Privacy Policy
Last updated: July 12, 2026
Forgetwell is operated by Bluelight Inc. ("we", "us", or "our"). We are committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding your data. If you apply for a job, Section 9 is also our Applicant Privacy Notice.
1. Information We Collect
We collect the minimum information necessary to provide the Forgetwell service:
- Account information: Your email address, display name, and a securely hashed password when you register. If you sign in with Google, we receive your email, name, and Google account ID. If you sign in with Apple, we receive your name (on first sign-in) and your email address (or, if you choose "Hide My Email," Apple's private relay address) along with a stable Apple user identifier.
- Notes and tags: The content you create within Forgetwell, including notes, tags, and your organizational preferences.
- Uploaded images: Images you attach to your notes are stored on our servers.
- Connected-app authorization: When you connect ChatGPT or another MCP client, we store the registered client, permissions you approve, and hashed authorization tokens needed to maintain and revoke that connection.
- Service and security information: Request timestamps, network address, browser or device information, and actions taken in your account may appear in server logs or time-limited security audit records. We use these records to operate, protect, and troubleshoot the service.
2. How We Use Your Information
We use product-account information to:
- Provide, maintain, and improve the Forgetwell service
- Authenticate your identity and secure your account
- Send account-related emails (verification, password reset) when applicable
We do not use product data for advertising or advertising profiles. Job-application information is handled only as described in Section 9.
3. Data Storage and Security
Core account and note data is stored in a SQLite database on our server. Uploaded files are stored in server-side file storage, and operational backups contain the database and files. Job resumes use separate private storage as described in Section 9. We take reasonable measures to protect your information, including:
- Passwords are hashed using bcrypt and never stored in plain text
- All connections are encrypted with HTTPS/TLS
- Authentication uses signed JWT tokens
- The server is hardened with firewall rules, SSH key authentication, and automatic security updates
4. Data Sharing
We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising. Your notes and tags are private to your account except when you deliberately connect a client and request an action that sends selected data to it. Uploaded image URLs are link-private: anyone who obtains a specific image URL can fetch that image.
We disclose only the information necessary to service providers that help us operate Forgetwell, such as infrastructure, authentication, and email-delivery providers; to Google or Apple when you choose their sign-in service; or when required by law, needed to protect rights and safety, or involved in a corporate transaction. Service providers may use the information only to provide their contracted service to us. Applicant-specific disclosures are described in Section 9.
5. Cookies and Tracking
Forgetwell does not use cookies for tracking or analytics. We store your authentication token and theme preference in your browser's local storage to keep you logged in and remember your settings. During MCP authorization, the Forgetwell authorization domain uses an HttpOnly session cookie that expires after 30 minutes so login and consent can complete.
To make the web app useful offline, browser storage also keeps account-scoped copies of notes and tag details that the server has returned, plus edits waiting to sync. These local copies can include complete note content. Signing out or switching accounts detaches that account's copy from the visible app but does not immediately delete it, so the same account can recover offline notes and pending edits when it returns. A different account cannot display or upload that copy. You can remove these local copies by clearing Forgetwell's site data in your browser; normal server-side export and account-deletion controls are described below.
6. Data Export and Deletion
You can export a JSON copy at any time using the export feature in the app. The JSON export includes your notes, trash, tags, and settings. Uploaded files are not bundled in the export. You can delete your account from Settings, or contact us if you cannot access it. Account deletion removes the account and its associated notes, tags, settings, uploads, and product audit records. A job application is a separate recruiting record: deleting the account removes its live account link, but the application follows the retention and deletion rules in Section 9.
7. Third-Party Services
If you choose to sign in with Google, Google's privacy policy applies to the authentication process. We only receive your basic profile information (email, name, account ID) and do not access any other Google data.
If you choose to sign in with Apple, Apple's privacy policy applies to the authentication process. We only receive your name (on first sign-in), email address, and a stable Apple user identifier. You may use Apple's "Hide My Email" feature, in which case we receive a private relay address instead of your real email; we do not attempt to unmask it.
ChatGPT and other MCP clients. If you choose to connect Forgetwell to ChatGPT or another compatible AI assistant, the client receives only the Forgetwell information needed for the action you request. Depending on the tool you approve, this can include note content or snippets, note and short IDs, tags, colors, created and updated times, an opaque revision used to prevent conflicting updates, settings, and trash entries. Markdown note content can include link-private uploaded-image URLs; anyone, including a connected client, that receives a specific URL can fetch that image. The client may also send the specific note content, search terms, tags, colors, or IDs needed to carry out your request. Forgetwell does not request your full chat history, and your Forgetwell password is submitted only to the Forgetwell authorization page.
OpenAI or the provider of the MCP client processes the information it receives under its own terms and privacy policy. Forgetwell uses that transfer only to perform the tool action you requested; we do not use it for advertising or profiling. Authorization codes expire after 10 minutes, access tokens after one hour, and refresh tokens after 30 days unless rotated or revoked sooner; expired authorization records are pruned daily. Client registration and security records are retained while needed to operate and protect the connection. You can disconnect in the client, revoke its access where that control is offered, delete your Forgetwell account, or contact us for help.
Operational metrics. Our hosted service records aggregate request or tool name, success or error outcome, count, and latency to detect outages and reliability problems. These metrics exclude note content, tags, note and account identifiers, authorization tokens, network addresses, and device information. Hosted metrics are retained for up to 90 days and are not used for advertising, behavioral profiling, or product analytics.
