Forth · Effective September 6, 2026 · Last updated September 6, 2026
This Privacy Policy explains how information is processed when you use the Forth iOS app, The Room, Forth's support and legal pages, or communicate with Forth support (together, the "Services"). Forth is operated by Nikita Borisov ("Forth", "we", "us", or "our"). It should be read together with our Terms of Use.
Recovery and sexual-wellness information can be sensitive. Washington and Nevada residents should also read the separate Washington Consumer Health Data Privacy Policy or Nevada Consumer Health Data Privacy Policy, as applicable.
Most of Forth works without a traditional account or sign-up. Web checkout collects billing contact information as described in Section 5.
Your assessment responses are used on your device to generate a plan. Once the plan is created, the raw responses are discarded and the resulting plan is stored locally.
The following information is also stored locally:
Forth does not send the content of your plan, ratings, reflections, blocker selections, custom website addresses, or browsing history to us. If product analytics is enabled, limited event details such as game mode, session duration, and placement count may be sent as described in Section 4.
Daily reminders are scheduled by your device. Forth does not operate a push notification server. If you enable the biometric lock, iOS performs the authentication and tells Forth whether it succeeded; Forth does not receive your fingerprint or Face ID data.
The Room is Forth's community feed, hosted by Supabase. When you first use it, Forth creates a community account with a random actor identifier and a generated handle. This account does not contain your name, email address, or phone number.
To operate and protect The Room, the community service stores your actor identifier, handle, account creation time, moderation status, posts and replies, blocks, reports, and related timestamps. Reports also include the selected report reason. The service keeps limited technical records used to control access and prevent a Room eligibility token from being reused.
The community database does not contain a direct field connecting your Room actor identifier to an Apple or RevenueCat customer identifier. We do not provide public profile pages, though posts are associated with the same actor identifier so that Forth can display conversations, identify your own posts, and apply blocks and moderation rules.
Posts are limited to 500 characters and replies are limited to one level. Published posts are visible to other people who have access to The Room under the generated handle shown with the post.
A generated handle is pseudonymous, but it does not guarantee anonymity. Details in a post may identify you, and the timing of a post may make a writer easier to recognize when the community is small. Avoid including names, contact details, or other information that could identify you or someone else.
Every submitted post is reviewed by an automated moderation service before it can be published. Forth sends the post text to Anthropic's commercial Claude API without the handle, actor identifier, subscription information, or post history. Forth does not use Room posts to train AI models or include them in product analytics.
Anthropic states that commercial API inputs and outputs are not used to train its models by default and are ordinarily deleted from its systems within 30 days, subject to limited safety, legal, or separately agreed exceptions. Its commercial data retention notice explains those periods and exceptions.
The submitted post is stored in Forth's community database until it expires, whether it is published, held, or rejected. Held posts and reported posts are available for manual review. An authorized reviewer may see the post text, handle, timestamps, moderation status, report details, and account moderation history when completing that review.
You can report a post and block or unblock a handle from inside the app. Reports are stored with the reporter's actor identifier and are available for manual review.
Posts leave the feed after seven days and are deleted from the active community database shortly afterward. Replies and reports linked to a deleted post are deleted with it. Other records, including the random Room account, handle, blocks, moderation history, and technical access records, may be retained for longer as described in Section 9.
Unless you turn analytics off, Forth sends a limited set of product events to PostHog. These events use a random app identifier that is not linked to your name or contact information. They help us understand whether app features work and where people leave the setup flow.
Events may record that a creator referral link was opened; an onboarding, plan-reveal, offer, purchase, or restore event occurred; the dashboard, World, gallery, or The Room was viewed; a reset or game activity occurred; a post or reply submission was attempted; the blocker changed; or a reminder was enabled. Limited fields may include a step number, offer identifier, game mode, duration, placement count, post type, restore outcome, and creator code.
Analytics does not include assessment responses, plan content, ratings, reflections, post text, handles, report or block reasons, blocker selections, custom website addresses, or browsing history. PostHog person profiles, session recording, automatic screen capture, and IP-based location lookup are disabled.
You can turn analytics off from the Privacy screen. This stops future analytics events from being sent; it does not automatically delete events already received by PostHog.
Apple processes App Store subscription payments. We do not receive your full payment card or Apple Account credentials. Forth uses RevenueCat to manage purchase status. RevenueCat receives an anonymous customer identifier, Apple receipt and purchase information, subscription status, last-use information, and basic device and operating-system details. RevenueCat does not receive your assessment responses, plan, reflections, blocker choices, or Room posts from Forth.
