About this policy
This Privacy Policy explains how VitalForge handles personal information when you use its website, iPhone application and Apple Watch companion. It describes the current implementation and identifies features that are available only when enabled. VitalForge is the product name. You can contact support@vitalforge.app. The legal operator’s identity is still being finalised.
Account information
The current ChatGPT sign in flow supplies an account identifier and email address, and a name when the provider supplies one. VitalForge uses the identifier to associate your profile, workouts and records with your account. The hosted sign in system processes the provider information needed for authentication. VitalForge does not receive your ChatGPT password.
The iPhone connection uses a temporary authorisation code and a device credential. The server stores a hash of the device credential with the account identifier and expiry information. The app stores its credential in the iPhone Keychain.
Sign in with Apple
Sign in with Apple uses the account identifier and authentication information Apple provides. VitalForge stores the verified email address when Apple supplies it, including a private relay address if you choose to hide your email. VitalForge does not receive your Apple password.
This policy will be updated before any materially different Apple authentication data handling is introduced. Apple’s own privacy terms govern its authentication service.
Sign in with Google
When you use Google sign in, Google provides a verified account identifier and email when available. VitalForge validates the signed response on the server. It does not receive your Google password or access your Gmail messages or Drive files.
If the verified email matches an existing VitalForge account, you can confirm connecting the new sign-in method before creating another profile. After connection, the linked methods open the same account. Already-created profiles use a separate confirmed merge through Linked accounts in Settings. Apple hidden-email addresses may need explicit linking because they differ from your regular email.
Linked accounts
If you choose to link accounts in Settings, VitalForge asks you to sign in with the other provider and confirm the merge. Different provider identities and their supplied email addresses can then access one VitalForge account. Email matching alone is not used to merge accounts.
The profile you start from is kept, and saved workout records, history, photos and social connections are combined. VitalForge stores an internal merge record with the account identifiers, date and previous profile information to support integrity and troubleshooting. Temporary linking requests expire after ten minutes. The current settings do not provide a way to undo a merge.
Sign in with ChatGPT
When you choose Continue with ChatGPT, OpenAI handles its sign in experience and supplies the identity information described above. VitalForge does not gain access to your full ChatGPT conversation history merely because you sign in.
Any future direct OAuth integration will be limited to its configured and disclosed permissions. OpenAI’s own terms and privacy policy apply to its services.
Workout information
VitalForge stores workout names, exercise plans, repetitions, weights, sets, rest periods, weekly plans and custom exercises you save. Session records can include completed exercises, duration, completion time, notes, effort, mood, sharing choices and a session photo if you upload one. An unfinished session can be saved so you can resume it.
Community activity can include follows, friend requests, invitations, comments, copied workouts and shared session information. These records support the community and ranking features.
Profile information and photos
Your profile can include your display name, country, bio, Instagram username, profile photo and setup preferences. The current setup also requests gender, height and weight. A birthday can be provided. These measurements are omitted from the community public profile summary. The current friend request service can also return stored profile details for accounts involved in a request, so those details should not be treated as visible only to you.
Progress photos you choose to upload are stored with their date and selected view. The progress photo service restricts access to the account that uploaded them. Profile photos and photos attached to shared sessions can be visible to other users through the corresponding social features.
Apple Health and Apple Watch
With your permission, the iPhone application can read steps, active calories and details of a recorded workout, including duration and average heart rate when available. These readings are displayed on the phone. The current interface does not send these Apple Health readings to the VitalForge server.
The Apple Watch companion can record a workout using Apple Health, display heart rate and active calories, and send live workout state and controls between your paired watch and phone. Recorded watch workouts are saved in Apple Health. The current workout save flow does not include these live readings in the session information sent to VitalForge’s server.
You can change Health permissions in Apple’s Health or device settings. Turning off a VitalForge display option does not itself revoke Apple’s permissions or erase workouts already recorded in Apple Health.
Technical information and local storage
Hosting and authentication services process the network requests needed to deliver VitalForge, including IP addresses, request paths and technical information supplied by your browser or device. Operational logs may record request failures and service errors.
VitalForge uses browser storage for preferences and active workout recovery. The iPhone app stores account related workout data, saved media and pending changes locally for offline use, then synchronises changes when a connection is available. Credentials are stored separately in the Keychain.
The reviewed application does not include an advertising tracking SDK or a separate marketing analytics integration. The website’s hosting and authentication providers may use their own essential storage and operational logging.
