Privacy Policy

Last updated 18 August 2026

TrailForge is a training app for endurance runners. This page explains exactly what it collects, why it needs it, who else sees it, and how to get it removed. It is written to be read, not to be survived.

The short version. TrailForge contains no analytics, no crash-reporting and no advertising software of any kind. Nothing you do in the app is tracked for marketing, profiling or resale. The only data leaving your phone is what the app needs to work: your training, and the accounts you deliberately connect.

Who we are

TrailForge is developed by Byte-Sized Systems. For any privacy question, or to have your data corrected or deleted, contact support@trailforge.run. We aim to respond within 30 days.

What we collect

Account

You can use TrailForge as a guest, in which case we hold only an anonymous account identifier — no name, no email address. If you sign in with Apple or Google we receive the identifier that provider gives us, plus your email address and, where you allow it, your name. There is no email-and-password sign-in, so we never receive or store a password.

Your athlete profile

Date of birth, gender, body weight and heart-rate zones — all optional, all entered by you. These are used to estimate training zones and to size fuelling recommendations. Body weight in particular is used to scale fluid targets; nothing about it is shared.

Training data

Route and activity data is location data, and it is often sensitive: a route that starts at your front door reveals where you live. It is stored against your account and is never published, shared with other users, or made searchable. TrailForge has no social feed, no friends list and no leaderboards.

Subscription

If you subscribe to TrailForge Pro, we record that the subscription is active and when it renews or lapses, so the app knows what to unlock. Apple handles the payment: we never see your card, your billing address or your Apple Account credentials.

Notifications

If you allow notifications, Apple issues a device token that we store so we can send you session reminders and trigger background syncing. It identifies the installation, not you.

Device integrity

TrailForge uses Apple's App Attest to confirm that requests come from a genuine, unmodified copy of the app before the server will release configuration such as third-party client identifiers. This produces a cryptographic attestation, not a device fingerprint, and it is not used to identify or track you.

What we deliberately do not collect

Who processes your data

ServiceWhat it handles
Microsoft AzureHosts the TrailForge backend and database, where your account and training data are stored.
Google Firebase AuthenticationVerifies who you are. Holds your account identifier and, if you signed in with Apple or Google, your email address.
MapboxServes map tiles, snaps drawn routes to real paths, and supplies terrain elevation. Receives the map areas and route coordinates needed to answer those requests.
Apple WeatherKitSupplies forecasts. Receives the coordinates and times of the sessions being forecast. Apple states WeatherKit does not associate requests with a user identity.
Apple Push Notification serviceDelivers notifications to your device.
EmailOctopusOnly if you join the launch mailing list on this website. Holds that email address and sends the announcement. Nothing from the app reaches it.
RevenueCatKeeps track of whether your TrailForge Pro subscription is active. Receives your account identifier and the receipt Apple issues for the purchase. It never sees your payment details — those go to Apple and never reach us either.
Garmin / StravaOnly if you connect them. They send us the activities and routes you have recorded there. See Garmin data and Connecting Strava.

These are processors acting on our instructions, not independent recipients, and none of them receives your data for their own marketing.

Garmin data: what we collect, how we use it, and who touches it

Connecting Garmin Connect is entirely optional. You authorise it on Garmin's own screen, and TrailForge never sees your Garmin password. Nothing in this section applies unless you have connected Garmin Connect yourself.

What Garmin data we collect

When you connect Garmin Connect, and for as long as it stays connected, we receive the activities you record:

On first connecting we also import your last 90 days of activities, so the app is useful immediately rather than empty until your next run. Heart rate is health data, and the GPS trace is sensitive location data — a route starting at your front door reveals where you live. We treat both accordingly.

How we use it

Garmin data is used only to provide the app to you: to display your activities, and to compute the views built from them — your training statistics and weekly volume, activity comparisons, shoe mileage, and matching completed runs to the sessions in your training plan. Every one of those figures is produced by ordinary deterministic code running on our own systems. We do not use Garmin data for advertising, we do not sell it, and we do not make it available to other users. TrailForge has no social feed, no friends list and no leaderboards.

How it is processed and stored

Activities arrive from Garmin at our backend, which normalises them into our own format and stores them in our database. Everything runs on Microsoft Azure: the backend in the West Europe region (Netherlands), and the database holding your activities in the Switzerland West region. Switzerland is recognised by the European Commission as providing an adequate level of data protection, so data may be held there without additional transfer safeguards. Activities are stored per athlete, encrypted at rest, and reachable only by an authenticated request carrying your own account's token.

The OAuth access tokens that let us talk to Garmin on your behalf are held only on our server, encrypted, in a store that the app itself cannot read. They are never written to your athlete profile and never sent to your phone.

