Privacy
Forge is the app a gym, box or studio runs itself on — a Quobo Labs product. The data below lives with the studio you belong to; nothing is sold, nothing feeds advertising, nobody is tracked, and nothing leaves except as described here. Last updated September 21, 2026.
What we collect
Your account. Email address and password (handled by our authentication provider, Supabase), the name you give the studio, a phone number if you add one, an optional line of bio, and the accent colour you pick.
Your training record. Class bookings, coach-confirmed attendance, results you choose to log, injuries you choose to flag — the part of the body and whatever you write beside it — and your messages with the studio and its members.
What you tell the studio on the way in. If your studio runs a welcome walk, your answers to its questions — a studio may ask about your health there, and those answers are read by its staff. Papers you sign are signed by typing your full name: we keep the name as typed, the time, whether it was in your app or at the desk, and at the desk, which staff member held the device. Coaches can keep notes behind your membership.
Photos, videos and documents. Uploaded by staff, not by members: event photos, demonstration photos and clips for the movement library, paperwork as PDFs, and files the desk attaches to your account for you to read. An owner can attach images, PDFs and text files to the Operations chat. The app never opens your camera or your photo library on its own.
Payments. What you were charged and what was settled — amounts, periods, method. Card payments run through Stripe; Forge never sees or stores a card number, only a label like “visa · 4242” if you put a card on file.
If you write to a studio before you have an account. A studio’s inquiry form keeps your name, the email or phone number you leave, and what you wrote; a text sent to a studio’s number keeps the number it came from and the message. Both go to that studio’s staff and nowhere else.
Connected services, if you connect one. Where a wearable or food diary (Oura, WHOOP, MyFitnessPal, FatSecret) is offered, connecting it stores an access key, not your readings — nothing is read until a screen needs it, and nobody at the studio sees a number from it. Disconnecting forgets the key.
Notifications. On the web, if you turn notifications on, a push subscription for that browser. If no browser is on file and the studio emails its news, your address is used for that and nothing else. The iPhone app sends no push notifications.
Apple Health
Only from the iPhone app, and only if you say yes in Apple’s own permission screen. Forge reads workout summaries — activity type, start and end, energy, average and peak heart rate — and writes nothing back to Health. Summaries only: no routes, no locations, no continuous streams.
They are visible to you alone. The database’s own rule on that table lets a row be read by the person it belongs to and by nobody else — not your coaches, not the studio’s owner, not other members. Health data is never used for advertising or marketing, never sold or shared, never sent to the AI model described below, and never stored in iCloud.
To disconnect: Profile → Your wearables → Take it off beside Apple Health. That deletes every synced summary at once. To stop the phone sharing as well, open the Health app → your picture → Apps → Forge, and turn the categories off. Deleting your account deletes the summaries too.
The AI at the desk
Some answers in Forge are written by an AI model, provided by Anthropic. It is used in four places, and what it receives is different in each.
The gym desk. When you message your studio, the desk can answer simple questions straight away. To do that it sends the model your message, the recent conversation, and the facts you could already see on your own screens: your name, your membership and credits, your bookings and the week’s schedule, your attendance and logged bests, your dues and the label of a card on file, your shop orders. It asks for your permission once, before the first time anything of yours is sent. If you decline, your message goes to the studio’s staff instead and a person answers. Questions about money, pain or injury go to a person regardless.
Injury suggestions. When you flag an injury, the model phrases the exercise swaps your coach reviews. It receives the part of the body you flagged and the names of the movements and classes involved — not your name, and not what you wrote.
The intake summary. For coaches, the model turns your welcome-walk answers and your coaches’ notes into one paragraph. Answers to health questions — conditions, medication, injuries, the cycle, digestion, allergies — are held back by the code and never sent.
The owner’s Operations chat. A studio’s owner can ask the model about their own studio. It receives what the owner types, any files the owner attaches, and the studio’s records it looks up to answer — the roster, schedule, bookings, sales and dues.
Anthropic processes this to produce the reply. We do not use your data to train AI models, and the AI never sees Apple Health data or a card number.
Who handles your data
These are the only outside services involved, each doing exactly the job named. None of them may use your data for their own advertising.
Supabase — the database, sign-in and file storage. Everything on this page is kept there, and it sends the sign-in and password emails. Always in use.
Vercel — hosts the app. Every request passes through it, and its server logs briefly hold technical details of a request — IP address, the page asked for, error lines. Always in use.
Anthropic — the AI model, as described above. It receives members’ messages and the membership facts around them, the body region of an injury, non-medical intake answers and coaches’ notes, and what an owner types or attaches.
Stripe — card payments. Used only if a card is involved: a studio’s subscription to Forge is billed on Stripe, and a studio that turns card payments on connects its own Stripe account, which is where its members’ payments go. Stripe receives your name and email, what is being paid for, and the card details you type into Stripe’s own form.
Twilio — text messages. Used only if your studio turns texting on. It receives the phone numbers on each text and the words of the message.
Resend — email. Used only where email delivery is switched on, to send you the studio’s news when no browser notification is on file. It receives your email address and the words of the notice.
Your browser’s push service — Apple, Google or Mozilla, whichever made your browser. Used only if you turn notifications on, and the notice is encrypted to your browser, so the service relays words it cannot read.
An error collector, if one is configured. Off by default. When on, a failure inside the app files a report: the error, where it happened, the studio’s id and the ids of the records involved — not names and not message contents. One report carries phone numbers: a text arriving at a number no studio claims.
What we never collect
No tracking, across apps or across sites. No advertising SDK and no analytics SDK in the app. No location, no contacts, no advertising identifiers, no data brokers, and no selling or sharing of personal data with anyone for their own purposes.
Who sees what
Your studio’s staff see what a front desk always has: who is booked, who attended, who owes what, and what you flag to them. Other members see your name and line only if you leave your profile visible — there is a switch on your profile that hides you from everyone but staff. Data is scoped to your studio; another studio on Forge sees nothing of you.
Deleting your account
You can delete your account yourself, in the app: Delete your account — it is beside Sign out on your profile, on the screen where you look for your studio, and on the screen a closed studio shows. Deletion is immediate and complete for everything that is yours — profile, memberships, bookings, logs, injuries, conversations, welcome-walk answers, signed papers and files attached to your account, connected services, synced health data, push subscriptions, and any card on file with Stripe.
What survives is the studio’s own bookkeeping, with your name struck off: attendance headcounts and settled payments remain as anonymous facts, the way a paper ledger would keep a total. No surviving record points back to you.
One exception, for the studio’s sake: the only admin of a studio that still has other people in it is asked to hand the admin seat to someone first, or to write to us so the studio and the account close together.
Or by mail: write to hello@quobo.co from the address on the account and we will delete it for you.
Questions
Ask the desk at your studio — in the app, the gym thread reaches a person. The studio whose room you belong to is the data controller for your records; Quobo Labs, LLC operates the platform they live on and processes them on the studio’s behalf. Reach us at hello@quobo.co, or through support. The terms of use are the other half of this page.
If you run a studio on Forge. The studio’s subscription is billed by card through Stripe, and its standing — paid, lapsed, cancelled — reaches us from Stripe. The iPhone app sells nothing and takes no payment for it.