Privacy Policy
Updated 18 September 2026
Who we are
Forge is operated by A&A Digital LLC, a company based in the United States (“we” and “us”). This policy explains what the Forge iOS app collects, where that data lives, how it is used and how you can delete it. Questions go to support@forgepeptide.app.
Forge is not a healthcare provider, health plan or insurer, so HIPAA does not apply to the data you enter in Forge. Forge does not claim HIPAA compliance.
What we collect, feature by feature
Forge keeps two kinds of data: data that stays on your phone, and data on our servers. Here is every category and where it lives.
- Account (server). Forge requires an account. With Sign in with Apple we receive your name and email address (the address may be an Apple Hide My Email relay that forwards to you). With email sign-up we receive your email address and a password, which Supabase Auth stores only as a hash. A sign-in session token is kept on your phone.
- Profile (server). Your handle, initials, whether you post anonymously, your “Blur my face” setting, your sourcing-hidden setting, and your onboarding answers: goals, frictions, experience level, how you heard about Forge and when you finished onboarding.
- Doses, vials, protocols, body weight, workouts, meals, water and progress photos (your phone only). These are stored in the app’s database on your phone and are never uploaded. Forge does not sync them to iCloud or between devices; your iPhone’s own backup may include them like any app’s data. If you delete the app they are gone unless your backup restores them. The one exception is when you publish a stack with before/after photos, described under Community.
- Community stacks (server). When you publish a stack we store its title, goal, category, compounds with dose labels, cadence and adherence statistics, plus — only if you choose to include them — weight statistics or a weight series and before/after photos. Comments, upvotes, follows, blocks and reports you make are stored too.
- Locked In (server). Your handle, the US state you pick, your streak, rest-day tokens and the time of your last check-in. The photo you take for a check-in is a progress photo and stays on your phone.
- Meal scans (server, in transit only). When you scan a meal, the photo is sent to our server function, forwarded to OpenAI for a calorie and macro estimate, and the result is stored on your phone. Our server keeps a daily count of your scans (25 per day) but does not keep the photo.
- Vial label scanning (your phone only). The camera image is read on your phone with Apple’s Vision framework to pre-fill a vial. Nothing is uploaded.
- Apple Health (your phone only). See the Apple Health section below.
- Support emails. If you email us from the app, the draft includes your device model, iOS version and Forge version so we can help; you can delete that footer before sending.
- Technical logs. Like any hosted service, our hosting provider records request logs (such as IP address and time) to run and secure the service.
How we use it
We use your data to run the features you use: signing you in, unlocking your subscription, publishing and showing community stacks, running the Locked In boards, analysing meal photos, and enforcing the daily scan limit.
We use reports, blocks and account data to keep the community safe, and the details you send us to answer support requests.
Onboarding answers help us understand who uses Forge and what to build next.
We do not use your data for advertising, do not sell it, do not share it with data brokers, do not run analytics or tracking SDKs, and do not train AI models on it.
Apple Health
Connecting Apple Health is optional. If you connect it, Forge reads weight, steps, active energy, sleep and workouts and imports them into the database on your phone. Forge is read-only: it never writes anything to Apple Health.
Data imported from Apple Health is never uploaded to our servers, never included in anything you publish (weigh-ins that came from Apple Health are excluded from published stacks), never shared with anyone and never used for advertising.
You can stop sharing at any time in the Health app or in iOS Settings under Privacy & Security › Health. Forge does not use iCloud or CloudKit.
Camera and meal photos
Forge uses the camera for three things: taking your progress and check-in photos, which stay on your phone; reading vial labels, which also happens entirely on your phone; and scanning meals.
A meal photo is sent as soon as you take or choose it inside the meal scanner, so open the scanner only for photos you want analysed. It goes through our Supabase server function to OpenAI, which returns a calorie and macro estimate. OpenAI processes it under its API terms: the photo is not used to train OpenAI’s models, and OpenAI may keep it for up to 30 days to monitor for abuse before deleting it. Our server does not keep a copy. The estimate is stored on your phone.
Each scan counts toward a limit of 25 scans per day, tracked against your account. Please do not include other people, or anything you would not want analysed, in a meal photo. Progress photos and check-in photos are never sent to OpenAI.
Community and photos
Publishing to the community is optional. Published stacks are visible to other signed-in Forge users, who can upvote, comment on, clone, report or block them. Every photo you publish is screened automatically by OpenAI's moderation model before it is stored: photos that fail are refused, and anything borderline — or anything the screening could not decide — is held out of the feed until a person has reviewed it.
Before/after photos you publish are stored in a private storage bucket. There is no address a stranger can open: the app requests each photo through a short-lived link that our storage service issues only to a signed-in Forge account, and that link stops working within the hour. Any signed-in Forge user can see the photos on a stack you publish, and anyone who can see a photo can screenshot or save a copy, so only publish photos you are comfortable other members seeing.
If you keep “Blur my face” on, Forge pixellates every face its on-device detector finds before the photo is uploaded, and warns you before publishing if it found no face. Face detection can miss a face, so only publish photos you are comfortable other members seeing.
If you post anonymously, your handle and initials are not shown with the post. We can still see which account posted it, which we need for moderation.
Forge has no field for vendor or sourcing details; a server rule rejects comments containing vendor or sourcing links, and any other sourcing content is removed when reported.
