forge-ai-legal

Privacy Policy — Forge AI

Effective date: May 19, 2026 — Last updated: August 11, 2026

This Privacy Policy explains how Forge AI (“we”, “us”, “our”) collects, uses, and protects your personal information when you use our mobile application (the “App”). We are committed to processing your data lawfully, transparently, and only as necessary to provide the service.

1. Data Controller

The data controller responsible for your personal data is:

For any question regarding your personal data or this Policy, contact us at the email above.

2. Data we collect

2.1 Account data

2.2 Profile data

2.3 Workout data

2.4 AI Coach interactions

2.5 Subscription data

2.6 Technical data

We do not collect: precise location, contacts, photos, microphone audio, biometric data, health/medical records, or payment card details (payment information is processed exclusively by Apple or Google).

3. Purposes and legal bases (GDPR Article 6)

Purpose Legal basis
Provide the service (account, programs, AI Coach, weight recommendations) Contract performance
Manage your subscription Contract performance
Respond to support requests Legitimate interest
Improve the App, prevent fraud and abuse Legitimate interest
Send service emails (password reset, important changes) Contract performance
Send marketing emails or push notifications Consent (opt-in, withdrawable any time)
Anonymous usage analytics Legitimate interest
Track via IDFA / AAID for performance attribution Consent (via the operating system’s tracking prompt)

4. Sub-processors

We share data only with the following providers, strictly as needed to operate the service:

Provider Purpose Region
Supabase Inc. Database hosting and authentication EU (Frankfurt); backups may be replicated to the United States
Anthropic PBC AI Coach (Claude API) United States
RevenueCat Inc. Subscription management United States
Apple Inc. In-app purchases via the App Store United States / Ireland
Google LLC In-app purchases via the Play Store United States / Ireland
Expo / EAS App distribution and crash reporting United States

We do not sell, rent, or trade your personal data to third parties for advertising purposes.

AI processing

When you use the AI Coach, generate a training program, or request a post-workout summary, the data strictly necessary to produce the answer (your message, and relevant profile and workout history) is sent to Anthropic PBC through a secured server-side proxy. Your data is not used to train third-party AI models. These features involve no automated decision-making producing legal effects or similarly significant effects within the meaning of Article 22 GDPR: AI outputs are informational recommendations that you remain free to follow, adjust, or ignore.

5. International data transfers

Some sub-processors are located in the United States. Data transferred outside the European Economic Area is protected by Standard Contractual Clauses (SCCs) approved by the European Commission, which ensure an adequate level of protection.

6. Retention periods

Data Retention
Active account As long as your account exists
Account after deletion request Soft-deleted for 30 days, then permanently erased
Workout history While your account is active, plus 30 days after deletion
AI Coach conversations Last 90 days; older conversations are automatically deleted
Subscription records 7 years (French tax and accounting law)
Crash and error logs 90 days

7. Your rights (GDPR)

You have the following rights regarding your personal data:

To exercise any right, email us at contact@louxia-agency.fr. We respond within 30 days.

8. Children

Forge AI is intended for users 16 years and older. We do not knowingly collect personal data from anyone under 16, and we do not direct the App to children.

Where the App is used by a minor aged 16 or 17, our Terms of Service require the prior consent of a parent or legal guardian. If you believe that a child under 16 has provided us with personal data, contact us at contact@louxia-agency.fr and we will delete it promptly.

9. Security

We protect your data with industry-standard measures:

No system is 100% secure. If a personal data breach occurs that may put your rights and freedoms at risk, we will notify you and the relevant supervisory authority within 72 hours, as required by GDPR.

10. Cookies and tracking

The App does not use web cookies. We may use anonymous device identifiers (IDFA on iOS, AAID on Android) only with your explicit consent, granted via the operating system’s tracking prompt. You can withdraw this consent at any time through your device’s privacy settings.

11. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will notify you within the App and update the “Effective date” above. Continued use of the App after the effective date of changes means you accept the updated Policy.

12. Contact

For any question, complaint, or rights request: