Privacy Policy
Who we are
Body Forge is developed and published by the operator of fueltheforge.app ("we", "us", or "our"). The Android app is distributed on Google Play under the package name app.fueltheforge. An iOS build, when available, uses the bundle identifier com.fueltheforge.bodyforge.
For privacy questions or requests, contact support@fueltheforge.app.
Introduction
Body Forge is a fitness and nutrition app for iOS and Android. This Privacy Policy explains what data the app handles, how it is stored, when it may leave your device, and what choices you have.
Body Forge is local-first: your workouts, food diary, progress photos, profile, and settings are stored on your device unless you explicitly use a feature that sends data to a third party (described below).
Data we store on your device
- Profile and settings (name, goals, macro targets, units, theme, coach preferences).
- Workout history, templates, plans, personal records, and scheduled sessions.
- Food diary entries, custom foods, favourites, meal plans, shopping lists, and ForgeChef meals you save to My Meals.
- Body weight, body composition entries, progress photos, supplements, and Forge Score history.
- AI Coach chat history and structured coach memory (stored locally per profile).
- Gym membership QR codes you save in Settings (stored locally).
- A local profile identifier used to scope multi-profile data on your device.
- Optional Google Sign-In session (display name, email, profile photo URL, Google user ID) in secure device storage when you sign in.
We do not operate a cloud backup of your workout or nutrition logs in the current release.
Google Sign-In (optional)
You may optionally sign in with Google in Settings. This uses Google's OAuth service (configured via a Google Cloud / Firebase project for client IDs only).
- We receive your Google user ID, email address, display name, and profile photo URL from Google when you sign in.
- This session is stored locally on your device (secure storage). We do not receive your Google password.
- On Android, sign-in may link your Google account to Google Play subscriptions (via RevenueCat) and ForgeClub access codes (see below). On iOS, subscriptions use your Apple ID via the App Store; Google Sign-In is not available.
- You can sign out at any time in Settings, which clears the local session.
Google processes sign-in data under its own Privacy Policy.
Subscriptions and billing (App Store and Google Play)
BodyForge Pro (some in-app and store strings may still say "Body Forge Premium") is sold through Apple In-App Purchase via the App Store on iOS, and through Google Play Billing on Android. We use RevenueCat on both platforms to verify subscription and purchase entitlement status in the app.
- Payment is processed entirely by Apple or Google. Body Forge does not receive your card or bank details.
- RevenueCat receives purchase receipts and entitlement status from the applicable store so the app can unlock BodyForge Pro features.
- If you sign in with Google on Android, RevenueCat may associate purchases with your Google user ID. If you do not sign in, an anonymous RevenueCat customer ID is used; you can still restore purchases on the same Apple ID or Google account used to subscribe.
- Manage or cancel iOS subscriptions in Settings → Apple ID → Subscriptions. Manage or cancel Android subscriptions in Google Play → Payments and subscriptions.
ForgeClub access codes
ForgeClub is available on Android only. It is an optional way to unlock Premium with a code (for example from a gym or partner). If you redeem a code:
- You must sign in with Google first.
- The app sends your Google user ID and the code to our API at
bodyforge.onrender.comto validate and record the entitlement. - Our server stores entitlement status (active/expired, code type, expiry) linked to your Google user ID. It does not receive your workouts, food diary, or other local app data.
ForgeClub admin tools for generating codes are staff-only and are not linked from this website.
Apple Health (iOS)
On iOS, you may optionally connect Apple Health to read steps, heart rate (when available from linked devices), weight, body fat percentage, lean body mass, and active energy when your linked apps or devices provide them.
- Body Forge does not write to Apple Health. Read access is requested only when you tap Connect in Settings → Health Data.
- Data read from Apple Health is used inside the app for progress charts, outdoor activity stats, and coach context. We do not upload your HealthKit records to our servers.
- We do not sell Apple Health data and do not use it for advertising. You can disconnect Apple Health at any time in Settings or in your device's Apple Health app settings.
Android Health Connect
On Android, you may optionally connect Health Connect to read steps, heart rate (when available), calories burned, and body metrics from linked apps or devices (for example smart scales).
- Health Connect is an Android-only platform feature.
- Data read from Health Connect is used inside the app for progress charts, outdoor activity stats, and coach context. We do not upload your Health Connect records to our servers.
- We do not sell Health Connect data and do not use it for advertising. You can disconnect Health Connect at any time in Settings or in your device's Health Connect permissions.
Location and outdoor activities
When you start an outdoor activity (for example a walk, run, cycle, or hike), the app may request location permission to draw your route on a map and estimate distance while tracking.
- Location data is processed on your device for activity history and is not uploaded to our servers in the current release.
- Background location may be used only while an outdoor activity is actively recording, so tracking can continue if you briefly switch apps.
- You can deny location permission; outdoor route tracking will not work without it. You can change location access later in your device settings.
