Privacy Policy
Grey Men Coffee LLC (“Forge Pulse,” “we,” “us”) provides a fitness and wellness app for nutrition logging, workouts, recovery, activity, and optional AI-assisted features. This policy explains what we collect, why we use it, who processes it, how long it is retained, and the choices available to you.
Wellness, not medical care. Forge Pulse does not diagnose, treat, prescribe, or replace a qualified health professional. If you enable GLP-1 Mode, the app may automatically adjust protein, calorie, and training targets using the bounded fitness rules described below. These estimates are not medication or treatment advice; custom targets remain under your control.
1. Information we process
- Account and profile: name, email, Supabase user ID, age, sex, height, weight, goals, preferences, and optional profile photo.
- Fitness and health: workouts, sets, reps, weights, body measurements, meals, calories, macros, micronutrients, water, steps, sleep, heart rate, HRV, active energy, readiness check-ins, optional menstrual-cycle dates, and an optional self-reported GLP-1 Mode preference.
- Location: precise GPS samples and route polylines only while you explicitly record an outdoor cardio session. Location is not used for passive tracking.
- Photos: optional profile photos stored with your account; meal photos selected or captured for AI analysis. Meal photos remain on your device as part of the meal record and are not stored on Forge Pulse servers.
- AI content: meal-scan prompts and images, and text you submit to user-requested coaching, program, or meal-plan features.
- Purchases: subscription status, product, transaction, device, and entitlement identifiers handled by Apple, Google, and RevenueCat.
- Diagnostics: PII-scrubbed crashes and errors; with Analytics consent, performance traces, screen views, feature-use events, and an account user ID.
- Device services: push token, app/build version, OS/device class, and permission status needed to deliver app functionality.
We do not collect biometric templates. Face ID, Touch ID, and Android biometric matching happen entirely through the operating system, which returns only success or failure. Voice input uses the operating-system speech-recognition service. On-device recognition is preferred; when a local model is unavailable, the OS may send audio to Apple or Google to return a transcription. Forge Pulse receives the transcription, does not record or store the voice audio, and does not send it to Forge Pulse servers.
2. How and why we use information
| Purpose | Examples | Primary basis |
|---|---|---|
| Provide the service | Account, sync, workouts, nutrition logs, targets, subscriptions | Contract |
| User-requested optional features | AI analysis, health sync, GPS routes, analytics | Consent |
| Reliability and security | PII-scrubbed crash reports, abuse prevention, authentication | Legitimate interests |
| Legal compliance | Consent records, verified deletion records, required responses | Legal obligation |
Health permissions, AI processing, GPS recording, wearable connections, and analytics are optional. You may withdraw consent in Forge Pulse under Profile → Data & Privacy and in system settings. Withdrawal stops new processing for that purpose but does not undo lawful processing already completed.
3. AI processing
When you request an AI feature, Forge Pulse sends the necessary photo or text through a Supabase edge proxy to Anthropic’s commercial Claude API. We do not use these inputs to train Forge Pulse models. Under Anthropic’s commercial API terms, inputs and outputs are not used for model training and are deleted within 30 days by default; they may be retained longer for Usage Policy enforcement or legal obligations.
AI nutrition results are estimates. Review them before saving and use manual entry where accuracy matters. If GLP-1 Mode is enabled, the preference stays in encrypted app storage on your device and local calculations may adjust protein, calorie, and training targets. When you request AI coaching, a program, or a meal plan, the prompt tells Anthropic only that GLP-1 Mode is enabled so the response can respect the same wellness boundaries. Forge Pulse does not request or transmit a medication name, dose, dosing schedule, prescriber, diagnosis, or side-effect history through this preference.
Do not use Forge Pulse for diagnosis, medication decisions, or emergency guidance. The app does not recommend dosing, titration, medication choice, interactions, or stopping treatment.