You can delete a stack or comment you published from within the app. Deleting your account removes all of them, including photos.
Subscriptions
Forge Pro is sold through Apple’s App Store as an auto-renewing subscription, offered monthly or yearly. The exact price, the billing period and any free trial are shown on the subscription screen in the app and confirmed by the App Store before you are charged, in your own currency. Apple bills you, and we never see your payment details.
RevenueCat processes App Store purchases for us. Its SDK sends RevenueCat your app user id (the same id as your Forge account), the App Store receipt, your device’s identifier for vendor, your IP address and your device and app version, and RevenueCat keeps your purchase history — products, dates and status — so that your subscription unlocks whenever you sign in. RevenueCat does not receive your name or email.
Subscriptions are managed in your Apple Account settings under Subscriptions.
Who we share with
We share data only with the five services that make Forge work, each for a single purpose. None of them may use your data for their own advertising.
- Apple — Sign in with Apple and App Store billing. Apple Health data is read on your phone and never leaves it.
- Supabase — hosting, sign-in, database, file storage and server functions. Our project runs on Amazon Web Services in the US West (Oregon) region, so your data is stored in the United States.
- RevenueCat — subscription status and purchase history, keyed to your account id.
- OpenAI — analysis of meal photos you choose to scan, and automated screening of photos you publish to the community for sexual, violent or self-harm content. Nothing else.
- Resend — delivers a moderation email to the operator when a report is filed. That email contains the report type, reason, target id, report id and time; it does not contain your name, email or the reported content.
We may also disclose data if the law requires it or to protect the safety of Forge users. If Forge is ever transferred to a new operator, your data would move with it under this policy.
If you use Forge from outside the United States, your data is transferred to and stored in the United States.
Retention and deletion
Server data is kept for as long as your account exists.
You can delete your account in Settings, or from the Manage account sheet on the subscription screen. Deletion runs immediately on our server and removes your sign-in, profile, onboarding answers, stacks, comments, upvotes, follows, blocks, reports, Locked In pledge, meal-scan counter and every photo you uploaded.
What remains after deletion: Apple’s records of your App Store purchases, which Apple manages; RevenueCat’s purchase records keyed to your account id, which contain no name or email and are needed for refunds and restores; any meal photo already sent to OpenAI within its 30-day abuse-monitoring window; and emails you sent to support, which stay in our support mailbox unless you ask us to delete them.
Deleting your account does not touch the data on your phone. Delete the app to remove doses, vials, protocols, weights and photos stored there.
Your rights
- Access: your profile, stacks, comments and Locked In pledge are visible in the app. Email us for a copy of everything we hold about your account.
- Correction: email support@forgepeptide.app and we will correct or update it.
- Deletion: delete individual stacks and comments in the app, delete your account in Settings, or email us.
- Withdrawal: stop sharing Apple Health in iOS Settings, stop publishing, or delete your account at any time.
Requests go to support@forgepeptide.app. To protect your account we will ask that requests come from the email address on the account. We do not treat you differently for exercising these rights.
Consumer health data
This section is for residents of Washington, Nevada, Connecticut and other states with consumer health data laws. It describes the consumer health data Forge handles, which is the data you enter about the compounds you use and your body.
- Categories on your phone only: doses and compounds you log, protocols, body weight, workouts, meals, water, progress photos and anything imported from Apple Health.
- Categories on our servers: the compounds, dose labels, cadence and adherence statistics in stacks you publish; weight statistics and before/after photos only if you include them; your onboarding answers about goals, frictions and experience; and your daily meal-scan count.
- Sources: you, by entering or publishing it; Apple Health, with your permission and on your phone only; and OpenAI’s meal estimates, which are stored on your phone.
- Purposes: to provide the features you use, to moderate the community and to answer your support requests. Nothing else.
- Sharing: Supabase stores the server data above; OpenAI receives meal photos you scan and community photos you publish, for screening only; RevenueCat and Resend receive no health data. We do not sell consumer health data and do not share it for advertising. We do not collect precise geolocation; the US state on a Locked In pledge is one you choose.
- Your rights: confirm whether we process your consumer health data, access it, receive a list of the third parties it was shared with, withdraw consent and have it deleted. Use the app’s delete controls or email support@forgepeptide.app. If we decline a request, you may appeal by replying to our decision and we will answer the appeal in writing.
California residents
We do not sell your personal information and do not share it for cross-context behavioural advertising, and we have not done so in the past 12 months. You have the right to know what we collect, to delete it, to correct it and not to be discriminated against for exercising these rights. Use account deletion in the app or email support@forgepeptide.app. Because Forge runs no tracking, there is nothing to opt out of.
Children
Forge is for adults aged 18 and over. Onboarding asks your age and we do not knowingly collect data from anyone under 18. If we learn that an account belongs to someone under 18 we delete it. If you believe that has happened, email support@forgepeptide.app.
Security
Data travels between the app and our servers over HTTPS, and our hosting provider encrypts stored data at rest. No system is perfectly secure, so only publish what you are comfortable sharing.
Changes
When this policy changes we update the date at the top. If the change is material we will say so in the app’s release notes or by email to your account address.
Contact
A&A Digital LLC, operator of Forge, United States.
Email: support@forgepeptide.app