logo

Privacy Policy

Effective Date: Sep 10, 2026

1. INTRODUCTION

1.1 Purpose and Scope

This Privacy Policy explains how Forge Blue Inc., a Delaware corporation doing business as OJAI ("Forge Blue", "OJAI", "we", "us", or "our"), collects, uses, discloses, and safeguards information when you access or use the OJAI platform, websites, applications, and related services (collectively, the "Services"). This Policy applies to all users globally, including organizational customers and individual users.

1.2 Contact Information

For questions or requests regarding this Privacy Policy, contact: Forge Blue Inc., a Delaware corporation d/b/a OJAI, Principal Place: 12117 NW 47th Manor, Coral Springs, FL 33076, United States; Registered Agent and Legal Notice Address: 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, United States; Telephone: 407-222-7227; Email: info@ojai.global for general and legal notices; privacy@ojai.global for privacy rights requests; support@ojai.global for support; accessibility@ojai.global for accessibility. For copyright notices under the Digital Millennium Copyright Act (DMCA), see Terms of Service Section 7; DMCA Agent: Forge Blue Inc., Attn: DMCA Agent – Germain Bebe, President, 251 Little Falls Drive, Wilmington, DE 19808, Telephone: 407-222-7227, Email: info@ojai.global.

1.3 Relationship to Terms of Service

Capitalized terms not defined herein have the meanings given to them in the Terms of Service. By creating an account with affirmative checkbox acceptance, or by using the Services where permitted, you agree to the terms of this Privacy Policy and the accompanying Terms of Service.

2. CATEGORIES OF DATA WE COLLECT

2.1 Data You Provide Directly

(a) Account and Profile Data: name, email address, organization, role, password (hashed), and settings. (b) Billing Data: payment method tokens, billing address, and tax information processed via our payment processor Stripe. We do not store full payment card numbers. (c) Content and User-Generated Content (UGC): text, photos, videos, audio files, datasets, maps, event listings, resource files, comments, and other user-generated content you upload, including AI-generated content you submit, subject to Terms of Service Sections 5.4 (Sensitive Content) and 8.3. (d) Sensitive Content: where you designate content as Sensitive Content (e.g., Indigenous Knowledge, precise endangered species locality data, culturally significant sites), such content is excluded from marketing use and model training without separate opt-in consent and is handled as private-by-default with coordinate generalization and access logging per Terms of Service Section 5.4. (e) Communications: support requests, feedback, surveys, and correspondence.

2.2 Data Collected Automatically

(a) Usage Data: activity logs, feature interactions, referring URLs, timestamps, and session information. (b) Device/Technical Data: IP address, browser type, device identifiers, operating system, language, and approximate location derived from IP address. (c) Cookies and Similar Technologies: cookies, web beacons, pixels, local storage, and software development kits (SDKs) used for core functionality, analytics, and fraud prevention (see Section 6).

2.3 Data from Third Parties

(a) Single Sign-On (SSO): when you use Google SSO, we receive basic profile information (e.g., name, email address) as permitted by your settings with the SSO provider. (b) Payment Processors: confirmation of payment status, limited billing details, and tax status from Stripe. (c) Integrations and Partners: data from optional integrations when you authorize such connections.

3. PURPOSES AND LEGAL BASES FOR PROCESSING

3.1 Purposes of Use

(a) Provide and Operate the Services: create and manage accounts, authenticate users, and deliver features (e.g., community hubs, maps, analytics). (b) Moderate and Secure the Platform: detect abuse, enforce policies, and maintain platform integrity, including the use of automated systems and artificial intelligence. (c) Billing and Account Management: process payments, manage subscriptions, and handle credits or refunds. (d) Improve and Develop the Services: analyze usage, test features, and enhance functionality and performance using de-identified or aggregated data where possible. (e) Communicate with You: send administrative messages, service updates, and responses to inquiries. (f) Marketing and Promotion: with your consent where required, send promotional communications (you may opt out at any time) and showcase success stories or public content only where you have provided separate opt-in consent and content is not Sensitive Content. (g) Compliance and Legal: comply with applicable laws, respond to lawful requests, and protect rights, safety, and property.

3.2 Legal Bases (EU/UK)

(a) Performance of a Contract: to provide and operate the Services you request. (b) Legitimate Interests: to secure, improve, and promote the Services; prevent fraud; and support our mission, balanced against your rights and expectations. Our legitimate interests include operating a community platform for environmental organizations, ensuring security, and improving features. (c) Consent: for certain cookies/trackers, marketing communications, and specific data uses where required, including marketing use of UGC and use of data to train general models. You may withdraw consent at any time. (d) Legal Obligations: to fulfill tax, accounting, and regulatory requirements. (e) Vital Interests or Public Interest: where necessary to protect individuals or comply with relevant public interest obligations.