4. Health, location, and background behavior
Apple Health and Health Connect access occurs only after system permission and is limited to the categories shown in the permission flow. Raw period-start dates, cycle length, day-in-cycle, preferences, and symptom or mood logs stay encrypted on the device. If Cycle Sync is enabled and the user invokes AI Coach, an AI training program, or an AI meal plan, only the current phase name (for example, “luteal”) is sent to Anthropic with that request. No date, day number, symptom, or mood log is sent. Self-reported GLP-1 status is likewise device-local except for the enabled/disabled context described above when the user invokes an AI feature.
Outdoor cardio GPS runs only during an explicitly started session and may continue while the screen is locked so the route remains accurate. The workout rest timer uses an ordinary scheduled local notification when the app is backgrounded. Forge Pulse does not use a silent-audio keep-alive or declare an iOS audio background mode.
5. Processors and recipients
| Processor | Purpose and data |
|---|---|
| Supabase | Authentication, database, storage, and edge functions for account and synced app data. |
| Anthropic | User-requested Claude API analysis and generation; meal images, relevant text, and the optional current cycle phase name described above, with commercial API retention described above. |
| RevenueCat | Subscription and entitlement management using account, device, and purchase identifiers. |
| Sentry | PII-scrubbed crash/error reporting; consent-gated performance telemetry. A user ID may be attached with Analytics consent. |
| PostHog EU Cloud | Consent-gated, PII-scrubbed product analytics linked to user ID. EU region; session replay disabled; no advertising use. |
| Expo | Push-notification delivery and over-the-air updates, including push token and app/build delivery telemetry. |
| Apple and Google | App distribution, sign-in, payments, health frameworks, maps/location platform services, and notifications as applicable. |
| Strava, Fitbit, Garmin | Optional read-only wearable sync where provisioned and explicitly connected by the user. |
| Railway | Immediate server-side depth-map processing for Elite LiDAR scans only; Forge Pulse’s Railway service does not retain scan input. |
| OpenFoodFacts and USDA FoodData Central | Food-database search queries without a Forge Pulse account identifier. |
| MapTiler and OpenStreetMap | Route-map tile delivery; ordinary request metadata such as IP address and user agent, without a Forge Pulse account identifier. |
| jsDelivr | Public exercise-media delivery; ordinary request metadata without a Forge Pulse account identifier. |
If you opt into an Accountability Partner or enabled Crew feature, the app shares only the activity signals and display name described in that feature with the other selected user(s). These features are off by default and include report/block controls. We do not sell personal information or share it for cross-context behavioural advertising.
6. Retention and deletion
- Profile, workout, nutrition, recovery, and optional route data remain while your account is active so the app can provide history and trends.
- Operational analytics are targeted for pruning after 90 days. Sentry event retention follows the configured Sentry plan, currently targeted at 90 days.
- Consent and deletion-accountability records may be retained for up to 24 months after closure, then anonymised, where needed to document compliance.
- Backups may take up to 90 days to expire after primary deletion.
Delete your account in Profile → Data & Privacy → Delete account, or use the public deletion page. Primary account records are removed through the deletion service. External processors may complete accepted deletion work asynchronously or require manual follow-up; we complete account-deletion requests within 30 days. Active subscriptions must be cancelled separately through Apple or Google to prevent future renewal.
7. Your choices and rights
Depending on where you live, you may request access, correction, export, deletion, restriction, objection, or portability, withdraw consent, or appeal a response. California residents may request information about collected data and opt out of sale or cross-context behavioural sharing; Forge Pulse does neither. European and UK residents may contact their supervisory authority after contacting us.
Use in-app export and deletion controls or email hello@forgepulse.app. We may verify your identity before fulfilling a request.
8. Security and international transfers
We use TLS in transit, app-private storage, OS secure storage for encryption keys, row-level database security, token validation, least-privilege server functions, and PII scrubbing for telemetry. No system is perfectly secure. Processors may handle data outside your country under their contractual safeguards and applicable transfer mechanisms.
9. Children
Forge Pulse is intended for users age 17 and older and is not directed to children. Contact us if you believe a child provided personal data so we can investigate and delete it.
10. Changes and contact
We will update the version and effective date when this policy materially changes and provide additional notice or renewed consent where required.