ReForge Privacy Policy
ReForge ("we", "us") is a personal recovery and discipline app. Privacy is a core feature of the product: there are no public profiles, no feeds, and your recovery data is visible only to you.
1. Data we collect
| Data | Why we collect it | Where it is processed |
|---|---|---|
| Email address and a password (stored only as a secure hash) | Creating and signing in to your account | Supabase (authentication); account emails such as password resets are delivered via Resend |
| Your app content: daily check-ins, urge logs, relapse logs, personal letter, ritual and reading progress | This is the product itself: your streak, progress, and history | Supabase (database), plus a local copy on your device so the app works offline |
| Subscription and purchase state | Unlocking Premium after a purchase and restoring it on a new device | Google Play Billing (Android) or the Apple App Store (iOS), and RevenueCat. We never see your card details; payment is processed entirely by Google or Apple. |
| Crash and error reports | Fixing bugs | Sentry, only if crash reporting is active in your app version |
We do not collect your location, contacts, photos, browsing history, or advertising identifiers. The app contains no advertising and no third-party analytics or tracking SDKs.
2. How your data is used
Your data is used for exactly one purpose: making the app work for you. We do not sell your data, we do not share it with advertisers, and we do not use it for marketing. The services named above (Supabase, RevenueCat, Sentry, Resend, Google Play, the Apple App Store) process data only on our behalf to provide the app's functionality.
3. Where your data lives
Your content is stored in your account in our Supabase-hosted database and transmitted only over encrypted connections (HTTPS). A copy is kept on your own device so the app works without an internet connection.
Your recovery content and account data are stored inside the EU: our database and authentication run in Supabase's Ireland region (eu-west-1), crash reports are stored in Sentry's EU data region (Germany), and account emails are sent through Resend's EU region (Ireland). Subscription and purchase state is processed by RevenueCat, which is based in the United States; this data is limited to purchase and entitlement records and never includes your recovery content. Where data is transferred outside the EU/EEA, we rely on the European Commission's Standard Contractual Clauses and/or the processor's certification under the EU-US Data Privacy Framework to safeguard it.
4. How long we keep it, and how to delete it
Your data is kept for as long as your account exists. You can delete your account at any time inside the app: Settings > Account > Delete account. This permanently removes your account and your recovery content from our systems. If you cannot access the app, email us (address below) and we will delete it for you.
Two narrow exceptions apply. We may retain a limited set of records where the law requires it: for example, purchase and transaction records are kept for 7 years under applicable accounting law. Residual copies may also persist in encrypted backups for a short period until those backups are rotated (typically within 30 days). Crash reports in Sentry are retained for 90 days and then deleted automatically.
5. Legal basis and your rights
The legal basis for processing your account and technical data (email address, subscription state, crash reports) is the performance of our contract with you (Art. 6(1)(b) GDPR) and our legitimate interest in keeping the app stable and secure (Art. 6(1)(f)).
Your recovery content (check-ins, urge logs, relapse logs, your personal letter, and your progress) is special-category data concerning your health and sex life. We process it only on the basis of your explicit consent (Art. 9(2)(a)), which you give in the app when you create your account and start logging. You can withdraw this consent at any time by deleting your account, which stops all further processing; withdrawal does not affect the lawfulness of processing that happened before it.
If you are in the EU/EEA, the GDPR also gives you the right to access, correct, export, or erase your personal data, the right to restrict processing, the right to object to processing based on legitimate interest, and the right to complain to your national data protection supervisory authority. Requests can be sent to the email address below and we will respond within 30 days.
6. Age
ReForge deals with a mature subject and is intended for users aged 18 and over. We do not knowingly collect data from children. If you believe a child is using the app, contact us and we will delete the account.
7. Changes to this policy
If we change this policy, the new version will be published at this address with an updated effective date. Material changes will also be announced inside the app.
8. Contact
The data controller for ReForge can be reached at:
Email: support@reforgeapp.app