Nevada Consumer Health Data Privacy Policy
Forth · Effective September 6, 2026 · Last updated September 6, 2026
1. Scope
This policy applies to Nevada consumers and explains how
Nikita Borisov, operating Forth ("Forth", "we", "us", or
"our") collects, uses, processes, and shares consumer health data under
Nevada law. Forth processes information related to behavioral and sexual
wellness. Nevada law can treat that information and information derived from
it as consumer health data when it is linked or reasonably capable of being
linked to a consumer.
2. Categories collected, purposes, and manner of use
- On-device recovery and sexual-wellness information: assessment responses; the plan derived from them; reset and setback history; urge or intensity ratings; reflections; progress, world discoveries, and saved artwork; blocker configuration, Screen Time selections and counts, and custom blocked domains; and reminder and privacy preferences. Forth processes these locally to personalize the plan, provide exercises and progress features, operate the blocker, schedule reminders, and apply privacy settings. Raw assessment responses are discarded after the plan is generated, and Forth does not send the content of these records to its servers. A creator attribution code may also be captured from a direct Forth referral link and stored locally to remember the referral source. When analytics is enabled, the code is used to measure that referral as described below.
- Room and moderation information: posts and replies; reports, blocks, and report reasons; moderation decisions and status; strikes, restrictions, and crisis flags; and related timestamps. Forth processes these to publish and thread eligible content, apply blocks, moderate and review content, show crisis resources, enforce the Terms of Use, and protect The Room.
- Pseudonymous identifiers and technical information: a Supabase authentication user identifier and an actor identifier, generated handle, authentication and session events, a per-install Room eligibility identifier, a blinded Room eligibility-token request, a redeemed Room eligibility-token hash, an eligibility-source identifier hash, request time and status, IP address, user agent, app or client version, and device or operating-system information. This may also include a random analytics identifier when analytics is enabled. Forth processes these to authenticate Room access, deliver and secure online features, enforce rate limits, prevent abuse and token reuse, and troubleshoot reliability.
- Product analytics: unless you turn analytics off, events showing that a creator referral link was opened; an onboarding, plan-reveal, offer, purchase, or restore event occurred; the dashboard, World, gallery, or The Room was viewed; a reset or game activity occurred; a Room submission was attempted; the blocker changed; or a reminder was enabled. Limited fields may include a step or offer identifier, post type, game mode, duration, placement count, restore outcome, and creator code. Forth uses these to measure and improve the product. They do not include assessment responses, plan or reflection content, Room text or handles, report reasons, blocker selections, custom domains, or browsing history.
- Purchase and subscription information: an anonymous RevenueCat customer identifier, Apple receipt and purchase information, transaction and product or offer information, subscription and entitlement status, restore outcome, last-use information, and basic app or device information. Forth processes these to complete and restore purchases and manage paid app access.
- Support information: the email address, message, attachments, and metadata you choose to send. Forth processes these to respond, troubleshoot, handle privacy requests, and keep a reasonable support record.
- Derived information: the plan derived on your device from assessment responses and moderation decisions derived from submitted Room text. Forth uses these to provide the requested plan and moderate The Room.
When you choose web checkout, purchase information also includes your billing email and the billing and payment details processed by RevenueCat and Stripe. These providers process that information for payments, renewals, receipts, cancellation, refunds, and support. Your billing email is not added to product analytics or used to identify you in The Room.