Camera and photos
The camera and photo library are used when you choose to:
- Set or change a profile photo
- Scan barcodes for food logging
- Scan or capture meal photos for ingredient estimates or ForgeChef ingredient detection
- Capture progress photos
- Upload a gym membership QR code in Settings
Profile photos, progress photos, meal photos, and gym QR images stay on your device unless you use a network or AI feature that sends data elsewhere (for example barcode lookup, meal/progress AI analysis via our server — see AI processing and Third-party services).
Camera access is requested only when you open a feature that needs it. You may deny permission; those features will not work without it.
Notifications
If you enable notifications, the app may send local reminders (for example workout or rest-timer alerts) on your device.
Notification content is generated on your device. We do not use notifications to collect personal data.
ForgeChef (AI meal generation)
ForgeChef is an optional BodyForge Pro feature that helps you turn ingredient photos into meal ideas and recipes.
- You choose when to use ForgeChef and which photos to add (for example your fridge, cupboards, worktop, or individual ingredients).
- Ingredient photos stay on your device until you continue to review or start analysis.
- When you request ingredient detection, meal suggestions, recipe generation, or smart adjustments, the app sends the selected images and related text (for example meal preferences or adjustment instructions) to our server at
bodyforge.onrender.com, which forwards them to OpenAI for processing. Only the content needed for the feature you started is transmitted. - AI-generated ingredient lists, meal suggestions, recipes, and adjustments are returned to the app. Saved ForgeChef meals are stored locally on your device. We do not upload your saved ForgeChef meals to our servers.
- We do not sell ForgeChef data to advertisers and do not use ingredient photos for advertising.
- ForgeChef only runs when you explicitly open and use it. Generic analytics events (for example that ForgeChef was used) may be logged without sending your photos to Firebase Analytics.
ForgeChef outputs are general nutrition guidance only — not medical advice. Verify ingredients, allergens, and cooking safety yourself before eating.
AI processing (OpenAI)
Production App Store and Google Play builds do not include an OpenAI API key in the app. When cloud AI is available, eligible requests — such as AI Coach chat, ForgeChef ingredient and meal generation, meal photo ingredient analysis, progress photo comparison, spoken coach replies, and weekly check-in summaries — are sent to our server at bodyforge.onrender.com, which forwards the request to OpenAI. Only the text or images needed for the feature you started are transmitted. If cloud AI is unavailable, the app falls back to on-device guidance. Development builds may optionally use a developer-configured OpenAI key instead of the server proxy.
AI Coach and ForgeChef responses and other AI outputs are general fitness and nutrition guidance only — not medical advice. Consult a qualified professional before changing your exercise or nutrition programme.
OpenAI processes data under its own terms and privacy policy.
You can turn off the AI Coach in Settings. ForgeChef, meal, and progress photo AI features only run when you explicitly start them.
Third-party services
| Service | What is sent | Purpose |
|---|---|---|
| Google Sign-In | OAuth tokens; profile fields from Google when you sign in | Optional account linking for billing and ForgeClub |
| Google Firebase (Analytics) | Privacy-safe app usage events on Android and iOS: app opens, screen navigation names, session activity, app version, platform, coarse entitlement status, and generic feature events (for example paywall viewed, workout started, food logged, ForgeChef opened). On Android, the SDK may also collect the Google Advertising ID when available for analytics measurement. We do not send fitness, nutrition, health, personal identity data, or photos to Firebase Analytics | Understand general app usage, improve navigation and features, measure engagement, and monitor general app reliability |
| App Store / Google Play / RevenueCat | Purchase receipts and entitlement status from Apple or Google; optional Google user ID on Android when signed in. RevenueCat verifies entitlement status. Body Forge does not receive card or bank details. | Premium subscriptions and restore purchases |
Body Forge API (bodyforge.onrender.com) | Food/recipe search queries; exercise library sync requests; ForgeClub code + Google user ID when redeeming; AI coach chat text and related context; ForgeChef ingredient photos and meal-generation text; meal and progress images for AI analysis; OpenAI proxy payloads when you start cloud AI features; waitlist email when you join on the website; optional app-open metrics (anonymous install identifier stored on your device, platform, app version, and optional Google user ID when signed in) | Recipe/food proxy, exercise library, ForgeClub entitlements, ForgeChef AI proxy, AI proxy to OpenAI, tester waitlist, coarse install metrics |
| Open Food Facts | Barcode or search terms | Product and nutrition lookup |
| OpenAI | Chat text and/or images (when cloud AI is used, including ForgeChef and via our server proxy in production builds) | AI coach, ForgeChef meal generation, TTS, photo analysis |
Our app uses Google Firebase configuration files (google-services.json on Android and GoogleService-Info.plist on iOS), delivered securely at build time, to enable Google Sign-In OAuth client IDs on Android and Firebase Analytics on Android and iOS. We do not use Firebase Auth, Crashlytics, or Firebase cloud storage for your fitness data.
Paid food API credentials stay on our server, not in the app. We do not use FatSecret or similar third-party nutrition account services.
We do not sell your personal data to third parties.
