Privacy Policy
Reforgr is built privacy first around the data that matters most: your recovery history. Core app use does not require an account, name, email address, or phone number. You may separately choose a public leaderboard nickname or give us a reply-to email when contacting support. This policy explains what stays on your device, what leaves it when you request a connected feature, who processes it, and the rights you have.
Who we are
Reforgr is a focus and self-discipline wellness app for iPhone. The data controller is Nomis IT, a French single-member limited liability company (societe a responsabilite limitee a associe unique) with share capital of 1,000 EUR, registered with the Trade and Companies Register (RCS) of Lille Metropole under number 921 726 170 (SIREN 921 726 170). Its registered office is at 2 ter rue d'Anchin, 59242 Templeuve-en-Pevele, France. The legal representative (gerant) and director of publication is Simon Brienne. You can reach us at support@reforgr.com.
The app is distributed through the Apple App Store (Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA). Our backend and static pages are hosted by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.
Our privacy-first model
Your primary recovery record is stored on your device and, if your device has it enabled, in your own private iCloud Key-Value Store: your streak, relapse history, completed program days, program notes and written reflections, answers to in-app questions, daily check-ins, urge logs, and conversation history with the in-app coach. That iCloud copy is controlled by Apple under your Apple ID and syncs only across your own devices signed in to that Apple ID. We do not maintain a Reforgr account or a durable server recovery profile containing this history. When you explicitly choose an AI feature, the relevant parts of this device-first record can be sent for processing as described below. In particular, program notes remain intentionally available to the coach, progress insights, and a later personalized cycle so those features can build on your own words. A personalized-program request transits temporarily through a Cloudflare Queue, and its finished result is held briefly in Cloudflare D1 until your device retrieves it or the automatic purge runs. Reforgr does not ask you to take or upload a photo, image, screenshot, video, audio recording, or file for the Program, and none is sent as part of it.
We want to be honest rather than overclaim: it is not true that nothing ever leaves your phone. A small, deliberate set of data does leave the device for specific features, described next. Everything outside that set stays local.
Exactly what leaves your device
The optional pseudonymous leaderboard. Only if you choose to join it. When you opt in, the app stores a randomly generated identifier, a nickname you pick, your streak numbers, your in-app rank level, the catalog identifier of the cosmetic relic you equip (if any), and an optional short public bio line in our Cloudflare database. The feature does not require your real name or contact details; do not put identifying details in the nickname or bio if you do not want them to be public. The relic is selected from Reforgr's fixed catalog and is not user-authored text. The bio line is checked automatically to remove links, contact handles, and offensive words. You can leave the leaderboard at any time, which deletes that entry.
The AI features. Reforgr offers an optional AI-personalized 30-day Program, a supportive coach chat, short progress insights, and an optional personalized line in Panic. After a premium purchase or when AI is first configured, one setup screen explains the data categories, purposes, and processors and presents two independent choices: (1) AI generation for the current Program and later cycles; and (2) recovery-context access shared by Coach, Insights, and the optional Panic line. You may allow both, choose either purpose separately, or keep both off. If Program AI is off, Reforgr installs a useful built-in 30-day path selected and run on your device without a Program-generation request. Coach and Progress then follow the saved choice without repeating consent prompts. Panic remains immediately usable with local tools and only requests its optional personalized line when the context purpose is already allowed; it never interrupts an urgent moment with a consent screen. You can change or withdraw either AI choice later in Settings without deleting your local notes, history, charts, or an already-delivered plan. For Program generation, the request can include allowlisted quiz option codes, your free-text reason for quitting, coarse progress signals (such as streak numbers, urge and check-in statistics, and panic-button usage), earlier day titles, your Program notes and reflections, and short excerpts from recent coach messages. The Program-generation request does not include your leaderboard alias. For the coach, the request includes your messages, relevant recovery context, recent Program notes and reflections, and a small on-device memory summary so the agent can answer with continuity. When context access is on, opening Your Progress may automatically request a fresh insight when one is due; the optional Panic line may also be requested when Panic is opened online. Progress insights and the optional Panic line use relevant recovery context and recent reflections. These requests are not attached to a Reforgr account or email address. However, free-text fields can contain anything you choose to type, including identifying or sensitive details, so avoid including details you do not want an AI processor to receive. Our Cloudflare Worker sends the AI content to OpenCode Zen, which runs the DeepSeek model used for the personalized Program and as the primary model for the coach; Cloudflare Workers AI may handle a coach, insight, or Panic-line request as a fallback. Program requests temporarily transit through Cloudflare Queue while the job is delivered and processed. The finished plan is stored in a transient Cloudflare D1 row under a random one-time job code and remains retrievable if a network response is lost; client cleanup may delete it sooner, and it is automatically purged about one hour after the request. Turning off Program AI asks the Worker to delete a queued job so it will be skipped; if provider processing has already started it cannot be recalled, but Reforgr discards the result. Coach replies and progress insights return directly and are not written to the Program-results database. If you have allowed notifications, a Program or coach request may also include your Apple push token. For a Program job, that token travels only with the temporary Queue message and is not written to D1; it is used to deliver a generic "your plan is ready" alert. A coach notification is also generic, and the reply itself is not included in the notification. No AI feature sends photos, images, screenshots, videos, audio recordings, or files because Reforgr does not request or accept them in these flows.
