Forjex legal

Privacy Policy

How Forjex collects, uses, stores, and protects the data behind your training.

Last updated
28 August 2026
Sections
17

1. Who We Are

Forjex is a fitness application operated by Reliability Works Ltd, a company registered in England and Wales under company number 16206723, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. Reliability Works Ltd is the data controller for the personal data described in this policy, which explains how we collect, use, and protect that data when you use our mobile app, web platform, and marketing site.

2. What Data We Collect

Account data: Name, username, email address, date of birth, profile photo, sign-in credentials, role, account settings, and optional profile fields such as pronouns, a website link, and a free-text location. We also record the country and region we read from your device locale and App Store storefront at signup, which is what the age check runs against.

Fitness data: Workout logs, exercise history, personal records, body measurements, progress photos, nutrition and meal logs, and training and nutrition plans.

Health data: What you allow Forjex to read from Apple Health, including heart rate, sleep, steps, workouts, and recovery metrics. Nothing is read until you grant permission, and only for the categories you allow. Once you have granted it, Apple Health can wake the app in the background when a workout finishes, including one you recorded on an Apple Watch, so the app can pull that session in and ask whether you want to log it. That background wake happens for workouts only, and it stops when you turn the permission off. Alongside each sample we store where it came from: the source app name and bundle id, the device name and model that recorded it, and whether you entered it by hand. That device model is the only hardware detail we hold, and it comes from Apple Health, not from profiling your phone. Forjex also writes back to Apple Health, if you allow it: the workout itself, the active energy it burned, and the walking, running, or cycling distance for a session you recorded in the app. That write stays on your phone, in Apple Health. It does not send anything to us.

Social data: Posts, comments, likes, reposts, bookmarks, follows, Bursts, videos, direct messages including photos, GIFs and voice notes, squad activity, reports, and moderation records.

Coach data: If you use the coaching platform, we collect coach profiles, client-coach relationships, program data, check-in responses, intake answers, progress-photo annotations, coach messages, pricing, leads, and payout status. Coaches can also import an existing client list, which means we hold the names and email addresses that coach uploaded until those people either join or the invite is withdrawn.

Payment data: Subscription status, transaction IDs, coach payout status, and receipts. We never see or store card numbers, bank details, or tax details. Apple handles in-app purchases; Stripe handles coach billing and payouts on its own hosted pages, and we keep only the Stripe account id, its status, balances, and a country code.

Support data: The messages you send us through in-app support and the email address attached to the ticket.

Device and diagnostic data: A push notification token if you turn notifications on, plus feature usage events, performance measurements, and crash reports from the app when you turn Share diagnostics on. This choice starts off and is available in Settings on iOS and the web platform. Our own usage events carry the app release, build variant, and environment they came from, and nothing about your hardware: no device model, no iOS version. They are not anonymous, though. Once you are signed in, our server attaches your account id to them.

Separate server-generated events record core actions such as starting or completing a workout. We use those first-party events to understand and improve the service under our legitimate interests. They do not use the native diagnostic channel and are not sent to Sentry. You can object through the privacy request route below.

Crash reports and masked session replays go to Sentry, our crash reporting provider. The iOS app and web platform send a bounded error type, and iOS also sends the device model and operating-system version. Convex server error capture stays off because background jobs and webhooks cannot prove one account's choice. Replay masks all text and blocks all images. Performance tracing, logs, and breadcrumbs are disabled. Before sending an error, we remove identity, request details, screenshots, view hierarchies, stacks, exception mechanisms, thread data, raw exception messages, and caller-supplied metadata. Health, body, meal, readiness, route, photo, message, authentication, and user-entered fitness content are prohibited from Sentry, whether or not diagnostics is on.

What we do not collect:Phone number, postal address, card or bank details, your contacts or address book, browsing history, saved search history, and advertising identifiers. The iOS app contains no attribution SDK and no data-broker SDK, it never asks for App Tracking Transparency permission, and we do not track you across other companies' apps or websites.

Ads: The app includes Google Mobile Ads (AdMob). When ads are turned on they appear in the social feeds, Following and Bursts, and nowhere else. Every request Forjex makes is marked non-personalized, so an ad is picked without a profile of you behind it, and the advertising identifier is never read. Google still receives the ad request and any impression or click on it, including your IP address and standard device information, and handles that under Google's ads and data policy.

