Privacy Policy

Last updated: August 20, 2026

1. Introduction

Welcome to RescueForge ("we", "our", "us"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application.

2. Information We Collect

We may collect information about you in a variety of ways. The information we may collect includes:

  • Account and Contact Data: Your name, email address, account ID, profile details, support requests, optional department membership, including display rank, station, shift group, and administrative role, the status, disclosure version, and time of an optional nutrition-AI consent or withdrawal, and content-free evidence of the disclosure version and request time when you separately consent to a workout import.
  • Health & Fitness Data: Fitness goals, body measurements, workouts, personal records, nutrition, hydration, sleep, injury, recovery, mood, stress, substance-use, private after-call check-ins, occupational exposure and decontamination logs, and other wellness information you choose to provide. When available, RescueForge combines the entry time and entry time zone with your private personal schedule and schedule exceptions to create a personal estimated on-shift, estimated off-shift, or unavailable context attached to a workout, nutrition, hydration, or substance entry. The estimate is not an official staffing record, an employer verification, or a fitness-for-duty determination. If you affirmatively consent and then request a macro estimate, this includes the food, portion, brand, restaurant, and preparation text you submit. If you request a nutrition-label scan, it also includes the photo you deliberately choose and the values extracted from it. If you separately consent to import a workout, it includes the selected workout photo, screenshot, or bounded TXT, CSV, or Markdown content and the editable draft extracted from it. Before transmission, RescueForge redraws a selected photo into a new JPEG to remove embedded metadata such as location and repackages selected workout text under a neutral filename. The prepared source is sent as in-memory request data through Base44's AI gateway; RescueForge does not create or store a Base44 file object for these scans, does not attach the source to the saved record, and does not save any AI draft automatically. If you use adaptive training, this can also include your role and shift context, available equipment and time, energy, fatigue, soreness, sleep quality, pain or movement limitations, illness or warning-symptom selections, recent strenuous-incident context, workout completion, perceived effort, and post-workout feedback.
  • Location Data: Approximate or precise device coordinates are sent to Open-Meteo only after you request local weather and are not saved by RescueForge for that weather request. Precise coordinates may be saved to a private schedule event when you deliberately choose its current-location button. We also store department, station, schedule, or call locations you type.
  • User Content: Diary entries, notes, schedules, any historical department shift-coverage posts or private crew or department messages retained from earlier pilots, department events, equipment requests, and any historical nutrition-label photos, wellness voice recordings, or record attachments retained from earlier website testing. New shift-coverage posts, messages, persistent user-content photos, audio, and file uploads are disabled in the App Store launch edition. Nutrition-label and workout-import sources are processed for the requested analysis without creating a stored Base44 file object.
  • Purchase and Legacy Financial Data: The App Store launch edition does not sell digital features. If separate web billing is enabled later, we may store plan, status, and payment-provider references. Historical crew-meal records can also contain an amount, a payment-method label, or an optional Venmo handle. Card details entered on a provider-hosted checkout page are processed by that provider and are not intended to be returned to or stored by RescueForge.
  • On-Device App Data: To resume an interrupted workout or retry a workout log after a network failure, this device can temporarily store the active workout, completed sets, timers, and a limited offline retry queue. It can also store account-scoped display preferences and recent app inputs. The app interface derives private repeat shortcuts from your recent substance entries after they are retrieved for your signed-in account; those shortcuts are not recommendations and require review before a new entry is saved. This limited resume/retry storage is not full offline mode.
  • Device, Usage, and Diagnostic Data: Browser or device type, IP address, access times, request metadata, any legacy web push-notification endpoint and keys previously registered through the website, and server or error logs needed to operate, secure, and troubleshoot the service. When you use a nutrition-assistant or workout-import tool, a content-free usage record of your account ID, assistant mode, disclosure version, and request time, plus a server-only per-account quota record containing your account ID, a derived quota key, shared fixed-window counters, bucket times, a last-request time, and integrity metadata, are used for abuse and cost control. Department invite-code attempts create a content-free security record containing your account ID, attempt time, and outcome; the invite code itself is not stored in that record, and the record is marked for deletion after 30 days.

