Legal
Privacy Policy
Effective August 15, 2026 · Applies to the FUT Forge website (https://futforge.vercel.app), FUT Forge Desktop, the FUT Forge Browser Extension, and the FUT Forge Bookmarklet ("Browser Mode") — together, "FUT Forge".
This policy describes what FUT Forge actually does with data, based on how each product is built today. FUT Forge is a set of tools for the EA Sports FC Ultimate Team Web App — squad building, SBC solving, Evolutions, club insights, and market prices. It is not affiliated with, endorsed by, or associated with Electronic Arts or EA Sports.
1. Products this policy covers
- The website (https://futforge.vercel.app) — marketing pages, account sign-in, the web-based tools under
/app, and Leaks articles. - FUT Forge Desktop — the Windows application that embeds the EA Web App and overlays FUT Forge's tools.
- The FUT Forge Browser Extension — a Chrome extension that injects the same FUT Forge tools directly into the EA Web App running in your browser, so Desktop is not required.
- The FUT Forge Bookmarklet ("Browser Mode") — a bookmark-triggered version of the same tools for browsers, including mobile, where installing an extension isn't possible.
All four share the same account system and the same core squad/SBC/EVO engine. Where their data handling differs, it is called out explicitly below.
2. Your FUT Forge account
Creating a FUT Forge account and signing in is handled by Supabase, our authentication and database provider. When you register or sign in, we process the email address and password (or username) you provide, and Supabase issues a session (an access token and a refresh token). We store, in your FUT Forge profile: your email, username, account plan (Free/Pro), plan expiry, account creation date, and the timestamp of your most recent login.
On sign-in, the client also reports a short client-version label (for example, which build of the FUT Forge Core you're running) so we can tell which app versions are active. This is a diagnostic label only — it is not your device identity, IP address log, or usage history.
Your session tokens are kept in localStorage under the origin of the page you're using FUT Forge from — futforge.vercel.app when you use the website, or www.ea.com (the EA Web App's own origin) when you use the Browser Extension, Bookmarklet, or Desktop, since all three run FUT Forge's interface on top of the EA Web App page itself. This is standard browser storage, scoped by the browser to that origin; FUT Forge does not read or export it anywhere else.
3. Data read from the EA Web App
To power Squad Builder, SBC tools, EVO Builder, and club-based features, FUT Forge reads Ultimate Team data that is already loaded into your signed-in EA Web App session — your club items (cards), their ratings, positions, rarity, chemistry styles, and your SBC/formation state. This is read the same way the EA Web App's own interface reads it, through EA's in-page APIs.
FUT Forge does not read, store, or transmit your EA account password, EA session cookies, or EA authentication tokens. Signing in to the EA Web App and signing in to FUT Forge are entirely separate systems.
In the Browser Extension and Bookmarklet, this club/card data is used locally, in your browser, to calculate META ratings, chemistry, and SBC/EVO solutions. It is not uploaded to FUT Forge's servers by the extension or the bookmarklet in the current release.
FUT Forge Desktop additionally offers an optional Club Sync feature: if you use it, a sanitized snapshot of your club (card identifiers, ratings, rarity, and tradeable status — never EA credentials or session data) is sent to FUT Forge's backend and stored against your FUT Forge account, so club-based tools can work outside the EA Web App. The equivalent Club Sync upload path exists in the Browser Extension's source code but is not enabled or exposed in the current release — the extension does not upload club data anywhere.
4. What's stored locally in your browser
Beyond your session tokens (Section 2), FUT Forge keeps a few functional values in localStorage on whichever origin you're using it from:
- Cached grade and chemistry-style configuration, so the app can score cards offline.
- A short-lived cache of public market prices (Section 5), so repeated SBC/EVO calculations don't need to re-fetch pricing.
- A local cache of your club snapshot, used to speed up SBC/EVO tools between visits without re-querying the EA Web App every time.
None of these values leave your browser on their own — they exist purely so the local calculation engine has fast access to data it already fetched. Clearing your browser's site data for that origin removes them.
5. Market price data
Public market-price data is downloaded from FUT.GG (r2.fut.gg) — a public, read-only price index, not tied to your FUT Forge account or your EA identity. This request is made by the Browser Extension's service worker (or by Desktop/the Bookmarklet host) on your behalf; it carries no personal data beyond what any standard HTTPS request includes (such as your IP address, visible to FUT.GG like any web request). FUT Forge does not sell this data or use it for advertising.
6. What reaches FUT Forge's servers
Depending on which product you use, FUT Forge's backend (built on Supabase) receives:
- Authentication requests — your email/password at sign-in, and session refresh calls.
- Profile reads/writes — plan, username, and the login-timestamp/version label from Section 2.
- On FUT Forge Desktop, if you use Club Sync: your sanitized club snapshot (Section 3).
The Browser Extension and Bookmarklet do not send club/card data, squad compositions, or SBC solutions to FUT Forge's servers in the current release — those calculations happen entirely in your browser.
7. Third-party services
- Supabase — authentication and database hosting for FUT Forge accounts and profiles.
- FUT.GG — source of the public market-price data described in Section 5.
- Vercel — hosts the FUT Forge website and provides privacy-focused, aggregated page-view analytics (Vercel Web Analytics) for the site. This analytics collection applies to the website only, not the Browser Extension or Bookmarklet running inside the EA Web App.
We do not sell personal data to third parties, and we do not use your data for advertising.
8. Data retention
Account data (email, username, plan, profile fields) is retained for as long as your FUT Forge account exists. Session tokens remain in browser storage until they expire, you sign out, or you clear site data. A Club Sync snapshot (Desktop only) is replaced each time you re-sync and is retained until you delete your account or request its removal.
9. Your rights and choices
You can request access to, correction of, or deletion of your FUT Forge account and any associated data at any time by contacting us through our official Instagram account, @futforgeofficial. You can also sign out to clear locally stored session tokens, or use your browser's site-data controls to clear anything else FUT Forge has stored locally.
10. Children's privacy
FUT Forge is intended for users old enough to hold an EA Account and use the EA Sports FC Ultimate Team Web App under EA's own terms. FUT Forge does not knowingly collect data from children below that threshold.
11. Chrome Web Store disclosure
The FUT Forge Browser Extension:
- Runs only on supported EA Sports FC Ultimate Team Web App pages.
- Uses the
scriptingpermission to inject FUT Forge's interface into that page, andstorageto keep short-lived, per-tab boot state so a page reload doesn't re-initialize FUT Forge twice. - Requests host access only to the EA Web App routes it runs on, and to
r2.fut.ggfor the public price data in Section 5. - Does not read EA passwords, cookies, or authentication tokens.
- Does not download or execute remotely hosted code — all extension logic ships in the package; only data (price responses, authentication API responses) is fetched at runtime.
- Does not sell or transfer user data to third parties for purposes unrelated to providing FUT Forge's features, and does not use data for advertising or creditworthiness decisions.
12. Changes to this policy
If FUT Forge's data practices change materially — for example, if Club Sync upload is enabled in the Browser Extension — this page will be updated and the effective date above will change accordingly.
13. Contact
Questions about this Privacy Policy or your data can be sent to us through our official Instagram account: @futforgeofficial.