8. Children's Privacy
Forgetwell is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13.
9. Applicant Privacy Notice
Who handles the application. Bluelight Inc. is the organization responsible for application data submitted at forgetwell.com/jobs. You can contact us at support@bluelight.ventures.
What we collect. We collect the role, contact email, message, resume file and filename you choose to submit, submission time, and the identity of the Forgetwell account used to apply. We also store the Applicant Privacy Notice version shown to you, timestamps for the required processing choices, whether and when you opted into or withdrew from consideration for future roles, and whether an authorized administrator has placed the record on legal hold. A related security audit record contains the account identifier, network address, browser information, request path, result, and time, but not the application text or resume. Administrators may add internal recruiting tags while reviewing an application. A Forgetwell account is required to reduce abuse and provide an authenticated application history; the account itself is handled under the other sections of this policy.
Why we use it. We use application data to receive and evaluate your application, communicate with you, administer recruitment, prevent abuse, comply with recordkeeping duties, and establish or defend legal claims. A human reviews applications; we do not use automated hiring decisions or keyword filters. We rely on your consent where local law requires it and otherwise on steps you ask us to take before a possible employment relationship, our legitimate recruiting and security interests, and applicable legal obligations.
Who receives it. Access is limited to authorized members of our hiring team and service providers that support secure hosting, storage, backup, and email delivery. An email-delivery provider receives your contact email and the role title to send an application receipt. We may also disclose records when legally required or necessary to protect legal rights. We do not sell application data or use it for advertising.
Processing in the United States. Bluelight Inc. receives application data in the United States over HTTPS and processes and stores it there for the purposes above. This includes the categories listed under “What we collect.” Before submission, the form separately asks for consent to collect and use the application data and to process it in the United States. You may refuse or later withdraw consent, but we cannot receive or continue processing an application without the information needed to evaluate and contact you. Contact us to exercise that choice. Withdrawal does not affect processing already lawfully completed, and we may retain limited records where law or a legal hold requires it.
Retention and deletion. We schedule an application and its resume for deletion when it reaches two years after submission so we can complete the hiring process and document our decision; a daily sweep removes records that have reached that point. We consider you for a different role during that period only if you separately opt in on the application form. We may keep a limited record longer when an applicable law, investigation, or legal claim requires it; operational backups and pre-migration snapshots age out under our backup rotation and are used only for recovery. You can ask us to delete an application sooner, withdraw it from future consideration, or correct it by emailing the address above. We may verify your identity before acting on a request.
Your choices and rights. Depending on where you live, you may have rights to know what we hold, obtain a copy, correct inaccurate information, request deletion, restrict or object to processing, withdraw consent, or complain to your privacy regulator. Contact us to make a request. These rights may be limited by recruitment recordkeeping and legal-claims obligations.
Please minimize sensitive information. Do not include government identification numbers, financial account information, passwords, medical or biometric information, or other sensitive personal information in a resume or message unless we specifically request it and it is necessary for the role or an accommodation.
10. Browser Extension
The Forgetwell browser extension is a client for your own Forgetwell account. It reads the current page's title, address, your text selection, and page metadata (such as Open Graph tags) only when you act — when you open the extension or use its save shortcut — so it can create a note. It has no always-on access to the pages you browse. The Save page composer offers a default-off "Save page content" choice. Only after you select that choice and press Save does the extension read the page's browser-rendered visible body text; this can include navigation, footer, and other visible text beyond the main article. Cancel and the save shortcut never read the full body. If you turn on "rich link previews," it also downloads the page's preview image to store with the note; this requires your permission to read images from the sites you save, which you grant explicitly.
If you run the one-time bookmark import, the extension requests read-only bookmark access and reads your browser bookmarks' titles, addresses, and folder names to create notes. It never modifies or deletes your browser bookmarks. Notes you save through the extension are sent to your Forgetwell account over HTTPS; any visible page text you explicitly include becomes normal note content and follows the same storage, search, export, deletion, and configured embedding behavior. The extension performs no analytics or tracking and shares nothing with third parties beyond the sign-in process described above.
The extension stores account- and server-scoped saves waiting to sync so closing its popup or losing the network does not discard your deliberate action. If you choose a replacement Bookmark preview image, its processed image bytes are also kept in that account-scoped extension storage until the exact note change is accepted or you explicitly discard the saved copy. It also keeps a bounded, best-effort cache of recently retrieved notes for offline recall; very large notes may not be cached. Signing out or switching accounts detaches those local copies from the visible extension instead of exposing them to another account. Returning to the same server and account can resume pending saves and reuse its cache. Synced queue entries and their staged images are removed, older cache entries are evicted as space is needed, and you can remove the remaining copies by clearing the extension's local data in your browser.
So that the extension and the Forgetwell website share one login, a small script on your Forgetwell site reads the sign-in token the website stores in your browser and mirrors it to the extension (and back), keeping the two in step when you sign in or out. This runs only on your Forgetwell site, accesses nothing else on the page, and sends the token to no one — it stays in your browser.
11. Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated "last updated" date. If a material change requires notice or consent under applicable law, we will provide it before applying that change to your information.
12. Contact
If you have questions, want to exercise a privacy right, or want to contact us about your data, email support@bluelight.ventures. For a job-application request, include “Applicant privacy request” in the subject so it reaches the right workflow.