Privacy policy
Last updated: 31 July 2026
BuckForge is operated by Sebastian Hjort, a sole developer based in Sweden. This policy explains what data the BuckForge app collects, why, and what choices you have. The data controller under the EU GDPR is Sebastian Hjort (Sweden). Contact: sebastianhjort.developer@gmail.com.
1. What we collect, why, and the legal basis
To use BuckForge you must create an account — providing this data is required to use the service.
- Account information — your email and a hashed password.
Purpose: identifying you and securing your account. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). - Training data — the plans, sessions, goals, and benchmarks you create.
Purpose: providing the app’s features and syncing across your devices. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). - Authentication and security signals — authentication tokens issued when you log in and counters used to detect abuse (e.g. failed login attempts).
Purpose: keeping your account secure. Legal basis: legitimate interests (Art. 6(1)(f) GDPR) — protecting accounts from unauthorised access.
We do not use advertising, ad networks, cross-app tracking, or marketing analytics, and we do not sell your data. The only diagnostic tool we use is crash reporting (see section 6). We do not make automated decisions that produce legal or similarly significant effects on you.
2. On-device image text recognition
The app can read workouts from a photo. Text recognition runs on your device using the operating system’s vision framework (Apple Vision on iOS, Google ML Kit on Android). The image is never uploaded.
3. Apple Health and Health Connect (optional)
If you choose to connect BuckForge to Apple Health (iOS) or Health Connect (Android), the app reads the following data types from your device:
- Heart rate, heart rate variability (HRV), and resting heart rate
- Sleep sessions
- Workout sessions (e.g. runs, rides) — used to suggest a match when you complete a session in the app
This data stays on your device. We use it to compute your daily Recovery Score and to suggest matching workouts when you complete a session. Both calculations run locally on your phone and the underlying samples are not uploaded to our servers.
Legal basis: explicit consent (Art. 9(2)(a) GDPR). You grant access through the operating system permission dialog and can revoke it at any time in your device settings or in BuckForge under Profile → Health & Activity. Revoking removes our access immediately; previously-computed Recovery Scores cached on your device are removed when you uninstall the app.
4. Community and social features (optional)
If you add friends, share a session or mobility flow, react to a friend’s activity, or enter a community challenge, we store the content and connections needed to provide those features — your friend list and pending friend requests, the items you share or receive, your reactions and activity-feed events, and your challenge submissions (scores and any notes you add). Content you share with a friend is visible to that friend.
Purpose: providing the social and community features you choose to use. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). These features are optional — you can use BuckForge without them.
5. Private coaching plans (optional)
If you accept an invitation to a coach’s private plan, we share a defined slice of your training data with that coach for as long as you are on the plan. Specifically, the coach can see your results for the sessions in that plan (whether you completed, skipped, or partly logged each one, your logged sets, RPE, and session notes) and your display name. They can also change the sessions in that plan and write comments on your results, which are delivered to you in the app.
The coach does not receive your email address, your training outside that plan, your diary entries, your other plans, or your data from any other coach’s plan. Other athletes on the plan cannot see your results unless the plan states otherwise at the point you join.
You are shown exactly what the coach will see and do before you accept, and you must confirm it. If we ever widen what a coach can see — for example by adding a shared leaderboard to a plan — we will ask you again before your data is included.
Purpose: letting a coach you chose write and follow up on your training. Legal basis: performance of a contract (Art. 6(1)(b) GDPR), on the terms you confirmed when joining. This feature is entirely optional — you only ever join a plan by accepting an invitation.
Leaving, and what the coach keeps. You can leave a plan at any time, and a coach can remove you. After that, the plan is archived on your device and everything you logged remains yours. The coach keeps aggregate totals for the period you were on the plan, but can no longer open your individual sessions. Your data export (section 12) lists every coach plan you have joined, when you joined, and when your access ended.
6. Crash diagnostics (Sentry)
To find and fix crashes, the app sends a diagnostic report to Sentry (Functional Software, Inc.) when an error occurs. A report contains the error and a stack trace, the app version, and basic device and operating-system information; Sentry also records the sending IP address. We do not attach your name or email to these reports, and crash reporting is switched off in development builds.
Purpose: diagnosing and fixing crashes so the app stays reliable. Legal basis: legitimate interests (Art. 6(1)(f) GDPR). Sentry processes this data on our behalf; see section 10 on international transfers.
7. Push notifications (optional)
If you enable notifications, your device registers a push token that we store so we can send them (for example, when a friend reacts to your activity). Delivery uses the Expo push service, which relays notifications through Apple Push Notification service (iOS) and Firebase Cloud Messaging (Android). You can turn notifications off in your device settings or in BuckForge under Profile → Notifications; the token is removed when you sign out.
Purpose: delivering the notifications you have enabled. Legal basis: consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. See section 10 on international transfers.
8. Connecting a gym or coaching account (optional)
BuckForge can import your booked classes and workouts from a third-party gym or coaching provider you already use (such as Wondr, Fitr, SugarWOD, or TrueCoach). If you connect one, you sign in to that provider and the app fetches your training data directly from them. Your provider login credentials are stored only on your device, in the operating system’s secure storage (Keychain / Keystore) — they are never sent to or stored on our servers. Disconnecting the provider deletes the stored credentials.
Purpose: importing the training data you ask us to. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Your use of the third-party provider remains governed by that provider’s own terms and privacy policy.
9. Where your data is stored
Your account and training data are stored on infrastructure located in the EU:
- Render (EU region) — backend hosting.
- TiDB Cloud (EU region) — database.
- Resend — sending transactional and account-related emails, including account verification, password reset, and the copy of your data you request through “Export my data” (delivered as a JSON attachment to your account email).
Two further providers process limited data outside the EU: Sentry (crash diagnostics) and Expo, together with Apple and Google, for push-notification delivery. See section 10.
All of these providers act as data processors on our instructions.
10. International transfers
Crash diagnostics (Sentry) and push-notification delivery (Expo, Apple, Google) may involve processing in the United States. Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards — the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. The data involved is limited to crash diagnostics and push tokens; your account and training data remain stored in the EU.
11. Retention
We keep your account and training data for as long as your account is active. If you request deletion, your account enters a 30-day grace period — you can cancel any time in that window by signing back in — after which it is permanently deleted. Backups may retain copies for up to 90 days before they age out.
12. Your rights
Under the GDPR you have the right to access, correct, export, restrict, or delete your personal data, and to object to processing. To exercise these rights, see the account deletion page or email sebastianhjort.developer@gmail.com. We aim to respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. The Swedish authority is Integritetsskyddsmyndigheten (IMY).
13. Security
Traffic between the app and our backend uses HTTPS. Passwords are hashed before storage. Sign-in tokens and any connected gym-account credentials are held in your device’s secure storage (Keychain / Keystore) and can be protected by your device biometrics (Face ID / fingerprint). Access to production infrastructure is restricted to the developer. No system is perfectly secure — please use a strong, unique password.
14. Children
BuckForge is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to this policy
If we make material changes, we will update the "Last updated" date above and notify you in the app or by email.
16. Contact
Sebastian Hjort, Sweden — sebastianhjort.developer@gmail.com