Last Updated: July 24, 2026
S3 Forge(“S3 Forge,” “Forge,” “we,” “us,” or “our”) operates the Forge fitness tracking and coaching platform (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, and password when you register.
- Profile Information: Role (athlete, trainer, coach), fitness goals, and preferences you choose to share, including sport, position, training schedule, available equipment, bodyweight, readiness check-ins, limitations, and coach notes.
- Workout Data: Exercise logs, sets, reps, weights, personal records, program designs, workout notes, technique videos, and progress photos you upload.
- Coach-Athlete Communications: Messages sent through team chat and any notes shared between coaches and athletes.
- AI Assistant Information: Messages, prompts, generated responses, weekly reviews, program review requests, and saved assistant notes when you use AI-assisted features.
- Wearable and Health Data: If you connect or sync supported integrations, we collect the data you choose to provide from WHOOP, Apple Health, or similar sources, which may include workouts, sleep, recovery, strain, heart rate, steps, calories, distance, and related device metadata.
- Notification Preferences: Push notification subscription endpoints, device keys, and notification opt-in status when you enable push notifications.
- Payment Information: Billing details collected and processed by Stripe. We do not store full credit card numbers on our servers.
1.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent, and interactions within the Service.
- Device Information: Browser type, operating system, device type, screen resolution, and IP address.
- Log Data: Server logs, error reports, request metadata, and security events used to operate, troubleshoot, and protect the Service.
- Cookies & Similar Technologies: Session cookies for authentication, preference cookies, and analytics. See Section 5 for details.
1.3 Information from Third Parties
- Stripe: Payment status, subscription tier, billing period, and transaction history.
- Supabase: Authentication tokens and session management data.
- WHOOP: Wearable profile, workout, sleep, recovery, and strain data if you connect WHOOP.
- Apple Health: Health and activity data transmitted from your device if you choose to sync Apple Health data.
- OpenAI: AI responses generated from prompts and relevant Service context when you use AI-assisted features.
2. How We Use Your Information
We use your information for the following purposes:
- Service Delivery: To provide, maintain, and improve the Service, including workout tracking, program management, personal record calculations, and coach-athlete facilitation.
- Account Management: To authenticate you, manage your subscription, process payments, and communicate about your account.
- Personalization: To tailor workout suggestions, weight recommendations, program suggestions, readiness insights, wearable summaries, AI-assisted reports, and 1RM estimates based on your logged data.
- Communication: To send account-related notifications, subscription reminders, trial expiration notices, workout reminders, team notifications, feature updates, and responses to your inquiries.
- Wearable and Health Sync: To connect integrations you authorize, refresh wearable tokens, import selected health data, and show training context derived from that data.
- AI-Assisted Features: To generate assistant replies, program reviews, coach reports, weekly summaries, and suggested notes using the context available in your account.
- Analytics & Improvement: To understand how users interact with the Service, identify issues, and improve features and performance.
- Legal & Safety: To comply with legal obligations, enforce our Terms of Service, prevent fraud, and protect the rights and safety of our users and our platform.
3. How We Share Your Information
We do not sell your personal information. We share information only as described below:
3.1 Service Providers
We share data with trusted third-party providers that help us operate the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database hosting, authentication, file storage | All user data, workout data, auth tokens |
| Stripe | Payment processing, subscription management | Email, payment details, subscription status |
| Vercel | Application hosting and edge functions | Server logs, IP addresses (transient) |
| OpenAI | AI assistant, program review, and report generation | Prompts and relevant account, workout, coach, and wearable context |
| WHOOP | Wearable connection and data sync | OAuth tokens and wearable data you authorize |
| Apple Health / HealthKit-enabled device software | Optional health data sync | Health and activity data you choose to sync |
| Browser and platform push services | Push notification delivery | Push subscription endpoints, device keys, notification payloads |
All providers are contractually obligated to protect your data and use it only for the services they provide to us.
3.2 Coach-Athlete Sharing
- Athletes sharing with Coaches: Your workout data, personal records, and progress are visible to Coaches you connect with on the platform.
- Coaches sharing with Athletes: Your program designs, exercise libraries, and communications are visible to Athletes you manage.
- You control these relationships. Data is only shared within coach-athlete connections you establish.
3.3 Legal Requirements
We may disclose your information if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
3.4 Business Transfers
If S3 Forge is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
4. Data Retention
- Active Accounts: We retain your data for as long as your account is active.
- Deleted Accounts: Upon account deletion, we delete or anonymize your personal data within thirty (30) days. Aggregated, anonymized data may be retained for analytics purposes.
- Wearable Connections: We retain wearable connection records and encrypted tokens while an integration is connected. Disconnecting an integration stops future syncs and removes connection tokens where technically supported.
- Push Subscriptions: We retain push subscription records until you disable notifications, the subscription expires, or the record is removed during routine cleanup.
- AI History: We may retain AI conversations, generated summaries, and saved assistant notes as part of your account history unless you delete them or request deletion.
- Inactive Accounts: We may delete accounts that have been inactive for an extended period after providing notice to the associated email address.
- Legal Holds: We may retain data beyond these periods if required by law, to resolve disputes, or to enforce our agreements.
5. Cookies & Tracking Technologies
5.1 Essential Cookies
We use session cookies for authentication. These are required for the Service to function and cannot be disabled.
5.2 Preference Cookies
We may use cookies to remember your preferences (such as theme, units, or display settings).
5.3 Analytics
We may use anonymous analytics to understand how users interact with the Service. No personally identifiable information is shared with analytics providers.
5.4 Your Choices
Most browsers allow you to control cookies through settings. Disabling essential cookies may prevent the Service from functioning properly.
6. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in transit: All data is transmitted over HTTPS/TLS.
- Encryption at rest: Database and file storage is encrypted at rest by our hosting providers.
- Authentication: Row-Level Security (RLS) policies in our database ensure users can only access their own data or data explicitly shared with them.
- Token Protection: Wearable access and refresh tokens are encrypted before storage.
- Access Controls: Strict access controls limit who can access production data.
However, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
7. Your Rights & Choices
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of your personal data.
- Correction: Update or correct inaccurate information.
- Deletion: Request deletion of your account and personal data.
- Portability: Request your data in a machine-readable format.
- Opt-Out: Unsubscribe from marketing communications (transactional emails will continue).
- Cookie Preferences: Control cookies through your browser settings.
- Wearable Choices: Disconnect supported wearable integrations and request deletion of previously synced wearable or health data.
- Notification Choices: Enable or disable push notifications from your device, browser, or app settings.
To exercise any of these rights, contact us at samuelsschmidt@gmail.com. We will respond within thirty (30) days.
7.1 California Residents
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information.
7.2 European Economic Area (EEA) & UK Residents
If you are in the EEA or UK, you have rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, data portability, and object to processing. Our legal basis for processing is:
- Performance of contract: Providing the Service you requested.
- Legitimate interests: Improving and securing the Service.
- Consent: Where you have given explicit consent (e.g., marketing communications).
8. Children’s Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete it promptly. Contact us if you believe a child has provided us with data.
9. International Data Transfers
Your data is stored and processed in the United States by our service providers, including Supabase, Vercel, Stripe, OpenAI, and other providers used for integrations you enable. If you access the Service from outside the United States, your data will be transferred to and processed in the United States, which may have different data protection laws than your country. By using the Service, you consent to this transfer.
10. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email and/or a notice on the Service. Your continued use after the effective date constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights:
- Email: samuelsschmidt@gmail.com
- Mailing Address: 1818 County Road 1210, Tuttle, Oklahoma
© 2026 S3 Forge. All rights reserved.