WOD ForgeAI functional training coach
Privacy Policy

Your data stays yours

Effective 24 August 2026 · Developer: Benjamin Tunaru · [email protected]

WOD Forge generates workouts with an AI coach, times your training, and logs your results. This policy explains exactly what data the app handles, where it goes, and the choices you have — in plain language.

The short version

1Data stored on your device

The following stays on your device and is not transmitted to us:

Deleting the app removes this data. You can also export or clear everything from Settings → Data & privacy.

2AI coach — data sent to OpenAI

When you send a message to the coach, the app transmits over an encrypted (HTTPS/TLS) connection, through our own relay server (which adds the API credential and forwards the request):

This is processed by OpenAI, L.L.C. to generate the coach's response. We request responses with application-state storage disabled. Under OpenAI's API data controls, API inputs and outputs are not used to train OpenAI models by default; standard abuse-monitoring logs may be retained for up to 30 days (OpenAI API data controls). We attach no email or account — the requests are not linked to a login. They carry a random per-install identifier (a UUID created inside the app on first launch, stored in the device keychain so it survives a reinstall — unrelated to your device's hardware identifiers). It is used solely to run the 7-day free trial, for rate limiting, cost monitoring, and engagement metrics that carry no workout content (for example whether a generated workout was regenerated, abandoned, or completed).

By default, our relay streams coach requests and responses without saving their content in our database. If you explicitly enable Settings → Help improve the coach, we may save a redacted diagnostic copy of your message, the coach's visible reply and workout-tool inputs for up to 30 days so we can investigate bad answers. This copy excludes your name, hidden AI reasoning, images and raw Health measurements. Turning the setting off prevents future diagnostic copies. Operational usage metrics — such as token counts, latency and estimated cost, keyed to the random install identifier — do not contain message content.

For rate limiting only, the server derives a short-lived key from your network address: the address is truncated — the last part is discarded — then hashed with a secret server key. The result is kept for at most 48 hours, then deleted. Your full address is never written to our database or our logs, and the key cannot be used to contact or identify you.

Multi-week programs are generated the same way as sessions: streamed to your app while you wait. Nothing is queued or stored on our server.

If you never use the AI coach, none of this data leaves your device.

3Apple Health (HealthKit)

With your explicit permission:

Health data is managed by Apple Health on your devices, under your permissions — change or revoke them anytime in the Health app or Settings → Privacy & Security → Health. We do not send your raw Health data to our servers. A summary you choose to keep in a score note (e.g. "72 bpm avg") is stored with that score and, like other score data, may be included in the training summary sent to the AI coach if you later chat with it. We never use Health data for advertising or share it with any third party.

4Subscriptions

WOD Forge is sold as an auto-renewing subscription through Apple's In-App Purchase. Apple processes the payment; we never see your payment details. Manage or cancel in Settings → Apple Account → Subscriptions.

5Notifications

If you enable the daily training reminder, the app schedules a local notification on your device. No notification data is sent to a server and no push tokens are collected.

6What we do not collect

7How long we keep server metrics

Server-side usage metrics (token counts, latency, estimated cost, the random install identifier, which safety belts fired) are kept for up to 13 months and contain no message content. Rate-limit keys are deleted after 48 hours. Consent-gated redacted diagnostic content is deleted after 30 days. OpenAI may retain standard API abuse-monitoring logs for up to 30 days under its API data controls.

8Website forms and TestFlight requests

If you enter your email address in the "Notify me at launch" form on getwodforge.com, we store it securely on Supabase for one purpose: sending you one email when WOD Forge launches on the App Store.

If you request access to the TestFlight beta, we store your first name, last name, and Apple Account email address so we can review the request and invite you through Apple’s TestFlight service. You must confirm your email within 24 hours. Unconfirmed reservations expire; confirmed details are shared with Apple only to issue and manage your beta invitation. Apple processes TestFlight tester data under its own privacy terms.

We never sell or use these details for advertising. You can request deletion at any time at [email protected]. The site has no cookies requiring consent and uses cookie-less, aggregate analytics only. The app itself never collects your email.

9Children

WOD Forge is a general fitness app for a general audience and is not directed at children under 13. We do not knowingly collect personal information from children.

10Your choices and rights

11Security

Network requests use HTTPS/TLS. The AI relay server holds the OpenAI API credential server-side so it never ships in the app. It does not save photos or training summaries in our database, and only saves redacted coach-turn content when you explicitly enable the diagnostic setting described in section 2.

12Changes to this policy

If we materially change how the app handles data, we'll update this page and the effective date above, and note it in the app's release notes.


Not medical advice. Consult a physician before starting any exercise program.