3. Use of Your Information

Having accurate information permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you to:

  • Create and manage your account.
  • Support self-directed training, nutrition, sleep, recovery, and schedule tracking.
  • Only after your affirmative consent, process the food and portion text you deliberately submit to prepare an editable macro-estimate draft. You may decline or later withdraw consent and continue entering nutrition manually. Estimates require your review and are not saved automatically.
  • Only after your affirmative consent and a separate deliberate photo selection, re-encode a nutrition-label image to remove embedded metadata and send it through Base44's AI gateway to prepare an editable label-value draft. The scan does not create a Base44 file object, the image is not saved with your nutrition entry, and you must review the extracted values before saving.
  • Only after a separate per-request workout-import consent, prepare the selected workout photo or bounded text, send it through Base44's AI gateway, and return an editable workout draft. The source is not stored as a Base44 file, the importer never saves a workout automatically, and you must review and explicitly save through the ordinary workout builder.
  • Create explainable training suggestions from the role, shift, equipment, time, movement limits, recent completed workouts, and feedback you choose to provide. These suggestions are not used to diagnose, treat, rehabilitate, or determine fitness for duty.
  • Combine the time and time zone you enter or use on your device with your private personal schedule and exceptions to show a personal shift-context estimate with the log-entry controls. Where the entry time can be edited before saving, the estimate is recalculated from that time. The entry time zone may be saved with the estimate. Missing, conflicting, or unavailable schedule information is shown as unavailable rather than assumed to mean off shift. This estimate does not verify official staffing or determine fitness for duty.
  • Derive private repeat shortcuts from exact patterns in your recent substance entries so you can review and reuse a prior product and amount. These shortcuts are not medical advice and do not diagnose impairment, intoxication, substance dependence, or fitness for duty.
  • Show summaries and analytics based on information you choose to log.
  • Respond to support requests and send necessary account or service messages.
  • Comply with legal requirements.
  • Calculate summaries that you request from your own logged information.
  • Store the limited department-membership context you choose to join. Expanded shared roster, event, equipment-request, messaging, and shift-coverage operations are disabled for ordinary accounts in the App Store launch edition while multi-account and user-content safety controls are completed.

4. How We Share Information

We may provide information to service providers that host, secure, support, or process RescueForge features, including Base44, authentication, email, file-storage, and legacy web-notification providers where an older website subscription remains. Account-deletion requests remain pending unless and until any required external evidence case system and completion-email provider have been configured and verified. When those systems are used, they receive only the identity, manifest, disposition, and completion evidence needed to prove the deletion, and the minimized RescueForge queue record retains only an opaque reference to that external case rather than its copied PII or manifest. After you affirmatively consent and request an estimate, Base44 processes the nutrition text you deliberately submit using its AI integration. Depending on service availability, Base44 may route that content to third-party AI model providers such as Anthropic, Google, or OpenAI. When you request a nutrition-label scan, the selected, metadata-stripped image is processed through the same provider categories as in-memory request data. RescueForge does not create a Base44 file object for the scan or save the image with the nutrition entry. Base44 and its model providers may retain or otherwise process request data according to their applicable service and privacy terms. When you separately consent to import a workout, the selected metadata-stripped image or bounded text content is processed through the same provider categories. The original filename is replaced with a neutral name before transport, RescueForge does not create a stored Base44 file object, and only the editable draft you explicitly save through the workout builder becomes a WorkoutPlan record. Open-Meteo receives coordinates only when you request local weather. Static recipe images can be requested from Unsplash. A reviewed exercise demonstration can connect to YouTube's privacy-enhanced service only after you choose to load it. The App Store launch edition does not expose expanded shared roster, event, equipment-request, messaging, or shift-coverage operations to ordinary accounts. Those collaboration paths remain in controlled administrator testing until their multi-account authorization and user-content safety controls are complete. Historical shared records remain subject to our retention and deletion procedures until verified deleted. Personal shift-context estimates and substance repeat shortcuts are not shared with a crew or department through these collaboration features. We may disclose information when required by law, to protect users or the service, or as part of a business transfer. We do not currently use RescueForge data for cross-app advertising tracking or sell personal data.

