This policy explains how Forma handles personal data in the web app, trainer workspace, notifications, and Apple Watch connection.
1. Who is responsible
The controller for Forma accounts, platform operation, subscriptions, security, and support is Kamil Dike Software, Robotnicza 3, 97-310 Wola Moszczenicka, Poland, NIP 7712920344.
2. Data we process
- Account data: Firebase UID, email address, display name, profile photo, sign-in provider, language, and app preferences.
- Training data: routines, exercises, notes, schedules, reminders, activity, completion history, and feedback.
- Trainer data: trainer profile, business name, coaching focus, invitations, client relationships, assignments, and adherence information.
- Device data: push-notification endpoint and keys, browser/device details, Watch pairing identifiers, token hashes, and last-seen timestamps.
- Billing data: Stripe customer and subscription identifiers, plan, price, currency, billing period, payment status, and invoice-related events. Forma does not store full card numbers or CVC codes.
- AI routine data: the routine request is sent to Google Vertex AI for generation but is not stored by Forma. Forma stores the normalized draft, validation issues, quota timestamps, credit ledger entries, and generation identifiers needed to deliver and secure the feature.
- Performance data: page-loading and interaction timings, network response duration and payload size, browser, country inferred from the IP address, connection type, page path, service-worker status, and Firebase installation identifier. Entry pages whose path contains an invite, Watch pairing, client, or routine identifier are excluded from performance monitoring.
- Support and security data: messages sent to support, operational logs, errors, event identifiers, and information needed to investigate abuse or service failures.
3. Where data comes from
We receive data from you, your selected sign-in provider, your device, Stripe, and—when you use trainer features—from the trainer or client connected to your account.
4. Why we use data
- To create and operate your account, save routines and activity, connect devices, deliver requested notifications, and provide trainer/client features. The legal basis is performance of the service contract or steps requested before entering it.
- To process subscriptions, payments, refunds, and access rights. The legal bases are performance of the contract and compliance with tax and accounting obligations.
- To search for suitable routines and generate a requested routine draft. The legal basis is performance of the service contract. AI output is validated and requires your confirmation before it becomes a routine.
- To secure Forma, prevent fraud, diagnose failures, answer support requests, and establish or defend legal claims. The legal basis is our legitimate interest in operating and protecting the service.
- To measure loading, responsiveness, and network reliability across countries, browsers, and connection types so we can find and correct performance problems. The legal basis is our legitimate interest in maintaining a reliable service.
- Where processing depends on consent or device permission, such as enabling browser notifications, you can withdraw it through the relevant app or device settings.
5. Trainers and clients
Kamil Dike Software is responsible for Forma accounts and platform operation. A trainer may separately decide why and how client information is used for coaching and may therefore act as a separate controller for that coaching activity. Trainers are responsible for giving clients any additional privacy information required for their own services.
Trainer and client accounts can see data needed for their active relationship, including assigned routines, schedules, completion status, and feedback. Archiving a relationship limits product access but does not itself delete its history.
6. Service providers and recipients
Providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, standard contractual clauses, or another lawful safeguard used by the provider.
- Google Firebase and Google Cloud provide authentication, database, hosting, functions, performance monitoring, logging, and infrastructure. Firebase Performance Monitoring receives technical timing and connection data but is not given names, email addresses, client content, or custom user identifiers. Google provides optional account sign-in when you choose that sign-in method.
- Google Cloud Vertex AI processes routine requests in the EU multi-region to produce structured exercise drafts. Forma does not enable model request/response logging, Search grounding, or explicit context caching for this feature.
- Stripe provides Checkout, subscriptions, payment processing, invoices, and the billing portal.
- Browser push providers deliver encrypted notifications when notifications are enabled.
- Google/Gmail processes support email. YouTube or another external video provider receives normal connection data only when its thumbnail or link is loaded or opened.
- Sentry (Functional Software, Inc.) provides application error monitoring. It receives diagnostic data about crashes—error messages, stack traces, and technical context such as browser and page—while workout and client content is excluded and identifiers such as email addresses are removed before an event is sent.
- A connected trainer or client receives the relationship and training information described above.
7. How long we keep data
- Core account, routine, activity, reminder, device, and coaching data is generally kept while the account remains active.
- AI routine prompts are not stored by Forma. Normalized, unconfirmed drafts are scheduled for deletion after 24 hours. Quota and credit records remain while needed to provide the balance, prevent abuse, handle refunds, and meet legal obligations.
- Deleting the account removes application data linked to it, revokes device records, cancels active subscriptions, removes operational Stripe mappings, and deletes Firebase Authentication.
- Billing, tax, fraud-prevention, dispute, and security records may be retained only for the period required by law or needed for a documented legal claim.
- Archived trainer relationships remain part of account history until relevant account deletion or later cleanup.
- Expired invitations, pairing sessions, notification-delivery history, resolved billing incidents, support messages, and technical logs may remain until routine cleanup or until they are no longer needed for their operational or legal purpose.
- Firebase Performance Monitoring keeps IP-associated performance events for 30 days and installation-associated and de-identified performance data for 60 days before beginning removal from live and backup systems.
8. Your rights and choices
Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing.
You can delete your Forma account from Settings. For another privacy request, contact us by email. We may ask for information needed to verify your identity. You may also complain to the President of the Personal Data Protection Office (UODO) in Poland.
9. Health and sensitive information
Forma is a training tool, not a medical-record or diagnostic service. Routine names, recovery notes, activity, and trainer feedback can still reveal health context. Do not enter diagnoses or other sensitive health information that is not necessary for ordinary training. Trainers must ensure they have an appropriate legal basis before entering client information.
10. Local storage and tracking
Forma uses browser storage, service-worker caches, and similar essential technology for sign-in, language, preferences, installation, offline behavior, and app reliability. Operational performance monitoring is used for reliability, not advertising or behavioral profiling. We currently do not use advertising trackers or analytics cookies.
11. Security
We use access rules, authenticated server functions, restricted secrets, hashed Watch tokens, signed Stripe webhooks, and provider security controls. No online service can guarantee absolute security.
12. Changes and contact
We may update this policy when Forma, its providers, or legal requirements change. The effective date above identifies the current version. Material changes will be communicated in an appropriate way.