4. HOW WE SHARE INFORMATION

4.1 Service Providers and Processors

We share data with vendors that perform services on our behalf under contractual obligations to protect data and use it only pursuant to our instructions, including a Data Processing Addendum with Standard Contractual Clauses where required. Our subprocessors are listed at https://ojai.global/subprocessors and in our DPA and include: (a) Amazon Web Services, Inc. (AWS) – hosting, storage, monitoring via AWS CloudWatch and Checkly; (b) OpenAI, LLC – AI features (AI Copilot, AI Story Summaries) with contractual restrictions prohibiting use of your data to train their models without your explicit informed consent; (c) Stripe, Inc. – payment processing; and (d) Google LLC – single sign-on authentication. We provide thirty (30) days' notice of new subprocessors via email and in-app notice and an opportunity to object on reasonable data protection grounds.

4.2 Organizational Administrators

If you join an organizational account, administrators may access certain information about your use of the Services (e.g., activity within that organization's workspace) and content you submit within their organization's environment.

4.3 Other Users and Public Areas

Your UGC may be visible to other users or the public based on your settings and the functionality of the Services. Sensitive Content designated pursuant to Terms of Service Section 5.4 is private-by-default and not used for marketing without separate opt-in consent. Please consider carefully what you share and with whom.

4.4 Legal, Safety, and Rights

We may disclose information if required by law or in a good faith belief that such action is necessary to: (i) comply with a legal obligation; (ii) protect and defend the rights or property of OJAI; (iii) act in urgent circumstances to protect the personal safety of users or the public; or (iv) protect against legal liability.

4.5 Business Transfers

We may disclose or transfer data in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to continued protections consistent with this Privacy Policy.

4.6 No Sale or Sharing for Cross-Context Behavioral Advertising

We do not sell personal information as defined by California law and do not share personal information for cross-context behavioral advertising without your consent where required. We do not process sensitive personal information for purposes of inferring characteristics without consent.

5. DATA RETENTION AND DELETION

5.1 Retention Periods

We retain personal data for as long as necessary to fulfill the purposes outlined in this Privacy Policy, including providing the Services, complying with legal obligations, and resolving disputes. Criteria for retention include: account active status, subscription term, legal obligations (e.g., tax, accounting), and dispute resolution. Following termination, we provide a reasonable opportunity to export data and then delete or de-identify data within a commercially reasonable period, typically within thirty (30) days, subject to a backup tail of up to ninety (90) days for disaster recovery and where retention is required by law or needed to protect our rights, consistent with Terms of Service Section 12.5. Sensitive Content is deleted per Terms of Service Section 5.4 with no marketing use and no model training.

5.2 Deletion Requests

You may request deletion of your personal data as described in Section 9 (Your Rights and Choices). We will honor valid requests subject to necessary recordkeeping, legal obligations, and the rights of others. Deletion will propagate to subprocessors within a commercially reasonable timeframe.

6. COOKIES AND TRACKING TECHNOLOGIES

6.1 Categories of Cookies

(a) Strictly Necessary Cookies: required for core features such as authentication, security, and account management. These cannot be disabled via banner. (b) Functional Cookies: remember preferences and enhance user experience. (c) Analytics Cookies: measure and analyze usage to improve the Services, only with consent where required. (d) Advertising/Marketing Cookies: used sparingly and only with consent where required; we do not sell personal data and do not share for cross-context behavioral advertising without consent.

6.2 Controls

(a) Cookie Banner and Settings: where required (e.g., EU/UK and where applicable US state laws), we provide a consent banner and cookie preference center to manage preferences, with granular opt-in for analytics and marketing cookies and record of consent. (b) Browser Settings: you can configure your browser to block or delete cookies; some features may not function properly if cookies are disabled. (c) Opt-Out Mechanisms: for certain third-party analytics or marketing tools, we provide links or settings to opt out where available. (d) Global Privacy Control and Do Not Sell or Share Link: where required, we honor Global Privacy Control signals and provide a "Do Not Sell or Share My Personal Information" link at https://ojai.global/privacy-policy#do-not-sell and in our footer, and a "Your Privacy Choices" icon where required. (e) Consent Withdrawal: you may withdraw cookie consent at any time via the preference center.

