Privacy Policy
01Who we are
Forme ("Forme", "we", "us") is a social accountability app operated by Forme ApS, based in Denmark. This policy explains how we handle personal data when you use the Forme mobile app or visit formeapp.io. We act as the data controller under the EU General Data Protection Regulation (GDPR).
02What we collect
We only collect what we need to make Forme work.
Account information
- Name and username you choose
- Email address (used for login and essential notifications)
- Date of birth (used to verify you meet our minimum age, see Children, and to make the account of anyone under 18 private by default). Stored privately and never shown to other users.
- Profile photo, if you upload one
- Date you joined and time zone
Content you create
- Commitments you set, along with your chosen audience (public, friends, or a specific circle)
- Progress logs, photos, and honest reviews you write
- Reactions, comments, and chats with other users
- If you connect Strava, the activities you choose to import (distance, pace, duration, and route)
- If you turn on the health switch on a commitment, the workouts your phone already holds in Apple Health (iPhone) or Health Connect (Android): the type of workout, when it started and ended, how long it lasted, the distance, and the title your watch gave it. Where your watch recorded one, the route of that workout, which is a series of locations and is used only to draw the map on that check-in. We read workouts and nothing else, we never write anything back, and we read nothing at all until you turn the switch on. The details of a workout (its type, length, distance or route) never go to our analytics, crash reporting or logging services.
Device and diagnostics
- Device model, operating system version, and app version
- Crash reports and basic performance data, linked to your account so we can tell whether a problem hit one person or everyone
- Product usage events (which features you use, when you check in), linked to your account, so we can understand and improve Forme
- The time you last opened the app. A single timestamp, updated at most once an hour and overwritten each time, never a history of every time you opened Forme. We use it to tell someone who has come back from someone who has left, so we stop sending reminders to people who are already here, and so we can tell whether those reminders help anyone. It is never shown to other users. We clear it after 90 days, see How long we keep it.
- Country, derived from the IP address of a sign-up request and only when the date of birth entered makes the applicant 13, 14 or 15, so we can apply the right minimum age for where you are. We keep the country decision, not a location history.
- IP address. Five narrow cases in our own records, plus the session record described at the end. We record the address of a sign-up attempt for up to 24 hours to stop the age check being hammered. We record it for up to one hour when you sign in or check whether a username is free, so the same checks cannot be used to enumerate accounts. We record it for up to one hour when the app sends us a diagnostic log line or asks us to sign a link to a shared image, so that one source cannot flood either and bury the alerts we rely on to notice that something is broken. In that last case we keep only a count of requests per address per minute, never the contents of what was sent. All three are deleted automatically by a job that runs every half hour. Separately, we keep an address for longer when we have blocked a connection for abuse or for evading a suspension (see "How long we keep it"). We also record a small sample of the addresses that fail authentication against our internal moderation tools, so we can see when someone is trying to break into them. Finally, while you are signed in, the sign-in system that issues your session stores the address that session was created from, and keeps it for as long as the session lives. That is how a signed-in session can be recognised and ended. We do not build a browsing history from any of this, and none of it is used for advertising or shared with advertisers.
We do not collect contacts, advertising identifiers, or browsing activity outside Forme. We do not track your location: Forme has no location permission and never follows where you are. The only locations we ever hold are the route of a workout you chose to import, from Strava or from your watch, attached to that check-in and to nothing else. Before we store one, we hide its start and its finish. At each end we remove a stretch reaching between 250 and 650 metres from where you started or finished, with the distance picked at random, separately for each end of every route. So a route map never starts or finishes where you did, and how much is hidden changes from route to route. If a route comes back near your start partway round, that part is still shown.
03How we use it
- To provide the core product, showing your commitments to the people you chose, keeping your streak, storing your reviews.
- To send essential notifications (a new comment, a commitment check-in, security alerts). You can disable non-essential notifications in settings.
- To diagnose and fix crashes and bugs.
- To protect against abuse, spam, and violations of our Terms.
- To comply with legal obligations when required.
We do not use your data to train advertising profiles, and we do not show ads.
Why we are allowed to use it
EU and UK law asks us to name the legal basis for each use of your data. These are ours.
- Running your account: sign-in, your commitments, check-ins, comments, reactions and challenges, the notifications you asked for, and answering you when you write to us or report something. Basis: performing our contract with you (GDPR Art. 6(1)(b)).
- Checking your age at sign-up, and keeping the account of anyone under 18 private by default. Basis: our legal obligations towards children (Art. 6(1)(c) and Art. 8).
- Reading workouts from Apple Health or Health Connect, and their routes. Basis: your explicit consent (Art. 9(2)(a)), given in your phone's permission sheet and withdrawable there at any time.
- Importing activities from Strava. Basis: your consent (Art. 6(1)(a)), given when you connect it. You can disconnect at any time.
- Keeping Forme safe: the content filter, reports, automatic pauses, blocks, rate limits, IP blocks and operational logs. Basis: our legitimate interest in a safe service (Art. 6(1)(f)).
