Fuel & Forge ("we", "us", "our") provides an AI-assisted training, nutrition, and physique-coaching application (the "Service"), available on the web and as native iOS/Android apps. This policy explains what data we collect, why, and the choices you have.
1. Information We Collect
- Account information: email address, password (stored securely), and optional profile details you provide (name, age, weight, height, fitness goals).
- Health and fitness data: workouts, sets, reps, weights, body-weight and body-measurement history, food and hydration logs, calorie/macro targets.
- Apple Health data (native iOS app only): if you connect Apple Health, we read your steps, sleep, and body weight to keep your dashboard up to date, and write completed workouts and weight entries back to Apple Health. This only happens if you explicitly grant permission, and you can revoke it at any time in iOS Settings > Privacy & Security > Health.
- Camera and photos: food photos and body-composition photos you capture or choose from your library, submitted for AI analysis. These are processed to return your results and stored so you can view your history.
- Microphone: if you use voice-to-text logging, your device's or browser's built-in speech recognition converts your speech to text locally/via the OS; we receive and store the resulting text, not an audio recording.
- Location data: if you use Cardio Tracker or Gym Finder, we access your device's GPS location (only while those features are active, including briefly in the background during an active cardio session so tracking continues if your phone locks) to record routes/distance/pace or find nearby gyms.
- Payment information: subscription billing is handled by Stripe (web) or Apple/Google's in-app purchase systems (native apps). We do not store your full card details on our servers.
- Device and usage information: app version, usage patterns (e.g. logs recorded), and push-notification tokens if you enable notifications.
- Content you create: messages sent to the AI Coach, social posts, and achievements you choose to share with friends.
2. How We Use Your Information
- To provide the core features of the Service: logging, tracking, and displaying your data back to you.
- To generate AI-powered analysis and coaching (food analysis, physique analysis, workout program generation, coaching chat) using OpenAI's API. Data sent for analysis is used only to produce your requested result, not to train AI models.
- To process payments and manage your subscription via Stripe, Apple, or Google.
- To send notifications you've opted into (reminders, achievement alerts, rest-timer alarms) via Firebase Cloud Messaging or on-device native notifications.
- To send transactional emails (welcome, subscription confirmation, payment issues) via Resend.
- To protect the Service from abuse (e.g. reCAPTCHA on sign-in/sign-up).
- To improve and maintain the Service.
We do not sell your personal data, and we do not use it for third-party advertising or cross-app tracking.
3. Third-Party Services We Use
- Supabase — database, authentication, and file storage.
- Stripe — subscription payment processing (web).
- Apple App Store / Google Play Billing — subscription payment processing (native apps).
- OpenAI — AI food/physique analysis and coaching chat.
- Apple HealthKit — steps, sleep, and weight sync (native iOS app, only if you connect it).
- Google — Google Sign-In, and Google Health Connect integration if you choose to connect it (see Section 4 for full detail on what this accesses and how it's used), Places/Maps for gym search, and reCAPTCHA.
- Firebase (Google) — push notification delivery.
- Resend — transactional email delivery.
- USDA FoodData Central — public nutrition database used for food search (no personal data is sent beyond your search query).
4. Google User Data
If you choose to connect Google Health Connect / Wear OS from Settings > Integrations, Fuel & Forge requests access to your Google Account through Google's OAuth consent screen. This section describes that access in detail, as required by the Google API Services User Data Policy.
- What Google user data we access: read-only fitness/activity data (daily steps, active minutes, distance, calories burned from tracked activity) and sleep data (sleep sessions, duration, sleep stages) from Google Health Connect. We request exactly two read-only OAuth scopes for this:
googlehealth.activity_and_fitness.readonly and googlehealth.sleep.readonly. We do not request access to your email, contacts, files, calendar, or any other Google data, and we never write, modify, or delete anything in your Google account.
- How we use it: the activity and sleep data above is synced into your Fuel & Forge account and shown back to you in your own in-app dashboards, charts, and progress/quest tracking (for example, so a walk tracked by Google Health Connect counts toward your weekly activity progress). It is not used to train any AI model, and it is not currently included in the data sent to our AI coaching feature.
- Who we share it with: we do not sell, rent, or share your Google user data with any third party, and we do not use it for advertising. It is stored in our own database (hosted on Supabase, see Section 3) purely to power the features described above, and is only ever shown back to you, the account owner.
- How we protect it: your Google OAuth tokens and the synced fitness/sleep data are encrypted in transit (HTTPS/TLS) and at rest, stored in an access-controlled database, and reachable only by your authenticated account and by backend services acting on your behalf (never by other users).
- Retention and deletion: synced Google fitness/sleep data and your OAuth tokens are kept only for as long as the connection stays active. You can disconnect Google Health Connect at any time from Settings > Integrations, which immediately revokes and deletes the stored OAuth tokens; deleting your account (Settings > Delete All Data) deletes this data along with everything else in your account, per Section 6.
Fuel & Forge's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Your Choices and Rights
- You can view, edit, or delete most of your logged data directly in the app.
- You can disconnect Apple Health at any time from Settings, or by revoking permission in iOS Settings.
- You can delete your account and its data at any time from Settings ("Delete All Data").
- You can request a copy of your data, or ask us to correct or delete it, by emailing support@fuelandforge.co.uk.
- If you're in the UK/EEA, you have rights under GDPR (access, rectification, erasure, portability, objection); California residents have rights under the CCPA. We respond to verified requests within the timeframes required by applicable law.
6. Data Retention
We retain your data for as long as your account is active, or as needed to provide the Service. If you delete your account, we delete your personal data within a reasonable period, except where we're required to retain it for legal, tax, or fraud-prevention purposes. See Section 4 above for retention specific to Google user data.
7. Data Security
We use industry-standard measures (encryption in transit and at rest, access controls) to protect your data, including any sensitive data such as health, fitness, and sleep information described in Sections 1 and 4. No system is 100% secure, and we cannot guarantee absolute security.
8. Children's Privacy
The Service is not directed at children under 16, and we do not knowingly collect data from children under that age.
9. International Users
Your data may be processed in countries other than your own (including the United States and United Kingdom) by us and the service providers listed above.
10. Changes to This Policy
We may update this policy from time to time. We'll post the updated version here with a new "Last updated" date.
11. Cookies, Local Storage & Similar Technologies
We keep our use of cookies and device storage to the minimum needed to run the Service:
- Essential storage: we use first-party cookies and browser local storage to keep you signed in, remember your preferences (such as units and theme), and let the app work offline. The Service does not function without these.
- Fraud prevention: Google reCAPTCHA is loaded on our sign-in and sign-up screens and sets its own cookies to tell humans from bots. This is used only to protect accounts from abuse.
- No advertising or analytics cookies: we do not run third-party advertising, cross-site tracking, or behavioural analytics cookies, and we do not use tracking pixels.
You can clear cookies and local storage in your browser or device settings at any time; doing so will sign you out and reset local preferences.
12. Contact Us
Questions or requests about this policy or your data: support@fuelandforge.co.uk