3. Categories of sources
- You, through answers, feature settings, Room activity, purchases, direct Forth referral links, and support requests
- Your device, app interactions, and technical connection to Forth's online services
- Apple, RevenueCat, and Stripe, for purchase and subscription information
- Forth's systems and service providers, which generate identifiers, handles, plans, moderation decisions, analytics records, and technical logs
- Other Room participants, when they reply to, report, or block content involving you
4. Categories shared and recipients
Forth shares the following categories for the purposes described above:
- Supabase: Room authentication, identifiers and handles, eligibility identifiers, blinded token requests and token hashes, content, reports, blocks, moderation and access records, and technical connection information
- Anthropic: submitted Room post or reply text for automated moderation, without the Room handle, actor identifier, subscription information, or post history
- PostHog: the random analytics identifier, approved product events and fields, creator code when present, and technical connection information when analytics is enabled
- Apple and RevenueCat: purchase, receipt, subscription, entitlement, restore, and related technical information
- RevenueCat and Stripe for web checkout: billing email, required billing and payment details, transaction records, and related technical information for payments, renewals, receipts, cancellation, refunds, and support
- Google: support email, attachments, and message metadata sent through Gmail
- GitHub: technical request information when it hosts Forth's support and legal pages
- Other Room participants: published post or reply text, generated handle, and post time
- Authorized human reviewers: held or reported content, handle, timestamps, moderation and report details, and relevant moderation history
- Legal, safety, or transaction recipients: limited information where permitted or required to comply with law, protect users or others, investigate misuse, or complete a business transfer in which the recipient assumes the applicable obligations
Forth currently has no affiliates with which it shares consumer health data.
It does not share the content of on-device recovery records with remote
service providers and does not sell consumer health data.
5. How consumer health data is processed
Forth's app and Apple's device services process on-device information locally.
Online information is transmitted to and processed by the recipients listed
in Section 4 for the stated purposes. Access is limited to the people and
providers reasonably necessary to operate the requested feature, provide
support, protect the service, or comply with law.
6. Requests, review, correction, and appeals
Nevada consumers may ask Forth to:
- Confirm whether Forth collects, shares, or sells their consumer health data
- Provide a list of third parties with which the data was shared or to which it was sold
- Stop future collection, sharing, or sale
- Delete their consumer health data
Submit a request by emailing
nikitaborisov724@gmail.com
with the subject "Nevada Consumer Health Data Request." Do not include
assessment responses, reflections, or other sensitive content in the email.
Because Forth does not use a name or email login, we may ask you to verify the
request through the existing Room session or another one-time method linked to
the device or record. You do not need to create a new account.
Forth does not currently offer a separate correction process. You may request
review of an apparent error through the same email channel, or request that
Forth stop processing or delete covered information.
We will respond without undue delay and within 45 days after authenticating
the request. When reasonably necessary, we may extend once by another 45 days
and will explain the extension during the first period. Requests are free at
least twice per year and for additional requests that are not manifestly
unfounded, excessive, or repetitive. Where permitted, we may charge a
reasonable fee for an additional manifestly unfounded, excessive, or
repetitive request.
For a verified deletion request, Forth will delete covered data from active
systems and notify relevant third parties. Active-system deletion will occur
within 30 days after authentication unless Nevada law permits an exception.
Deletion from archived or backup systems may be delayed only as Nevada law
permits and for no longer than two years after authentication.
To appeal a refusal, reply to the decision with the subject "Nevada Privacy
Appeal." We will respond to the appeal in writing within 45 days. If the
appeal is denied, we will provide contact information for the
Nevada Attorney General.
Forth will not unlawfully discriminate against you for exercising these
rights.
7. Material changes
Forth will post material changes with a new effective date and, where the app
is available, provide a conspicuous notice in the app's Privacy screen before
the change takes effect. Before collecting, using, or sharing a new category
of consumer health data, sharing it with a new category of recipient, or using
it for a new purpose not disclosed here, Forth will update this policy and
obtain affirmative, voluntary consent where Nevada law requires it.
8. Collection over time and across services
Google and GitHub may process account or technical information over time
across their services under their own privacy policies when you use Gmail for
support or visit Forth's hosted support and legal pages. Forth does not send
them on-device recovery records or Room content. Forth does not enable
advertising or cross-app or cross-website tracking through PostHog or another
analytics provider.
9. Contact
Questions about this policy:
nikitaborisov724@gmail.com