- Crash reports and product analytics sent by your device. Basis: our legitimate interest in fixing and improving the app (Art. 6(1)(f)). You can switch them off, see Who we share it with.
- An occasional email if you have been away. Basis: our legitimate interest (Art. 6(1)(f)). Every one carries an unsubscribe link.
Where we rely on legitimate interest, you can object at any time by writing to hello@formeapp.io, and we will stop unless we have a compelling reason not to, for example a block on someone who has abused other people.
04Who we share it with
We share data only with trusted service providers (sub-processors) that help us run Forme, and only to the extent they need it:
- Supabase (cloud hosting), to store your account and content on secure servers in the EU.
- Sentry (crash reporting), to collect crash traces and performance diagnostics so we can fix problems. These traces carry your account identifier, so we can tell whether a crash hit one person or everyone. They are stored in Sentry's EU region.
- PostHog (product analytics), to understand which features are used so we can improve the app. This is tied to your account identifier, never sold, and never shared with advertisers. It records no location: PostHog's location lookup is switched off and it does not keep your IP address. It is stored in PostHog's EU cloud.
- Resend (email delivery), to send the emails Forme itself generates: acknowledgements when you report something, decisions about reported content, account suspension notices, and an occasional message if you have been away for a while. Password reset emails are sent by Supabase, not Resend. When you report content, the alert that reaches our moderation inbox includes the text you reported.
- Expo, Apple and Google (push notifications), to deliver notifications to your device.
- Strava (fitness data import), only if you connect it, to bring the activities you choose into your check-ins.
- Apple Health and Health Connect are on your own phone, not companies we send anything to. If you allow it, Forme reads workouts from them so a Garmin, Apple Watch, Polar, Coros or Fitbit session can log itself. Nothing is sent to Apple or Google by us, and you can withdraw the permission at any time in your phone settings, which stops the reading immediately.
- BetterStack (operational logging), to record errors and significant events so we can tell when something is broken. These records carry your account identifier when you are signed in. They are not used to build a profile of you and are kept only as long as we need them to diagnose problems.
- Slack (team messaging), which receives feedback you send us in the app, and a headline and link when someone files a report. It does not receive the reported content itself unless we have set up a dedicated moderation channel for it. We are moving off Slack; while the connection exists it is disclosed here.
- Google Fonts (typefaces), which serves the fonts this website uses. Your browser fetches them from Google when you load a page here, so Google sees the address and browser making that request, as it does for any site that uses them. This applies to the website only, not to the app.
- Netlify (website hosting), which serves formeapp.io along with the shared commitment, profile and support pages. Like any web host, its servers see the address and browser of anyone who loads one of those pages. It receives nothing from the app itself.
- ipapi.co (country lookup), which receives the IP address of a sign-up request only when the date of birth entered makes the applicant 13, 14 or 15, so we can apply the right minimum age for that country. At 16 and over no lookup is made and no address leaves our servers. It receives no account identifier and no other data, and we store only the country decision, never a location history.
You can turn off the crash reporting and product analytics collected from your device at any time. Open your profile, then the settings sheet, and switch off Product analytics under Preferences.
To be exact about what that switch does and does not reach: it stops your device sending analytics and crash reports. It does not stop our servers recording that an action happened, because some of that is how the service runs and how we keep it secure. Server-side records of that kind carry your account identifier, are kept only as long as we need them, and are never used for advertising or sold. Everything else in this list is needed to run the account itself and cannot be switched off separately while you have one.
Data that leaves the EU
Most of your data stays in the EU: our database (Supabase, in Ireland), crash reports (Sentry), product analytics (PostHog) and operational logs (BetterStack, in Germany) are all hosted there. Some providers are based in, or process data in, the United States: Expo, Apple and Google (push notifications), Resend (email), Slack (feedback and report headlines), Netlify and Google Fonts (this website), Strava (only if you connect it) and ipapi.co (the country check at sign-up for 13 to 15-year-olds). When data goes to them, it is protected by the EU-US Data Privacy Framework where the provider is certified under it, and otherwise by the European Commission's Standard Contractual Clauses. You can ask us for a copy of the relevant safeguards at hello@formeapp.io.
We never sell your personal data. We never share it with advertisers. We will only disclose it to authorities when we are legally required to do so.
05How long we keep it
We keep your account data for as long as your account is active. Content you post stays until you or the owner of the shared thread deletes it.
When you delete your account, the erasure is immediate and irreversible. Your profile, commitments, check-ins, reviews, messages, reactions, uploaded images and any feedback you sent us are removed from our live systems as the request runs, not queued for later. We cannot recover any of it afterwards, and neither can you. Encrypted database backups are kept on a rolling schedule, so a deleted account can persist inside a backup until that backup ages out on its own. We never restore an individual account from a backup. Crash traces, analytics records and operational logs held by Sentry, PostHog and BetterStack expire on those services' own retention schedules rather than at the moment you delete. If you want them erased sooner, email us and we will submit the deletion request on your behalf.
