Privacy Policy
Last updated: 8 August 2026. FORM is a free, privacy-first side project for workout logging and training decision support. This policy describes what the software stores, why it is used, what can be public, and how you can remove it.
1. Data FORM may store locally
When you use FORM in local mode, information is stored in your browser using local storage. This can include:
- training profile choices such as goal, experience level, days per week, equipment and session duration;
- workout plans, exercise selections, sets, repetitions, weight, RIR, rest settings, notes and workout history;
- personal records and derived analytics such as estimated 1RM, adherence, weekly workload and session-efficiency statistics;
- optional bodyweight, optional body-fat entries and circumference measurements;
- optional FORM Decision Engine inputs such as self-reported sleep quality, energy, stress, soreness, motivation, joint-discomfort signal and time available;
- decision preferences such as muscle priorities, preferred or avoided exercises and broad movement constraints;
- local decision history, substitutions and temporary Session Rescue backups.
Local-mode data does not leave your browser merely because you use the app.
2. Optional cloud sync
If a FORM backend is configured and you use cloud features, FORM may create an anonymous authentication identity. You can optionally add an email address only if you want recoverable magic-link access across devices. Cloud sync may store the same functional records described above, including workouts, measurements, readiness check-ins and decision preferences.
The purpose of cloud storage is to provide synchronization, account recovery, the optional Club leaderboard and deletion/export functionality. FORM is not designed to use this data for advertising, sale, unrelated profiling or marketing analytics.
3. FORM Club
Club publication is opt-in. When you enable a public Club profile and publish activity, only a deliberately reduced leaderboard projection is intended to be public: display name, activity date, daily score, completed-set count, manually entered steps, manually entered active minutes, streak and aggregate workout volume.
Exact bodyweight, circumference measurements, workout notes, individual sets, readiness answers, exercise preferences, constraints and email address are not intended to be placed in the public leaderboard. Turning the public Club option off is designed to remove the user's public leaderboard rows.
4. Decision Engine calculations
FORM's readiness signal, training-stress ledger, goal-alignment bands, plateau diagnosis, Session Rescue, substitution ranking and other recommendations are calculations for app functionality. They are not medical diagnoses, injury assessments, biological recovery measurements or guarantees of training outcomes. Some calculations may be performed entirely in your browser even when cloud sync is available.
5. What FORM does not intentionally collect
FORM does not require GPS location, contact lists, call logs, microphone access, camera access, wearable data, Apple Health, Health Connect, sleep-device feeds, browsing history outside FORM, advertising identifiers or third-party ad tracking.
6. External services and links
FORM can link to external websites such as YouTube search results and GitHub. Opening an external service subjects you to that service's own privacy practices. FORM does not control those services. If Supabase is configured for cloud functionality, data sent to that backend is also processed by the infrastructure provider according to the deployment configuration and applicable provider terms.
7. Retention and deletion
Local data remains until you clear it, use FORM's local deletion control, clear browser storage, or remove the site data. If cloud sync is active, FORM provides an account-deletion flow intended to remove the authentication identity and app data that cascades from it. You can also export your available FORM data before deletion.
8. Security
The supplied backend design uses row-level security for private training tables, owner-scoped access rules and a reduced public Club projection. Browser code must never contain a Supabase service-role or other server secret. No internet service can be promised to be perfectly secure; do not store information in FORM that you do not want associated with your account or device.
9. Children
FORM is intended for adults. It is not designed as a service for children, and the onboarding flow states that adult-use expectation.
10. Your choices
You can use local-only mode, choose whether to provide optional body/readiness data, opt in or out of Club publication, export your information, delete local data, and—when cloud sync is configured—delete the cloud account. Mandatory privacy rights under applicable law are not waived by this policy.
11. Changes
If FORM's data practices materially change, this policy should be updated before or alongside the functionality. Because FORM is an open-source side project, users should also inspect the current source and deployment configuration when privacy is important to them.
12. Contact
For questions about the project, use the repository associated with FORM or the contact method published by the project owner. Do not send highly sensitive medical information in a support request.