Device check (App Attest). To stop automated abuse of the AI features without making you create an account, the app uses Apple's App Attest. Your device's Secure Enclave generates an anonymous cryptographic key that proves a request comes from a genuine, unmodified copy of Reforgr on a real Apple device. The first time you use the AI features, the app sends this anonymous attestation to our backend, which verifies it (a step that involves Apple's App Attest service); after that, each AI request carries a short anonymous token derived from it. This key is specific to your installation, contains no name, email, or other personal information, is not an account, and is never used to identify or track you.
In-app feedback and bug reports. If you choose to send feedback or report a bug from Settings, the app sends your message, basic device information (for bug reports), an optional reply-to email if you decide to give one, and, only if you switch it on, an optional diagnostics attachment (a short technical log of app opens and network calls, with no content of your notes or chats). This is delivered to us as an email and handled like any support email; it is not stored in our database and is not linked to the anonymous identifiers above.
Purchases and paid-ad attribution. If you subscribe or buy the lifetime option, the purchase is handled by Apple In-App Purchase and managed for us through RevenueCat using an anonymous app user identifier. We never receive your Apple ID, your email, or your payment details. The app only learns whether your paid access is currently active. To understand whether our own Meta and TikTok ads lead to installs, onboarding steps, free trials, subscriptions, renewals, refunds, or trial cancellations, the app may use ad-network SDKs, app-scoped anonymous identifiers, device/ad identifiers where iOS allows them, and RevenueCat may send subscription lifecycle events to Meta Ads. For TikTok, the app may send app activation, anonymous funnel-step, trial-start, and subscription-start events through the TikTok App Events SDK. These events do not include your name, email, payment details, streak data, relapse history, urge logs, check-ins, quiz answers, notes, reflections, or coach messages. We do not log purchase revenue directly with ad SDKs, so Apple and RevenueCat remain the source of truth for subscription status and revenue.
Your IP address. When your device contacts our backend, Cloudflare processes your IP address transiently for security and to apply a per-IP rate limit that prevents abuse. We do not use it to identify you and we do not build a profile from it.
What we do not do
- We do not show ads inside the app.
- We do not send your streaks, slips, urge logs, check-ins, quiz answers, notes, reflections, coach messages, or generated program content to ad platforms.
- We do not collect IDFA unless you explicitly allow Apple's tracking prompt in a version that asks for it.
- We do not sell your data.
Cookies and tracking
The app uses no cookies. For paid-ad measurement, the app may use the Meta SDK, the TikTok App Events SDK, and RevenueCat attribution attributes to measure app installs, onboarding events, and subscription events from our own campaigns. Our marketing website uses only Google Fonts to display its typefaces, which may cause your browser to log a font request to Google when the page loads. The website has no analytics, advertising, or tracking cookies.
The third parties we rely on
To run the features above we use a small number of processors, each acting on our instructions for the limited purposes described:
- Apple distributes the app, processes all purchases through In-App Purchase, provides the App Attest service used to confirm that AI requests come from a genuine device without identifying you, and, when you have allowed notifications, delivers the "your plan is ready" and "your coach replied" notifications through its Apple Push Notification service using a pseudonymous device-routing token.
- RevenueCat verifies and manages purchase status using a pseudonymous app user identifier and may forward subscription lifecycle events to Meta Ads when our Meta Ads integration is enabled.
- Meta may receive app activation and subscription lifecycle events for our paid-ad measurement. We do not send Meta your sensitive in-app content, notes, answers, chat messages, urge logs, relapse history, or payment details.
- TikTok may receive app activation, anonymous funnel-step, trial-start, and subscription-start events for our paid-ad measurement. We do not send TikTok your sensitive in-app content, notes, answers, chat messages, urge logs, relapse history, payment details, or subscription revenue.
- Cloudflare hosts our static pages and backend Worker, carries Program jobs temporarily through Cloudflare Queue, stores finished Program results briefly in D1, processes IP addresses for security and rate limiting, and may provide Cloudflare Workers AI as a fallback processor for the coach, progress insights, or optional Panic line.
- OpenCode Zen, which runs DeepSeek, processes AI content for the personalized Program and is the primary AI processor for the coach.
