Updated 8 September 2026 · Developer: Benjamin Tunaru · support@getwodforge.com
WODForge creates workouts, guides training and keeps a personal journal. This page describes version 1.1, including its beta, and explains the differences for version 1.0 below.
Your profile, conversations, saved workouts, programs, results, remembered preferences and protected body areas are kept on your device. They can include personal or health information you provide. You can review or remove memories, manage conversations, and export or clear local data in Settings → Data & privacy. Starting another conversation does not erase your saved history. Turning memory off stops recall and learning of preferences; it does not erase existing records or remove your profile and protected areas.
Temporary conversations are held in memory and disappear when that screen closes. They use your profile and protected areas, but do not read conversation history or save memories, workouts or results. Sending a temporary message still shares it with OpenAI.
After you agree to sharing with the Coach, your messages, the images you explicitly attach, and relevant context pass through our HTTPS relay to OpenAI to generate a reply. Context may include your first name, goals, equipment, training history, results, remembered facts and pain you report. Health and Watch summaries are included only when you enable the separate Coach-sharing option. Information you type yourself can also contain health details.
We request OpenAI responses with application-state storage disabled. API inputs and outputs are not used for model training by default; standard abuse-monitoring logs may be retained for up to 30 days, subject to OpenAI’s exceptions and policies. See OpenAI API data controls. This is separate from WODForge’s storage. We do not collect conversations to improve WODForge.
For ordinary conversations, the relay temporarily stores response events so an interrupted request can be replayed without generating another answer. Replay expires after 10 minutes; a cleanup runs every 10 minutes. Temporary conversations do not store response content in this replay cache. Technical logs and provider processing still apply.
Version 1.1 offers an optional private WODForge account hosted on Supabase, using Sign in with Apple. Apple’s account identifier and authentication credentials establish and protect access to your account. The native sign-in does not request your name or email. The account is separate from your Apple subscription.
In version 1.1 build 350 and later, open Settings → Account or the account option on the welcome screen. The sign-in screen explains the data transfer before you continue. Continuing with Apple enables automatic saving of your profile, conversations, training, results, memories, attached photos and profile picture, including health information recorded in the journal and Watch summaries attached to sessions. Existing signed-in installations must enable Save my history to start automatic saving. Sharing with the Coach remains a separate choice.
With automatic saving enabled, WODForge synchronizes while the app is running and retries interrupted transfers when it can. After reinstalling, signing in to the same WODForge account recovers the data already saved there without importing a file. Data that has not reached the server cannot be recovered after deletion of the app. The account screen shows pending or failed synchronization; you can pause automatic saving there at any time.
Each account’s records are protected by server access rules; this is not end-to-end encrypted storage. The server copy remains until you erase it or delete the WODForge account. Pausing saving, signing out, deleting the app or clearing local data alone does not erase it. Delete WODForge account requires Apple verification and removes the account and its journal from the active service, then clears this device’s journal. Infrastructure backups and security logs follow the hosting provider’s retention policies; contact us for help with a data request.
Recovery tools contains the separate actions for older exports, previous iCloud data and the server copy. Replacing the local journal requires confirmation and keeps a protected local recovery copy first. In earlier version 1.1 builds, these controls are under Settings → Data & privacy → Journal & sync: Sync now transfers the journal manually, photos and profile pictures are excluded, and restoring the server copy is an explicit action. Installing build 350 does not silently enable automatic saving for an existing account.
Health access is optional and can be declined or revoked in Apple’s settings. With permission, WODForge reads relevant Health measurements for training context and records completed workouts. Watch workout recording can collect heart rate, active energy and duration. Running can additionally use location and workout metrics to record a route and guide the session. Location is used for running features, not advertising. Routes and workout records are managed on your devices and in Apple Health.
Health-derived data is not used for advertising or marketing. Sharing summaries with the Coach requires a separate choice; private journal synchronization also has its own explanation and action. WODForge 1.1 does not mirror its journal to iCloud. Earlier versions used private CloudKit storage: existing local data is preserved, and Previous iCloud journal provides recovery/export and a separately confirmed deletion of the old remote copy. Formats that cannot be validated are kept in the exportable recovery copy, rather than silently imported.
Camera and photo access are used for images you select. Attached Coach images are sent to OpenAI; the app does not scan your library. Dictation uses Apple’s speech services when you tap the microphone; microphone audio is not sent to WODForge’s servers. Daily reminders are local notifications.
Apple processes subscriptions and payments. We do not receive payment-card details. We verify Apple transactions on the server to authorize paid Coach use. A random installation identifier, transaction references, trial dates and entitlement status support access control and fraud prevention. Restore Purchases uses your Apple purchase account; it does not restore a journal. Manage or cancel subscriptions through Apple’s subscription settings.
We retain technical usage data such as request identifiers, installation identifiers, token counts, latency, cost and categorical feedback to operate and protect the service. These metrics do not contain conversation text. Latency records are scheduled for removal after 90 days, usage and feedback records after 400 days. Rate-limit keys derived from a truncated, hashed network address expire after 48 hours. Authentication and purchase records are also used to secure accounts and subscriptions. No third-party advertising or tracking SDK is included in the app.
Providers including Apple, OpenAI and Supabase process data under their respective terms; processing may take place outside your country. Network transfers use HTTPS/TLS and local recovery files use iOS data protection. Exported copies are under your control: choose a destination appropriate for their personal contents.
The launch notification form stores your email on Supabase to send the launch announcement. TestFlight requests collect your first name, last name, and Apple Account email address to review your request and manage an invitation through Apple. You must confirm your email within 24 hours. Unconfirmed reservations expire. Confirmed details are shared with Apple for the beta invitation, under Apple’s TestFlight privacy terms.
We do not sell these details or use them for advertising. Request deletion at support@getwodforge.com. The website uses cookie-less aggregate analytics.
You can manage sharing, memory, export, local deletion and private-account deletion in the app. You can withdraw Health permissions through Apple. Deleting your WODForge account does not cancel an Apple subscription or delete workouts already saved in Apple Health. For access, correction, deletion or other privacy requests, contact support@getwodforge.com. Depending on your location, you may also have rights to restrict or object to processing and to contact your data-protection authority.
WODForge is not directed at children under 13. We do not knowingly collect their personal information. Material changes to data handling will be reflected here and in release information.
Version 1.0 has no WODForge journal account and may mirror local records through private iCloud. Its local conversation and memory controls differ from version 1.1. The shared Coach service now disables the former optional training-content diagnostic collection, including requests from older apps. The current relay and operational-data disclosures above also apply to requests from version 1.0.
Not medical advice. Consult a physician before starting any exercise program.