Privacy Policy
Last updated: May 2026
ForgeRestore (“we,” “our,” or “us”) is committed to protecting your privacy. This policy explains what personal information we collect, why we collect it, how it is used, and what rights you have over your data. We designed ForgeRestore with privacy as a core value — your recovery journey is yours alone.
This Privacy Policy is part of, and should be read together with, our Terms & Conditions, which cover eligibility, acceptable use, and the disclaimer that ForgeRestore is a peer-recovery organizing tool for general wellness use — not a medical device or therapeutic service.
1. Who We Are
ForgeRestore is a web application designed to support individuals in Crystal Meth Anonymous (CMA) recovery. It is not affiliated with CMA, AA, NA, or any other twelve-step organization. ForgeRestore operates as an independent tool to help users and their sponsors organize and track the 12-step process.
For privacy-related inquiries, please use the contact information on our website.
2. What Data We Collect
We collect only what is necessary to provide the service. Here is every category of data we hold:
- Account Identity
- Your name, email address, and profile picture provided when you sign in through Replit’s authentication service. We receive this from your Replit account; we do not collect passwords.
- Recovery Information
- Your sobriety date and 12-step progress (which steps you have completed and any step-work you submit). This is the core purpose of the app.
- Journal Entries
- Personal journal entries including free-text reflections, body-scan fields (how you feel, what you did, what you want, what you will do), and meetings attended. Journal entries are private by default and visible only to you unless you explicitly grant access.
- Triggers & Cravings Logs
- Craving logs (intensity, emotional state, physical state, thoughts, actions taken), known personal triggers by category, and deterministic on-device pattern reflections derived from your own logs. GPS location is collected only with your explicit, separate consent and only at the moment of logging a craving.
- Sponsor / Sponsee Relationships
- Connection requests, active relationships, tasks assigned by your sponsor, and task submissions.
- Home Group
- Your selected CMA home group meeting. Whether this is visible to other members of the same meeting is controlled by a privacy toggle you set.
- Technical Data
- Your device timezone (used to ensure journal dates display correctly), session cookies (necessary for login), and server access logs (IP address and request path, retained for up to 30 days for security purposes). We do not use tracking pixels, advertising cookies, or analytics cookies.
- Device Class (sign-in only)
- On each sign-in we log a coarse platform bucket only: your operating-system family (iOS, Android, Windows, Mac, Linux, other), your browser family (Safari, Chrome, Firefox, Edge, other), and whether you’re using the installed PWA or a regular browser tab. We do not store your full user-agent string, IP address, or any advertising or fingerprinting identifier with this row. This data is used only to inform internal product decisions (for example, which platforms to prioritize). It is never shared and never used for advertising or tracking.
3. Why We Collect This Data
We process your data for the following purposes:
- To provide the service: Authenticating you, storing your recovery data, and enabling sponsor/sponsee collaboration. ForgeRestore does not use AI; reflections on your data are computed deterministically.
- To keep the service secure: Detecting abuse, preventing unauthorized access, and maintaining session integrity.
- To improve the service: With your consent, understanding how features are used (no data is currently shared with third-party analytics services).
Under GDPR, our lawful basis for processing is consent (for sensitive recovery data) and legitimate interests (for security and basic service operation). Under PIPEDA and the Australian Privacy Act, we rely on your consent and the necessity of processing to fulfill our service agreement with you.
4. How We Store Your Data
All user data is stored in a PostgreSQL database hosted by Neon (neon.tech), a cloud database provider with servers located in the United States. Data is encrypted in transit (TLS) and at rest. Session data is stored server-side and never exposed to third parties.
End-to-end encryption for journal entries. When you set up a personal vault from Settings → Privacy & Data, every new journal entry you write is encrypted on your own device with a key derived from your vault password, which the server never sees. Existing journal entries are migrated to the same encrypted-at-rest format the first time you unlock the vault. For those rows the server stores only ciphertext — ForgeRestore’s own staff cannot read your journal even by inspecting the database directly. The trade-off is that if you forget your password and never set up the recovery key, the data is unrecoverable.
Integrity of the code you actually run. The ForgeRestore application bundle is served from our own origin with a content-hash filename so the file you load can be matched to the exact build we shipped.
No in-the-moment recovery chat is sent to any third party. The Recovery Playbook (the page that opens after a Burning Desire SOS is successfully sent, or any time you visit “Recovery Playbook” from the sidebar) is static, deterministic content delivered by ForgeRestore itself. It is not a chatbot, it does not call any AI model, and nothing you read on that page leaves your device beyond the normal page request.
