Effective 8 October 2026
Privacy policy
FitForge is operated by Philip Kirkbride, acting as an individual. For privacy questions, access requests or removal requests, contact fitforge@lobbykit.net.
This policy covers FitForge's local records, optional hosted AI, account service and support correspondence. The initial public release is being prepared as a free app, with no in-app purchases, subscription or trial.
Records on your iPhone
Detailed workout, food, weight and run records are stored on your iPhone. Manual recording does not require an account or AI. Exported backups are files you control and can include run routes. Removing a server account does not erase local records or exported copies; remove those separately when you want to.
Location permission lets a started run record its route. AI Run Companion uses minimized run summaries rather than GPS coordinates or the route. Optional Apple Health access and writes use the permissions you enable; an authorized run write can include its route. Sharing summarized Health observations with Coach is a separate choice.
Account and service operation
Sign in with Apple links hosted access to a FitForge account. The service stores an opaque account identifier, a protected representation of your Apple identity, membership and session records. It does not use an email match to identify or merge accounts.
Usage records include request and token counts, outcomes and timings to enforce allowances and operate the service. Security records include App Attest installation key identifiers, public keys, assertion counters and hashed request-source admission information. Hosting and security logs can contain technical request information. These records support service operation and abuse prevention, rather than advertising.
Optional AI processing
Before sending content for hosted AI, FitForge asks you to allow AI data processing and names the providers. This permission starts off; you can decline or revoke it in More → Settings → Coach & Privacy. Manual logging and saved workouts remain available. Workout-history, Apple Health and AI Run Companion sharing choices remain separate.
A Coach request can include its visible/current workout context, such as exercises and recorded values, independently of saved-history sharing. Selecting or capturing a Coach photo can upload its resized, sanitized image after AI permission, before the separate Send action. Source camera/location metadata is removed, but visible pixels can still identify you. Messages, chosen photos, tool proposals/results and permitted summaries are associated with your account-scoped conversation.
Automatic Today reflections can send short training observations while Today is visible after AI permission is granted. Turn them off in Today's Personalize controls to stop future automatic requests. Turning a sharing control off does not delete material already sent.
AI and voice providers
FitForge sends Coach, insights and image-estimate requests to Microsoft Azure OpenAI, user-invoked voice clips to Groq for transcription, and spoken reply text to Deepgram for speech synthesis. The service does not durably store raw transcription clips or synthesized audio; a transcript you later send can become a retained Coach message.
The Deepgram request includes its model-improvement opt-out. This is not a promise that every provider immediately deletes every item. Provider processing can include safety, reliability and abuse monitoring under their applicable data policies. AI processing can take place outside your country; this policy does not promise that all processing stays in one region. Do not include information you do not want processed by these services.
Retention and deletion
Account and account-scoped usage records remain part of the service until removed through account deletion. Coach topics are scheduled for cleanup after seven days of inactivity. Turn/event state has a separate 30-day window applied on a later turn; this is not a 30-day expiry promise for conversation messages in an active topic.
Unused Coach uploads expire after 15 minutes. Consumed photo bytes are normally removed after a completed reply. Background cleanup also handles expired photos or photos older than one day, excluding live turns. Cleanup is bounded and retries failures, so these configured rules are not guaranteed exact erasure times.
Use More → Settings → Account → Delete account to initiate removal of FitForge server-held account and product data, including bound Coach records and prior Friends data. The service records deletion intent and can resume interrupted cleanup. The app reports whether removal was confirmed or needs another attempt. Data belonging to another LobbyKit app is separate.
FitForge account deletion and removal of Sign in with Apple authorization are distinct. The app's completion notice explains whether Apple authorization was removed, is pending or requires removal in your Apple Account settings. Account deletion does not remove your local logs, exported files, support email, system logs or historical backup copies. Those have separate handling; no immediate erasure deadline for logs or historical backups is promised.
Earlier testing features
Earlier testing versions included Friends profiles, relationships and shared content. Installed testing builds can send information under their sharing controls; everyday workout/run, achievement and nutrition sharing defaults on for an active friendship unless overridden. If you used those features, the service may still hold the data you supplied until cleanup or account deletion. Copies already saved by another person cannot be retracted. Friends sharing and separate ChatGPT connections are held in the initial free release. Earlier testing builds could also use a separately selected ChatGPT route processed by OpenAI; review the permission explanations in that installed build.
Support correspondence and this website
Email to fitforge@lobbykit.net is forwarded through Namecheap to a Google/Gmail-hosted inbox. Messages include sender details, email metadata, contents and attachments you provide. The destination inbox address is private. Correspondence is kept separately to handle your request and record the response; there is no automatic deletion schedule. You may contact us to request its removal.
This static website has no registration form or advertising analytics. Requests can produce hosting/security logs. FitForge does not sell your training records or use them for advertising. You can ask about access, correction or removal at the contact address above; applicable privacy rights are not waived by using the app.
Policy updates
We will update this page when relevant data handling changes and show the effective date. Review the permission explanations in your installed app before using optional features.