The ad consent tool:Ads come with a second Google component, the User Messaging Platform (UMP). It is what asks for consent where the law requires it, and nothing is requested from AdMob until it says a request is allowed. Before it can answer, it checks with Google once per app session, and that check is itself a connection to Google: it carries our AdMob app id, your app version and language, your device model and iOS version, and your IP address, which Google uses to work out which country's rules apply. It does not read the advertising identifier and it does not tie any of that to your Forjex account. If you have never been asked for consent and ads are switched off for your app, none of it runs: UMP never contacts Google and the ad privacy choices row does not appear in Settings. Once you have answered a consent form, that answer stays on your device even if we pause ads, so the check still runs and the row stays in Settings. Switching ads off is not a way of taking back your consent, and you should not have to wait for ads to come back to change it.

3. Location Data

Forjex asks for location once, and only for one thing: recording an outdoor activity you start yourself, a walk, run, or cycle. We ask for the "while using the app" permission and never the always-on one, so the app cannot read your location at any other time.

Once you tap start, recording carries on with the app in the background and the screen locked. Without that your route would stop at the moment you pocketed your phone. iOS shows its blue location indicator the whole time. Both stop the moment you pause or finish the activity. We never use location for advertising, tracking, or building a profile of where you go.

We only upload the route coordinates if you opt in for that specific activity. If you do not, the coordinates stay on your phone and what leaves it is the totals (distance, duration, elevation, split summaries) plus a bounding box: the furthest north, south, east, and west corners the activity reached, which the app uses to size a map preview. A route you do upload is saved with your account and is private by default, so nobody else sees it unless you switch it to squad or public, and each route is capped at 1,200 points.

While you record, the app sends your current coordinates to Apple's weather service to look up the conditions we save alongside the activity. Apple receives that request. We keep only the temperature and the condition it sends back.

Separately, you can attach a place to a post. That check-in saves the place name and its coordinates on the post, and anyone who can see the post can see the check-in, so only add one when you are happy for it to be visible.

4. How We Use Your Data

We use different lawful bases for different purposes:

  • Contract. We use the data needed to create and secure your account, provide training and nutrition logs, plans, posts, messages, squads, coaching, subscriptions, support, notifications you request, and the other features you choose to use. This includes selecting and ordering Feed and Explore posts as part of the personalised social service
  • Consent. We use consent for Apple Health sync, health and body details, outdoor route-point uploads, health or injury answers in a coach intake, health data used by AI Coach, diagnostics sharing, website analytics, and the Google ads consent form where it is shown. You can turn optional processing off
  • Legal obligation. We use data where the law requires a specific step, including applicable online-safety, child-safety, financial-record, privacy-rights and complaint-handling duties
  • Legitimate interests. We use limited data to keep Forjex secure, prevent abuse, run safety controls beyond a specific legal duty, measure and improve features and recommendations, deliver service and security messages, and answer people who contact us. We assess necessity and the effect on users, including users aged 16 and 17, before relying on this basis

Feed and Explore use interactions, information about the post, recency, and safety eligibility to select and order content. These signal categories and their relative effect can change as we improve recommendations. We do not publish model weights, source code, or anti-abuse logic. Using interaction events to improve the system is a separate legitimate interest purpose from delivering the ranked feed itself.

Health data is special-category data. We rely on explicit consent under Article 9(2)(a) for Apple Health, health and body details, AI health context, and health or injury answers in a coach intake. AI Coach sees only the health categories you turn on. Sentry is prohibited from receiving health, body, nutrition, or AI health-context values.

5. AI and Your Data

Our AI coaching features analyse your workout history, body metrics, stated goals, check-ins, and uploaded form-analysis media when you ask for AI help. We use Google Gemini to generate training plans, nutrition plans, chat responses, and form feedback. We send only the data needed for each request. Health context is sent only from the categories you turn on in Health & Data. AI providers are not allowed to train their models on your Forjex data.

6. Who Can See Your Data

Public: Your profile name, avatar, public stats, and any posts, Bursts, comments, lift submissions, or leaderboard entries you share publicly, including any check-in place you attach to a post.

Your coach: If you hire a coach, they can see your workout history, check-in responses, adherence data, progress photos you share, and messages you send them.

Squad members: Members of your squad can see your squad activity and challenge participation.

