PRIVACY POLICY
LAST UPDATED: 01 SEP 2026 • VERSION 2.2
CONTROLLER + CONTACT
SENTINEL FORGE™ is a product of ANQ LLC (“we,” “us,” “our”), a Wyoming limited liability company. ANQ LLC is the data controller for the SENTINEL FORGE application (“the Service”). This Privacy Policy explains how we collect, use, store, share, and protect personal information.
Principal office: 2330 Poe Road, Secane, PA 19018, USA.
Questions, data-rights requests, or complaints: Contact us. We do not currently have a designated Data Protection Officer or EU/UK representative (pending). Users in the EU/EEA/UK may contact us directly using the form above.
DATA WE COLLECT
- Account information — callsign, email address, authentication credentials, optional military branch and MOS.
- Demographics — height, weight, date of birth, biological sex (for baseline calibration).
- Fitness data — workout logs, exercise sets, ACFT scores, nutrition entries, body composition.
- Health metrics — heart rate, resting heart rate, HRV, VO2 max (cardio fitness), oxygen saturation (SpO2 / blood oxygen), respiratory rate, sleep stages, stress signals, recovery scores, menstrual cycle (optional). Availability varies by device and platform — we only receive what your connected hardware and health platform actually provide.
- Device data — OAuth tokens, sensor-sourced records, device identifiers for connected peripherals.
- Media — body-scan photos, meal photos, barbell plate-scan photos, marksmanship target photos, food barcode photos, Form Check video clips, and lab-result documents that you upload. Any image analysed by a feature leaves your device and is processed by Anthropic’s Claude vision model — without exception, and not on-device (see AI Features). We keep the result, not the image.
- Audio — short voice recordings captured only while you actively use voice logging, sent for speech-to-text transcription. On every platform, including iOS and Android, that recording leaves your device and is transcribed by a third party (Apple, Google, your browser vendor, or OpenAI — see Sub-processors). We do not record in the background, there is no always-on listening, and we do not retain the audio after transcription.
- Usage + diagnostics — app events, error logs, IP address, browser / OS, timestamps.
- Signup progress (before you have an account) — when you start creating an account, we record which step of the signup form you reached, the time, your platform (iOS / Android / web) and the app version, so we can find out where the process is failing people. It is tied to a random token generated on your device, not to you: it contains no name, email, callsign, IP address or device identifier, it is not derived from your device, it does not survive reinstalling the app, and it cannot be traced back to a person. If you finish signing up, the token is deleted from your device. We do not use it for advertising, we do not share it, and it never follows you to any other app or website.
- Communication — contact-form submissions, email replies, support tickets.
LEGAL BASIS (GDPR ART 6)
- Performance of a contract — account creation, subscription billing, core app function.
- Consent — optional features (AI features, marketing email, sensor linking). You can withdraw consent in Settings at any time.
- Legitimate interest — error tracking, fraud prevention, aggregated analytics, security monitoring.
- Legal obligation — tax records, responding to lawful requests from authorities.
HOW WE USE YOUR DATA
- Deliver personalized fitness analytics and performance dashboards.
- Generate AI-powered workout, recovery, nutrition, and cycle recommendations.
- Track progress across strength, endurance, and readiness metrics.
- Provide leaderboards, groups, chat, and head-to-head challenges when enabled by you.
- Debug errors, monitor abuse, and improve the Service.
- Send transactional email (account, billing, password reset). Marketing email is opt-in only.
We do not sell your personal data. We do not use your data for cross-site advertising.
SUB-PROCESSORS + SERVICES
We share data only with the service providers necessary to operate the Service:
- Anthropic (Claude API) — AI Coach, Form Check, Body Scan, Meal Scan, training guidance. Data is sent only when you use AI features. Anthropic does not train on API inputs under their Commercial Terms.
- Microsoft Azure — application hosting, PostgreSQL database, object storage, CDN. United States region.
- Stripe — payment processing (subscriptions, one-time purchases). Card data is handled entirely by Stripe; we receive only billing metadata.
- Resend — transactional email delivery (password reset, receipts, account notices).
- Capgo — over-the-air updates for the mobile app bundle.
- Sentry — crash and performance monitoring. We scrub PII where reasonably feasible.
- Google Play — Android app distribution and in-app billing (once enabled). Separately, Google’s speech-recognition service receives your voice recordings when you use voice logging on Android — see the speech-to-text entry below.
- Apple — iOS app distribution via the App Store and in-app purchase processing. Apple provides us subscription status and transaction identifiers; we do not receive your payment card details. Apple’s speech-recognition service also receives your voice recordings when you use voice logging on iOS — see the speech-to-text entry below.
- RevenueCat — subscription and entitlement management across the App Store and Google Play. Receives your account identifier and purchase/subscription events so the app knows which tier you are entitled to.
- Google Firebase — app-event analytics and push-notification delivery for the mobile app. Firebase receives in-app event names and a pseudonymous app-instance identifier, plus a device push token on iOS. We use the Analytics build that has no advertising-identifier support: we do not collect the IDFA, we do not track you across other companies’ apps or websites, and we do not use this data for advertising. This is a separate service from Google Play above.