Third parties, and the use of AI

Garmin data is not shared with, sold to, or disclosed to any third party for their own purposes. It is handled by the following service providers, who act only on our instructions and only to make the app work:

ProviderWhat it receives
Microsoft AzureHosts our backend and database, and therefore stores your Garmin activities. Also collects operational telemetry (request timing and errors) used to keep the service running.
Apple WeatherKitReceives the coordinate and time an activity started, in order to return the weather at that moment. It receives a location and a timestamp — not your activity, your identity or your Garmin account. Apple states WeatherKit does not associate requests with a user identity.
Apple Push Notification serviceDelivers the notification telling you an activity is ready. The notification carries an identifier so the app can open the right activity — not the activity's contents.
MapboxSupplies the map tiles your activity is drawn on. The route itself is drawn on your device; your Garmin activity trace is not sent to Mapbox.

Google Firebase Authentication and RevenueCat appear elsewhere in this policy because they handle your sign-in and your subscription. Neither receives any Garmin data.

No artificial intelligence, machine learning, or model-training service processes Garmin data. We do not send Garmin data to any AI or large-language-model provider, we do not use it to train models of our own, and we do not permit any third party to use it for training. Every training insight, recommendation and statistic in TrailForge is computed by deterministic, rule-based code that we wrote and run ourselves.

Data we send back to Garmin

Two optional, off-by-default settings let TrailForge write to Garmin Connect: routes you have drawn can be sent as courses, and workouts from your training plan can be sent to your Garmin calendar. Both are yours to switch on and off at any time in the app.

Keeping it, and getting rid of it

Connecting Strava

Connecting Strava is likewise optional and authorised on Strava's own screen; we never see your Strava password. Strava sends us the activities you have recorded there, and routes where it supplies them. Strava is import-only — TrailForge never writes anything to Strava. Strava data is collected, used, stored, retained and deleted exactly as described for Garmin above, is subject to the same statement on third parties and AI, and its access tokens are held under the same server-side encryption.

Legal basis and retention

Where the UK and EU GDPR apply, we process your data to perform the contract you enter into by using the app, and on the basis of your consent for the optional parts — connecting a provider, allowing notifications, allowing location while using maps. Health-related data such as heart rate is processed on the basis of your explicit consent, given by choosing to connect a provider or enter it yourself. You may withdraw consent at any time by disconnecting the provider or contacting us.

We keep your data for as long as your account exists. Delete your account and it is removed from our systems, with routine backups aging out within 30 days.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to that use. You can also complain to your national data protection authority — in Norway, Datatilsynet.

Deleting your account. Open Profile → Account → Delete Account. If you signed in with Apple you will be asked to authenticate once more, after which we revoke the Sign in with Apple grant, erase everything held against your account on our servers, and delete the sign-in record itself. It is immediate and it is not reversible — there is no grace period, and nothing is kept that we could restore you from. Routine backups age out as described above.

There is no self-service data export yet. Until there is, email support@trailforge.run from the address on your account — or, if you are a guest, from the app — and we will send you a copy within 30 days at no charge.

Children

TrailForge is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.

International transfers

Our infrastructure is operated in Europe: application servers in Microsoft Azure's West Europe region (Netherlands), and the database in Azure's Switzerland West region. Switzerland sits outside the EEA but holds a European Commission adequacy decision, so no additional transfer safeguard is required for data held there. Some processors listed above are US-headquartered and may process data outside the EEA under Standard Contractual Clauses or an equivalent safeguard.

This website

trailforge.run is a static site with no cookies, no analytics, no tracking pixels and no third-party fonts or scripts. Nothing is stored in your browser, so there is no consent banner to dismiss. Our host records standard server access logs, including IP addresses, for security and reliability.

One thing on this site does collect something: the mailing list. It changes nothing above — the form posts straight out and still sets no cookie and loads no third-party script — but before TrailForge is released you can leave your email address to be told when it goes on sale, and to hear from us occasionally afterwards. That address is the only thing collected, and it is stored with EmailOctopus, our email provider. We never share or sell it.

Expect the launch announcement, then a handful of emails a year: product news when something significant ships, and occasionally an offer. That is the whole of it — no drip campaign, and we don't mail you about anything else. You tick a box to say yes before any of it, and the box is not pre-ticked.

A mailing-list address is kept separately from any TrailForge account and is not connected to one. Signing up for it does not create an account, and deleting your account does not remove you from the list — unsubscribe separately if you want both gone.

Changes

If this policy changes in a way that materially affects you, we will say so in the app — or by email, if the mailing list is the only way we know you — before the change takes effect. The date at the top always reflects the current version.