Privacy Policy
Effective 2026-08-14 · updated 2026-09-16 · Privacy officer: Varsal — varsal@autoopsai.ca
What we collect
Your account (name, email — handled by Clerk, our sign-in provider), and what you put into the product: goals, daily logs, weekly scores, notes, reviews, and your conversations with the AI coach. If you buy a sprint, payment is processed by Stripe; we receive confirmation and a billing country/state, never your card number. We do not ask for a home address, government ID, or a phone number as a condition of using The Forge.
If you join the waiting list on our landing page, we store the first name and email you give and, when you arrived from an advert, which campaign it was — so we know which adverts are worth running. If you bought the 4-week challenge on Skool, Skool handles that purchase and its own data under its own policy; we only ever see the access code you type in here.
What we use it for
To run The Forge for you — including sending the relevant parts of your tracker to our AI provider (OpenAI) so the coach can coach you — and nothing else. We do not sell your personal data. Inside the product — every page you see once you are signed in — there are no advertising pixels, no session-recording scripts and no cross-site tracking. The app uses Vercel's privacy-friendly analytics to count page views and measure loading speed — it sets no cookies and does not identify you — and PostHog as described below. Health, journal and body numbers live in our product database and are never sent to an advertiser or a CRM. The one place advertising measurement exists is the public landing page, and only with your consent — see "Advertising on the landing page" below.
For our own bookkeeping we keep an operational copy of account and cycle status — who has an account, whether a cycle is paid, active or finished, and when someone last logged — in Airtable, which we use as an internal spreadsheet. That copy never contains your goals, logs, notes, scores or coach conversations.
Advertising on the landing page
Our public landing page (the one an advert sends you to) can load a Meta (Facebook / Instagram) pixel so we can tell which advert brought you. It does not load until you press Accept on the cookie notice shown there; if you decline, nothing from Meta is loaded and nothing is set on your device. The pixel is never loaded on any page inside the product.
Separately, our servers tell Meta when someone who arrived from a Meta advert joins the waiting list, starts a checkout, registers or pays. Those reports carry only Meta's own click identifiers (the cookies its pixel set when you accepted) and, for a purchase, the amount — never your email, name or phone, not even hashed, and nothing about what you track. Someone who declined the notice, or who found us without an advert, is not reported at all.
Product analytics
We measure how the public side of the site performs — which pages people land on, how far they get toward the free interview, where they give up — with PostHog, a product-analytics provider. The browser script loads only while you are signed out: the landing page, pricing, the FAQ, sign-in, sign-up, and these legal pages. Once you are signed in, that script does not run. The address of a page inside your tracker, a goal, a note, a weight, or a coach conversation is not sent to PostHog from your browser. It is not masked on the way out. It is never sent.
A small number of named events are sent from our servers after you have an account — things like "account created", "checkout started", "sprint paid", or "week completed". Those events carry an opaque id (forge: plus an internal number), never your email, never your name, and never the contents of your tracker. That is how we know whether the product is actually being used without handing a vendor your logs.
Where the browser script does run, it is configured down to the minimum: autocapture is off, so it records only page views rather than every click and keystroke; session recording is off; heatmaps are off; and it keeps nothing on your device (memory only — no cookie, no local storage). The one exception is the landing page: if you accept the cookie notice there, PostHog is allowed to keep a cookie on that page so a return visit counts as the same visitor, which is what lets us judge an advert honestly. What it receives is the page address, where you arrived from, a rough country and region worked out from your IP, and your browser and device type.
PostHog processes this in its US cloud as our processor — it is not free to use your data for its own purposes. We do not sell it, we do not send it to advertisers, and none of it is joined to your email.
If you would rather not be counted: switch on Do Not Track or Global Privacy Control in your browser and the script will not load at all. A tracker blocker stops it too, and nothing on the site breaks if you use one.
Cookies
Clerk uses cookies so you can stay signed in. Those are required for the account to work. Stripe Checkout runs on Stripe's domain when you pay. Inside the product no analytics tool sets a cookie — Vercel's is cookieless by design and PostHog is configured to keep nothing on your device — so there is no cookie banner there. The landing page is the one place with optional cookies (Meta's, and PostHog's return-visit cookie), and it asks first. Your answer is remembered for six months in a cookie called forge_consent; declining stores the same and loads nothing.
Health-adjacent data is optional
Some members track body metrics (weight, calories). That is entirely optional — The Forge works fully with non-body goals — and any such numbers you log are used only to show you your own trend and score.
Who can see your data
You. If you invite a partner, they see the weekly snapshot you explicitly choose to share — nothing live, nothing you didn't pick. Our service providers process data to run the product: Vercel (hosting and analytics), Supabase (database), Clerk (sign-in), OpenAI (AI coach), Stripe (payments), Resend (email), PostHog (page views on signed-out pages, and the named server events above), Airtable (the operational status copy described above), and Meta (advertising measurement, landing page only, with consent, click identifiers only). If you subscribe to the calendar feed, your calendar provider — Google, Apple or whoever you use — fetches it from us on your instruction. Each receives only what its job requires.
Retention and deletion
Your tracker history is kept so your cycles can be compared — that's part of the product. You can delete your account yourself at any time from Account or Settings, and it deletes everything: your sprints, every day you logged, your notes and your conversations with the coach. It is immediate and it cannot be undone. If you would rather have a copy first, or want us to do it for you, email varsal@autoopsai.ca and it is actioned within 30 days.
Refunds, access, and deletion
A refund is not a delete. If you take the first-cycle money-back guarantee, we still keep your logs. You keep full use of The Forge until 21 days after that purchase. After that date, if the refund is on file, the site locks and the only in-app action left is deleting this account. If you never refund, you keep the 13-week cycle you paid for. A bank dispute is not the same as a Billing refund and may end access when we are notified.
Where
The Forge is sold for use in Canada and the United States, except Washington State and Quebec, to people 18 or older. That is a term you agree to, not a border we enforce — Stripe Checkout will take a card from anywhere, and we do not geo-block. The terms say why those two are out. We do not knowingly collect personal information from anyone under 18. Data is processed in the United States and Canada by the providers above, and in the United States by PostHog.
Changes
Material changes to this policy will be announced in the app before they take effect. Questions: varsal@autoopsai.ca.