The time you last opened the app is kept for 90 days and then cleared automatically by a job that runs every night. Because we only ever store the most recent time, a person who keeps using Forme has one timestamp that keeps being overwritten, and a person who stops has one that is erased within 90 days of their last visit.
A few short-lived records outlast a deletion briefly, and each is deleted automatically: the notices Strava sends us about your activities (30 days), a record of the invitations you sent or received, used to limit spam (7 days), and a record of which reports led to an automatic pause, used to stop abuse of reporting (8 days). None of them holds your name. Notifications you caused in other people's inboxes stay with them, with your name and your words removed.
There is one longer exception. If we have blocked a connection for abuse or for evading a suspension, we keep that IP address until the block expires plus 30 days, and then delete it automatically. A block lasts 90 days unless we set it otherwise. If the account it was linked to is deleted, that link is removed straight away and only the address remains. We rely on our legitimate interest in keeping Forme safe for this, and you can object by writing to hello@formeapp.io.
06Your rights (EU / UK)
If you are in the EU or UK, GDPR gives you the right to:
- Correct, fix anything that's wrong.
- Delete, have your personal data erased ("right to be forgotten"). You do not have to ask for this one: open your profile, then the settings sheet, then Delete account. It runs immediately.
- Access and Export, request a copy of the data we hold about you in a portable format. There is no button for this yet, so it is a manual request: email us and we will send you a machine-readable copy of your account, commitments, check-ins, reviews, comments and messages within 30 days. We would rather say that plainly than imply a self-service export that does not exist.
- Object, ask us to stop processing in certain cases. For crash reporting and product analytics you do not have to ask: switch off Product analytics in the app's settings sheet and collection stops on that device.
- Complain, file a complaint with your local data protection authority (in Denmark, Datatilsynet).
Email hello@formeapp.io and we'll respond within 30 days.
07Your rights (United States)
We extend the same core privacy rights to every Forme user, wherever they live. If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, or any other US state with a consumer privacy law, you have the right to:
- Know what personal information we have collected about you, the categories of sources, the purposes for collection, and any categories of third parties we share it with. The "What we collect" and "Who we share it with" sections above cover this for every user.
- Access a copy of the personal information we hold about you.
- Correct inaccurate information.
- Delete the personal information we hold about you, subject to narrow legal exceptions.
- Opt out of "sale" or "sharing" of personal information. We do not sell your personal information for money or other value, and we do not share it for cross-context behavioural advertising. There is nothing to opt out of, and that is why you will not see a "Do Not Sell or Share My Personal Information" link on this site.
- Limit the use of sensitive personal information. We do not use sensitive personal information to infer characteristics about you or for advertising.
- Non-discrimination. We will never deny you service, change pricing, or reduce quality because you exercised a privacy right.
Your data is stored on servers in the European Union. That includes your account and content, and it includes the crash and analytics records described in "Who we share it with". By using Forme from outside the EU, you understand and agree that your personal information will be transferred to and stored in the EU, which has a strong privacy framework (GDPR) that often exceeds US state-law protections.
To exercise any of these rights, email hello@formeapp.io from the address on your account so we can verify you. We respond within 45 days, as required by US state law. You may also designate an authorised agent to make a request on your behalf, in which case we will ask for proof of authorisation.
08Deleting your account
You can delete your account and all associated personal data at any time, from inside the app:
Open your profile
Tap Profile in the tab bar at the bottom.
Open Settings
Tap the menu icon in the top-right of your profile to open the settings sheet.
Tap "Delete account"
It's at the bottom of the settings sheet.
Confirm
Confirm that it is really you. The screen asks for whichever your account has: Apple, Google, or your password. If it cannot offer any of them on the device you are using, it says so and points you to email instead. Your account and its data are erased straight away. There is no grace period and no undo, so only confirm if you are sure.
You can also request deletion by email at hello@formeapp.io. Include the email address on your account so we can verify the request.
09Children
Forme requires you to be at least 13 years old to use our service. In the European Economic Area, the United Kingdom, and Switzerland, the minimum age is 16, in line with the strictest reading of GDPR-K. We check this at registration by asking for your date of birth and applying the regional minimum based on the country your sign-up request comes from.
If an account is created that does not meet the minimum age, we refuse the sign-up and no profile is created. We do not knowingly collect personal data from anyone below the minimum age. If you believe an underage account exists, contact hello@formeapp.io and we will remove it.
Forme is not directed to children under 13. We comply with the Children's Online Privacy Protection Act (COPPA) by not knowingly collecting data from US users under 13.
10Security
We encrypt data in transit (TLS) and at rest. Access is restricted to a small number of employees on a need-to-know basis. No system is perfect; if a breach affects you, we will notify you and the relevant authority within 72 hours, as required by GDPR.
11Changes to this policy
If we make material changes, we will notify you in the app and by email before they take effect. The "Last updated" date above always reflects the current version.
12Contact
Privacy requests, support, legal
Copenhagen, Denmark