Privacy Policy
Version 2026-08-21 · Last updated August 21, 2026
Forge is a personal fitness, training, and health-record app operated by Healthspan Group LLC. This policy explains what information we collect, how we use it, how we share it, and the choices you have. We have written it in plain English on purpose: if something here is unclear, that is a bug — email us and we will fix the wording.
Forge is a personal tool, not a medical provider. We are not a doctor's office, a hospital, a lab, or a health plan, and we are not a "covered entity" or a "business associate" under HIPAA — so HIPAA does not govern the record you keep here. What protects your information is this policy and the security described below, not a healthcare regulation. Anything Forge shows you, including anything written by AI, is information — not medical advice, diagnosis, or treatment.
For how we handle consumer health data specifically — including injuries and pain you log — see our Consumer Health Data Privacy Policy. Where that policy and this one differ on consumer health data, that one controls.
Information we collect
- Account information — your name, email address, and authentication credentials.
- Training and fitness information — workouts, sets and loads, cardio sessions, routes, effort and recovery metrics.
- Nutrition information — meals, foods, and the photos or messages you send to log them.
- Sleep and body-composition information — sleep sessions and stages, weight, body fat, and scale readings.
- Your health record — see the dedicated section below.
- Data from services you connect — Strava, Garmin, Oura, Whoop, 8sleep, Intervals.icu, Google Health, and Google Drive. We pull nothing until you connect the service yourself.
- Mobile phone number — collected only if you choose to turn on coaching text messages.
- Usage information — basic product analytics about how the app is used, so we can fix problems and improve features.
Your health record
Forge Health lets you keep your medical information in one place. It is the most sensitive thing in the app, so it gets its own rules.
What can go in it: medical documents you upload or forward (visit notes, discharge summaries, imaging reports), lab and blood-test results, genetic and genomic results, medications and supplements you take, allergies, immunizations, conditions and procedures, and family medical history — including information about your relatives that you choose to record.
How documents get in: you upload them; or you forward them to your personal Forge email address; or you point Forge at one Google Drive folder and we check it for new files; or you sign into your hospital's own patient portal (MyChart) yourself and pull your lab results and clinical visit notes, in which case we never see or store your portal password. Lab results bring in nothing saved to your record until you confirm it in the review queue. Visit notes are different: we store them as-is, viewable in your Documents, without ever sending their text through the two-reader review process that lab results go through. Every route is one you switch on yourself, and you can switch it off.
AI reads your documents. To turn a PDF into values you can actually chart, we send the document — and relevant parts of your record — to Anthropic's API. Anthropic processes it on our behalf as our service provider, and its API terms commit that data sent this way is not used to train its models. We cannot audit another company from the inside, so here is the promise that is actually ours to make: we only use AI providers whose terms make that commitment, and if that ever changed we would tell you and ask for your agreement again — not carry it forward silently. AI extraction makes mistakes: every extracted value links back to the page it came from, and the review queue exists so you can confirm or correct values before they count. You are the one who verifies what your record says — please do.
Family history means other people's information. If you record a relative's condition, you are recording information about them in your account. Only record what you are comfortable holding, and remember that anyone you share your record with can see it too.
Genetic results and family history are held under the same rules as the rest of your record: we never use them for advertising, never sell them, never share them with insurers or employers, and they go to AI providers only under the same no-training terms as everything else.
How we use your information
- To show you your own data — rendering your record, your training history, your trends and charts.
- To run AI features — extracting values from documents, summarizing your record, and generating coaching guidance — using Anthropic's API as described above.
- To notify you — the coaching text messages you opted in to, and email about your account.
- To keep your account secure and to diagnose and fix problems.
What we never do
- We do not sell your personal information — not to anyone, not in any form, including de-identified or aggregated forms.
- We do not use your data for advertising, and we do not let anyone else use it for advertising or ad targeting.
- We do not hand your data to AI providers that train on it — we only use providers whose terms commit to processing your data solely to answer the request in front of them, and if a provider changed that we would stop, tell you, and ask for your agreement again.
- We do not share your information with insurers, employers, data brokers, or credit agencies.
Services you connect (integrations)
Forge reads data from Strava, Garmin, Oura, Whoop, 8sleep, Intervals.icu, Google Health, and Google Drive. We pull nothing from any of them until you connect it yourself, we ask for the narrowest access that makes the feature work, and you can disconnect any of them at any time in Settings. Disconnecting stops future syncing; data already synced stays in your record until you delete it or your account.
