REFORGR

Privacy Policy

Last updated July 16, 2026

Reforgr is built privacy first around the data that matters most: your recovery history. Core app use does not require an account, name, email address, or phone number. You may separately choose a public leaderboard nickname or give us a reply-to email when contacting support. This policy explains what stays on your device, what leaves it when you request a connected feature, who processes it, and the rights you have.

Who we are

Reforgr is a focus and self-discipline wellness app for iPhone. The data controller is Nomis IT, a French single-member limited liability company (societe a responsabilite limitee a associe unique) with share capital of 1,000 EUR, registered with the Trade and Companies Register (RCS) of Lille Metropole under number 921 726 170 (SIREN 921 726 170). Its registered office is at 2 ter rue d'Anchin, 59242 Templeuve-en-Pevele, France. The legal representative (gerant) and director of publication is Simon Brienne. You can reach us at support@reforgr.com.

The app is distributed through the Apple App Store (Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA). Our backend and static pages are hosted by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.

Our privacy-first model

Your primary recovery record is stored on your device and, if your device has it enabled, in your own private iCloud Key-Value Store: your streak, relapse history, completed program days, program notes and written reflections, answers to in-app questions, daily check-ins, urge logs, and conversation history with the in-app coach. That iCloud copy is controlled by Apple under your Apple ID and syncs only across your own devices signed in to that Apple ID. We do not maintain a Reforgr account or a durable server recovery profile containing this history. When you explicitly choose an AI feature, the relevant parts of this device-first record can be sent for processing as described below. In particular, program notes remain intentionally available to the coach, progress insights, and a later personalized cycle so those features can build on your own words. A personalized-program request transits temporarily through a Cloudflare Queue, and its finished result is held briefly in Cloudflare D1 until your device retrieves it or the automatic purge runs. Reforgr does not ask you to take or upload a photo, image, screenshot, video, audio recording, or file for the Program, and none is sent as part of it.

We want to be honest rather than overclaim: it is not true that nothing ever leaves your phone. A small, deliberate set of data does leave the device for specific features, described next. Everything outside that set stays local.

Exactly what leaves your device

The optional pseudonymous leaderboard. Only if you choose to join it. When you opt in, the app stores a randomly generated identifier, a nickname you pick, your streak numbers, your in-app rank level, the catalog identifier of the cosmetic relic you equip (if any), and an optional short public bio line in our Cloudflare database. The feature does not require your real name or contact details; do not put identifying details in the nickname or bio if you do not want them to be public. The relic is selected from Reforgr's fixed catalog and is not user-authored text. The bio line is checked automatically to remove links, contact handles, and offensive words. You can leave the leaderboard at any time, which deletes that entry.

The AI features. Reforgr offers an optional AI-personalized 30-day Program, a supportive coach chat, short progress insights, and an optional personalized line in Panic. After a premium purchase or when AI is first configured, one setup screen explains the data categories, purposes, and processors and presents two independent choices: (1) AI generation for the current Program and later cycles; and (2) recovery-context access shared by Coach, Insights, and the optional Panic line. You may allow both, choose either purpose separately, or keep both off. If Program AI is off, Reforgr installs a useful built-in 30-day path selected and run on your device without a Program-generation request. Coach and Progress then follow the saved choice without repeating consent prompts. Panic remains immediately usable with local tools and only requests its optional personalized line when the context purpose is already allowed; it never interrupts an urgent moment with a consent screen. You can change or withdraw either AI choice later in Settings without deleting your local notes, history, charts, or an already-delivered plan. For Program generation, the request can include allowlisted quiz option codes, your free-text reason for quitting, coarse progress signals (such as streak numbers, urge and check-in statistics, and panic-button usage), earlier day titles, your Program notes and reflections, and short excerpts from recent coach messages. The Program-generation request does not include your leaderboard alias. For the coach, the request includes your messages, relevant recovery context, recent Program notes and reflections, and a small on-device memory summary so the agent can answer with continuity. When context access is on, opening Your Progress may automatically request a fresh insight when one is due; the optional Panic line may also be requested when Panic is opened online. Progress insights and the optional Panic line use relevant recovery context and recent reflections. These requests are not attached to a Reforgr account or email address. However, free-text fields can contain anything you choose to type, including identifying or sensitive details, so avoid including details you do not want an AI processor to receive. Our Cloudflare Worker sends the AI content to OpenCode Zen, which runs the DeepSeek model used for the personalized Program and as the primary model for the coach; Cloudflare Workers AI may handle a coach, insight, or Panic-line request as a fallback. Program requests temporarily transit through Cloudflare Queue while the job is delivered and processed. The finished plan is stored in a transient Cloudflare D1 row under a random one-time job code and remains retrievable if a network response is lost; client cleanup may delete it sooner, and it is automatically purged about one hour after the request. Turning off Program AI asks the Worker to delete a queued job so it will be skipped; if provider processing has already started it cannot be recalled, but Reforgr discards the result. Coach replies and progress insights return directly and are not written to the Program-results database. If you have allowed notifications, a Program or coach request may also include your Apple push token. For a Program job, that token travels only with the temporary Queue message and is not written to D1; it is used to deliver a generic "your plan is ready" alert. A coach notification is also generic, and the reply itself is not included in the notification. No AI feature sends photos, images, screenshots, videos, audio recordings, or files because Reforgr does not request or accept them in these flows.

Device check (App Attest). To stop automated abuse of the AI features without making you create an account, the app uses Apple's App Attest. Your device's Secure Enclave generates an anonymous cryptographic key that proves a request comes from a genuine, unmodified copy of Reforgr on a real Apple device. The first time you use the AI features, the app sends this anonymous attestation to our backend, which verifies it (a step that involves Apple's App Attest service); after that, each AI request carries a short anonymous token derived from it. This key is specific to your installation, contains no name, email, or other personal information, is not an account, and is never used to identify or track you.

