Bolt’s New Policies Permit Training Beyond Its Forge-Only Pitch

Forge is presented as a separate opt-in lane for training open models. StackBlitz’s new terms instead describe broader potential use of content processed through Bolt’s AI features, subject to opt-outs and significant account exclusions.

By 5 min read
Original researchBolt Forge’s 50× Trade: What a Builder Consents to Donate for Open-Model Training

The supplied record describes a substantial opt-in bargain, including broad Forge Content classes, mode-specific consent, some exclusions, and prospective withdrawal controls. It does not fully specify the transformation procedure, secret-removal limits, retention of training copies, the non-public Bolt-Arcee agreement, or deletion from completed training and delivered datasets.

Explore the full research
Bolt’s New Policies Permit Training Beyond Its Forge-Only Pitch
Superpower DailyOriginal research
Bolt’s New Policies Permit Training Beyond Its Forge-Only Pitch

Listen to this story

The audio brief

About 1:33
0:001:33
Read transcript
StackBlitz’s new terms appear to authorize broader uses of Bolt users’ work than Bolt’s Forge pitch suggests. Forge is presented as a clearly labeled, opt-in lane: builders consent each time, and Bolt says Standard and Max do not train on user data. But the updated policies define eligible material by whether it passes through Bolt AI Features—not by which mode or model handled it. That can include prompts, generated answers, error messages, correction sequences, tool calls, edit histories, and project files. StackBlitz says this material may support model training, evaluation, and improvement, and may also be turned into de-identified datasets licensed to outside AI developers or researchers, potentially for payment. That is broader than Forge’s specifically described preview, in which sessions shared between September fourteenth and October fourteenth go to Arcee AI, with training expected in October and model weights slated for publication. The policy is not universal. Accounts tied to the European Economic Area, the United Kingdom, or Switzerland are excluded, as are most organization-managed accounts unless an administrator enables the practice. Only material created or generated from September fourteenth qualifies, and StackBlitz says it will not use it before September twenty-ninth. Users can opt out, but the change is prospective: it does not undo completed processing, trained models, or datasets already delivered. The key unresolved point is whether the practical fences truly match Forge’s promise that training is opt-in and mode-specific.

Story brief

3 key points

StackBlitz’s September 14 Forge preview is paired with policy language that may authorize model-development and dataset-licensing uses for content processed through Bolt AI Features—not just sessions explicitly entered into Forge. The scope includes prompts, outputs, corrections, tool calls, histories, and project files; EEA, UK, Swiss, and most organization-managed accounts are excluded. Users can opt out, but only...

  1. 01

    Forge consent is required each time; Standard and Max are advertised as not training on user data.

  2. 02

    Only material created or generated September 14 onward qualifies; StackBlitz says eligible content will not be used before September 29.

  3. 03

    Forge sessions shared September 14–October 14 go to Arcee AI under a data-processing agreement; training is expected in October.

Bolt describes Forge as an opt-in experimental lane where builders donate anonymized sessions to train open-weight models. But StackBlitz’s new terms and privacy policy define content eligible for model development and paid dataset licensing by whether it passes through Bolt AI Features, regardless of model or mode. That creates an apparent gap between a product promise that training happens only in Forge and policy language that can reach beyond it, subject to opt-out controls and regional, organizational, and contractual exclusions.

The distinction arrives with Forge’s September 14 research-preview launch, but it is not mainly about the offer of up to 50 times more usage for individual Pro subscribers. It is about the boundary around builders’ work. Bolt says Forge requires one-tap consent each time a user enters the mode; declining keeps the user in Standard or Max, which the launch page says never train on user data.

The updated legal documents use a different organizing principle. They define Bolt Model Development Content as inputs and outputs submitted through Bolt, plus related interaction records and project material processed by Bolt AI Features. The definition says eligibility turns on the feature through which content is processed, not the AI model, mode, or inference provider involved.

The policy is broader, but not universal

That broader language does not mean every Bolt account is in scope. StackBlitz says it will not use content associated with accounts it determines are in the European Economic Area, United Kingdom, or Switzerland for AI model development or licensed datasets. Separate written agreements can control instead, and organization-managed accounts are generally outside these practices unless an administrator enables them with required notice and choices.

The documents also set a prospective start. Only content created or generated on or after September 14 is eligible for model-development or dataset-licensing uses, according to StackBlitz, and it says it will not use that eligible material before September 29. Earlier project material remains out of bounds; for older files, only new versions or edits created after September 14 can qualify.