- Speech-to-text providers (Apple, Google, your browser vendor, and OpenAI) — voice logging sends a short recording for transcription, only while you are actively using a voice feature. On every platform, your voice recording leaves your device and is transcribed by a third party. Which one depends on your device: your device’s or browser’s own speech-recognition service is tried first where one exists — Apple’s on iOS, Google’s on Android, your browser vendor’s on the web. We do not restrict these services to on-device processing, so they may transcribe your audio on their servers; whether any given recording is handled on your device or on theirs is decided by that provider and your device, and is not something we control or are told. If no such service is available, or it fails, or it returns nothing usable, the recording is sent to OpenAI (Whisper API) instead — OpenAI does not train on API inputs under their API terms. We do not record in the background, there is no always-on listening, and we do not retain the audio after transcription.
- OpenFoodFacts — barcode and packaged-food lookups. Barcode scans query the OpenFoodFacts database directly from your device.
- Spoonacular — recipe search for meal recommendations. Receives your remaining macro targets for the day.
- USDA FoodData Central — nutrition database lookups for food search. Receives the food text you search for.
- Third-party sensor providers — Oura, Fitbit, Eight Sleep, Suunto, Withings, Whoop, Ultrahuman. We request only the scopes needed for performance tracking. We do not push your data back to these providers.
AI FEATURES
SENTINEL FORGE uses Anthropic’s Claude model to generate workout analysis, training recommendations, recovery notes, meal parsing, and body-scan analysis. When you invoke an AI feature, relevant fitness and biometric data is sent to Anthropic for processing and discarded by them after the response is returned (per their Commercial Terms). AI output is probabilistic and may contain errors. You are responsible for evaluating AI guidance against your own judgment and professional advice. AI outputs are not medical advice.
Photographs. Every feature that analyses an image you supply sends that image to Anthropic’s Claude vision model. As of this writing that is the barbell plate scanner, the food barcode scanner (which photographs a product barcode and reads the digits printed beneath it), the marksmanship target scanner, Form Check, the body-composition scan, and meal photo scan / import — but the rule is the category, not this list: if a feature reads a picture, the picture is sent. The image leaves your device and is processed on Anthropic’s servers — we do not perform this analysis on-device, and we do not restrict these services to on-device processing. We do not store the image after the analysis returns; only the result (a weight, a score, a barcode number, a macro estimate) is saved to your account. Anything else visible in the frame is sent along with the subject, so point the camera at what you intend to capture.
INTERNATIONAL TRANSFERS
Our infrastructure is hosted in the United States. If you access the Service from the EU, EEA, UK, or elsewhere outside the U.S., your data will be transferred to and processed in the United States. Where required, such transfers are governed by the Standard Contractual Clauses (SCCs) issued by the European Commission, including the UK Addendum.
DATA STORAGE AND SECURITY
Your data is encrypted at rest using Azure PostgreSQL with encryption enabled and encrypted in transit via HTTPS/TLS 1.2+. OAuth tokens for connected peripherals are stored encrypted. Passwords are hashed using industry-standard adaptive hashing. Access is restricted to authorized personnel on a least-privilege basis. No security program is perfect; we will notify affected users and regulators of material breaches as required by law.
DATA RETENTION
- Account + fitness + health data — retained while your account is active. Deleted within 30 days of account deletion request.
- Error + diagnostic logs — 90 days.
- Signup progress events — 12 months, then deleted automatically.
- Email metadata (Resend) — 90 days.
- Billing records — retained for 7 years to meet U.S. tax obligations.
- Backups — encrypted backups rotate out within 35 days.
YOUR RIGHTS
Depending on your jurisdiction, you may have the right to:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure — delete your data (“right to be forgotten”).
- Portability — export your data in a machine-readable format.
- Objection + restriction — object to or restrict processing.
- Automated decision-making — the Service uses algorithmic scoring for readiness and training recommendations. You can request human review of any automated output that materially affects you.
- Withdraw consent — for any consent-based processing.
- Complain to a regulator — EU/UK users may lodge a complaint with their supervisory authority.
Exercise these rights in-app (Settings → Account) or via our contact form. We respond within 30 days (GDPR) or 45 days (CCPA).
CCPA (CALIFORNIA) + STATE PRIVACY
California residents, and residents of other U.S. states with comprehensive privacy laws (Colorado, Connecticut, Virginia, Utah, and others) have the rights described above, including the right to know, delete, correct, and opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined under the CCPA.
A "Do Not Sell or Share My Personal Information" link is not required because we do not engage in such activity. If this ever changes, we will add the link and update this policy with reasonable notice.
COOKIES + TRACKING
SENTINEL FORGE uses cookies (or equivalent local storage) for session authentication, user preference storage, and one random token that links the steps of a single signup attempt together (see “Signup progress” above). That token is deleted from your device as soon as the account is created; if you do not finish signing up it stays on your device until you clear your browser data or remove the app. We do not use third-party advertising cookies, cross-site trackers, or analytics cookies.
AGE RESTRICTIONS
SENTINEL FORGE is intended for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we become aware that a user under 18 has created an account, we will delete it. Users in the EU/EEA/UK must be at least 16 to provide consent for data processing without parental authorization.
CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. Material changes will be announced in-app and by email. The “last updated” date at the top reflects the most recent revision. Continued use of SENTINEL FORGE after a change takes effect constitutes acceptance of the updated policy.