We use these processors only to operate the feature you request. We do not use AI request content for advertising and do not create a durable Reforgr recovery profile from it. The temporary Queue and D1 handling used for Program generation is described above and in the retention section below.
Legal bases under the GDPR
Where the GDPR applies, we rely on the following legal bases:
- Consent (Article 6(1)(a)) for joining the pseudonymous leaderboard, using the optional AI features, receiving notifications, including use of the Apple push token to tell you a plan is ready, and, where required by law or platform rules, advertising attribution. To the extent text you choose to send to an AI feature reveals special-category data, such as religious beliefs, health information, or information about your sex life, we rely on your explicit consent under Article 9(2)(a). The app records the Program and context choices separately, and you can change or withdraw either one from the AI choices control in Settings or clear all Reforgr data; you can also leave the leaderboard, turn off notifications, or change device privacy settings for those separate choices. Withdrawal does not affect processing already completed at your request. For a Program job, Reforgr deletes the queued/transient record when possible; processing already started by the model provider cannot be recalled, but its result is discarded.
- Performance of a contract (Article 6(1)(b)) to provide the app and to process your purchase and entitlement status through Apple and RevenueCat.
- Legitimate interests (Article 6(1)(f)) to keep the service secure and available, to measure whether our own paid campaigns are economically sustainable, including the transient processing of your IP address for security and rate limiting, the App Attest device check that prevents automated abuse of the AI features, paid-ad attribution that does not include sensitive Reforgr content, and the automated moderation of the public bio line.
International transfers
Some of our processors and advertising-measurement providers are located in the United States (Apple, RevenueCat, Meta, TikTok, and Cloudflare); if you allowed notifications, the push token used to send your "plan ready" or "coach replied" notification is also transferred to Apple's push service in the United States. OpenCode Zen may process AI requests outside the European Economic Area. When data is processed there, the transfer is governed by appropriate safeguards under the GDPR, such as the European Commission's Standard Contractual Clauses, together with the technical measures described in this policy, in particular that sensitive Reforgr recovery content is not sent to advertising platforms and is not linked to a Reforgr account. Free text can nevertheless contain identifying or sensitive information if you choose to write it.
Data retention
The data stored on your device and in your iCloud stays until you delete it, for example by deleting the app or clearing its data. This data is under your control. Deleting the app removes the local copy from your phone. The iCloud copy is held by Apple under your Apple ID and stays under your control, so you decide when to remove it.
Your optional leaderboard entry is kept while you remain opted in and is deleted when you leave the leaderboard. Leaving the leaderboard deletes that entry.
A coach or progress-insight request is processed in the request path and is not written to our application database. A personalized-Program request is carried temporarily in Cloudflare Queue and removed after the job is successfully processed and acknowledged. Both Program queues are configured with a one-hour message-retention limit, including when delivery must be retried or the consumer is unavailable. The Apple push token for a Program job is part of that temporary Queue message and is not written to D1. The finished Program is held in D1 under a random one-time job code and may remain there after retrieval so a lost network response can be retried; client cleanup or cancellation may delete it sooner, and it is automatically deleted about one hour after the original request. Your device then stores the generated content and any later Program notes locally and, if enabled, in your private iCloud store.
The per-IP records that Cloudflare uses for the security rate limit are kept only for about one hour, then expire. We keep no durable server recovery profile of you.
Purchase records are kept by Apple and RevenueCat for as long as needed to manage your access and meet their legal obligations.
Your rights
Because we hold almost no data about you, most of your information is already under your direct control on your device, where you can view, edit, and delete it at any time. For any data that does leave the device, and to the extent the GDPR applies, you have the right to access, rectification, erasure, restriction of processing, objection, and portability, as well as the right to withdraw consent where processing is based on consent.
To exercise any of these rights, email us at support@reforgr.com. We answer requests to exercise your rights within one month, as required by the GDPR. AI requests are not keyed to a Reforgr account and their temporary job codes are not a durable user identifier, so we may be unable to locate transient data as yours after processing. For a leaderboard entry, a chosen nickname may help us locate it. You also have the right to lodge a complaint with the French data protection authority, the CNIL (Commission Nationale de l'Informatique et des Libertes), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr.
Children
Reforgr is intended for users aged 13 and over. It is not directed to children under 13, and we do not knowingly collect data from anyone under 13.
Not a medical service
Reforgr is a wellness, focus, and discipline tool. It is not a medical device, it makes no medical claims, and it does not diagnose, treat, or cure any condition. It is not a substitute for care from a qualified professional.
Changes to this policy
If this policy changes, we will update this page and the date at the top. For significant changes affecting the few things that leave your device, we will make the update clear.
Contact
Questions about your privacy or this policy? Email support@reforgr.com.