← Back to Forfeit

PRIVACY POLICY

Last Updated: September 29, 2026

Introduction

Forfeit Inc ("we," "us," or "our") respects the privacy of our users ("user" or "you"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website www.forfeit.app and our mobile application Forfeit, including any other media form, media channel, mobile website, or mobile application related or connected thereto (collectively, the "Service"). If you do not agree with the terms of this Privacy Policy, please do not access the Service.

We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the "Last Updated" date of this Policy. Any changes are effective immediately upon posting, and your continued use of the Service signifies acceptance.

Collection of Your Information

We may collect information about you in a variety of ways, including:

Personal Data

Personally identifiable information, such as your name, shipping address, email address, telephone number, and demographic information (age, gender, hometown, interests) that you voluntarily provide when you register or participate in activities related to the Service. Refusal to provide personal information may limit certain features.

Derivative Data

Information our servers automatically collect when you access the Service, such as IP address, browser type, operating system, access times, pages viewed before and after visiting, device name, device type, phone number, country, likes, replies, and other interactions logged on the server.

Financial Data

Payment-method details (e.g., card brand, last four digits, expiration date) collected when you make a purchase. We store only a Stripe customer token; full card data are held by our payment processor Stripe. Please review Stripe's privacy policy for details.

Mobile Device Data

Device ID, model, manufacturer, and location information (if you grant permission) when you access the Service from a mobile device.

Third-Party Data

Information from third parties, such as personal data or friend lists, if you connect your account to the third party and grant the Service permission.

Mobile Application Information

Location Information and Background Location

Forfeit collects location data to automatically verify GPS goals, detect arrival at or departure from saved places, and deliver location-based reminders even when the app is closed or not in use, when you enable the relevant features and grant background location permission. On Android, background access requires the "Allow all the time" location setting. We show an in-app disclosure before requesting this access.

Location data may include precise latitude and longitude, accuracy, observation time, saved-place names and boundaries, arrival/departure events, and device identifiers and monitoring status needed to associate observations with your account. Forfeit uses location events and occasional location fixes rather than continuously recording your route.

Ordinary arrival/departure reminder notifications are processed and delivered locally on your phone, including offline. Configurations that use only local reminders do not acquire coordinates or upload ordinary location observations; saved reminder settings and setup/registration acknowledgements may still be stored on our servers. When GPS verification, the Overlord location integration, or a server-side location-triggered task is enabled, relevant observations, including available coordinates, may be uploaded to Forfeit for processing and storage. Queued observations may be sent when connectivity returns. Enabling a GPS goal or local reminder alone does not enable Overlord known-place history.

We use uploaded location information to evaluate GPS goals, maintain the location history and last-observed position you enable, and run requested location-triggered tasks. Cloud hosting and database providers, including Google Firebase, process this information on our behalf. When the Overlord location integration or a location-triggered AI task is enabled, relevant location context may also be processed by our AI service providers, which may include OpenAI, Microsoft Azure, Google, or Anthropic depending on service routing. Requested messages may be sent through the delivery providers described in this Policy.

Location observations and history may be retained with your account while needed for the enabled features, goal records, support and operation of the service, subject to the Data Retention section below. Revoking permission stops future location access through that permission but does not automatically delete information already uploaded. You can request deletion of stored location information or your account through the available account-deletion process or by contacting support@forfeit.app, subject to the retention exceptions described below.

Location permission is optional. You can decline background access, disable the relevant location features in Forfeit, or change location access in Android Settings > Apps > Forfeit > Permissions > Location. Declining or revoking permission limits automatic GPS verification and background arrival/departure reminders. Notification permission is separate and can also be changed in device settings.

External Messaging Channels

If you voluntarily connect or use iMessage, WhatsApp, or Telegram with Forfeit, we collect the channel identifier needed to match and deliver your messages, such as your telephone number, Apple ID email address, or Telegram chat ID. We also process the messages and attachments you send through that channel and the replies Forfeit sends. We use this information to link the channel to your account, maintain your conversation history, provide requested coaching and goal features, and deliver service notifications you enable.

External messaging data is shared as needed with the channel and delivery providers involved in the feature, including LoopMessage for iMessage and WhatsApp delivery, WhatsApp and its operator Meta, and Telegram. Message content may also be processed by our third-party AI service providers, which may include OpenAI, Microsoft Azure, Google, or Anthropic depending on service routing. These providers process data under their applicable terms and our service arrangements.

External messaging notifications are off until you enable or initiate the relevant channel. You can disable proactive delivery through the available channel settings. Messages already stored in your Forfeit conversation history remain subject to the retention and account-deletion terms in this Policy. A messaging provider may retain data under its own privacy policy.

Health and Fitness Data (Android Health Connect)

If you grant permission, we read the health and fitness data types you authorize solely to verify the goals and features you enable in Forfeit. These metrics stay on your device unless you enable Cloud Sync or another feature that requires server processing. Selected metrics are transmitted using encrypted connections and stored by our cloud infrastructure with encryption at rest so enabled service features can use them. They are not end-to-end encrypted: authorized Forfeit service systems and personnel can access stored metrics when needed to provide and protect the service. You can disable future Cloud Sync at any time. To request deletion of previously synced metrics, use the available account-deletion process or contact support@forfeit.app. Some records may be retained where required for billing, legal obligations, disputes, fraud prevention or security.

