Skip to content
ForgeFit
Features Exercises Guides Help
Join the waitlist
FeaturesExercisesGuidesHelp Join the waitlist

Privacy Policy

Last updated: 3 August 2026 · Version 4.0

Contents

  1. 1. What we collect
  2. 2. Apple Health data
  3. 3. Voice and microphone
  4. 4. AI features
  5. 5. Social features and sharing
  6. 6. Analytics and your opt-out
  7. 7. Push notifications
  8. 8. How we use your data
  9. 9. Legal bases (EU/UK users)
  10. 10. Service providers
  11. 11. Data retention
  12. 12. Your rights and controls
  13. 13. Overseas disclosure
  14. 14. Children
  15. 15. Security and data breaches
  16. 16. This website
  17. 17. Changes
  18. 18. Contact

ForgeFit ("we", "us", "the app") is a fitness tracking application operated by Campbell Blair, a sole trader registered in Australia, ABN 14 278 891 663. This policy explains what personal information we collect, why, who we share it with, how long we keep it, and how you can access, correct, export or delete it.

We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we comply with the Spam Act 2003 (Cth) for all commercial electronic messages. If you are in the EU or UK, Section 9 sets out our legal bases under the GDPR.

This policy covers the ForgeFit iOS app, the website at forgefit.fitness, and our backend services.

The short version: we collect what we need to run your training log and AI coach, and nothing more. We never sell your data, never use it for advertising, and never use your Apple Health data for anything except showing you your own recovery. You can turn analytics off, export everything, and permanently delete your account and all its data from inside the app at any time.

1. What we collect

Account and profile

  • Account: your email address, display name, and a password (stored only as a secure hash; we never see the plain text). If you use Sign in with Apple or Google, we receive only the basic identity information those providers return; with Apple you may choose to hide your real email.
  • Guest mode: if you start without registering, we create an anonymous account identified by a generated ID on your device. It holds no personal details until you choose to register.
  • Fitness profile: gender, date of birth, height, body weight, training goal, experience level, training days per week, session length, available equipment, and any injuries you tell us about, all used to tailor plans and AI suggestions.

Training data you log

  • Workouts, exercises, sets, reps, weights, RPE, rest times, personal records, training plans and templates, goals, body measurements, and any notes you add.
  • Imported history. If you import a workout history from another app, that file and the training records inside it are stored in your account exactly as your own logged data is.
  • Progress photos and programme screenshots you choose to upload. These are stored privately and are visible only to you. They are never shared to any social feature, never made public, and never used for any purpose other than showing them back to you.

Health and fitness data from Apple Health

  • Only with your permission, and only these categories: steps, heart rate, heart-rate variability (HRV), resting heart rate, sleep, and active energy. See Section 2.

Voice input

  • If you use Ember's voice mode, your speech is converted to text so it can be sent as a message. See Section 3.

Social data (only if you use social features)

  • A username you choose, your friend connections, workouts you share to your feed, likes and comments you post, and any users you block. See Section 5.

Device and technical data

  • Push notification token: a device identifier issued by Apple or Google that lets us deliver notifications you've asked for (see Section 7).
  • Server logs and error diagnostics: when a request to our servers fails, technical details of that request are recorded so we can fix it.
  • Product analytics: anonymous feature-usage events, which you can switch off (see Section 6).

Subscription and billing

  • ForgeFit V1 is free and no subscription is currently sold. The app includes the RevenueCat purchase SDK so subscriptions can be enabled in a future release; it is inert until then. If and when paid tiers launch, iOS purchases are processed by Apple's In-App Purchase and web purchases by Stripe. We never see or store your card details: Apple and Stripe handle those. We would receive only your subscription status and a purchase identifier.

Waitlist

  • If you join the waitlist, we collect your email address, IP address (for rate limiting and abuse prevention), and signup and confirmation timestamps together with the version of the consent wording shown to you: this is how we evidence double opt-in under the Spam Act.

