DRAGONFORGE
Dragon Workflows

Privacy Policy

How DragonForge handles information when clients use the portal and mobile app.

Effective July 16, 2026

Information we collect

We process information needed to provide each client's Dragon Workflows services, including:

How we use information

We use information to authenticate users, deliver and improve purchased services, show business results, complete client-requested actions, provide support, send opted-in service notifications, prevent abuse, maintain security, and meet legal obligations. We do not sell personal information.

AI and service providers

Some client-requested features use AI, communications, hosting, calendar, social-network, payment, or infrastructure providers. We send them only the information reasonably needed for the requested feature. Dragon Workflows' secure web checkout handles purchases; the mobile app does not collect payment-card details.

Google Calendar data

Calendar sync is optional and off until a client connects their own Google account from their portal. Connecting requests two narrowly limited permissions, which Dragon Workflows uses for exactly two purposes:

We deliberately request these limited permissions instead of full Google Calendar access. Dragon Forge cannot change calendar sharing settings or delete calendars, and its event-sync code only updates or removes events that Dragon Forge created.

We store the authorization token needed to keep sync working, and cache busy times briefly to limit how often we call Google. A client can end this at any time using Disconnect in their portal, which deletes the stored token; access can also be revoked at myaccount.google.com/permissions. Google Calendar data is never sold, never used for advertising, never used to train AI models, and is not sent to our AI providers. It is not shared with anyone outside the client's own account except as required by law.

Dragon Workflows' use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Retention and deletion

We retain information while the client account is active and as needed for service delivery, security, billing, dispute resolution, backups, and legal compliance. Clients may request account-data access, correction, export, or deletion. Some records may be retained where law or legitimate security needs require it.

Security

We use access controls, encrypted connections, scoped client sessions, tenant ownership checks, and other reasonable safeguards. No system can guarantee absolute security, so users should protect their credentials and promptly report suspected unauthorized access.

Choices

Mobile notifications are optional and can be declined or disabled in device settings. Marketing SMS and email follow applicable consent, opt-out, and unsubscribe requirements. Transactional service messages may still be sent when necessary to provide a requested service.

Children

DragonForge is a business service and is not directed to children under 13.

Changes and contact

We may update this policy as the service changes. Material revisions will be posted here with a new effective date. Questions or privacy requests can be sent to support@dragonworkflows.com.