7. INTERNATIONAL DATA TRANSFERS

7.1 Transfer Mechanisms

(a) We operate globally and may transfer your personal data to countries outside your country of residence, including to the United States, where data protection laws may differ. (b) For EU/UK users, we rely on appropriate safeguards such as the EU Standard Contractual Clauses EU 2021/914 Module 2 and 3 and the UK International Data Transfer Addendum, incorporated in our Data Processing Addendum at https://ojai.global/dpa. We do not rely on the EU-U.S. Data Privacy Framework unless certified and listed; where we are certified, we will list certification at https://ojai.global/dpa.

7.2 Additional Measures

We implement technical and organizational measures to protect data during transfer and at rest, including encryption in transit (TLS 1.2+), encryption at rest (AES-256), access controls, role-based access, logging, monitoring via AWS CloudWatch and Checkly, and internal policies. We conduct transfer impact assessments where required.

8. DATA SECURITY

8.1 Security Measures

We maintain administrative, technical, and organizational safeguards designed to protect personal data, including role-based access controls, two-factor authentication for Admins and Editors, encryption in transit and at rest, logging, monitoring via AWS CloudWatch and Checkly, vulnerability management, and regular assessments of vendors and models for privacy and security risks.

8.2 Your Responsibilities

You are responsible for securing your credentials, enabling two-factor authentication where required, maintaining updated devices/browsers, and promptly notifying us of any suspected unauthorized use at support@ojai.global or privacy@ojai.global.

9. YOUR RIGHTS AND CHOICES

9.1 Access, Correction, Deletion, and Portability

You may request access to, correction of, or deletion of your personal data, and, where applicable, data portability in a structured, commonly used, machine-readable format. We will respond within timeframes required by applicable law (e.g., 45 days for CCPA, one month for GDPR, with extension where permitted).

9.2 Objection and Restriction

Where we process data based on legitimate interests, you may object to processing on grounds relating to your particular situation. You may request restriction of processing in certain cases. You may object to marketing at any time.

9.3 Consent and Marketing Preferences

Where we rely on consent, you may withdraw consent at any time without affecting lawfulness of processing before withdrawal. You may opt out of marketing emails by using unsubscribe links or contacting privacy@ojai.global. Withdrawal of consent for marketing use of UGC is honored prospectively. We maintain a record of marketing consents and opt-outs.

9.4 How to Exercise Rights

Submit privacy requests to: privacy@ojai.global or info@ojai.global, or by mail to: Forge Blue Inc., 251 Little Falls Drive, Wilmington, DE 19808 and 12117 NW 47th Manor, Coral Springs, FL 33076, Attn: Privacy. Provide sufficient information to verify your identity and locate your records. We will verify your identity via email verification or account authentication. You will not be discriminated against for exercising your rights.

9.5 Authorized Agents

You may designate an authorized agent to make a request on your behalf. We will require: (a) proof of your identity; (b) proof of agent's identity; and (c) signed permission authorizing agent to act on your behalf, or power of attorney. We may contact you directly to confirm.

9.6 Region-Specific Rights

(a) EU/UK (GDPR): You have rights of access, rectification, erasure, restriction, portability, objection, and not to be subject to solely automated decision-making producing legal or similarly significant effects, and the right to lodge a complaint with your supervisory authority (e.g., EU data protection authority or UK ICO). (b) California (CCPA/CPRA): See Section 14.2 for detailed California rights including right to know, access, correct, delete, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination.

10. PRIVACY NUTRITION LABEL

10.1 Data Used to Track You

(a) Identifiers: advertising identifiers or device identifiers only where marketing cookies are enabled by consent. (b) Approximate Location: derived from IP address for analytics and fraud prevention, only with consent where required.

10.2 Data Linked to You

(a) Contact Information: name, email, organization, and role for account and communications. (b) Financial/Billing Information: limited billing details and tax status (processed via Stripe; we do not store full payment card numbers). (c) Content: UGC (text, photos, videos, audio, datasets, maps, comments) linked to your account, excluding Sensitive Content which is private-by-default and not used for marketing without opt-in. (d) Identifiers: IP address, device ID, SSO identifiers. (e) Usage Data: activity logs and engagement metrics tied to your account for security and service improvement.

10.3 Data Not Linked to You

(a) Aggregated or De-identified Analytics: usage metrics aggregated for performance and feature planning. (b) Diagnostics and Performance Data: error logs and telemetry that do not identify individuals.

10.4 Your Rights (Quick Reference)

(a) Access, correct, or delete your data. (b) Opt out of marketing communications. (c) Manage cookies and tracking preferences via banner and preference center. (d) Opt out of sale/sharing via Do Not Sell or Share link and Global Privacy Control where required. (e) Exercise regional rights (e.g., GDPR, CCPA) via methods in Section 9.