2. Apple Health data

ForgeFit uses Apple Health to show you your recovery and training readiness. We follow Apple's HealthKit requirements:

  • We only read health data: steps, heart rate, HRV, resting heart rate, sleep and active energy. We never write to your Health record.
  • Health data is used solely to calculate and display your recovery, strain and readiness, and to scale AI-generated training suggestions. We never use it for advertising or marketing, and we never sell it or disclose it to any data broker.
  • Health data is not stored in iCloud by us and is not used for any purpose you have not granted permission for.
  • Summary recovery values derived from this data are stored on our servers so your recovery history is available across devices. The underlying raw Health records stay on your device.
  • You can revoke access at any time in iOS Settings → Privacy & Security → Health. Revoking access does not delete workouts you have already logged in ForgeFit.

Health information is sensitive information under the Privacy Act and special category data under the GDPR. We collect it only with your express consent, given through the iOS Health permission prompt, and you may withdraw that consent at any time as described above.

3. Voice and microphone

Ember has an optional voice mode. When you use it, and only while you are actively holding or running a voice session:

  • Your microphone is accessed and your speech is converted to text using Apple's on-device and system speech recognition, which is governed by Apple's own privacy terms.
  • We do not record, store, or transmit raw audio to our servers. Only the resulting text is sent, and it is treated exactly like a message you typed.
  • Ember can also read replies aloud using the system text-to-speech voice. This happens on your device.
  • Microphone and speech recognition permissions are requested separately by iOS and can be revoked at any time in Settings → Privacy & Security.

4. AI features

ForgeFit uses third-party AI models to generate coaching responses, plans, critiques and images:

  • Anthropic (Claude): coaching chat, workout and plan generation, progression suggestions, and programme critique. Processed under Anthropic's privacy policy.
  • Google (Gemini): image generation for features such as share cards. Processed under Google's privacy policy.

To produce a response we send the relevant inputs: your message, any programme text or image you submit, and the relevant parts of your training history and fitness profile. Providers process the request to return a result and are contractually restricted from using your inputs to train their models beyond what their own terms permit.

AI output is not medical, fitness or professional advice. It is generated automatically and can be wrong. See our Terms of Service.

5. Social features and sharing

ForgeFit includes optional social features. They are off by default and opt-in. If you never enable them, none of the data below is collected.

What becomes visible to others

  • Your username and display name are visible to other users, including in search and on leaderboards.
  • Workouts you share appear in your friends' feed, where they can like and comment on them. You choose your default visibility in Settings → Privacy & Social, and you can hide any individual workout.
  • Comments and likes you post are visible to everyone who can see that workout.
  • Leaderboard entries show your username and the relevant training statistic.

What never becomes visible

  • Your email address, date of birth, body weight and body measurements.
  • Your progress photos: these are never shared to any social surface.
  • Your Apple Health data, recovery scores, HRV or sleep.
  • Your conversations with Ember.

Blocking and reporting

You can block any user, which stops them contacting you or seeing your activity. You can report any post, comment or profile that breaches our Community Guidelines, and we action reports as quickly as possible, and generally within 72 hours. Reports are stored with the reporting user's ID so we can act on them and identify abuse of the reporting system itself.

Public share links

If you choose to share a programme critique as a link, the critique text and the programme you submitted are stored and made available at an unguessable public URL so it can be opened by anyone you send it to and previewed by messaging apps. This content is public to anyone holding the link and is not tied to your name or account. Do not share a critique containing anything you would not want a stranger to read. Email privacy@forgefit.fitness to have a share link revoked.

6. Analytics and your opt-out

We use PostHog for first-party product analytics, which features get used, and where the app can improve. Events are tied to a randomly generated identifier stored on your device, not to your name, email, IDFA or any cross-app advertising identifier.

We do not track you across other apps or websites, which is why ForgeFit does not show the App Tracking Transparency prompt.

You can turn analytics off completely at any time: Settings → Privacy & Social → "Share anonymous usage data". When it is off, no product-analytics events are sent.

