Privacy Policy

Last updated: May 5, 2026

Forge (“the App”, “we”, “us”) is a workout coaching application for iOS. This Privacy Policy explains what information the App collects, how it is used, and the choices you have. By using Forge you agree to the practices described below.

1. Information we collect

Account information. When you create an account we collect an account identifier and authentication token issued by Amazon Cognito. We do not collect your password — Cognito handles authentication directly.

Profile and training data. During onboarding and ongoing use, you provide:

Subscription and purchase data. When you subscribe to Forge Pro, we use RevenueCat to manage purchases. RevenueCat receives an anonymous account identifier and the App Store transaction record from Apple. We do not receive your payment card or Apple ID.

Device and diagnostic data. We use limited Apple-provided telemetry (build version, OS version, crash reports through Apple) to investigate problems. We do not use third-party advertising or behavioral analytics SDKs.

2. Where your data is stored

On your device. The vast majority of your data — your full workout history, body stats, personal records, program details, and preferences — is stored locally on your iPhone in an on-device SQLite database. It is not uploaded to our servers.

On our servers, only when needed for AI generation. When you request an AI-generated program, post-workout summary, or daily brief, the relevant subset of your profile and recent training context is sent to our backend (hosted on AWS Lambda) and forwarded to Anthropic Claude (via Amazon Bedrock) to produce the response. We do not retain these requests beyond the time needed to generate and return the response.

With our subscription processor. Subscription state is held by RevenueCat under your anonymous account identifier so that Pro features unlock on devices where you sign in.

With Apple. Apple processes your purchase under Apple’s Privacy Policy and provides receipts to us via RevenueCat.

3. How we use your information

We do not sell your personal information. We do not share it with advertisers. We do not use it to train third-party AI models.

4. Third-party services we rely on

Service Purpose Data shared
Amazon Cognito Authentication Account identifier, auth tokens
Amazon Bedrock (Anthropic Claude) AI program / insight generation Profile and training context for the request
Apple App Store / StoreKit Purchase processing Transaction receipts
RevenueCat Subscription management Anonymous account ID, receipts

Each provider has its own privacy practices, which apply to data they receive.

5. Your choices and rights

6. Children

Forge is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact wk03965@gmail.com and we will delete it.

7. International data transfers

Forge’s backend runs in the United States (AWS, us-east-1). If you use the App from outside the US, your data will be transferred to and processed in the US.

8. Health and fitness disclaimer

Forge provides general training guidance generated by software. It is not medical advice and is not a substitute for consultation with a qualified medical professional. Do not use Forge to diagnose, treat, or prevent any condition. Stop training and seek medical advice if you experience pain, dizziness, or other symptoms.

9. Security

We use industry-standard practices: TLS for all network traffic, AWS-managed key storage for backend secrets, on-device encryption provided by iOS for the local database. No system is perfectly secure, and we cannot guarantee against all threats.

10. Changes to this policy

We may update this Privacy Policy. The “Last updated” date at the top will reflect the most recent change. Material changes will be communicated in-app on next launch.

11. Contact

Questions about this policy or your data:

Email: wk03965@gmail.com