Who this policy applies to
This policy describes how Forge & Frequency LLC handles consumer health data as defined by the Washington My Health My Data Act (chapter 19.373 RCW) and the Nevada consumer health data law (NRS 603A.400 et seq.).
It applies to you if you are a resident of Washington or Nevada, or if your consumer health data is collected in one of those states. It applies in addition to our general Privacy Policy, which covers all other personal information.
The short version: Mjölnir Forge stores your training information on your own device. We operate no server that receives it. The only consumer health data that ever reaches us is what you choose to put in an email to support, and we delete that as soon as we have answered you.
Categories of consumer health data we collect
Mjölnir Forge stores the following categories of information on your device, which may constitute consumer health data:
- Body measurements, including bodyweight.
- Recorded injuries and physical limitations you enter into your athlete profile.
- Training performance information, including loads lifted, repetitions, distances, times, and rate of perceived exertion.
- Completed workout history and notes you write about how a session felt.
This information is stored locally using Apple's on-device storage. It is not transmitted to Forge & Frequency LLC in the ordinary operation of the app. We do not operate a server that receives, stores, or processes your training data, and we cannot see it.
The only circumstance in which we collect consumer health data is when you send it to us — for example, if you include health or training details in an email to support. We ask that you do not send health information to support unless it is necessary to answer your question.
Sources of consumer health data
Consumer health data comes only from you: information you enter into the app, or information you send to us directly.
We do not obtain consumer health data from any other source. We do not purchase it, receive it from data brokers or advertising networks, or infer or derive it from non-health information.
Purposes of collection and use
Information stored on your device is used to generate and manage your training programs, to record what you have done, and to show you your own history and progress. That processing happens on your device, for you.
Where we receive consumer health data through a support request, we use it for one purpose only: to investigate, respond to, and resolve that request.
We do not use consumer health data for advertising, profiling, product analytics, research, or any secondary purpose. We do not use it to train machine learning models.
Third parties and affiliates with whom we share consumer health data
None. We have no affiliates. We share consumer health data with no third parties.
If that ever changes, we will identify each category of recipient in this policy and obtain your affirmative consent before sharing, as described under Changes to this policy.
Sale of consumer health data
We do not sell consumer health data, and we have no plans to do so.
We will not sell consumer health data without first obtaining your valid written authorization, separate and distinct from any other consent, as required by law.
Your rights
In relation to consumer health data, you have the right:
- To confirm whether we are collecting, sharing, or selling your consumer health data.
- To access that data, including a list of all third parties and affiliates with whom we have shared or sold it, and a way to contact them.
- To withdraw your consent to our collection and sharing of it.
- To have it deleted.
- Not to be discriminated against for exercising any of these rights.
How to exercise your rights
Because your training data is stored on your device, you can exercise most of these rights directly and immediately, without involving us:
- To see it — open the app.
- To delete it — delete the individual records in the app, reset the app's data if that option is available in your version, or delete the app from your device.
For any consumer health data we hold — which will only ever be support correspondence you sent us — email privacy@mjolnirforge.com from the address you used to contact us.
You do not need to create an account to make a request. We verify requests by corresponding with the email address that sent us the information. If we cannot verify a request using reasonable efforts, we will tell you and may ask for additional information reasonably necessary to verify it.
We respond without undue delay and within 45 days of receiving your request. Where reasonably necessary we may extend that period once by a further 45 days, and if we do we will tell you within the first 45 days and explain why. Responses are free of charge up to twice a year.
Appeals
If we refuse to act on your request, we will tell you why. You may appeal by replying to our response with the word "appeal."
Within 45 days of receiving your appeal we will inform you in writing of any action taken or not taken, with a written explanation of our reasons.
If we deny your appeal, you may submit a complaint to the Washington Attorney General at atg.wa.gov/file-complaint, or to the Nevada Attorney General at ag.nv.gov.
Retention and deletion
We do not retain consumer health data. If you send us an email containing health or training details, we delete it from our mailbox as soon as your request is resolved.
To be accurate about what that means in practice: once deleted, a copy may persist for a short period in our email provider's routine backups and deleted-items retention before being overwritten. We do not access those copies and we do not restore them. We maintain no other archive.
Consumer health data stored on your device remains there under your control until you delete it.
Security
Access to support correspondence is restricted to those who need it to answer your request.
Because we operate no server holding your training data, there is no central store of consumer health data to compromise. Data on your device is protected by your device passcode, biometric lock, and Apple's on-device encryption. Keeping your device updated and locked is the most effective protection available for it.
Changes to this policy
If we change this policy we will update the effective date above and post the revised policy at this address.
We will not collect, use, or share any additional category of consumer health data, or use it for any purpose, that is not described in this policy without first disclosing the addition and obtaining your affirmative consent.
Contact
For any question or request relating to consumer health data, contact privacy@mjolnirforge.com.
Forge & Frequency LLC
[REGISTERED AGENT / BUSINESS STREET ADDRESS]
[CITY], Maryland [ZIP], United States