Google user data. Forge's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: we read your Google Drive folder only to find and import the health documents you pointed us at, and we read Google Health only for the sleep and body metrics shown in your app. We never use Google user data for advertising, never sell it, never transfer it except as needed to provide the feature you asked for, to comply with law, or as part of a merger you are notified of, and no human at Forge reads it except with your explicit permission, for security, or where the law requires.
Text messaging (SMS)
Coaching text messages are entirely optional. If you turn them on in Settings, you enter your own mobile number and confirm it with a one-time verification code. You can turn them off at any time.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Your mobile number, and the content of the messages you send and receive (which can include health information you text to the coach), are disclosed only to our SMS delivery provider (Twilio) for the sole purpose of delivering and receiving your coaching messages. Neither is ever shared with advertisers or used for marketing by anyone else.
You can reply STOP at any time to stop receiving messages, or HELP for help. Message and data rates may apply.
How we share information
With people you choose. You can share parts of your record with a coach or a family member. Sharing is off by default and only ever happens through a grant you create: you pick the person and you pick what they get — for example read-only access to your health record, or permission to write to it. You can change or revoke any grant at any time, and revoking takes effect immediately.
Disputing something a coach wrote. If someone you shared with has added a fact to your record and you disagree with it, removing it marks it as disputed rather than erasing history: the entry is retired as member-disputed and the person who wrote it is notified. Your record is yours; the audit trail is what keeps that honest.
With service providers. We share information only with the providers that help us run the app, and only as far as needed to do so: cloud hosting and our database (US-hosted), our AI provider (Anthropic), our SMS provider (Twilio), our email provider (Resend), authentication (Google Identity Platform), and error monitoring and product analytics. Each one's terms with us require it to protect your information and forbid using it for its own purposes — and we pick providers on that basis.
When the law requires it. We may disclose information where required by law or to protect our legal rights or someone's safety.
Keeping and deleting your data
We keep your information for as long as your account is active, because your record is only useful if it has history in it. You can delete an individual document or workout at any time. A value already in your health record can be corrected through the review process; to remove a single stored lab value entirely, email info@protocol.us until that control ships in the app.
Deleting your account deletes your data. When you ask us to delete your account we remove your record, your training data, your uploaded documents, and your notification settings. We also disconnect every third-party service you connected and delete the access credentials we hold for it. For some providers that is the whole story. For others, deleting our credential stops Forge from reading any more of your data, but fully revoking Forge's authorization has to be done in that provider's own settings — you can do that at any time, whether or not you delete your account. Backups roll off on their normal schedule, and we may keep the minimum required to meet a legal obligation.
Consumer health data — including injuries and pain you log — is retained and deleted under the terms of our Consumer Health Data Privacy Policy.
How we protect it
- Encrypted in transit. Everything between your device and Forge, and between Forge and its providers, travels over TLS. Our hosting and database providers encrypt stored data at rest.
- Row-level isolation. Your data is separated from every other member's in the database itself, not just in application code. A query runs as you and can only reach your rows — and we test that isolation automatically on every change.
- Audited administrative access. The few operations that need to bypass per-member isolation — running a migration, investigating a bug you reported — go through a separate, logged path that records what was accessed and why.
- Account security. Sign-in is handled by Google Identity Platform, and multi-factor authentication is available and encouraged.
No system is perfectly secure, and we will not pretend otherwise. We hold no security certification — Forge has not been audited against SOC 2, ISO 27001, or any similar standard. If we ever learn that your information was exposed, we will tell you.
Where your data lives
Forge's database and file storage are hosted in the United States. If you use Forge from outside the US, your information is processed in the US.
Your choices
- Turn coaching text messages off at any time in Settings, or by replying STOP.
- Disconnect any third-party integration at any time in Settings.
- Change or revoke any sharing grant at any time.
- Request a copy of your data, or deletion of your account and its data, by contacting us.
Children
Forge is not for children. You must be 18 or older to have an account, and we do not knowingly collect information from anyone under 18. If you believe a minor has an account with us, email us and we will delete it and the data in it.
Changes to this policy
This policy is versioned — the version and date sit at the top of the page. For small changes (a clearer sentence, a new service provider of the same kind) we update the page and move the date.
For a material change to how we handle your health record — a new purpose, a new category of recipient, anything that would surprise you — we bump the version and ask you to agree again the next time you open your health record. Your previous agreement is not silently carried forward.
Contact us
Questions about this policy, your data, or a deletion request? Email info@protocol.us. A real person reads it.