Private: Your health data, nutrition logs, AI chat history, payment information, saved routes, and biometric-protected progress photos are never visible to other users unless you choose to share specific items with a coach or another supported surface.

7. Third Parties We Share Data With

We do not sell your personal data and we do not share it with data brokers. One advertising company is on this list: Google Mobile Ads receives what it needs to serve and count an ad in the iOS app, which is your IP address, standard device information, and the impressions and clicks. Nothing you train, eat, measure, or post is sent to it, and the requests carry no advertising identifier, so it cannot build a profile of you from what we send. This is the full list of companies that receive personal data from Forjex:

  • Convex hosts our database and backend, so effectively everything in this policy is stored there
  • Cloudflare stores your uploaded media (photos, videos, voice notes) in R2, runs the bot check on our website forms, and sits in front of our backend, so it sees the request your app makes. It tells us which country the request came from, which the age check weighs alongside your device locale and storefront
  • Vercel hosts forjex.com and the web platform
  • Google Gemini generates training plans, nutrition plans, chat responses, and form feedback from the data described in section 5
  • Applehandles in-app purchases and tells us your subscription status. Apple's weather service also receives your coordinates while you are recording an outdoor activity, as described in section 3
  • Stripehandles coach billing and payouts. Card, bank, tax, and address details are entered on Stripe's own pages and never reach us
  • Resend delivers transactional email such as password resets and replies to the website contact form
  • Giphypowers GIF and sticker search. Your search term goes to Giphy through our server, so Giphy does not learn who searched. But when a GIF or sticker is shown, your phone loads the image file straight from Giphy's network, which means Giphy receives your IP address and the standard request details any website sees
  • OpenAI screens the text of posts and comments for policy breaches before they go live. We send the text of the post or comment and nothing else, with no name, username, or account id attached
  • Sightengine checks images for nudity when a post has been reported several times. We mint a short-lived signed link and Sightengine fetches the image from it
  • Sentryreceives a bounded error type from the iOS app and web platform. iOS also sends the device model and operating-system version. Convex server error capture stays off because background jobs and webhooks cannot prove one account's choice. Capture starts only after Share diagnostics is on. Masked replay follows the same choice, masks all text, and blocks all images. Performance tracing, logs, and breadcrumbs are off. Before sending an error, Forjex removes identity, request details, screenshots, view hierarchies, stacks, exception mechanisms, thread data, raw exception messages, and caller-supplied metadata. Health, body, meals, readiness, routes, photos, messages, auth data, and entered fitness content are prohibited. Sentry stores this event data and its backups in Frankfurt. Account, organisation, and project administration metadata may be stored in the US under Sentry's Data Privacy Framework and UK Extension, with standard contractual clauses as an alternative
  • PostHog collects product analytics on forjex.com and the web platform only. It is not in the iOS app
  • Google Mobile Ads (AdMob) serves the ads described in section 2, from the iOS app only. It receives the ad request and any impression or click, including your IP address and standard device information. Requests are non-personalized and carry no advertising identifier
  • Google User Messaging Platform (UMP)is the consent tool described in section 2, from the iOS app only. It is a separate Google SDK from AdMob. Once per app session, while ads are switched on or you have already answered a consent form, it sends Google our AdMob app id, your app version and language, your device model and iOS version, and your IP address, so Google can tell it which country's consent rules apply and whether there is a form to show you. Your current consent answer also stays in the app's local storage until you change it or remove the app's stored data

Google's AdMob retention page says User Activity reports are kept for 90 days, while Ads Activity and Privacy & Messaging reports are kept for 2,555 days. Google is an independent controller for the ad and consent-tool data it holds. You can use the Google Privacy Help Center to ask Google for access to or deletion of that data. The Forjex Privacy rights screen covers the copies held by Forjex.

Sentry, Google Mobile Ads, and Google's User Messaging Platform are the only third-party SDKs inside the iOS app. There is no attribution or data-broker SDK, and no third-party product analytics: which features you use is recorded in our own database, not sent to an outside analytics company.

We may also share data if required by law or to protect our legal rights.

8. Data Storage and Security

Your data is stored on servers in the United States and Europe. All data is transmitted over HTTPS and encrypted at rest. We use access controls, audit logging, and regular security reviews.

Sending your data outside the UK: Some of the companies in section 7 process data outside the United Kingdom, mostly in the United States. UK data protection law lets us do that only where the destination gives your data the same protection it has here. For transfers that Forjex makes, we use one of the following safeguards.

