Operator
Who runs EVE Forge
EVE Forge is closed source, by decision. That costs you the check this ecosystem normally uses — you cannot read the code before deciding whether to hand over wallet, journal, contract and corporation scopes. What is left is knowing who receives them. This page names that person, gives you a way to reach them, and states what they will do when you do.
EVE Forge is built and run by one person. Not a company, not a team with a support rota — which is worth knowing before you decide what an answer within a day is worth, and worth knowing when you read the wind-down policy.
Latte's profile and other projects are available at hiddenden.cafe.
Contact
How to reach the operator
Two channels, both read by the same person. Use whichever you already have open — there is no ticket system, no form, and no address that forwards into a void.
One thing this cannot promise: a copy of your data, or its deletion. There is no button for either and no committed process behind a request, which the privacy policy says in as many words. Asking is allowed; being answered inside the window above is not something this page will claim for it.
For anything involving another pilot's data or a security hole, use one of these two directly rather than a public channel, and say what you found before you say where.
What the operator will neverdo: message you first asking for your EVE password, your account credentials, an ESI token or a “support code”; ask you to log in anywhere other than CCP's own SSO page; or ask you to send ISK or items to resolve a problem with EVE Forge. Anything that does one of those is not from us, whatever name is on it.
Expectations
What you may expect back
A first reply within a working week. One person answers, so a message sent on a busy weekend may wait for the end of it. What you will not get is silence: if the answer is no, it is sent as a no.
- A bug report gets a verdictConfirmed or not reproducible, and if confirmed, whether it is being fixed now or parked. Parked is a real answer and is given as one.
- A feature request may be declinedOut loud, with the reason. A quiet maybe is worse than a no, because you cannot plan around it.
- A data question is answered with your dataAsk what is stored about you and you get the answer, not a policy quotation. What is stored is described on the privacy page.
- Anything that touched your records is written downA data loss, a bad migration, a failed sync that left gaps: it goes on the changelog with a date whether or not anyone asked, and directly to you if your own records were affected.
Abuse and security
What happens to a report
Report anything where EVE Forge itself is the problem: a page showing you another pilot's data, an account you believe is not the pilot it claims to be, a session or token you think has leaked, a message impersonating EVE Forge, or a hole you found while poking at it. Poking at it is fine — tell us what you find and you will not be threatened for it.
- 1 · AcknowledgedWithin 48 hours, on the channel you used, by the person named above. An acknowledgement is not a verdict — it exists so you know the report did not vanish.
- 2 · ContainedIf data may be exposed, containment comes before diagnosis: the affected account's sessions are ended at once and its access is suspended for as long as the investigation needs. Every session belonging to an account can be revoked in one action, so this does not depend on catching a login.
- 3 · InvestigatedAgainst the stored records and the server logs. You will be asked for detail if the report needs it, and told if it turns out to be working as designed — including when the answer is that the operator disagrees with you.
- 4 · Fixed and written downA security fix is published on the changelog with its date, what was exposed and for how long. If your own records were in scope, you are told directly rather than left to read a list.
- 5 · You are told the outcomeIncluding when the outcome is that nothing was done, and why. A report that gets no answer is a report you will never send twice.
What this cannot cover: anything that happened in the game. Scams, theft, awoxing, RMT and harassment in New Eden belong in a CCP petition — EVE Forge reads ESI and never writes to it, so it cannot freeze an account, recover ISK, undo a trade or see anything you did not grant a scope for. A report about another player's in-game conduct will be sent back with that pointer, which is not a brush-off but the only honest answer.
And the honest part, since you are being asked to trust one person: the operator can reach the records EVE Forge has stored for you. What bounds that is where the permission lives — an allowlist of EVE character IDs in the server environment, never a role in the database, so nothing inside the app can hand it out and a list typed wrong lets nobody in rather than everybody. It never includes your ESI tokens, and it never includes acting in game as your character. The privacy page says the same in more detail, and access can be withdrawn from your side at any time through CCP's authorised applications page.
Continuity
Still here, and what if not
Third-party EVE tools die quietly, and a promise that this one will not is worth nothing. Dated evidence is worth something, so every release is listed with its date on the changelog. If that page has not moved in months, believe the page rather than this paragraph.
The other half of the question is what happens when it does end — whether that is the operator stopping or CCP withdrawing ESI access, which their developer licence permits them to do without notice. How much warning you get, how you get your stored history out, how long it is kept afterwards and what happens to time already paid for are set out in the wind-down and data-retention policy, published with the privacy policy.