Washington Consumer Health Data Privacy Policy

Forth · Effective September 6, 2026 · Last updated September 6, 2026

1. Scope

This policy applies to Washington consumers and explains how Nikita Borisov, operating Forth ("Forth", "we", "us", or "our") collects, uses, and shares "consumer health data" under the Washington My Health My Data Act. Forth processes information related to behavioral and sexual wellness. The Act can treat that information and information derived from it as consumer health data when it is linked or reasonably linkable to a consumer.

2. Categories of consumer health data collected and how they are used

2.1 On-device recovery and sexual-wellness information

This category includes assessment responses; the plan derived from those responses; reset and setback history; urge or intensity ratings; reflections; progress, world discoveries, and saved artwork; blocker configuration, Screen Time selections and counts, and custom blocked domains; and reminder and privacy preferences. Forth processes this information on your device to personalize the plan, provide exercises and progress features, operate the blocker, schedule local reminders, and apply privacy settings. Raw assessment responses are discarded after the plan is generated. Forth does not send the content of these records to its servers. A creator attribution code may also be captured from a direct Forth referral link and stored locally to remember the referral source. When analytics is enabled, the code is used to measure that referral as described in Section 2.4.

2.2 Room and moderation information

This category includes posts and replies; reports, blocks, and report reasons; moderation decisions and status; strikes, restrictions, and crisis flags; and related timestamps. Forth uses it to publish and thread eligible content, apply blocks, check and review content, show crisis resources, enforce the Terms of Use, and protect The Room.

2.3 Pseudonymous identifiers and technical information

This category includes a Supabase authentication user identifier and an actor identifier, generated handle, authentication and session events, a per-install Room eligibility identifier, a blinded Room eligibility-token request, a redeemed Room eligibility-token hash, an eligibility-source identifier hash, request time and status, IP address, user agent, app or client version, and device or operating-system information. It may also include a random analytics identifier when analytics is enabled. Forth and its providers use this information to authenticate Room access, deliver and secure online features, enforce rate limits, prevent abuse and token reuse, and troubleshoot reliability.

2.4 Product analytics

Unless you turn analytics off, this category includes events showing that a creator referral link was opened; an onboarding, plan-reveal, offer, purchase, or restore event occurred; the dashboard, World, gallery, or The Room was viewed; a reset or game activity occurred; a Room submission was attempted; the blocker changed; or a reminder was enabled. Limited fields may include a step or offer identifier, post type, game mode, duration, placement count, restore outcome, and creator code. Forth uses this information to understand whether features work and improve the product. It does not include assessment responses, plan or reflection content, Room text or handles, report reasons, blocker selections, custom domains, or browsing history.

2.5 Purchase and subscription information

This category includes an anonymous RevenueCat customer identifier, Apple receipt and purchase information, transaction and product or offer information, subscription and entitlement status, restore outcome, last-use information, and basic app or device information. Forth uses it to complete and restore purchases and manage paid app access.

When you choose web checkout, purchase information also includes your billing email and the billing and payment details processed by RevenueCat and Stripe. These providers process that information for payments, renewals, receipts, cancellation, refunds, and support. Your billing email is not added to product analytics or used to identify you in The Room.

2.6 Support information

This category includes the email address, message, attachments, and message metadata you choose to send to support. Forth uses it to respond, troubleshoot, handle privacy requests, and keep a reasonable support record.

2.7 Derived information

This category includes the plan derived on your device from assessment responses and moderation decisions derived from submitted Room text. Forth uses those results to provide the requested plan and to moderate The Room.

3. Categories of sources

Forth collects consumer health data from:

4. Categories of consumer health data shared

Forth shares the following categories for the stated purposes:

Forth does not share the content of the on-device recovery records described in Section 2.1 with remote service providers. Forth does not sell consumer health data.

5. Categories of third parties and specific affiliates

Forth currently has no affiliates with which it shares consumer health data.

6. Washington consumer rights and requests

Washington consumers may ask Forth to:

Submit a request by emailing nikitaborisov724@gmail.com with the subject "Washington Consumer Health Data Request." Do not include assessment responses, reflections, or other sensitive content in the email. Because Forth does not use a name or email login, we may ask you to verify the request through the existing Room session or another one-time method linked to the device or record. You do not need to create a new account.

We will respond without undue delay and within 45 days after receiving the request. When reasonably necessary, we may extend once by another 45 days and will explain the extension during the first period. Requests are free up to twice per year, except that we may charge a reasonable fee or decline to act on a request that is manifestly unfounded, excessive, or repetitive. If we cannot authenticate a request using commercially reasonable efforts, we may ask for additional information reasonably necessary to authenticate it.

For a verified deletion request, Forth will delete covered data from active systems and notify affiliates, processors, contractors, and other third parties that received it. Covered data in archived or backup systems will be deleted within six months after authentication unless an applicable legal exception permits it to be kept.

To appeal a refusal, reply to the decision with the subject "Washington Privacy Appeal." We will respond to the appeal in writing within 45 days. If the appeal is denied, we will provide the method for submitting a complaint to the Washington Attorney General. Forth will not unlawfully discriminate against you for exercising these rights.

7. Changes to this policy

Before collecting, using, or sharing a new category of consumer health data, or using consumer health data for a new purpose not disclosed here, Forth will update this policy and obtain affirmative consent where Washington law requires it.

8. Contact

Questions about this policy: nikitaborisov724@gmail.com