In-app feedback and bug reports. If you choose to send feedback or report a bug from Settings, the app sends your message, basic device information (for bug reports), an optional reply-to email if you decide to give one, and, only if you switch it on, an optional diagnostics attachment (a short technical log of app opens and network calls, with no content of your notes or chats). This is delivered to us as an email and handled like any support email; it is not stored in our database and is not linked to the anonymous identifiers above.

Purchases and paid-ad attribution. If you subscribe or buy the lifetime option, the purchase is handled by Apple In-App Purchase and managed for us through RevenueCat using an anonymous app user identifier. We never receive your Apple ID, your email, or your payment details. The app only learns whether your paid access is currently active. To understand whether our own Meta and TikTok ads lead to installs, onboarding steps, free trials, subscriptions, renewals, refunds, or trial cancellations, the app may use ad-network SDKs, app-scoped anonymous identifiers, device/ad identifiers where iOS allows them, and RevenueCat may send subscription lifecycle events to Meta Ads. For TikTok, the app may send app activation, anonymous funnel-step, trial-start, and subscription-start events through the TikTok App Events SDK. These events do not include your name, email, payment details, streak data, relapse history, urge logs, check-ins, quiz answers, notes, reflections, or coach messages. We do not log purchase revenue directly with ad SDKs, so Apple and RevenueCat remain the source of truth for subscription status and revenue.

Your IP address. When your device contacts our backend, Cloudflare processes your IP address transiently for security and to apply a per-IP rate limit that prevents abuse. We do not use it to identify you and we do not build a profile from it.

What we do not do

Cookies and tracking

The app uses no cookies. For paid-ad measurement, the app may use the Meta SDK, the TikTok App Events SDK, and RevenueCat attribution attributes to measure app installs, onboarding events, and subscription events from our own campaigns. Our marketing website uses only Google Fonts to display its typefaces, which may cause your browser to log a font request to Google when the page loads. The website has no analytics, advertising, or tracking cookies.

The third parties we rely on

To run the features above we use a small number of processors, each acting on our instructions for the limited purposes described:

We use these processors only to operate the feature you request. We do not use AI request content for advertising and do not create a durable Reforgr recovery profile from it. The temporary Queue and D1 handling used for Program generation is described above and in the retention section below.

Legal bases under the GDPR

Where the GDPR applies, we rely on the following legal bases:

International transfers

Some of our processors and advertising-measurement providers are located in the United States (Apple, RevenueCat, Meta, TikTok, and Cloudflare); if you allowed notifications, the push token used to send your "plan ready" or "coach replied" notification is also transferred to Apple's push service in the United States. OpenCode Zen may process AI requests outside the European Economic Area. When data is processed there, the transfer is governed by appropriate safeguards under the GDPR, such as the European Commission's Standard Contractual Clauses, together with the technical measures described in this policy, in particular that sensitive Reforgr recovery content is not sent to advertising platforms and is not linked to a Reforgr account. Free text can nevertheless contain identifying or sensitive information if you choose to write it.

Data retention

The data stored on your device and in your iCloud stays until you delete it, for example by deleting the app or clearing its data. This data is under your control. Deleting the app removes the local copy from your phone. The iCloud copy is held by Apple under your Apple ID and stays under your control, so you decide when to remove it.

Your optional leaderboard entry is kept while you remain opted in and is deleted when you leave the leaderboard. Leaving the leaderboard deletes that entry.

A coach or progress-insight request is processed in the request path and is not written to our application database. A personalized-Program request is carried temporarily in Cloudflare Queue and removed after the job is successfully processed and acknowledged. Both Program queues are configured with a one-hour message-retention limit, including when delivery must be retried or the consumer is unavailable. The Apple push token for a Program job is part of that temporary Queue message and is not written to D1. The finished Program is held in D1 under a random one-time job code and may remain there after retrieval so a lost network response can be retried; client cleanup or cancellation may delete it sooner, and it is automatically deleted about one hour after the original request. Your device then stores the generated content and any later Program notes locally and, if enabled, in your private iCloud store.

The per-IP records that Cloudflare uses for the security rate limit are kept only for about one hour, then expire. We keep no durable server recovery profile of you.

Purchase records are kept by Apple and RevenueCat for as long as needed to manage your access and meet their legal obligations.

Your rights

Because we hold almost no data about you, most of your information is already under your direct control on your device, where you can view, edit, and delete it at any time. For any data that does leave the device, and to the extent the GDPR applies, you have the right to access, rectification, erasure, restriction of processing, objection, and portability, as well as the right to withdraw consent where processing is based on consent.

To exercise any of these rights, email us at support@reforgr.com. We answer requests to exercise your rights within one month, as required by the GDPR. AI requests are not keyed to a Reforgr account and their temporary job codes are not a durable user identifier, so we may be unable to locate transient data as yours after processing. For a leaderboard entry, a chosen nickname may help us locate it. You also have the right to lodge a complaint with the French data protection authority, the CNIL (Commission Nationale de l'Informatique et des Libertes), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr.

Children

Reforgr is intended for users aged 13 and over. It is not directed to children under 13, and we do not knowingly collect data from anyone under 13.

Not a medical service

Reforgr is a wellness, focus, and discipline tool. It is not a medical device, it makes no medical claims, and it does not diagnose, treat, or cure any condition. It is not a substitute for care from a qualified professional.

Changes to this policy

If this policy changes, we will update this page and the date at the top. For significant changes affecting the few things that leave your device, we will make the update clear.

Contact

Questions about your privacy or this policy? Email support@reforgr.com.

Reforgr · Privacy · Terms of Use · Terms of Sale · Legal Notice