11. FTC AI DISCLOSURE AND TRANSPARENCY

11.1 Overview of AI/ML Use

We use AI and machine learning systems to assist with content moderation, knowledge discovery, and analytics supporting impact reporting, coalition building, and community engagement. AI features include AI Copilot and AI Story Summaries, powered by OpenAI with contractual restrictions.

11.2 Data Used with AI/ML

(a) Inputs to Run Models: we may process usage data, technical data, and UGC (excluding Sensitive Content unless you provide separate opt-in consent) to run moderation and recommendation features. (b) Training and Fine-Tuning: by default, we do not use your personal data or private UGC to train or fine-tune proprietary or third-party foundation models unless: (i) the data has been de-identified or aggregated; or (ii) you (or your organization) provide explicit, informed consent via in-product settings or a written agreement. (c) Third-Party AI Vendors: when we use third-party AI services such as OpenAI, we impose contractual restrictions prohibiting those vendors from using your data to train their models, unless you have given explicit, informed consent. These restrictions are included in our DPA and subprocessor agreements.

11.3 Automated Decision-Making and Profiling

(a) We use automated systems to flag potential policy violations, prioritize content for review, recommend resources, and surface insights. These systems may affect content visibility but do not make irreversible decisions without the possibility of human review. AI-generated content is labeled as AI-generated and conversational AI discloses that it is AI when interacting with users pursuant to EU AI Act Article 50. (b) Opt-Out and Controls: where required by law, you may opt out of certain profiling or automated decision-making that produces legal or similarly significant effects. Request this via methods in Section 9.4. We provide human review upon request for contested moderation outcomes where legally required.

11.4 Avoiding Deceptive Claims and Safety Measures

We do not make deceptive claims about AI capabilities. We disclose material limitations and ensure appropriate safeguards, including: (i) data minimization and access controls; (ii) audit logging; (iii) data segregation for enterprise workspaces; (iv) coordinate generalization and private-by-default for Sensitive Content; and (v) regular assessments of vendors and models for privacy and security risks.

12. CHILDREN'S PRIVACY

12.1 No Users Under Thirteen (13)

The Services are not directed to children under thirteen (13), or under sixteen (16) where applicable. We do not knowingly collect personal data from such children directly. Organizations that invite members under 18 are solely responsible for obtaining parental consents and configuring spaces to private-by-default pursuant to Terms of Service Section 2.1. If we learn that such data has been collected directly without appropriate consent, we will delete it promptly.

13. DATA CONTROLLER, PROCESSOR ROLES, AND ORGANIZATIONAL ACCOUNTS

13.1 Role Clarification

(a) For users who access OJAI through an organization, Forge Blue Inc. generally acts as a processor or service provider for content and personal data controlled by that organization; the organization acts as the controller. For direct-to-consumer accounts, Forge Blue Inc. acts as the controller. (b) We process personal data pursuant to our contracts and customers' instructions, including our Data Processing Addendum at https://ojai.global/dpa. If you submit a request and your organization controls your data, we may redirect your request to the organization's administrator. (c) Data Processing Addendum: where we act as processor, our DPA governs and is incorporated by reference, including Standard Contractual Clauses EU 2021/914 Module 2 and 3 and UK Addendum.

14. REGIONAL DISCLOSURES

14.1 EU/UK

(a) Controller Identity: Forge Blue Inc., a Delaware corporation doing business as OJAI, Principal Place: 12117 NW 47th Manor, Coral Springs, FL 33076, United States; Registered Agent and Legal Notice Address: 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, United States; Telephone: 407-222-7227; Email: info@ojai.global for general and legal, privacy@ojai.global for privacy rights. (b) Legal Bases: see Section 3.2. (c) Data subject rights: see Section 9. (d) International transfers: see Section 7, with safeguards via Standard Contractual Clauses EU 2021/914 and UK Addendum in our DPA. (e) Right to lodge complaint: you have the right to lodge a complaint with your supervisory authority (e.g., in the EU, your local data protection authority; in the UK, the Information Commissioner's Office). (f) Data Protection Officer or Representative: we do not currently have a designated DPO or EU/UK representative; if one is appointed, details will be published here and at https://ojai.global/privacy-policy. (g) Retention: see Section 5. (h) Source: see Section 2. (i) Automated decision-making: see Section 11.3 with human review and opt-out where required.