How information is used
Information is used to authenticate you, save and restore your workouts, show progress, support offline access, provide the social features you choose, manage AI usage limits and keep the service operating securely.
Where applicable data protection law requires a lawful basis, core account and workout processing is necessary to provide the service you request. Necessary security and operational processing serves legitimate interests, subject to your rights. Optional device permissions and sensitive health processing depend on your permission and, where required, consent. Information may also be retained or disclosed to meet legal obligations.
AI processing
When an AI coaching feature is enabled and you submit a request, the conversation text you submit is sent to OpenAI to generate a workout response. If you choose voice transcription, the submitted recording is sent to OpenAI to produce text. These features do not automatically send your entire workout history or photo library.
The coaching request is configured not to store the generated response through OpenAI’s response storage option. That setting does not mean OpenAI keeps no operational or safety records. OpenAI processes API requests under its applicable data policies.
VitalForge records AI usage information such as account identifier, request counts, model, token counts, recording size and processing duration for limits and service management. Do not include information about another person or unnecessary sensitive information in an AI request.
Service providers and sharing
The current hosted service uses OpenAI Sites and Cloudflare infrastructure. Workout and profile records are stored in the hosted database, and uploaded images are stored in object storage. OpenAI processes authentication and, when enabled, the AI requests described above. Apple processes Apple Health and watch features under its own terms.
Your public profile includes your display name, country, bio, Instagram username and avatar when provided. Shared workouts, comments and sessions can be shown to other users and contribute to rankings. Workouts are shared by default in the current data model, and sessions are not private unless the private option is selected. Review sharing controls before saving.
Information may be disclosed when legally required, to protect people or the service, or as part of a lawful business transfer with appropriate notice and safeguards. The reviewed implementation does not sell personal information or share it with advertising networks.
Data retention
Saved account, workout and photo records remain in the service until removed through available controls or an account deletion process. The current implementation does not set an automatic expiry for these saved records. Account deletion is available in Settings → Account → Delete account.
Temporary mobile authorisation codes expire after 60 seconds. Mobile device credentials expire after 90 days. Expiry prevents their use but does not guarantee immediate deletion of the corresponding database record.
Local offline copies can remain on a device separately from server records. Signing out is not full account deletion. Copies saved by other users, Apple Health records and records held by authentication providers are controlled separately. Retention needed for legal obligations or security may continue after a deletion request where lawful. Provider logs are subject to the provider’s retention practices.
Data security
VitalForge uses encrypted network connections, account based access checks, credential hashing and the iPhone Keychain to help protect information. Progress photo access is checked against the requesting account. No system can guarantee absolute security.
Protect your device and authentication accounts. Do not share connection credentials. Offline records are held on your device, so its passcode, operating system protections and access controls also matter.
Your rights and account deletion
Depending on the law where you live, you may have rights to access, correct, receive a copy of or delete personal information, restrict or object to certain processing, and withdraw consent. You may also complain to your local data protection authority. These rights may have lawful exceptions.
You can edit profile information and use the existing controls to remove supported records or photos. You can change Apple Health permissions through Apple’s settings. Withdrawing permission does not affect processing that was lawful before withdrawal.
Delete your account in Settings → Account → Delete account. Contact support@vitalforge.app for privacy requests or deletion assistance. Deleting a VitalForge account will not delete your Apple or ChatGPT account, erase Apple Health records or cancel purchases managed by Apple.
Children and age requirements
VitalForge is intended for people aged 16 or older, subject to any higher local requirement. It is not designed for children under 16. The current account flow does not verify age, and a supplied birthday does not constitute age verification.
If information about a child has been submitted contrary to these requirements, contact support@vitalforge.app so it can be investigated and addressed.
International processing
Hosting, authentication and AI providers can process information in countries other than where you live. Those countries may have different data protection laws. International transfers must use safeguards required by applicable law, such as recognised contractual protections or an applicable adequacy decision. This policy does not promise that all information stays in one country.
Changes to this policy
We may update this policy when the service or its data handling changes. The Last Updated date identifies the latest revision. Material changes will be communicated through the service or another appropriate method, and consent will be requested where required.
Contact information
For support, privacy questions and account deletion assistance, contact support@vitalforge.app. The legal operator identity will be added before public launch.
Contact support@vitalforge.app for support, privacy questions and account deletion assistance. Do not send passwords, authentication tokens or unnecessary medical information.