ForgeFit · Privacy Policy
Jurisdiction: Australia (Privacy Act 1988 / APP) + GDPR-aware · Last updated: 2026-05-05
ForgeFit — Privacy Policy
Status — DRAFT skeleton. This document is structural; the legal language must be reviewed by Australian counsel familiar with the Privacy Act 1988 (and the Australian Privacy Principles), with a read-through for GDPR adequacy if EU users are reachable. The headings below are what AU counsel will expect.
Last updated: 5 May 2026 Operator: Storm Forge Pty Ltd (Australian Pty Ltd, ACN 697 468 081, ABN 71 697 468 081) trading as AppTree, publisher of ForgeFit. Contact for privacy queries: privacy@apptree.com.au
1. Who we are
ForgeFit is a fitness and coaching app published by AppTree, the trading name of Storm Forge Pty Ltd, an Australian proprietary company.
2. What we collect
ForgeFit is built around an on-device-first architecture. Workout history, weight, body measurements, and progress photos are stored locally on your phone, encrypted with AES-256.
We collect, only to the minimum needed:
- Account identifier (Google or Apple sign-in, when you sign in)
- Subscription state (App Store / Play Store billing receipts)
- Crash reports and diagnostic logs (no workout data, no PII)
- Bug reports you choose to send (route, app version, device model, OS version, optional screenshot)
- Wearable readiness signals (only if you connect a wearable; readings remain on your device unless you opt into cloud sync)
We do not collect: contacts, SMS, call logs, microphone, or camera content unless you explicitly invoke a feature that requires it (and even then the content stays on your device).
3. How fitness data is stored
- Default: workouts, weight, measurements, photos — all stored locally with AES-256 encryption.
- Cloud sync (opt-in): when enabled, an encrypted backup blob is written to your own Google Drive or iCloud. We do not have access to the unencrypted contents.
4. Bug reports
When you send a bug report from the app, we receive the note you typed, an optional screenshot, the route, app version, device model, OS version, recent crash summaries, and the last 200 lines of the app’s debug log. The screenshot shows exactly what was on your screen at the moment of capture; you can untick “Include screenshot” before sending.
5. The coaching engine
ForgeFit Coach is a deterministic, on-device recommendation engine. It does not call any external AI provider. There is no “AI request body” that ever leaves your phone for coaching purposes. Every recommendation is computed locally and accompanied by a five-bullet explanation showing the inputs that produced it.
6. Your rights under the Privacy Act / APP / GDPR
You have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Erase your data (factory reset + revocation of any cloud sync)
- Object to processing (we have no advertising or marketing processing to object to)
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or, if you are an EU resident, your local data protection authority
7. International transfers
If you reside outside Australia, your account identifier and subscription state may be processed on infrastructure located in Australia (asia-southeast1) or other regions where AppTree operates hosting. We do not transfer encrypted backup blobs out of the region where they were stored.
8. Children
ForgeFit is rated for users 16 and over. We do not knowingly create accounts for children under 16. If you believe a child has created an account, contact privacy@apptree.com.au and we will close it and erase the associated data.
9. Changes
We will publish material changes to this policy at least 30 days before they take effect.
10. Contact
Storm Forge Pty Ltd t/a AppTree Sydney, New South Wales, Australia ABN 71 697 468 081 · ACN 697 468 081