Privacy Policy

Version 2026-08-21 · Last updated August 21, 2026

Forge is a personal fitness, training, and health-record app operated by Healthspan Group LLC. This policy explains what information we collect, how we use it, how we share it, and the choices you have. We have written it in plain English on purpose: if something here is unclear, that is a bug — email us and we will fix the wording.

Forge is a personal tool, not a medical provider. We are not a doctor's office, a hospital, a lab, or a health plan, and we are not a "covered entity" or a "business associate" under HIPAA — so HIPAA does not govern the record you keep here. What protects your information is this policy and the security described below, not a healthcare regulation. Anything Forge shows you, including anything written by AI, is information — not medical advice, diagnosis, or treatment.

For how we handle consumer health data specifically — including injuries and pain you log — see our Consumer Health Data Privacy Policy. Where that policy and this one differ on consumer health data, that one controls.

Information we collect

Your health record

Forge Health lets you keep your medical information in one place. It is the most sensitive thing in the app, so it gets its own rules.

What can go in it: medical documents you upload or forward (visit notes, discharge summaries, imaging reports), lab and blood-test results, genetic and genomic results, medications and supplements you take, allergies, immunizations, conditions and procedures, and family medical history — including information about your relatives that you choose to record.

How documents get in: you upload them; or you forward them to your personal Forge email address; or you point Forge at one Google Drive folder and we check it for new files; or you sign into your hospital's own patient portal (MyChart) yourself and pull your lab results and clinical visit notes, in which case we never see or store your portal password. Lab results bring in nothing saved to your record until you confirm it in the review queue. Visit notes are different: we store them as-is, viewable in your Documents, without ever sending their text through the two-reader review process that lab results go through. Every route is one you switch on yourself, and you can switch it off.

AI reads your documents. To turn a PDF into values you can actually chart, we send the document — and relevant parts of your record — to Anthropic's API. Anthropic processes it on our behalf as our service provider, and its API terms commit that data sent this way is not used to train its models. We cannot audit another company from the inside, so here is the promise that is actually ours to make: we only use AI providers whose terms make that commitment, and if that ever changed we would tell you and ask for your agreement again — not carry it forward silently. AI extraction makes mistakes: every extracted value links back to the page it came from, and the review queue exists so you can confirm or correct values before they count. You are the one who verifies what your record says — please do.

Family history means other people's information. If you record a relative's condition, you are recording information about them in your account. Only record what you are comfortable holding, and remember that anyone you share your record with can see it too.

Genetic results and family history are held under the same rules as the rest of your record: we never use them for advertising, never sell them, never share them with insurers or employers, and they go to AI providers only under the same no-training terms as everything else.

How we use your information

What we never do

Services you connect (integrations)

Forge reads data from Strava, Garmin, Oura, Whoop, 8sleep, Intervals.icu, Google Health, and Google Drive. We pull nothing from any of them until you connect it yourself, we ask for the narrowest access that makes the feature work, and you can disconnect any of them at any time in Settings. Disconnecting stops future syncing; data already synced stays in your record until you delete it or your account.

Google user data. Forge's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: we read your Google Drive folder only to find and import the health documents you pointed us at, and we read Google Health only for the sleep and body metrics shown in your app. We never use Google user data for advertising, never sell it, never transfer it except as needed to provide the feature you asked for, to comply with law, or as part of a merger you are notified of, and no human at Forge reads it except with your explicit permission, for security, or where the law requires.

Text messaging (SMS)

Coaching text messages are entirely optional. If you turn them on in Settings, you enter your own mobile number and confirm it with a one-time verification code. You can turn them off at any time.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Your mobile number, and the content of the messages you send and receive (which can include health information you text to the coach), are disclosed only to our SMS delivery provider (Twilio) for the sole purpose of delivering and receiving your coaching messages. Neither is ever shared with advertisers or used for marketing by anyone else.

You can reply STOP at any time to stop receiving messages, or HELP for help. Message and data rates may apply.

How we share information

With people you choose. You can share parts of your record with a coach or a family member. Sharing is off by default and only ever happens through a grant you create: you pick the person and you pick what they get — for example read-only access to your health record, or permission to write to it. You can change or revoke any grant at any time, and revoking takes effect immediately.

Disputing something a coach wrote. If someone you shared with has added a fact to your record and you disagree with it, removing it marks it as disputed rather than erasing history: the entry is retired as member-disputed and the person who wrote it is notified. Your record is yours; the audit trail is what keeps that honest.

With service providers. We share information only with the providers that help us run the app, and only as far as needed to do so: cloud hosting and our database (US-hosted), our AI provider (Anthropic), our SMS provider (Twilio), our email provider (Resend), authentication (Google Identity Platform), and error monitoring and product analytics. Each one's terms with us require it to protect your information and forbid using it for its own purposes — and we pick providers on that basis.

When the law requires it. We may disclose information where required by law or to protect our legal rights or someone's safety.

Keeping and deleting your data

We keep your information for as long as your account is active, because your record is only useful if it has history in it. You can delete an individual document or workout at any time. A value already in your health record can be corrected through the review process; to remove a single stored lab value entirely, email info@protocol.us until that control ships in the app.

Deleting your account deletes your data. When you ask us to delete your account we remove your record, your training data, your uploaded documents, and your notification settings. We also disconnect every third-party service you connected and delete the access credentials we hold for it. For some providers that is the whole story. For others, deleting our credential stops Forge from reading any more of your data, but fully revoking Forge's authorization has to be done in that provider's own settings — you can do that at any time, whether or not you delete your account. Backups roll off on their normal schedule, and we may keep the minimum required to meet a legal obligation.

Consumer health data — including injuries and pain you log — is retained and deleted under the terms of our Consumer Health Data Privacy Policy.

How we protect it

No system is perfectly secure, and we will not pretend otherwise. We hold no security certification — Forge has not been audited against SOC 2, ISO 27001, or any similar standard. If we ever learn that your information was exposed, we will tell you.

Where your data lives

Forge's database and file storage are hosted in the United States. If you use Forge from outside the US, your information is processed in the US.

Your choices

Children

Forge is not for children. You must be 18 or older to have an account, and we do not knowingly collect information from anyone under 18. If you believe a minor has an account with us, email us and we will delete it and the data in it.

Changes to this policy

This policy is versioned — the version and date sit at the top of the page. For small changes (a clearer sentence, a new service provider of the same kind) we update the page and move the date.

For a material change to how we handle your health record — a new purpose, a new category of recipient, anything that would surprise you — we bump the version and ask you to agree again the next time you open your health record. Your previous agreement is not silently carried forward.

Contact us

Questions about this policy, your data, or a deletion request? Email info@protocol.us. A real person reads it.