No journal, craving, or recovery content is sent to any AI model. Relapse-pattern reflections are computed deterministically in your own browser from your own logs — no machine-learning model is involved at all. There is no longer an on-device summarization model either: the previous browser-side AI runtime was removed, and your browser’s cached copy of the model is automatically deleted on your next visit.
Intended use. ForgeRestore is a peer-recovery organizing tool for general wellness use. It is not a medical device, not a software-as-a-medical-device, not a clinical decision-support system, not a therapeutic service, and not a diagnostic service. Nothing in the app — including the Burning Desire button, the Recovery Playbook, trigger and craving trackers, sponsor communication, the deterministic pattern reflections and weekly/monthly digests computed from your own data, or the check-in indicator tiles you build from your own data — is medical, psychiatric, or clinical advice, and none of it is a substitute for a sponsor, a meeting, a therapist, a physician, or emergency services.
5. Who Can See Your Data
Only you can see your journal entries, step work, and relapse logs by default.
Your sponsor can see your step-work submissions, task progress, and — only if you explicitly enable it in your Triggers & Cravings privacy settings — your craving logs. Your sponsor cannot see your journal entries unless you grant access in your Privacy settings.
Other home group members can see that you are a member of the same meeting only if you enable the “Show my home group to other members” toggle in your Profile.
ForgeRestore staff may access database records for technical support, security investigation, or legal compliance only.
We do not sell, rent, trade, or share your personal data with any third party for marketing, advertising, or commercial purposes — ever.
6. Data Retention
Your data is retained for as long as your account is active. If you delete your account, all of your personal data — including your profile, journal entries, step work, relapse logs, triggers, sponsor relationships, and assignments — is permanently deleted immediately. This deletion is irreversible. Server access logs (IP addresses) are retained for up to 30 days and then deleted. Backups may retain deleted data for up to 7 additional days before being purged.
7. Your Rights
Depending on where you live, you have different rights over your data. We honor all of the following regardless of your jurisdiction:
- Right to Access (GDPR Art. 15 / CCPA / PIPEDA / Australian APPs)
- You can download a complete copy of all data ForgeRestore holds about you at any time from Settings → Privacy & Data → Download My Data.
- Right to Correction (GDPR Art. 16 / PIPEDA / Australian APPs)
- You can update your name, profile picture, sobriety date, location, and phone number at any time in Settings.
- Right to Erasure / Deletion (GDPR Art. 17 / CCPA)
- You can permanently delete your account and all associated data from Settings → Privacy & Data → Delete My Account. This is immediate and irreversible.
- Right to Data Portability (GDPR Art. 20 / CCPA)
- Your data export is provided in JSON format, which is machine-readable and can be imported into other systems.
- Right to Restrict Processing (GDPR Art. 18)
- You can withdraw consent for GPS location collection, sponsor data sharing, and analytics at any time from Settings → Privacy & Data or from within the Triggers & Cravings section.
- Right to Opt Out of Sale (CCPA)
- ForgeRestore does not sell personal information. There is nothing to opt out of.
8. Cookies
ForgeRestore uses a single session cookie to keep you logged in. This is a strictly necessary functional cookie. It contains no personal information and is not used for tracking or advertising. No third-party cookies are set by ForgeRestore. You can delete this cookie at any time by logging out or clearing your browser cookies, which will end your session.
9. Children’s Privacy
ForgeRestore is intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, please contact us and we will delete it promptly.
10. Jurisdiction-Specific Notices
European Union (GDPR): If you are in the EU or EEA, you have the right to lodge a complaint with your local data protection authority. Our lawful basis for processing sensitive recovery data is explicit consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
California, USA (CCPA/CPRA): We do not sell or share personal information with third parties for cross-context behavioral advertising. California residents have the right to know, delete, and opt out as described in Section 7.
Canada (PIPEDA): We collect, use, and disclose personal information only with your knowledge and consent, and only for purposes that a reasonable person would consider appropriate. You may withdraw consent at any time, subject to legal or contractual restrictions.
Australia (Privacy Act 1988 / APPs): We comply with the Australian Privacy Principles. You have the right to access and correct your personal information, and to make a complaint to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs.
11. Changes to This Policy
We may update this Privacy Policy as the app evolves. When we make material changes, we will notify you within the app. The “Last updated” date at the top of this page will always reflect the most recent revision. Continued use of ForgeRestore after changes constitutes acceptance of the updated policy.
12. Contact Us
For any privacy-related questions, requests to exercise your rights, or concerns, please contact us through the ForgeRestore application or website. We will respond to all requests within 30 days.
To exercise your data rights, go to Settings → Privacy & Data.