, which can include email addresses, intake details, payment identifiers, and generated files
  • Request information and application diagnostics, which can include IP addresses, browser information, requested URLs, and details included in logged errors

Current provider reports and certifications were not independently reviewed for this inventory. Privacy policy · Provider data processing terms

Stripe

Processes payments, billing records, and refunds for products using Stripe.

Recorded usage scope: Stripe-backed product checkout and API credit top-ups; the root directory has no checkout.

Data described in the inventory

  • Card details entered into Stripe-hosted Checkout fields, rather than our own card-entry form
  • Customer email, purchase details, payment identifiers, and payment events used by the application
  • Some products attach intake details and a visit identifier to payment metadata, linking payment and order records to earlier visits

Current provider reports and certifications were not independently reviewed for this inventory. Privacy policy · Provider data processing terms

OpenRouter

Routes model requests and responses for text generation, analysis, image generation, and image description.

Recorded usage scope: AI-assisted product features. Configured model families include OpenAI, Anthropic, Google, and xAI; actual upstream inference providers depend on routing and settings, not just the model name.

Data described in the inventory

  • Prompts containing submitted content, selected extracts, or derived facts, depending on the feature; these are not necessarily a verbatim copy of the intake
  • Images extracted from submitted documents for description, generated images submitted for judging, and model outputs returned through OpenRouter
  • Model selection and request metadata, including a product identifier where the application sends it
  • Requests pass to upstream inference providers. OpenRouter's linked privacy policy says some providers may retain inputs and outputs or use them for training or improvement. This is not a portfolio-wide no-training or zero-retention guarantee

Current provider reports and certifications were not independently reviewed for this inventory. Privacy policy

Resend

Sends product delivery, account, and support email where implemented.

Data described in the inventory

  • Sender and recipient addresses, subject, and message body supplied by the application
  • Order and download links, including signed links or access tokens, and any product content included in the message
  • Attachments where supplied, such as Storypic's generated image; its delivery flow also includes order and download links

Current provider reports and certifications were not independently reviewed for this inventory. Privacy policy · Provider data processing terms

Migadu

Hosts the contact and product mailboxes that receive email sent to us.

Data described in the inventory

  • Incoming email, including sender and recipient addresses, subject, body, headers, and attachments
  • Mailbox connection and authentication information used by our inbound-email polling

Current provider reports and certifications were not independently reviewed for this inventory. Privacy policy

GitHub

Hosts source code and internal issues used to handle feedback and support messages.

Data described in the inventory

  • Feedback text, selected type, and an optional reply email; forwarded support issues can include sender, recipient, subject, message text, and Message-ID
  • Feedback context, including the submitted URL with any query parameters or fragments, page title, viewport, browser user agent, session identifier, and optional product context
  • The feedback session identifier is not anonymous when linked to identifying message content or an email address
  • Attachment names, types, and sizes recorded by the reviewed inbound-email workflow; that issue builder does not copy attachment bytes

Current provider reports and certifications were not independently reviewed for this inventory. Privacy policy

Neon

Hosts the API service's Postgres database for accounts, billing, API activity, feedback, webhooks, and product visit attribution.

Recorded usage scope: The API service at api.forage.bot and product sites that submit events to it; this does not describe every root-directory visit.

Data described in the inventory

  • API account email addresses and account state, email verification tokens, sign-up IP addresses, and email-send records
  • Credit top-up amounts and payment identifiers, API usage records, and account and key activity records
  • Registered webhook URLs, event subscriptions, and signing secrets
  • API feedback messages, optional email, and submitted context stored in activity records
  • Visit and purchase event fields, including product, channel, campaign, external identifiers, and metadata. The random visit identifier is not anonymous: it can link to payment and order records containing an email address

Current provider reports and certifications were not independently reviewed for this inventory. Privacy policy · Provider data processing terms

Unkey

Issues, verifies, and manages credit balances for customer API keys.

Recorded usage scope: Keys are issued by the API service; shared authentication also verifies them in product APIs using that integration.

Data described in the inventory

  • API keys sent for verification, key-management identifiers, enabled state, and credit amounts supplied by the application
  • An internal account identifier used when creating keys; it can be linked to an email address in our API account database and is not an anonymisation mechanism
  • The reviewed create-key and verify-key payloads do not include email or product input fields. That limited payload scope does not establish the contents of provider-side request logs

Current provider reports and certifications were not independently reviewed for this inventory. Privacy policy

Porkbun

Provides domain registration and DNS management for our domains.