What builders may be contributing

The scope is wider than finished code. The policies include prompts, generated output, error messages, correction and fix sequences, tool invocations, edit histories, and project files, code, and configuration that Bolt AI Features process. That can make the material useful for improving an AI coding system because it captures attempts, mistakes, and repairs—not simply a completed application.

bolt
Connect Source: bolt.new.

The policy separates three uses of that material

  • Operating the service: StackBlitz may process AI inputs and outputs to provide, secure, troubleshoot, and maintain Bolt.
  • Model development: eligible content may be used to train, fine-tune, evaluate, benchmark, and improve AI models developed by or for StackBlitz.
  • Dataset licensing: StackBlitz says it may prepare de-identified datasets and license them, including for compensation, to AI developers and researchers.

Forge has a specifically named destination for its first preview run: Bolt says shared sessions from September 14 through October 14 will go to Arcee AI under a signed data processing agreement, with training expected to begin in October. Bolt says the resulting model’s weights will be published. The broader policy, however, allows licensing to third-party AI developers and researchers and is not limited in its wording to open-weight models or to Arcee.

Consent is a control, not a reset button

Forge’s consent is unusually visible: the terms require a separate, distinguishable consent statement and a record of the accepted terms version, date, and time. Switching out of Forge ends collection of new Forge Content. For the broader policy practices, users can opt out through account settings or by contacting StackBlitz, and the company says it will implement the request across applicable systems within 15 days.

Those choices work prospectively. StackBlitz says an opt-out or withdrawal does not itself unwind completed processing, models already trained, or datasets already delivered to licensees. A deletion request removes content from StackBlitz training corpora and datasets not yet delivered, subject to legal exceptions, but carries the same limit for work already completed.

The practical question is whether the fences match

StackBlitz does promise safeguards before licensing a dataset: it says it will remove or transform information that could reasonably identify an individual, keep the result de-identified, and contractually prohibit recipients from re-identifying it or disclosing it onward without equivalent restrictions. Bolt’s Forge page separately says it strips secrets, sensitive data, and personal information before shared sessions leave its infrastructure.

Yet the public materials do not explain how the apparent Standard-and-Max conflict is resolved in practice. Nor do they specify a Forge-specific retention period for raw sessions, transformed corpora, partner copies, or licensed datasets. The launch’s clear Forge bargain and the policies’ broader Bolt-wide definitions can both be read in the documents; builders deciding where to work need StackBlitz to make their relationship unambiguous.

Editorial analysis

Our Read

Bolt’s Forge launch makes a visible bargain: extra experimental capacity in exchange for training material. The policy language creates a second, less visible question about whether the product boundary matches the legal one. The important next evidence is not another description of Forge’s consent screen; it is a clear operational explanation from StackBlitz of how Standard and Max content is excluded, selected, or suppressed once the new terms take effect. That answer would determine whether Forge is a genuinely fenced-off data program or simply the most explicit route into a wider model-development framework.

Citation desk / original work

Cite this

Permanent attributionView citation
Finding 01

No. The bounded public record specifies substantial portions of the Forge bargain, but it does not completely specify the anonymization procedure, secret-removal limits, training-corpus and licensee retention, the full Bolt-Arcee recipient-rights package, or downstream deletion from trained and distributed models.

/posts/bolt-launches-forge-but-its-training-terms-reach-beyond-the-pitch#finding-claim-01
Finding 02

Deletion is prospective and copy-dependent: a deletion request removes Bolt Model Development Content from StackBlitz training corpora and datasets not yet delivered, but stopping, withdrawal, or deletion does not by itself unwind completed processing, trained models, or datasets already delivered to licensees except where law requires.

/posts/bolt-launches-forge-but-its-training-terms-reach-beyond-the-pitch#finding-claim-10
Finding 03

Stopping Forge and withdrawing consent are separate actions. Switching modes stops collection of new Forge Content but permits continued use of previously collected content until consent is withdrawn by email or a future account control; withdrawal must be implemented across applicable systems within 15 days and blocks new training selections and newly prepared or licensed datasets.

/posts/bolt-launches-forge-but-its-training-terms-reach-beyond-the-pitch#finding-claim-09

Sources

  1. bolt.newWhat is Bolt Forge? Open-source AI building on Bolt.new
  2. stackblitz.comStackBlitz | Terms of Service | Instant Dev Environments | Click. Code. Done.
  3. stackblitz.comStackBlitz | Privacy Policy | Instant Dev Environments | Click. Code. Done.
  4. bolt.newSecurity & Trust | Bolt
  5. arcee.aiTerms and conditions

Loading discussion...