5. Account Deletion

You may initiate permanent account deletion from the app's Settings page. After the request is recorded, RescueForge attempts to clear account-scoped personal app data stored on the device used to submit it and reports whether the browser confirmed that cleanup. Another signed-in device clears its RescueForge app data after it reconnects and the deleted or invalid session is rejected; an offline device cannot be erased remotely before it reconnects. We begin processing authenticated deletion requests promptly and set an initial operational target seven calendar days after the request. A provider recovery period can require more than 30 days from the last deletion action and can restart if a late account-linked record is found. Ownership transfer, billing, or legally required retention can also take longer. Support will provide updated timing instead of claiming completion early. We delete the account and associated personal data, including posts and messages you authored and the uploaded photos, audio, attachments, or other managed file objects tied to those records. We also remove your memberships, reactions, and other account-linked participation data. We do not record completion until the underlying managed file objects are verified removed or verified not applicable, every account-data sweep has been repeated after account and session removal, and no unexplained match remains. If Base44 places a deleted custom record in its Recently Deleted recovery state, we treat that record as recoverable rather than permanently deleted. The request remains processing until a permanent purge is verified or the provider recovery window ends. A single recovery window can take up to 30 days, but the full request can take longer for the reasons described above. We will update you if processing extends beyond the initial target. For an account that historically used Sign in with Apple, we also require provider-confirmed authorization revocation or verified evidence that it does not apply. We may anonymize a retained shared record only when retaining that record is necessary for an ongoing crew or department operation affecting other members, or for a required financial, legal, security, fraud-prevention, or dispute obligation. In those cases, we remove account identifiers and do not retain authored content or uploads merely for historical convenience. You will receive confirmation when the request is recorded, an initial target date with timing updates, and a separate confirmation after processing is complete.

6. Contact Us

If you have questions or comments about this Privacy Policy, please contact us at: support@rescueforge.com

7. Data Retention

We retain personal data while your account is active and as needed to provide the service. Nutrition-label and workout-import photos are re-encoded on the device to remove embedded metadata; workout text is bounded and repackaged under a neutral filename. These sources are sent as in-memory request data for analysis. RescueForge does not create or retain a Base44 file object for a scan, attach a source to the saved record, or automatically save the returned draft. Base44 and its model providers may process or retain request data under their applicable service and privacy terms. Content-free nutrition-assistant and workout-import usage records are marked for expiry after approximately 24 hours, with scheduled hourly cleanup. A protected, server-only per-account quota record retains fixed-window counters, bucket timestamps, the last-request timestamp, and integrity metadata while the account is active; expired buckets no longer limit a later window and are overwritten when a later request initializes the current bucket. That linked quota record is deleted with the account and checked again during the post-account deletion sweep. Protected legacy quota fields may remain on an older account record, are no longer used for admission, and are removed with the account. A separate app-wide operational counter has no requesting-account identifier in its custom fields. Base44 may attach operational creator or request metadata, which is audited under our retention and deletion process. Content-free department invite-attempt security records are marked for expiry after 30 days and have a scheduled daily cleanup; account deletion must remove any remainder. An adaptive training check-in expires for purposes of creating or starting a recommendation, but the account-linked check-in and recommendation records may remain stored until they are removed under our retention process or your account is deleted. After an authenticated deletion request, associated personal data is deleted or anonymized from active systems as soon as reasonably practicable and within applicable legal deadlines, except limited records retained as required by law or for legitimate security, fraud-prevention, dispute, necessary shared-operation, or financial obligations. Retained anonymized records are limited to what is necessary for those operational or financial purposes; authored posts, messages, and their uploads are deleted rather than retained as attributed history. After completion, RescueForge replaces the explicit account ID and email fields in the deletion queue with nonidentifying placeholders. The minimized completion record can still contain Base44-generated operational metadata and the limited evidence fields described here; it is assigned a deletion deadline 365 days after completion and is then removed through an operator-controlled review. If an approved external evidence case was required, it follows the same 365-day maximum unless a documented legal requirement requires longer retention. A queue or evidence record that Base44 places in Recently Deleted can remain recoverable for up to 30 additional days before permanent purge. RescueForge does not claim that this evidence cleanup is automated. Leaving a department removes future workspace access but does not automatically delete messages, events, or equipment requests already shared with that department. Those shared records may be retained, deleted, or anonymized under the department and account deletion processes. The app attempts to clear limited active-workout and network-retry data on the requesting device when the deletion request is recorded and shows a warning if the browser cannot confirm removal. Account-scoped data on another device is cleared when that device next reconnects and its invalid session is detected.

8. Security

We use administrative, technical, and organizational safeguards intended to protect personal data. No internet service can guarantee absolute security. Keep your sign-in credentials private and contact us if you believe your account has been compromised.

9. Your Rights

You have the right to access, correct, or delete your personal data at any time. You may submit a data deletion request through the app's Settings page or by contacting us at support@rescueforge.com. You may also withdraw nutrition-AI sharing consent from Settings; withdrawal prevents new nutrition-AI requests but does not alter nutrition entries you previously reviewed and chose to save. Workout importing uses a separate per-request disclosure and confirmation; you can decline it and continue building workouts manually.

10. Children's Privacy

RescueForge is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by updating the date at the top of this page.