Separately, Sentry records technical details of errors so we can fix them: failed server requests, and crashes in the app itself. A crash report describes the fault, not you, and covers the error, the screen it happened on, your device model and the app version. It is error monitoring, not behavioural tracking. The same "Share anonymous usage data" switch turns crash reporting off along with analytics.

7. Push notifications

If you allow notifications, your device is issued a push token by Apple or Google which we store against your account so we can deliver rest-timer alerts, workout reminders and achievement notifications you have opted into.

You control which categories you receive in Settings → Notifications inside the app, and can revoke notifications entirely in iOS Settings. Turning notifications off in iOS removes the token's usefulness; deleting your account deletes the stored tokens.

8. How we use your data

  • Authenticate you and keep you signed in.
  • Store your workouts, plans, goals, measurements and photos so your history persists across devices.
  • Calculate and display recovery and readiness from Apple Health, if connected.
  • Generate AI workout plans, coaching responses and programme critiques.
  • Calculate ranks, achievements and progress statistics.
  • Operate social features, if you enable them, and enforce our Community Guidelines.
  • Send transactional emails (verification, password reset, waitlist confirmation) and notifications you have opted into.
  • Diagnose errors, prevent abuse, and improve the app.
  • Process subscription payments, if and when you subscribe.
  • Comply with our legal obligations.

We do not sell your personal information. We do not use it for advertising, and we do not disclose it to anyone except the service providers listed in Section 10, each only to the extent needed to run the service.

9. Legal bases (EU/UK users)

If the GDPR applies to you, we rely on the following legal bases:

PurposeLegal basis
Providing the app and your accountPerformance of a contract (Art. 6(1)(b))
Apple Health dataExplicit consent (Art. 9(2)(a)): withdrawable in iOS Settings
Voice inputConsent (Art. 6(1)(a)): withdrawable in iOS Settings
Social featuresConsent (Art. 6(1)(a)): opt-in, withdrawable in app
Product analyticsConsent (Art. 6(1)(a)): opt-out in app
Error monitoring, security, abuse preventionLegitimate interests (Art. 6(1)(f))
Transactional emailPerformance of a contract (Art. 6(1)(b))
Waitlist marketing emailConsent (Art. 6(1)(a)): double opt-in, unsubscribe any time
Billing and tax recordsLegal obligation (Art. 6(1)(c))

You have the right to access, rectify, erase, restrict and port your data, to object to processing based on legitimate interests, and to lodge a complaint with your local supervisory authority. Section 12 explains how to exercise these.

10. Service providers

ProviderPurposeLocation
SupabaseAuthentication, database, file storage (including progress photos)US
VercelServer and website hostingUS
AnthropicAI coaching, plan generation, critiqueUS
GoogleGemini image generation; Sign in with GoogleUS
PostHogAnonymous product analytics (opt-out available)US / EU
SentryServer error and app crash diagnostics (opt-out available)US
ResendTransactional and waitlist email deliveryUS
RevenueCatSubscription management (inert until paid tiers launch)US
StripeWeb subscription billing (when applicable)US
AppleSign in with Apple, HealthKit, speech recognition, push, In-App PurchaseUS

Each provider receives only the minimum data needed to perform its function, and none is permitted to use your data for its own marketing.

11. Data retention

  • App data: retained while your account exists. Deleted permanently within 30 days of you deleting your account.
  • Progress photos: deleted when you delete the photo, or with your account.
  • Social content: comments and likes are deleted with your account. Where a comment is needed as evidence in an unresolved abuse report, it may be retained until that report is closed.
  • Public share links: retained until you ask us to revoke them, since they are not tied to your account.
  • Push tokens: deleted when you sign out, revoke notifications, or delete your account.
  • Analytics: anonymous, retained in aggregate, not linked to your identity.
  • Waitlist: retained until you unsubscribe or launch completes. Consent audit records kept for 3 years after the last message, as the Spam Act requires.
  • Server error logs: retained up to 90 days.
  • Billing records: retained by Apple, Stripe and us as long as tax and audit law requires (generally 5 years in Australia).