Data described in the inventory

  • Our DNS-management API sends authentication credentials, domain names, and DNS record fields such as name, type, target, and TTL; these payloads do not include order or feedback fields
  • Provider infrastructure processing is separate from those payloads. Porkbun's linked privacy policy describes account, domain, and usage information; DNS-query logs and their retention were not independently reviewed here

Current provider reports and certifications were not independently reviewed for this inventory. Privacy policy

Google

Search Console supports public-page indexing and search reporting. Google Gemini models are also selected through OpenRouter for some text and image features.

Recorded usage scope: Search submission tooling and features including Geo Audit model probes, Brand Pack and Storypic image generation, and Docaccess image descriptions. Deployed model overrides and actual serving providers were not independently reviewed.

Data described in the inventory

  • Search Console receives site, sitemap, and page URLs in indexing and reporting requests; public pages may contain information deliberately published through a product
  • Where Google serves the selected model through OpenRouter, requests can contain prompts or images, including document images used by Docaccess. Outputs return through OpenRouter; this use is not limited to marketing-page addresses

Current provider reports and certifications were not independently reviewed for this inventory. Privacy policy

Reddit

Provides an advertising campaign and reporting API integration.

Recorded usage scope: Recorded as a dormant advertising capability, not evidence of ads being served. Active advertising has not been confirmed in this review; campaign creation is paused and activation is a separate step.

Data described in the inventory

  • When the management or reporting tools run, they send account authentication, campaign or reporting parameters, and any supplied advert content, destination URLs, budgets, and audience settings
  • If advertising is activated, Reddit's own handling of ad interactions also applies under its privacy policy; the management API payloads do not establish the full scope of that processing

Current provider reports and certifications were not independently reviewed for this inventory. Privacy policy

Upstream model providers and product-specific connections can receive data in addition to the companies named here. A provider's own service chain may include further processors. This page is not an exhaustive recipient list for a particular customer's processing instruction.

Connected services and public content

Products that connect to customer-selected services can read or send information using the permissions supplied for that integration. Disconnecting may stop future requests, but does not necessarily delete information already copied, delivered, or retained. Refer to the product's controls and the connected service's own terms.

Public pages may be indexed by search engines. Information deliberately published through a product may then be copied by others. Submission to a form, public-page removal, and deletion of all copies are different actions; a takedown control is not a promise to erase search results or third-party copies.

Some product sites use first-party visit identifiers to relate visits to purchases. That does not by itself make storage exempt from consent requirements or make the records anonymous. The root directory's separate feedback-session storage is described in its Privacy Policy.

Retention, access requests, and deletion

Retention differs by product and record type. Inputs, generated artifacts, payment metadata, support issues, mail, and provider logs may have different lifetimes. Link expiry, an order's completion, account closure, or cancellation does not establish deletion from every system. We do not claim a verified portfolio-wide deletion or tax-record anonymisation process.

Request access, correction, or deletion through the product's support address or hello@forage.bot. There is no central self-service tool that completes every request across all providers. Requests need appropriate identification of records, legally permitted verification, and assessment of any lawful retention exception. Missing automation does not suspend statutory response deadlines, required explanations, or complaint and appeal rights.

Data-processing agreements and international transfers

We do not publish a standard customer DPA. If you need us to process personal information on your organisation's behalf, contact us before sending it so the service's suitability and any required agreement can be established. Sending a request does not mean that an agreement has been accepted or that a particular security requirement is met.

A required agreement must describe the subject matter, duration, nature and purpose of processing, the types of information and categories of people concerned, and each party's responsibilities. It must address instructions, confidentiality, provider authorisation, safeguards, assistance with individual rights and compliance duties, incident obligations, return or deletion arrangements, and audit and inspection rights required by law. Links to vendor DPAs are not a Jobbot-customer DPA and do not establish that each relevant term has been executed or applies to your use.

Processing may occur in the United States and other countries used by providers. We do not offer a general residency commitment or assert that a named transfer mechanism covers every flow. The applicable locations, recipient roles, and legally required transfer safeguards need to be established for the relevant service. Merely using a site or acknowledging this page is not transfer consent.

Updating this page's date is not the same as giving any required advance notice of a new subprocessor, obtaining authorisation, or honouring an objection right. This overview does not amend an existing agreement or displace a legal obligation.

Security evidence and reporting

We do not offer a SOC 2 report or ISO 27001 certificate for Jobbot Inc. This page does not establish a verified portfolio-wide history of administrative access, restore testing, independent security testing, or a formal incident-response programme. Do not infer those controls from a vendor's reports or our automated product tests.

Live reachability information is available at status.forage.bot; it is not a measured uptime commitment or evidence of data-security compliance.

Report a suspected security problem to hello@forage.bot, describing the affected product and a minimal reproduction without other people's data or live credentials. Do not access, alter, or retain anyone else's data while investigating. We do not offer a paid reporting programme or a contractual response-time guarantee on this page. Applicable duties to investigate and provide required incident notices remain.