Skip to content
Privacy overview

Privacy Policy — ForgeFit

App: ForgeFit - Training & Diet · Last updated: 30 July 2026

This privacy policy explains how personal data is processed in the Android app ForgeFit - Training & Diet (the “App”).

1. Controller

Jonas Berenshausen
c/o Stahlbau Berenshausen
Untere Aue 14
37318 Uder OT Schönau
Email: contact@twentythreeforge.com

2. Principle: local processing

ForgeFit is designed as a privacy-friendly offline app. The content you enter — e.g. meals, logged sets, body weight, training and nutrition plans — is stored exclusively locally on your device in an app-internal database. There is no user account, and this data is neither collected by us nor transmitted to a server.

3. No collection by the studio

Through your use of the App, we (the controller) receive no personal data. There is no tracking, no analytics and no sharing with ad networks.

4. Permissions

The App only requests a permission once you use the corresponding feature. If you decline, only that feature is limited.

  • Camera — only for scanning barcodes for the food search. Barcode recognition runs entirely on your device (Google ML Kit, on-device). No images are stored or transmitted.
  • Microphone — exclusively for the optional hands-free session, where you can advance your workout by voice command (“next”, “skip”). Details and an important note in section 5.
  • Notifications (Android 13+) — only if you enable training or nutrition reminders.
  • Vibration — for haptic feedback, e.g. at the end of the rest timer.
  • Physical activity (activity recognition) — to read steps and distance from your device’s motion sensor when you use the activity display. Processing is local.
  • Health Connect (steps, distance) — as an alternative to the device sensor, you can let the App read step and distance data from Health Connect. Only steps and distance covered are read; the App does not write any data back to Health Connect. The data is processed locally and not transmitted to us. You can revoke this access in Health Connect at any time.
  • Internet — for the product lookup (see section 5). Apart from that, the App works fully offline.

5. External services and system features

For individual features the App uses external or system-side services. For technical reasons, your IP address may be transmitted to the respective provider.

  • Open Food Facts — when searching for foods or querying a barcode, a request is sent to the open product database Open Food Facts (world.openfoodfacts.org or search.openfoodfacts.org) to retrieve product and nutrition data. Only the search term or barcode number and technically necessary connection data are transmitted. No information about you, your account or your stored data is transmitted. Privacy information: https://world.openfoodfacts.org/privacy.

  • Speech recognition in the hands-free session — for voice control the App uses your Android system’s speech recognition (SpeechRecognizer). Important: depending on your device and settings, recognition may not run locally but through your device vendor’s service (usually Google). In that case the recorded speech data is transmitted to that provider and processed under its privacy terms. We ourselves receive neither audio recordings nor transcripts; the App only evaluates whether one of the known commands was recognised. The microphone is active only during an actively started hands-free session. If you want to avoid this, do not use the hands-free session, or enable on-device offline speech recognition in your Android settings if your device supports it.

  • Speech output (text-to-speech) — announcements in the hands-free session are produced by your Android system’s speech output. Only the texts to be read out (e.g. exercise names) are passed to the system’s speech engine.

5a. No tracking, no advertising

The App contains no analytics, tracking, advertising or crash-reporting SDKs (e.g. no Firebase/Crashlytics, no Google Analytics, no ad networks). No cross-device profiling takes place.

6. No sharing with third parties

Beyond the functionally necessary calls named in section 5, no data is shared with third parties.

7. Retention & deletion

Your data remains local until you delete it in the App or uninstall the App. When uninstalling, the locally stored app data is removed by the operating system. For details on deletion, see “Data Deletion”.

8. Your rights

Under the GDPR you have the rights to access, rectification, erasure, restriction of processing, data portability and objection. Since we do not store any personal data about you, these rights generally only concern the data stored locally on your device, which you manage yourself. For requests: contact@twentythreeforge.com.

You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the Thuringian Commissioner for Data Protection and Freedom of Information (TLfDI), Häßlerstraße 8, 99096 Erfurt, Germany, https://www.tlfdi.de.

9. Changes to this policy

We adjust this privacy policy when the App or the legal situation changes. The version published here at the time applies.