12. Your rights and controls

You control your data. From inside the app:

  • Access and export: Settings → Data → Export All Data (APP 12; GDPR Art. 15 and 20).
  • Correct: Settings → Profile (APP 13; GDPR Art. 16).
  • Opt out of analytics: Settings → Privacy & Social.
  • Control social visibility: Settings → Privacy & Social, plus per-workout hiding and user blocking.
  • Delete: Settings → Delete Account. Permanent and irreversible (APP 11.2; GDPR Art. 17).
  • Waitlist: use the unsubscribe link in any email.

For anything you cannot do in the app, including revoking a public share link, restricting processing, or objecting to processing: email privacy@forgefit.fitness. We respond within 30 days.

If you believe we have breached the APPs, please complain to us first. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (OAIC). EU and UK users may complain to their local data protection authority. California residents have rights under the CCPA/CPRA, including the right to know and delete: note that we do not sell or share personal information as those terms are defined.

13. Overseas disclosure

Your data may be processed in the United States, and for PostHog optionally the European Union, by the providers listed in Section 10. We take reasonable steps to ensure they handle your information consistently with the APPs (APP 8). For transfers of EU/UK personal data, we rely on the providers' Standard Contractual Clauses or equivalent transfer mechanisms under their data processing agreements.

14. Children

ForgeFit is intended for users aged 16 and over. We do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has created an account, email privacy@forgefit.fitness and we will delete it promptly.

15. Security and data breaches

Passwords are hashed, data in transit is encrypted with TLS, and card details never touch our servers. Access to your data is authenticated and scoped to your account. Progress photos are stored in private storage that is not publicly listable.

No system is perfectly secure, but we take reasonable steps to protect your information (APP 11). If a data breach occurs that is likely to result in serious harm, we will notify affected users and the OAIC as required by the Notifiable Data Breaches scheme, and any other regulator we are obliged to inform.

If you believe your account has been compromised, change your password and email privacy@forgefit.fitness immediately.

16. This website

forgefit.fitness sets no cookies, runs no analytics or advertising trackers, and loads no third-party resources: fonts and images are served from our own domain, so no data about your visit is sent to any other company.

If you submit the waitlist form we receive your email address, your IP address (used for rate limiting), and a timestamp. We send a confirmation email you must click before we add you to the list, and every email includes an unsubscribe link.

17. Changes to this policy

If we change this policy materially, we will notify you in the app or by email and update the "Last updated" date above. Previous versions are available on request.

18. Contact

Campbell Blair, trading as ForgeFit
ABN 14 278 891 663 · Australia
Privacy: privacy@forgefit.fitness
Safety and abuse: safety@forgefit.fitness
General: hello@forgefit.fitness

A postal address is available on request to any individual or regulator who requires one for a formal privacy complaint.

Privacy Policy · Terms of Service · Community Guidelines

ForgeFit is operated by Campbell Blair, sole trader, ABN 14 278 891 663, Australia.

ForgeFit

The AI gym coach in your pocket.
Train smarter. Get stronger.

Product

  • Features
  • Workout Logger
  • Ember AI Coach
  • Recovery Tracking
  • Ranks & Trophies

Resources

  • Training Guides
  • Exercise Library
  • Help Centre
  • RSS Feed

Workout Splits

  • Push / Pull / Legs
  • Upper / Lower Split
  • 3 Day Workout Split
  • 4 Day Workout Split
  • 5 Day Workout Split
  • Arnold Split

Company

  • Privacy Policy
  • Terms of Service
  • Community Guidelines
  • Contact

© 2026 ForgeFit · Campbell Blair · ABN 14 278 891 663

ForgeFit is a training log and planning tool, not medical advice. Always train within your ability and consult a qualified professional before starting a new programme.