Privacy Policy

Forge Pulse · Version 3.0 · Effective July 29, 2026

Grey Men Coffee LLC (“Forge Pulse,” “we,” “us”) provides a fitness and wellness app for nutrition logging, workouts, recovery, activity, and optional AI-assisted features. This policy explains what we collect, why we use it, who processes it, how long it is retained, and the choices available to you.

Wellness, not medical care. Forge Pulse does not diagnose, treat, prescribe, or replace a qualified health professional. If you enable GLP-1 Mode, the app may automatically adjust protein, calorie, and training targets using the bounded fitness rules described below. These estimates are not medication or treatment advice; custom targets remain under your control.

1. Information we process

We do not collect biometric templates. Face ID, Touch ID, and Android biometric matching happen entirely through the operating system, which returns only success or failure. Voice input uses the operating-system speech-recognition service. On-device recognition is preferred; when a local model is unavailable, the OS may send audio to Apple or Google to return a transcription. Forge Pulse receives the transcription, does not record or store the voice audio, and does not send it to Forge Pulse servers.

2. How and why we use information

Purpose Examples Primary basis
Provide the service Account, sync, workouts, nutrition logs, targets, subscriptions Contract
User-requested optional features AI analysis, health sync, GPS routes, analytics Consent
Reliability and security PII-scrubbed crash reports, abuse prevention, authentication Legitimate interests
Legal compliance Consent records, verified deletion records, required responses Legal obligation

Health permissions, AI processing, GPS recording, wearable connections, and analytics are optional. You may withdraw consent in Forge Pulse under Profile → Data & Privacy and in system settings. Withdrawal stops new processing for that purpose but does not undo lawful processing already completed.

3. AI processing

When you request an AI feature, Forge Pulse sends the necessary photo or text through a Supabase edge proxy to Anthropic’s commercial Claude API. We do not use these inputs to train Forge Pulse models. Under Anthropic’s commercial API terms, inputs and outputs are not used for model training and are deleted within 30 days by default; they may be retained longer for Usage Policy enforcement or legal obligations.

AI nutrition results are estimates. Review them before saving and use manual entry where accuracy matters. If GLP-1 Mode is enabled, the preference stays in encrypted app storage on your device and local calculations may adjust protein, calorie, and training targets. When you request AI coaching, a program, or a meal plan, the prompt tells Anthropic only that GLP-1 Mode is enabled so the response can respect the same wellness boundaries. Forge Pulse does not request or transmit a medication name, dose, dosing schedule, prescriber, diagnosis, or side-effect history through this preference.

Do not use Forge Pulse for diagnosis, medication decisions, or emergency guidance. The app does not recommend dosing, titration, medication choice, interactions, or stopping treatment.

4. Health, location, and background behavior

Apple Health and Health Connect access occurs only after system permission and is limited to the categories shown in the permission flow. Raw period-start dates, cycle length, day-in-cycle, preferences, and symptom or mood logs stay encrypted on the device. If Cycle Sync is enabled and the user invokes AI Coach, an AI training program, or an AI meal plan, only the current phase name (for example, “luteal”) is sent to Anthropic with that request. No date, day number, symptom, or mood log is sent. Self-reported GLP-1 status is likewise device-local except for the enabled/disabled context described above when the user invokes an AI feature.

Outdoor cardio GPS runs only during an explicitly started session and may continue while the screen is locked so the route remains accurate. The workout rest timer uses an ordinary scheduled local notification when the app is backgrounded. Forge Pulse does not use a silent-audio keep-alive or declare an iOS audio background mode.

5. Processors and recipients

Processor Purpose and data
Supabase Authentication, database, storage, and edge functions for account and synced app data.
Anthropic User-requested Claude API analysis and generation; meal images, relevant text, and the optional current cycle phase name described above, with commercial API retention described above.
RevenueCat Subscription and entitlement management using account, device, and purchase identifiers.
Sentry PII-scrubbed crash/error reporting; consent-gated performance telemetry. A user ID may be attached with Analytics consent.
PostHog EU Cloud Consent-gated, PII-scrubbed product analytics linked to user ID. EU region; session replay disabled; no advertising use.
Expo Push-notification delivery and over-the-air updates, including push token and app/build delivery telemetry.
Apple and Google App distribution, sign-in, payments, health frameworks, maps/location platform services, and notifications as applicable.
Strava, Fitbit, Garmin Optional read-only wearable sync where provisioned and explicitly connected by the user.
Railway Immediate server-side depth-map processing for Elite LiDAR scans only; Forge Pulse’s Railway service does not retain scan input.
OpenFoodFacts and USDA FoodData Central Food-database search queries without a Forge Pulse account identifier.
MapTiler and OpenStreetMap Route-map tile delivery; ordinary request metadata such as IP address and user agent, without a Forge Pulse account identifier.
jsDelivr Public exercise-media delivery; ordinary request metadata without a Forge Pulse account identifier.

If you opt into an Accountability Partner or enabled Crew feature, the app shares only the activity signals and display name described in that feature with the other selected user(s). These features are off by default and include report/block controls. We do not sell personal information or share it for cross-context behavioural advertising.

6. Retention and deletion

Delete your account in Profile → Data & Privacy → Delete account, or use the public deletion page. Primary account records are removed through the deletion service. External processors may complete accepted deletion work asynchronously or require manual follow-up; we complete account-deletion requests within 30 days. Active subscriptions must be cancelled separately through Apple or Google to prevent future renewal.

7. Your choices and rights

Depending on where you live, you may request access, correction, export, deletion, restriction, objection, or portability, withdraw consent, or appeal a response. California residents may request information about collected data and opt out of sale or cross-context behavioural sharing; Forge Pulse does neither. European and UK residents may contact their supervisory authority after contacting us.

Use in-app export and deletion controls or email hello@forgepulse.app. We may verify your identity before fulfilling a request.

8. Security and international transfers

We use TLS in transit, app-private storage, OS secure storage for encryption keys, row-level database security, token validation, least-privilege server functions, and PII scrubbing for telemetry. No system is perfectly secure. Processors may handle data outside your country under their contractual safeguards and applicable transfer mechanisms.

9. Children

Forge Pulse is intended for users age 17 and older and is not directed to children. Contact us if you believe a child provided personal data so we can investigate and delete it.

10. Changes and contact

We will update the version and effective date when this policy materially changes and provide additional notice or renewed consent where required.