If you choose web checkout, RevenueCat manages your subscription and Stripe processes payment. We pass RevenueCat's app customer identifier to checkout so the purchase can unlock access in Forth. Checkout collects your billing email and the payment and billing details needed to complete the purchase. RevenueCat and Stripe process these details and transaction records to manage charges, renewals, receipts, cancellation, refunds, security, and support. We can access billing contact information, subscription status, and transaction records through their dashboards, but do not receive your full card number or security code. Your billing email is not added to product analytics or used to identify you in The Room. Forth does not send your assessment responses, plan, reflections, blocker choices, or Room posts to web checkout.
Apple's handling of your purchase is described in Apple's Privacy Policy, and RevenueCat's handling of purchase information is described in its RevenueCat Privacy Policy. Stripe's handling of web payment information is described in the Stripe Privacy Policy.
Forth's optional blocker uses Apple's Screen Time system. For apps, categories, and web domains selected through Apple's picker, Forth receives opaque tokens and counts rather than the selected names. Those tokens stay on your device. Custom website addresses are also stored locally and passed to the blocking system on your device. When you enable Forth's Safari extension, it checks the current top-level website hostname locally against your blocking rules to open a Reset for supported matches. It does not send visited hostnames to us or store browsing history.
Forth does not request access to your contacts, photos, microphone, camera, or precise location. It may request notification permission for a local daily reminder and biometric authentication permission for the optional app lock.
If you email us, we receive your email address and the information you include in your message. We use it to respond, troubleshoot, and keep a reasonable record of the support request. Please avoid sending sensitive information that is not needed to answer your question.
Forth's support and legal pages are hosted through GitHub Pages. When you visit them, GitHub receives standard technical request information such as your IP address, request time, and browser or device information to deliver and secure the pages.
We use the information described above to:
Our service providers include Supabase, which hosts The Room and its community accounts; Anthropic, which processes post text for moderation; PostHog, which processes product analytics; RevenueCat, which manages purchase status and web subscriptions; Stripe, which processes web payments; Apple, which processes App Store payments and provides device services; Google, which delivers support messages through Gmail; and GitHub, which hosts the support and legal pages. We use these providers for the purposes described in this policy. Their handling of information is also governed by their terms, privacy commitments, and applicable law.
When Forth connects to an online service, the provider also receives technical connection information such as an IP address, request time, and app, browser, device, or operating-system information. Providers may create authentication, security, and diagnostic logs to deliver, protect, and troubleshoot their services. Forth does not collect precise location, and PostHog's IP-based location lookup is disabled.
We do not sell personal information, use it for targeted advertising across unrelated apps or websites, or provide it to data brokers. We may disclose limited information if reasonably necessary to comply with law, protect the rights or safety of users and others, investigate misuse, or complete a business transfer. Where required, we will provide notice of a material change in who controls the information.
Local information remains on your device until it is changed or removed. The Privacy screen includes a control for erasing certain local recovery records. That control does not cancel your subscription, delete Room records, or reset every iOS-managed setting or credential. Some security credentials are stored through the iOS Keychain and may remain after an app uninstall under Apple's device-storage behavior.
Room posts leave the feed after seven days and are deleted from the active community database shortly afterward. Reports linked to those posts are deleted with them. Pseudonymous account records, handles, blocks, moderation history, and technical access records may be kept while needed to operate and protect The Room, meet legal obligations, or resolve disputes.
Analytics, purchase, moderation-provider, and support records are retained according to the purpose for which they were collected and the applicable provider settings or legal requirements. Deleted information may remain in service-provider backups subject to their retention practices and legal requirements.
Depending on where you live, you may have rights to access, correct, delete, or restrict the use of personal information, or to object to certain processing. To make a request, email us at the address below. Because Forth does not collect your name or email as an app account, we may need information from your device to verify that a Room record belongs to you. We may retain information when required by law or when a legal exception applies.
The separate Washington and Nevada consumer health data policies explain additional rights and request and appeal procedures for residents covered by those laws.
We use reasonable technical and organizational safeguards designed to protect information processed for Forth. No storage or transmission system is completely secure. Our service providers may process information in the United States and other countries, which may have different data-protection laws from where you live.
Forth is intended for people age 16 and older and is not directed to children under 13. If we learn that we collected online personal information from a child under 13, we will delete it and take any other steps required by applicable children's privacy law.
We may update this Privacy Policy as Forth changes. We will update the date at the top of this page and provide additional notice or obtain fresh consent when required by law.
Questions or privacy requests: nikitaborisov724@gmail.com