FORAXION LTD

Privacy Policy

We built The Forecasting Machine for organisations that make important decisions. Protecting the information they trust us with is part of that job. This page explains, in plain terms, what we collect and why.

Last updated: 30 September 2026

In short

  • Your content stays yours

    Questions, documents and forecasts in your workspace belong to your organisation. We process them only to run the service for you.

  • No selling, no ads

    We do not sell personal data, show advertising, or use advertising or third-party analytics cookies.

  • Security first

    Technical details such as IP address and browser type are used to protect your account, for example to recognise a new device and ask for a sign-in code.

  • You stay in control

    You can ask us to access, correct, export or delete your personal data at any time.

Who we are

The Forecasting Machine is operated by FORAXION LTD, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom (“we”, “us”).

This policy explains how we handle personal data when you use the Forecasting Machine platform, visit this website and blog, request a demo or access, or subscribe to The Forecasting Brief.

Our role

For account, website, sales and newsletter data, we decide how the data is used and act as the data controller.

For the content that an organisation and its members add to the platform, such as questions, uploaded documents, discussions and forecasts, we act on behalf of that organisation. We process this content only to provide the service, following our agreement with the organisation. Business customers can contact us about a data processing agreement.

Information we collect

We collect only what we need to provide and protect the service.

  • Account details: your name, work email, password (stored only as a secure hash), organisation, role, profile picture and preferences such as language, theme and email digest settings. If you sign in with Google, Microsoft, LinkedIn or X, we receive your basic profile from that provider.
  • Workspace content: the questions, documents, links, comments, AI assistant conversations, forecasts and reports that you and your team create or upload.
  • Security and device information: IP address, browser and device type, and an approximate location (city or country) derived from the IP address. See how we use security information.
  • Billing details: your organisation’s name, billing email and purchase history. Payments are handled by Stripe; we never see or store full card numbers.
  • Demo and access requests: the name, work email, organisation and message you send us through the contact form.
  • Newsletter: your email address and a record of your consent. See below.

How we use information

We use personal data to:

  • create and manage accounts, organisations and invitations, and deliver the features you use;
  • keep accounts and the platform secure and prevent misuse;
  • process purchases and keep accurate billing and usage records;
  • send service emails, such as sign-in codes, invitations and the digests you have chosen;
  • reply to demo, access and support requests;
  • send The Forecasting Brief to readers who asked for it;
  • maintain and improve the reliability of the service.

Under UK and EU data protection law, we rely on performing our contract with you or your organisation, our legitimate interest in running a secure and reliable service, your consent (for the newsletter), and our legal obligations (for example, keeping billing records).

Security information

We use IP address and device details for one purpose: protecting your account. They let us:

  • recognise a new device and ask for a one-time sign-in code when two factor authentication is on;
  • show you your active sessions, with device and approximate location, so you can sign out of any you don’t recognise;
  • limit repeated sign-in attempts and block abusive traffic.

To remember a trusted device we keep only a fingerprint of the browser type, not a copy of it. Sign-in codes expire after ten minutes, and sessions end after 30 days without use. We do not use this information for profiling or marketing.

AI features

Forecasting and the AI assistant rely on large language models from established providers, including OpenAI, Anthropic, Google and xAI, and models hosted on Amazon Web Services. When you use these features, the relevant question, document text or message is sent to the model provider to produce a result.

We use these providers’ business services, and they process the content on our behalf. We send only what a request needs, and we never include your password or payment details. We keep records of AI requests to deliver results, track usage for billing, and investigate issues. AI assistant conversations are removed automatically 30 days after their last activity.

Shared reports and embedded widgets

You can share a forecast as a read-only report link or embed it on another website. Only the forecast you choose to share is visible, and you can turn a shared link off at any time.

To show publishers where their widgets appear, we count widget views by embedding website and by hour. We do not record who views a widget: no visitor IP addresses, cookies or identifiers are stored for this.

The Forecasting Brief

When you subscribe, we store your email address, where you signed up, and when you confirmed. Like most email services, we also keep the IP address and browser type used to subscribe and confirm, as a record of your consent.

We add you to the list only after you confirm by email. Unconfirmed sign-ups are removed after 30 days. Every issue includes a one-click unsubscribe link. After you unsubscribe, we keep your address on a do-not-send list so you are not emailed again, unless you subscribe once more. You can ask us to erase it completely.

Cookies and local storage

We use only the cookies and browser storage needed for the service to work:

  • secure sign-in cookies that keep you logged in;
  • a trusted-device cookie, so you are not asked for a sign-in code on every visit;
  • browser storage for your preferences, such as theme and language, and for drafts in progress.

We do not use advertising cookies or third-party analytics trackers, so there is nothing to opt out of.

Service providers

We work with a small number of trusted providers that process data on our behalf, under contract and only for the purposes below:

  • Cloud hosting, database and file storage: Amazon Web Services and Microsoft Azure
  • Website hosting: Vercel
  • AI model providers: as described in AI features
  • Email delivery: Google Workspace
  • Payments: Stripe
  • Sign-in: Google, Microsoft, LinkedIn and X, only if you choose to sign in with them
  • Session location: an IP location service that turns an IP address into an approximate city or country for your active sessions list
  • Research sources: search and news services that receive search terms when we gather evidence for a forecast, never your account details

We may also disclose information where the law requires it, or as part of a merger or acquisition, in which case this policy continues to apply.

International transfers

Some of our providers, including AI model providers, may process data outside the UK and the European Economic Area, for example in the United States. Where that happens, we rely on recognised safeguards, such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, and on the providers’ own security commitments.

How long we keep data

We keep personal data only for as long as it is needed:

  • account and workspace data, while the account or organisation is active, or until you or your organisation ask us to delete it;
  • sign-in sessions, 30 days after last use;
  • sign-in codes, 10 minutes;
  • AI assistant conversations, 30 days after last activity;
  • unconfirmed newsletter sign-ups, 30 days;
  • billing records, for as long as tax and accounting rules require.

How we protect data

All traffic is encrypted in transit. Passwords, sign-in codes and invitation links are stored only as secure hashes. Access to data is limited by role within each organisation, and two-factor authentication and session controls are available to every user. We review our practices as the product grows.

Your rights

You can ask us to access, correct, export or delete your personal data, or to restrict or object to how we use it. Where we rely on consent, you can withdraw it at any time. If your account belongs to an organisation, we may involve its administrator for requests about workspace content.

We will respond within one month. If you are not satisfied, you can contact the UK Information Commissioner’s Office (ico.org.uk) or your local data protection authority.

Children

The Forecasting Machine is a professional service and is not intended for anyone under 18.

Changes to this policy

We will update this page when our practices change and revise the date at the top. If a change is significant, we will tell account holders by email or in the app.

Contact us

For any privacy question or request, email contact@theforecastingmachine.com or use our contact form.