FORGE

Privacy Policy

Effective date: EFFECTIVE_DATE_TBD · Operated by Jason Roberts

Forge is a strength-training log made by Jason Roberts, an individual developer in the United States (“we”, “us”). This policy explains what Forge collects, why, who helps us process it, and how to delete it. It covers the Forge Android app and the Forge website.

The short version

  • We collect what we need to run your account, sync your training log, and confirm your purchase.
  • No ads. No third-party analytics or tracking SDKs. We don’t sell your data or share it for advertising.
  • You can export your data at any time, and delete your account in the app or at /delete-account.

What we collect

Account details. Your email address, your name (optional; if you leave it blank we use the part of your email before the “@”), your password (stored only as a salted hash, never in plain text), and whether you have confirmed your email.

If you choose “Continue with Google”. Google tells us your Google account ID, your email address, whether Google has verified it, and your name. We use them only to create or sign you in to your Forge account, and to link it to an existing Forge account with the same verified email. We don’t store your Google profile photo or any Google access tokens, and we can’t see your Google password or anything else in your Google account (we only ask for the basic “openid”, “email” and “profile” permissions). You can remove Forge’s access at any time in your Google Account settings (Security → Third-party apps).

Your profile and training log, which you type in. Sex, age, height, bodyweight, goal weight, activity level, program start date, phase setting, and your chosen training split. Workouts: exercises, sets, weights, reps, reps-in-reserve, dates and times, and personal records. Daily entries: calories, protein, steps, morning bodyweight, and rest days. Forge syncs this to our servers automatically so it is on every device you sign in to, and keeps a working copy in your device’s app storage (so a brief connection drop doesn’t lose a set).

Purchase records. When you buy Forge on Google Play we store the Google Play order ID, purchase token, product, purchase time, status (for example paid or refunded), purchase type (for example a test purchase), and the country or region code Google reports. We never receive your card or bank details. Google handles the payment.

Free trial. Every new account gets a free trial. We store when your trial started and when it ends on your account, so it follows you across devices and reinstalls.

Sign-in and technical data. A cookie that keeps you signed in. For each signed-in session we store the IP address and the browser or device description (user agent) it came from, for security. Our host keeps standard server logs (such as IP address, time, and page requested) for LOG_RETENTION_TBD.

Emails. We only send account emails: email confirmation and password reset links. No marketing emails.

What we don’t collect

We don’t collect your location, contacts, photos, camera or microphone, advertising ID, or data from other apps (Forge doesn’t read Health Connect or Google Fit). There are no analytics, crash-reporting, or advertising SDKs in Forge.

How we use it

  • To run Forge: your account, sync across devices, and the training and nutrition targets.
  • To confirm your purchase with Google Play, unlock Forge, and remove access if a purchase is refunded or charged back.
  • To send the account emails you ask for (confirmation, password reset).
  • To keep Forge secure and prevent fraud and abuse.
  • To answer you when you contact support, and to meet legal obligations.

We don’t use your data for advertising, we don’t sell it, and we don’t share it with data brokers. We don’t make automated decisions about you that have legal or similar effects. Forge’s calorie, protein, and load targets are estimates for you to use or ignore.

Who processes your data for us

These service providers handle data only to provide their service to us:

  • Railway hosts the Forge servers and database, so your account, training log, and purchase records are stored there. Servers are located in HOSTING_REGION_TBD.
  • Resend delivers account emails. It receives your email address, your name, and the email content (which includes the link).
  • Google Play processes your payment. We use the Google Play Developer API to confirm purchases and receive refund and cancellation notices. Google’s own privacy policy covers your Google account.
  • Google Sign-In (only if you use “Continue with Google”) confirms your identity and shares the account details listed above with us.
  • Google Fonts serves the typeface Forge uses, so your device requests font files from Google, which receives your IP address and user agent.

We may also disclose data if the law requires it, to protect people’s safety or our rights, or as part of a sale or transfer of Forge. If Forge is ever transferred, we will tell you and this policy will continue to apply to your data.

Security

Data travels between your device and our servers over encrypted HTTPS connections. Passwords are hashed. Every request for your data is checked on the server against your signed-in account, and one account can’t read another’s data. No system is perfectly secure, but we work to protect your data and will notify you if a breach affects it, as the law requires.

How long we keep data, and deleting it

We keep your data while your account exists. You can delete your account at any time in the app (Profile → Delete account) or at /delete-account. Deletion is immediate and permanently removes your account (email, name, password hash, and any linked Google sign-in), every sign-in session on every device (including the IP addresses and user agents stored with them), your settings, any pending reset or confirmation links, and all synced training, fuel, and progress data. The copy on the device you delete from is cleared too. Other devices clear their copy the next time Forge opens and finds the account gone.

Purchase records are kept, but detached from you. When you delete your account, your purchase records are unlinked from it, so they no longer identify you in Forge. We keep them only for refund, chargeback, tax, and fraud-prevention records, for PURCHASE_RECORD_RETENTION_TBD. Because Google ties the purchase to your Google account, you can restore it onto a new Forge account later, and that re-links the record to the new account.

Trial record (hashed email). So that the free trial can be used only once per email address, when you delete your account we keep a one-way SHA-256 hash of your email address (lowercased, with any “+tag” and, for Gmail, dots removed) together with your trial start and end dates. We don’t keep the email itself or anything else about you, and the hash can’t be turned back into your email. If you later sign up again with the same address, the new account continues the old trial instead of starting a new one. We keep this record for TRIAL_TOMBSTONE_RETENTION_TBD, for fraud and abuse prevention.

Deleted data may remain in server backups until they expire, within BACKUP_RETENTION_TBD. We don’t restore deleted accounts from backups. If you can’t sign in to delete your account, email support@forgesplit.app from the address on the account.

Your choices and rights

  • See and correct your data in the app at any time.
  • Export it: CSV from Progress, and a JSON backup from Today or Profile.
  • Delete it by deleting your account, as described above.
  • Depending on where you live (for example California or another US state, the EU, or the UK), you may have rights to access, correct, delete, or port your data, or to object to or limit how it is used. Email support@forgesplit.app to use them. We will answer within the time the law requires and won’t treat you differently for asking.

We treat bodyweight, nutrition, and training data as sensitive. We use it only to provide Forge to you, and we never sell it or use it for advertising.

Children

Forge is for adults 18 and over and isn’t directed at children. If you believe a child has created an account, email support@forgesplit.app and we will delete it.

Changes to this policy

If we change this policy, we will update the effective date above. If a change is significant, we will tell you in the app or by email before it takes effect.

Contact

Jason Roberts, developer of Forge. Email: support@forgesplit.app.