Bolt describes Forge as an opt-in experimental lane where builders donate anonymized sessions to train open-weight models. But StackBlitz’s new terms and privacy policy define content eligible for model development and paid dataset licensing by whether it passes through Bolt AI Features, regardless of model or mode. That creates an apparent gap between a product promise that training happens only in Forge and policy language that can reach beyond it, subject to opt-out controls and regional, organizational, and contractual exclusions.
The distinction arrives with Forge’s September 14 research-preview launch, but it is not mainly about the offer of up to 50 times more usage for individual Pro subscribers. It is about the boundary around builders’ work. Bolt says Forge requires one-tap consent each time a user enters the mode; declining keeps the user in Standard or Max, which the launch page says never train on user data.
The updated legal documents use a different organizing principle. They define Bolt Model Development Content as inputs and outputs submitted through Bolt, plus related interaction records and project material processed by Bolt AI Features. The definition says eligibility turns on the feature through which content is processed, not the AI model, mode, or inference provider involved.
The policy is broader, but not universal
That broader language does not mean every Bolt account is in scope. StackBlitz says it will not use content associated with accounts it determines are in the European Economic Area, United Kingdom, or Switzerland for AI model development or licensed datasets. Separate written agreements can control instead, and organization-managed accounts are generally outside these practices unless an administrator enables them with required notice and choices.
The documents also set a prospective start. Only content created or generated on or after September 14 is eligible for model-development or dataset-licensing uses, according to StackBlitz, and it says it will not use that eligible material before September 29. Earlier project material remains out of bounds; for older files, only new versions or edits created after September 14 can qualify.
What builders may be contributing
The scope is wider than finished code. The policies include prompts, generated output, error messages, correction and fix sequences, tool invocations, edit histories, and project files, code, and configuration that Bolt AI Features process. That can make the material useful for improving an AI coding system because it captures attempts, mistakes, and repairs—not simply a completed application.
The policy separates three uses of that material
- Operating the service: StackBlitz may process AI inputs and outputs to provide, secure, troubleshoot, and maintain Bolt.
- Model development: eligible content may be used to train, fine-tune, evaluate, benchmark, and improve AI models developed by or for StackBlitz.
- Dataset licensing: StackBlitz says it may prepare de-identified datasets and license them, including for compensation, to AI developers and researchers.
Forge has a specifically named destination for its first preview run: Bolt says shared sessions from September 14 through October 14 will go to Arcee AI under a signed data processing agreement, with training expected to begin in October. Bolt says the resulting model’s weights will be published. The broader policy, however, allows licensing to third-party AI developers and researchers and is not limited in its wording to open-weight models or to Arcee.
Consent is a control, not a reset button
Forge’s consent is unusually visible: the terms require a separate, distinguishable consent statement and a record of the accepted terms version, date, and time. Switching out of Forge ends collection of new Forge Content. For the broader policy practices, users can opt out through account settings or by contacting StackBlitz, and the company says it will implement the request across applicable systems within 15 days.
Those choices work prospectively. StackBlitz says an opt-out or withdrawal does not itself unwind completed processing, models already trained, or datasets already delivered to licensees. A deletion request removes content from StackBlitz training corpora and datasets not yet delivered, subject to legal exceptions, but carries the same limit for work already completed.
The practical question is whether the fences match
StackBlitz does promise safeguards before licensing a dataset: it says it will remove or transform information that could reasonably identify an individual, keep the result de-identified, and contractually prohibit recipients from re-identifying it or disclosing it onward without equivalent restrictions. Bolt’s Forge page separately says it strips secrets, sensitive data, and personal information before shared sessions leave its infrastructure.
Yet the public materials do not explain how the apparent Standard-and-Max conflict is resolved in practice. Nor do they specify a Forge-specific retention period for raw sessions, transformed corpora, partner copies, or licensed datasets. The launch’s clear Forge bargain and the policies’ broader Bolt-wide definitions can both be read in the documents; builders deciding where to work need StackBlitz to make their relationship unambiguous.
Reader comments
Newest comments first. Replies stay oldest first.