14.2 California

(a) Categories Collected in Last 12 Months: identifiers (name, email, IP address, device identifiers, SSO identifiers); commercial information (subscription details, billing tokens); internet or other electronic network activity (usage logs, feature interactions, cookies); geolocation (approximate location derived from IP); professional or employment-related information (if provided by organizational accounts); contents of communications where you provide support requests; and user-generated content you upload. (b) Sensitive Personal Information: account logon credentials (hashed password), precise location only if you provide precise coordinates (generalized for Sensitive Content), and contents of mail/email/text where you provide support communications. We do not use sensitive personal information to infer characteristics and do not use it for purposes other than those permitted by Cal. Code Regs. Title 11 §7027(m). (c) Sources: you, your devices, your organization, service providers. (d) Business/Commercial Purposes: as outlined in Section 3.1 – provide and operate Services, moderate and secure platform, billing and account management, improve and develop Services, communicate with you, marketing with consent, compliance and legal. (e) Disclosures for Business Purposes in Last 12 Months: to service providers and processors listed in Section 4.1 and https://ojai.global/subprocessors (AWS, OpenAI, Stripe, Google) for purposes in Section 3.1; to organizational administrators per Section 4.2; as required by law per Section 4.4; in connection with business transfers per Section 4.5. (f) Retention: see Section 5.1 – account data retained for duration of account plus 30 days then de-identified/deleted with 90-day backup tail, unless longer required by law; billing data retained per tax/legal obligations (typically 7 years); usage logs retained 12 months then aggregated. (g) Sales/Sharing: we do not sell personal information as defined by California law. We do not share personal information for cross-context behavioral advertising without consent where required. We do not have actual knowledge of selling or sharing personal information of consumers under 16 years of age. (h) Rights: California residents have rights to know/access (up to twice per 12 months), correct, delete, obtain copy/portability, opt out of sale/sharing (via Do Not Sell or Share link and Global Privacy Control), limit use of sensitive personal information, and non-discrimination. To exercise rights, use methods in Section 9.4. You may designate an authorized agent per Section 9.5 with appropriate proof. (i) How We Verify: we verify via email verification or account authentication and may request additional information to verify identity. (j) Non-Discrimination: we will not discriminate against you for exercising your rights. (k) Metrics: where required, we will publish annual metrics on requests received, complied with, and denied at https://ojai.global/privacy-policy.

14.3 Other Jurisdictions

We will honor mandatory rights and disclosures required by local law and will provide additional notices as needed.

15. DATA ACCESS AND PORTABILITY ON TERMINATION

15.1 Export Tools

During an active subscription and for a reasonable period following termination, typically thirty (30) days, we provide self-service export tools where available. Additional assistance may be available for a fee at $185 per hour as outlined in the Terms of Service Section 12.5.

15.2 Post-Termination Handling

After the export window, we will delete or de-identify personal data, except where retention is required for legal, regulatory, fraud prevention, or dispute resolution purposes, subject to a backup tail of up to ninety (90) days. Sensitive Content is deleted per Terms of Service Section 5.4 with no marketing use and no model training.

16. CHANGES TO THIS PRIVACY POLICY

16.1 Updates

We may update this Policy from time to time to reflect changes to our practices or legal requirements. Material changes will be announced via thirty (30) days' advance notice via email to the account email and in-product notice with a summary of changes. Changes apply prospectively only from their effective date. Where a change materially reduces your rights or increases your obligations, we will require affirmative acceptance where required by law, and if you do not accept, you may terminate per Terms of Service Section 12.3 and receive a pro-rata refund of prepaid unused fees where applicable.

16.2 Effective Date

Changes take effect on the date indicated in the updated Policy. Your continued use of the Services after the effective date and, where required, after affirmative acceptance, signifies acceptance. If you do not agree, you should discontinue use and, if applicable, adjust your settings or cancel your subscription.

17. CONTACT US

17.1 Methods of Contact

Email: info@ojai.global for general and legal notices. For privacy rights requests: privacy@ojai.global or info@ojai.global. Support: support@ojai.global. Accessibility: accessibility@ojai.global. Mailing address for legal notices: Forge Blue Inc., a Delaware corporation d/b/a OJAI, Registered Agent and Legal Notice Address: 251 Little Falls Drive, Wilmington, DE 19808, United States and Principal Place: 12117 NW 47th Manor, Coral Springs, FL 33076, United States, Telephone: 407-222-7227, Attn: Privacy. DMCA Agent: Forge Blue Inc., Attn: DMCA Agent – Germain Bebe, President, 251 Little Falls Drive, Wilmington, DE 19808, Telephone: 407-222-7227, Email: info@ojai.global.

© 2026 Forge Blue Inc., OJAI. All rights reserved.