This notice applies to Washington residents and anyone whose consumer health data Forjex collects in Washington. It supplements our Privacy Policy. Forjex is operated by Reliability Works Ltd, company number 16206723.
1. Categories of consumer health data we collect
- Health and body details: Date of birth, sex, height, weight, body measurements, progress photos, injuries, limitations, symptoms, and health or wellbeing answers you choose to provide
- Apple Health data: The categories you allow Forjex to read, such as heart rate, heart rate variability, resting heart rate, sleep, steps, active energy, workouts, distance, and recovery signals
- Training and activity data: Goals, experience, workout plans and logs, exercise history, personal records, outdoor activity totals, uploaded route points, and weather saved with an activity
- Nutrition data: Nutrition plans, targets, meal and food logs, hydration, and related progress
- Coaching data: Health or injury answers in coach intake forms, check-ins, adherence, programs, messages, and progress photos you share with a coach or linked training partner
- Health-related content and inferences: Health information you put in posts, messages, support requests, or AI Coach prompts, plus readiness scores, fitness age, form feedback, progress-photo analysis, and other results Forjex or its AI providers derive from your data
2. Sources of consumer health data
- You, when you enter, upload, record, or share information
- Apple Health, only for categories you allow
- Your iPhone and Apple Watch during an activity you start
- Apple's weather service, which returns the conditions saved with an outdoor activity you record
- Apple's MapKit service, which returns a selected place name and coordinates when you search for a location to attach to a post
- USDA FoodData Central and Open Food Facts, which return food and nutrition details when you search for a food or scan a barcode
- A coach or linked training partner when you use a sharing flow
- Other members who create a post, comment, message, report, or mention about you
- Forjex and its AI providers when they calculate or infer results from the data above
3. How we use consumer health data
We use consumer health data to provide the features you request, including:
- Recording training, nutrition, body, and outdoor activity history
- Calculating readiness, progress, fitness insights, and personal targets
- Generating plans, AI Coach answers, meal-photo estimates, form feedback, progress-photo analysis, lift verification, and squad or real-world battle judgements
- Supporting coaching, check-ins, and sharing you choose
- Answering support and privacy requests
- Protecting the service, preventing abuse, and meeting legal duties
We collect or share consumer health data only with your consent or where it is necessary to provide a product or service you requested. We do not collect or share a new category, or use consumer health data for a new purpose, without updating this notice and obtaining consent where the law requires it.
4. Categories of consumer health data we share
We share only the categories needed for the feature you request. This can include account-linked health and fitness records with our infrastructure providers, uploaded health media with our storage provider, selected health context, meal photos, and AI Coach image attachments, imported plan text, images, PDFs, and proof videos with our AI provider, signed form-video links, relevant health context, and rendered progress-photo frames with our Google Cloud Run services, activity coordinates with Apple's weather service, health-related push notification content with Apple's notification service, a complete website contact message with our email provider when you put health information in that form, completed workout data with Apple Health when you authorize writes, health information a coach puts in a payment-request note with Stripe, and information you choose to share with a coach, linked training partner, squad, or social audience. A training or nutrition plan-share link can open the complete shared plan in the Forjex iOS app, including exercises, sets, loads, and meals. The public web preview shows only plan metadata. When you use the iOS share sheet, the people, apps, or cloud services you select receive the exported content. This can include a GPX route with its coordinates, a progress-photo timelapse, or your protected account data export.
If you put health information in a social post, comment, message, or report, the processors that host or screen that content can receive it as part of that content. USDA FoodData Central or Open Food Facts receives a food search term, and Open Food Facts receives a barcode when you scan one. Giphy receives a GIF or sticker search term. We do not attach your Forjex account ID to these searches. Sentry is prohibited from receiving health, body, nutrition, readiness, route, photo, message, or AI health-context values.