Use of Your Information

We use collected information to: administer sweepstakes, promotions, and contests; assist law enforcement and respond to subpoenas; compile anonymous statistical data; create and manage accounts; deliver advertising, coupons, newsletters, and promotions (never using health data); email you about your account or orders; enable user-to-user communications; fulfill and manage purchases and payments; generate personal profiles; increase the efficiency and operation of the Service; monitor and analyze usage and trends; notify you of updates; offer new products or services; perform business activities; prevent fraud and protect against criminal activity; process payments and refunds; request feedback; resolve disputes and troubleshoot problems; send newsletters; solicit support for the Service; and, specifically, verify and approve or fail your habit-tracking goals via automated and human review. Health data are used only for goal verification and optional Cloud Sync.

Disclosure of Your Information

By Law or to Protect Rights

We may share information if required to respond to legal process or protect the rights, property, and safety of others, including fraud prevention and credit-risk reduction.

Third-Party Service Providers

We may share information with vendors performing services for us—for example payment processing (Stripe, Inc.), hosting and analytics (Firebase, Google LLC), cloud infrastructure (Amazon Web Services), AI verification (OpenAI LLC), data analysis, email delivery, customer service, crash reporting, or marketing assistance. Vendors may process data only under our instructions.

Marketing Communications

With your consent or an opportunity to withdraw consent, we may share information with third parties for marketing, but never health data.

Interactions with Other Users

If you interact with other users, they may see your name, profile photo, and activity descriptions.

Online Postings

Comments or other content you post may be publicly viewable and redistributable.

Third-Party Advertisers

We may allow advertising companies to serve ads; they may use cookies but do not receive health data.

Affiliates, Business Partners, Other Third Parties

We may share information with affiliates and business partners consistent with this Policy. We may share anonymised data with advertisers and investors for business analysis.

Sale or Bankruptcy

If we undergo a business transfer, your information may be transferred to the successor.

We do not sell personal or health data.

Tracking Technologies

We use cookies, web beacons, tracking pixels, and similar technologies to customise and improve the Service. You can disable cookies in your browser, but certain features may be unavailable.

Third-Party Websites

The Service may contain links to third-party sites not governed by this Policy. Review each third party's privacy practices before providing information.

Security of Your Information

We use administrative and technical safeguards intended to protect information, including encrypted connections while data is transmitted and encryption at rest provided by our cloud infrastructure. Access is limited to service systems and authorized personnel who need it to operate, support or protect the service. No storage or transmission method is completely secure, and these safeguards do not make server-stored information end-to-end encrypted.

Data Retention

Health metrics remain on your device unless Cloud Sync or another feature that requires server processing is enabled. Account information and synced data are retained while needed to provide enabled features and operate the account. When you delete content, disable a feature or request account deletion, applicable live-service data are removed through the relevant deletion process, subject to technical completion and records we must retain for billing, legal obligations, disputes, fraud prevention or security. Deleted Cloud Storage objects currently have a seven-day recovery period. We do not make a fixed Firestore-backup deletion promise because the database backup schedule has not been independently verified. Anonymous or aggregated statistics that no longer identify a person may be retained.

Policy for Children

We do not knowingly collect data from children under 13. If you believe we have collected such data, contact us.

Do-Not-Track Features

We do not currently respond to DNT signals. If standards emerge, we will update this Policy.

Options Regarding Your Information

Account Information

You may review or change account information through available settings. You may request deletion through the account process or by contacting support@forfeit.app, including where an in-product lock prevents use of the product control. Account deletion is separate from canceling a subscription through its billing provider. We remove applicable live-service data through our deletion processes, but may retain records required for billing, legal obligations, disputes, fraud prevention or security. Contact support if you need confirmation about a specific request.

Emails and Communications

To stop receiving emails or other communications, contact us or follow the unsubscribe instructions. For third-party communications, contact the third party directly.

Additional Regional Rights

Residents of the EEA, United Kingdom, California, and other jurisdictions with data-protection laws have additional rights, including access, rectification, restriction, objection, portability, and complaint to a supervisory authority. To exercise any of these rights, contact us using the details below.

California Privacy Rights

California residents may request information on data disclosed for direct marketing once per year. Residents under 18 with registered accounts may request removal of publicly posted data.

International Data Transfers

We operate in the United States and may process data in other countries where our providers operate, relying on Standard Contractual Clauses or other adequacy mechanisms as required for EEA/UK transfers.

Screen Blocking Permissions for Android Users

The Forfeit Android app offers an optional Screen Blocking feature that prevents access to user-selected apps during active goal periods. To implement this feature we request three Android system permissions. These permissions are granted only when you enable Screen Blocking and are never used for any other purpose.

Accessibility Service (BIND_ACCESSIBILITY_SERVICE)

Detects when a blocked app is brought to the foreground so we can display the blocking overlay.

Display Over Other Apps (SYSTEM_ALERT_WINDOW)

Allows Forfeit to place a full-screen overlay on top of a blocked app.

Usage Access (PACKAGE_USAGE_STATS)

Backup method to identify when blocked apps become active if the Accessibility Service is paused by the system.

General Principles

Compliance with Google Play Policies

Our implementation follows Google Play requirements for sensitive permissions, including prominent disclosure, user consent, minimal access, purpose limitation, and the ability to disable the feature at any time.

Contact Us

For questions or comments about this Privacy Policy, contact:

Forfeit Inc

support@forfeit.app