  • Adequacy. The UK recognises the European Economic Area as providing equivalent protection. PostHog uses its EU Cloud. Sentry stores and processes the limited event data described in section 7 in Frankfurt.
  • The UK-US Data Bridge. Cloudflare, Vercel, Google LLC for Gemini and UK advertising or consent-tool processing, Resend, and Sentry are certified under the Data Privacy Framework and its UK Extension.
  • Standard contractual clauses. The standard data-processing terms published by Convex, OpenAI, Sightengine, Google, and Sentry incorporate the EU Standard Contractual Clauses and the UK Addendum when a transfer is not covered by adequacy or the UK-US Data Bridge.

Apple and Stripe are different. They decide for themselves how they handle the payment and subscription data they receive, and Apple does the same with the coordinates its weather service receives, so they are responsible for those transfers under their own terms rather than ours. Giphy also decides how it handles the search term and request data it receives. We send your search term through our server. When your phone loads a GIF, it connects to Giphy directly and shares your IP address and standard request details. Ads work the same way: your phone requests them from Google directly, and Google decides how it handles what that request carries.

You can ask us which mechanism covers a particular company, and get a copy of the relevant clauses, by emailing contact@reliabilityworks.co.uk.

9. Data Retention

We keep your data for as long as your account is active. When you delete your account, we remove your sign-in access first and sign you out. A background cleanup job then removes your profile, remaining account data, and stored media, apart from the four groups described in section 11. Diagnostics do not start before sign-in because the account choice is not available yet.

Some records are cleared on a fixed schedule whether or not you delete your account. A nightly job removes them once they pass these windows:

  • Usage events, the record of which features were used and when: 24 months
  • Notification delivery records and media request logs: 24 months
  • Notifications in your in-app inbox: 12 months once you have read one, 24 months if you never open it
  • Reports and the moderation decisions taken on them: 5 years from the decision. A report that is still open is kept until it is decided, however long that takes
  • Failed sign-in counters, which are how we lock out password guessing: 90 days at the outside, and in practice about a day after the last failed attempt

Apple and Stripe keep their own transaction records for as long as tax and accounting law requires them to.

10. Deleting Your Account

You can delete your account from inside the app. Open Settings, tap Account, then Delete Account and confirm. The app asks you to prove that you signed in recently. It also removes the Forjex workouts it can find in Apple Health before it starts account deletion. If Apple Health access is off, those workouts stay on your device and you can remove them in the Health app. There is no form to fill in and no need to email us.

Forjex then removes your sign-in record and signs you out. A durable background job removes your profile, workouts, health data, body records, progress photos, nutrition logs, posts, comments, messages, squad membership, coaching records, usage events, and stored media. The job works in bounded steps and retries safely if a step fails. If automatic retries cannot finish the work, the job remains visible to our operations team in a manual-intervention state so we can inspect and resume it. The deletion request cannot be undone once your sign-in record is removed.

If you cannot use the in-app flow, email contact@reliabilityworks.co.uk. We verify account ownership before starting a support deletion request. This is a separate process from in-app deletion.

One thing to know: deleting your Forjex account does not cancel a subscription you bought through Apple. Cancel that in your App Store subscription settings.

11. What We Keep After Deletion

Some records can remain after account deletion. They fall into four groups:

  • Financial and transaction records: payments, subscriptions, payouts, refunds, and identity-verification records needed for financial and compliance duties
  • Trust, safety and appeal records: reports, appeals, bans, moderation decisions, and competition rulings needed for safety and review history
  • Administrative audit and configuration: administrative decisions, access records, and shared configuration needed for audit history
  • Shared product records: shared catalog data, squad configuration, and abuse-control records needed by other users or for system safety

We also keep a small set of operational records so deletion can finish safely. The deletion job keeps opaque deleted-user and sign-in identifiers, plus completion and retry facts. It does not keep your profile or email address. We have not set an automatic expiry for this job record.

Media cleanup records keep an opaque user id, the exact storage object key, and the cleanup state for 30 days after they become tombstones. This covers uploads and generated files that can finish late. We remove each tombstone only after confirming that the stored object is absent or has been deleted.