Device, diagnostics, and analytics
Body Forge uses Firebase Analytics (Google Analytics for Firebase) on Android and iOS to understand general app usage, improve navigation, improve features, measure engagement, and monitor general app reliability.
Firebase Analytics may collect app opens, screen views, session activity, app version, platform and device information, coarse entitlement status, and generic feature usage events (for example app_open, screen_view, login_success, paywall_viewed, subscription_restore_attempted, workout_started, food_logged, and forge_code_redeemed). Google Firebase may also collect standard app and device metadata as part of the Analytics SDK.
Body Forge does not send the following to Firebase Analytics: names; email addresses; Google user IDs; ForgeClub codes; food details; meal details; barcode data; workout details; reps; sets; weights lifted; body weight; body composition; health data; progress photos; ingredient photos; PT notes; or medical information.
- We do not include advertising SDKs and do not use the advertising ID for targeted advertising or sell it to data brokers. On Android, the Google Analytics for Firebase SDK may collect the Google Advertising ID when available, as part of standard SDK operation for analytics and measurement. We use Firebase Analytics only to understand aggregate app usage and improve the app — not to serve ads.
- We do not include in-app crash-reporting SDKs such as Firebase Crashlytics in the current release.
- Network features use HTTPS. Our hosting provider (Render) may temporarily log standard connection metadata (for example IP address and user agent) for security and reliability.
- When you redeem a ForgeClub code, our server may write operational logs that include your Google user ID and event type for fraud prevention and support. Raw access codes are not stored in logs after redemption.
- Apple and Google may independently collect crash and diagnostic data on App Store and Google Play store builds. That collection is governed by Apple and Google respectively.
How long we keep data
| Data | Retention |
|---|---|
| On your device (workouts, diary, photos, settings) | Until you reset app data, reset progress, sign out of Google, or uninstall |
| ForgeClub entitlements (server) | While access is active, plus a reasonable period after expiry or revocation for audit and support |
| App Store, Google Play, and RevenueCat purchases | Per Apple, Google, and RevenueCat policies |
| OpenAI (when cloud AI is used, including via our server proxy in production builds) | Per OpenAI policies |
| Firebase Analytics (Google) | Per Google Firebase / Analytics retention settings in our Firebase project and Google policies |
| Website tester waitlist (server) | Until you request deletion or we remove inactive entries after the tester programme ends |
| Server operational logs | Short-term, per our hosting provider's defaults |
To request deletion of ForgeClub entitlement data, waitlist records, or other server-side data linked to your account, email support@fueltheforge.app or use our account deletion page.
Website tester list
If you join the Android tester waitlist on fueltheforge.app, we collect the email address you submit and send it to our API at bodyforge.onrender.com to record your signup.
- We use your email to contact you about closed testing access, tester programme updates, and related Body Forge announcements.
- Waitlist data is stored on our server; it is not stored in the Android app unless you later sign in with the same Google account in the app.
- You can request deletion of waitlist records at any time by emailing support@fueltheforge.app or using our account deletion page.
Your rights (UK and EU)
If you are in the United Kingdom or European Economic Area, you have rights under UK GDPR including:
- Access — ask what personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete data we control (most app data can be deleted on your device in Settings)
- Restriction and objection — in certain circumstances, limit or object to how data is processed
- Data portability — where applicable, receive a copy of data you provided in a portable format
Because most Body Forge data stays on your device, you can access and delete it directly using Settings. For server-held data (for example ForgeClub entitlements), contact support@fueltheforge.app. We aim to respond within one month.
You may lodge a complaint with the UK Information Commissioner's Office at ico.org.uk if you believe your data has been handled unlawfully.
Security
- Network requests from the app use HTTPS encryption in transit.
- Local data is stored in the app sandbox on your device. On Android, backup of app data is disabled for fitness logs in release builds.
- We do not operate a remote cloud backup of your workout or food diary in the current release.
Data deletion
- Settings → Data → "Reset local app data" — deletes locally stored app data (including Google Sign-In session) and returns you to setup. Primary way to remove your data.
- Settings → Data → "Reset Progress" — clears logs and history while keeping profile, settings, and plans.
- Sign out of Google in Settings — clears the local Google session without deleting other app data.
- Uninstalling the app removes all local data from your device.
- Server-side records — ForgeClub entitlements, waitlist signups, and other data we hold on our servers can be deleted on request. Email support@fueltheforge.app or follow the steps at fueltheforge.app/delete-account.
Because fitness and nutrition data is stored locally, we cannot delete it from your device remotely. App Store and Google Play purchase history is retained by Apple and Google respectively. If you used cloud AI features (including via our server proxy in production builds), retention by OpenAI is governed by OpenAI's policies.
Children's privacy
Body Forge is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided data in the app, uninstall the app or use Reset local app data in Settings.
Changes to this policy
We may update this Privacy Policy when we add or change features. The "Last updated" date at the top shows the current version. Material changes will be reflected on this page and, where appropriate, in app updates.
Privacy questions: support@fueltheforge.app