5. Who receives consumer health data
- Infrastructure providers: Convex hosts the Forjex database. Cloudflare hosts uploaded media and carries app requests. Vercel hosts forjex.com and the web platform. Forjex services hosted on Google Cloud Run receive signed workout, form, or proof-video links and the exercise or health context needed to process them. A separate Google Cloud Run service receives rendered progress-photo frames to make a timelapse
- AI and safety providers: Google Gemini receives the data needed for a requested plan, AI Coach answer, meal-photo estimate, form review, progress-photo analysis, imported plan extraction, lift verification, squad challenge judgement, real-world battle judgement, weekly progress-photo digest, or scheduled coaching roster insight, or a readiness insight you request. Scheduled analyses and readiness insights can include readiness score, state, summary, signals, trajectory, recovery history, recent training, plans, goals, weight, mood, earlier analysis, streak, workout volume, personal records, check-ins, training summaries, and body trends you chose to share. Imported plans send the complete pasted text or original uploaded image or PDF bytes. AI Coach image attachments also send the original image bytes. OpenAI screens user-authored social text, including posts, comments, captions, and direct messages. Sightengine screens every finalized image post for nudity and gore. It also screens reported social images and images held during a first-contact message request before the recipient can view them. Langfuse receives redacted AI trace metadata, such as internal user or client IDs, dates, session and analysis counts, model and token counts, and request duration. Prompt and response text is replaced with [redacted]
- Resend: If you use the website contact form, Resend receives your name, email address, subject, and complete message so it can deliver the request and our reply. For authenticated privacy requests, Resend receives your email address, the consumer-health ticket subject, and our complete written decision and appeal instructions. These messages can include consumer health information
- Food and media search providers: USDA FoodData Central receives a food search term. Open Food Facts receives a food search term or scanned barcode. Giphy receives a GIF or sticker search term. We do not attach your Forjex account ID to these searches. When your phone loads selected Giphy media, Giphy also receives your IP address and standard request details
- Apple:If you authorize Apple Health writes, Apple Health receives completed strength workouts and active-energy samples, or completed outdoor workouts with their distance and elevation. Apple's weather service receives your coordinates while an outdoor activity is being recorded. If you enable notifications, Apple Push Notification service receives the device token and notification title, body, route, and type needed to deliver alerts. These can describe training, form-analysis, check-in, or coaching activity, even when lock-screen previews use generic text. Apple's MapKit service receives a complete place-search term and standard request data when you search for a location to attach to a post. MapKit also receives route-derived coordinates and standard request data when it renders a live outdoor activity, saved route, or route-animation preview
- Linked websites:The destination server receives a post link's complete URL, including its path and query, during automatic preview generation. A third-party preview-image host receives each viewer's IP address and standard request details when the advertised image loads
- Stripe: If a coach puts health information in the optional note for a payment request, Stripe receives that note as the checkout product name when the client opens checkout
- Stripe coach subscriptions:Stripe receives the athlete's email address and internal user ID, coach, offer, and session IDs, and the coach-entered offer description when an athlete opens coach-subscription checkout
- People you choose: A coach, linked training partner, squad member, social audience, or anyone who receives a plan-share link receives what the relevant sharing control or capability URL makes visible. People, apps, or cloud services you select through the iOS share sheet receive the GPX route, progress-photo timelapse, or protected account-data export you choose to send
- Legal disclosures: We may disclose data where the law requires it or where it is necessary to establish, exercise, or defend legal rights
We do not currently share consumer health data with an affiliate. We do not sell consumer health data. We do not share consumer health data with data brokers or use it for advertising.
6. Your Washington rights
You can ask us to:
- Confirm whether we collect, share, or sell your consumer health data and give you access to it, including the third parties and affiliates that received it
- Withdraw consent from future collection or sharing
- Delete your consumer health data and notify processors and other recipients that must also delete it
We do not discriminate against you for exercising these rights. Access information is free up to twice each year. We respond without undue delay and within 45 days. We may extend once by another 45 days when reasonably necessary, and will explain the delay within the first 45 days. Deletion from an archived or backup system can take up to six months where Washington law permits that delay.
7. How to make a request or appeal
If you have a Forjex account, open Settings or Help & Support, then Privacy rights. That route sends an authenticated request to our support team. You can also email contact@reliabilityworks.co.uk. You do not need to create an account to make a request. We may ask for information reasonably needed to authenticate you and the request.
If we refuse a request, reply to the decision or use the same Privacy rights or email route to appeal. We will respond to the appeal in writing within 45 days and explain the decision. If we deny the appeal, we will tell you how to contact the Washington State Attorney General.
8. Contact
Email contact@reliabilityworks.co.uk, or write to Reliability Works Ltd, 345 Kenbrook Road, Hucknall, Nottingham, England, NG15 8HS, United Kingdom.