Privacy Policy
Effective 19 September 2026
Forced Rep is a strength-training companion made by Mbit (Finland). This policy describes what data the Forced Rep apps and website handle, why, and what control you have over it. The short version: your data exists to run your account, we do not sell it, and there is no advertising or cross-app tracking anywhere in the product.
Who is responsible
The data controller is Mbit, a business registered in Finland. You can reach us about anything in this policy at hello@forcedrep.app.
What we collect
- Account data — your email address and a securely hashed password.
- Training data — workouts, sets, rest periods, workout plans, strength references, training history, and notes you write.
- Body and nutrition data you enter — body weight, nutrition logs, custom foods, nutrition targets, and habits. Nothing is read from or written to Apple Health or Health Connect.
- AI content — messages you send to the AI coach and nutrition features, and the proposals they produce, plus server-side metering of AI usage (tokens and cost) to operate the credit wallet.
- Device and session identifiers — a per-install device identifier used to pair your watch and sync your active workout, and short-lived session identifiers used to correlate error reports.
- Purchase references — when you buy something, we store a reference to the transaction. Card details never touch our systems; payment processing happens at Stripe or your app store.
What we do with it
Everything above is used to provide the product: syncing your workouts across phone, watch, and web, showing your history, and operating the AI features you invoke. We also collect basic product usage data — screens visited, features used — and diagnostics to keep the app working: error reports, performance timings such as how long a screen takes to load or a change takes to save, and the app's own diagnostic log lines about failed saves and sync retries. There are no advertising SDKs and no sale or sharing of personal data for marketing.
To reproduce errors, the phone and web apps record masked session replays: a reconstruction of the screens you moved through and where you tapped or clicked. Masking happens on your device before anything is sent — all text, images, and form inputs are replaced with blank blocks — so a replay shows the app's layout and never your workouts, meals, messages, or anything you type. Every session that hits an error is recorded, along with a small sample of other sessions. Replays are used only for diagnostics and are stored with our error-reporting provider, Sentry, in the United States. The watch apps and this website record no replays.
AI features and AI model providers
The AI coach, nutrition chat, and workout naming run on third-party AI models. When you use one of these features — and only then — the content that feature needs is sent for processing: your message, the relevant training or nutrition context, and recent chat history. Requests are routed through Vercel's AI Gateway to one of the model providers we use, currently OpenAI, Anthropic, and xAI. Every request runs under zero-data-retention terms: the provider processes it to answer and does not store it or train on it. We may add or change model providers; this list is kept current. Using AI features is optional and asked for explicitly in the app, and you can withdraw that permission in Settings; manual features work fully without them.
Service providers
- Convex — database, authentication, and live sync (our backend).
- Vercel AI Gateway — routes AI requests to the model provider, only when you use AI features.
- OpenAI, Anthropic, xAI — AI model processing under zero-data-retention terms, only when you use AI features.
- Stripe — payment processing for web purchases.
- Apple / Google — payment processing for purchases made inside the apps.
- Sentry — crash, error, and performance reporting, masked session replay (United States).
- PostHog — product analytics, hosted in the European Union.
- Vercel — website and web-app hosting.
Where a provider processes data outside the European Economic Area, transfers rely on safeguards such as the EU–US Data Privacy Framework or standard contractual clauses.
Retention and deletion
Your data is kept while your account exists. You can export your data and delete your account from Settings in the app or on the web; deletion removes your account data from the production systems. Error reports and aggregated usage metering are kept only as long as operationally needed.
Your rights
Under the GDPR you can access, correct, export, and delete your data, object to or restrict certain processing, and complain to a supervisory authority (in Finland: the Data Protection Ombudsman). Export and deletion are self-service in the app; for anything else, email hello@forcedrep.app.
Changes
If this policy changes materially, the effective date above changes and the app will point out the new version before you continue using the affected features.