UK tax law requires us to hold transaction records for six years (UK GDPR Article 17(3)(b)). We can also keep records needed to bring or defend a legal claim (Article 17(3)(e)). Financial records are kept for six years from the end of the relevant tax year. Reports and moderation decisions are kept for five years from the decision. Administrative and shared product records are kept only while their audit, safety, or shared-product purpose still applies.

Linked retained rows use an opaque account reference that no longer resolves to your Forjex profile. Older audit text without an immutable account link can remain when we cannot safely identify it from a changeable email address. We do not use retained records to rebuild your profile.

12. Your Rights

You have the right to:

  • Accessyour data. Settings, then Health & Data, has an Export my data button that builds a machine-readable JSON archive of the personal data Forjex can provide. The archive explains any limits or omissions inside the file
  • Correct inaccurate data through your profile settings
  • Delete your account, as described in sections 10 and 11
  • Withdraw consent for optional processing such as Apple Health access, health and body details, route uploads, diagnostics sharing, website analytics, and the ads consent form. Withdrawal stops new processing. It does not always erase rows already stored unless you delete the account or use a delete control that already exists for that item
  • Objectto processing, including direct marketing and any processing we rely on as a legitimate interest, such as first-party measurement, recommendation improvement and safety processing beyond a specific legal duty. An objection is reviewed against your circumstances. It is not an automatic product switch. Direct-marketing objections are followed without a balancing override. Send an objection from Settings or Help & Support > Privacy rights, or email contact@reliabilityworks.co.uk
  • Restrict processing while we look at a correction, deletion, or objection. Same routes as objection. Restriction is a human action on the request, not an automated product setting
  • Port your data to another service. The export is a machine-readable JSON archive
  • Ask about automated processing.Forjex ranks feeds and Explore using view events, and it can auto-hide content that fails a safety screen. Auto-hide is appealable in Settings > Content decisions. A different reviewer decides the appeal. We have not classified either process as a solely automated decision with a legal or similarly significant effect. Privacy rights lets you ask how the processing worked for your account

Signed-in requests from the Privacy rights screen write a support ticket that staff can read in the existing admin support inbox. Email to the mailbox above is the other route. We aim to acknowledge a rights request within five working days and normally respond within one calendar month. A complex request may take up to two additional months, but we will tell you during the first month if that applies.

13. Cookies and Website Analytics

forjex.com and the web platform use essential cookies to keep you signed in and Cloudflare Turnstile on forms to block bots. PostHog, which measures page views and clicks, runs on this site only if you accept it on the consent banner shown on your first visit. Declining means it never loads, and if your browser sends a Global Privacy Control signal we treat that as a decline. Once you sign in on the web, PostHog events carry your account id.

Your choice is stored on this device. Clearing your browser's site data removes it and brings the banner back.

The iOS app does not use cookies for analytics.

14. Children

Forjex is for users who are at least 16. We check date of birth before signup and block accounts that do not meet this requirement. If you believe someone under 16 has provided us with personal data, please contact us and we will delete it.

Users aged 16 and 17 get a plain-language privacy page. New accounts in that age band start private, off the friends leaderboard, and closed to new message requests. The same privacy rights and complaint routes apply.

15. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes by email or in the app. Where a new agreement or consent is required, we will ask you to review it before the new processing starts.

16. Contact

Callum Spencer is Forjex's privacy lead. He is not appointed as a data protection officer. Questions about this policy can be sent to contact@reliabilityworks.co.uk, or write to us at Reliability Works Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. The Privacy rights screen in the app sends a signed-in ticket to our support system.

17. Complaints

If you are unhappy with how Forjex has used your personal data, we recommend contacting us first so we can investigate. You may complain to a regulator at any time. Email contact@reliabilityworks.co.uk or send a complaint from the Privacy rights screen in the app. We aim to acknowledge a data-protection complaint within five working days, investigate it, keep you informed, and normally provide the outcome within one calendar month. The inbox is not monitored continuously outside ordinary working hours.

You can complain to the UK Information Commissioner's Office (ICO) at any time. The ICO recommends giving us a chance to resolve the complaint and keeping a copy of what you send. It cannot award compensation. Start here: ico.org.uk/make-a-complaint/data-protection-complaints. The ICO can also be reached on 0303 123 1113.

If you live in the EU or EEA, you can also complain to your local data protection authority. The European Data Protection Board lists them here: edpb.europa.eu/about-edpb/about-edpb/members_en. We have not named a lead EU authority in this notice.