Legal
Foreshape Privacy Policy
Effective date: June 24, 2026 · Last updated: August 3, 2026
Foreshape ("Foreshape", "we", "us") is a fitness progress visualization app for adults. It helps you preview a possible future body shape based on your own photo and the workout/nutrition data you enter. Foreshape is not a medical service and does not provide medical advice, diagnosis, or guaranteed results.
This policy explains what we collect, why, who we share it with, and your choices. Questions: support@getforeshape.com.
Who can use Foreshape
Foreshape is intended only for adults 18 and older. We do not knowingly collect data from anyone under 18. The app asks for your date of birth and blocks users under 18.
What we collect
We collect only what's needed to run the app:
- Account data — the email address you sign up with (via our auth provider, Supabase). Used to create and secure your account.
- Your photo — the full-body photo you voluntarily choose for a preview, including the facial appearance that is naturally visible in that photo.
- Body & activity data you enter — e.g. height, weight, waist, age, sex, goal, and daily workout/nutrition logs (workouts, meals, calories, macros, sleep, steps). Some of these are optional.
- Identifiers — your account user ID, a randomly generated install ID, and your device's vendor identifier (used only to associate render jobs with your device and to administer free-trial credits).
- Device settings — non-personal preferences (units, age-gate flag) stored locally on your device.
We do not collect location, contacts, browsing history, or advertising identifiers, and we use no third-party analytics, tracking, or advertising SDKs.
Face data and uploaded photos
For purposes of this policy, face data means only the visible appearance of your face as part of the photo you voluntarily select and the private preview images generated from it. Foreshape does not extract or store separate face geometry, landmarks, faceprints, embeddings, biometric templates, or facial recognition identifiers. We do not use face data to identify or authenticate you.
Your selected photo stays on your device until you tap Allow & Generate. Before the first remote preview, the app asks for your clear permission to send the selected photo, including visible facial features, and a simplified summary of your profile to Foreshape and its AI and cloud service providers. You may decline without sending the photo.
We use the uploaded photo and visible facial appearance only to:
- check whether the submitted image complies with our safety rules;
- generate the private fitness-goal preview you requested; and
- keep the generated preview depicting the same person rather than replacing the person's identity.
The photo and visible facial appearance are processed by the following service providers solely to provide those functions:
- Alibaba Cloud (United States) hosts the Foreshape backend that securely receives and routes the preview request.
- Google (Gemini API) performs image-safety review and generates the requested preview. We use Google's paid Gemini API. Under Google's paid API terms, submitted photos are not used to train or improve Google's models. Google may retain limited API logs for a limited period for abuse monitoring, safety, and legal compliance under its terms.
- Supabase (United States, us-west-2) stores the selected reference photo and generated previews in a private storage bucket. The app accesses them using short-lived signed URLs.
Foreshape does not sell face data or share it with advertisers, advertising networks, data brokers, analytics providers, or social networks. We do not use it for advertising, marketing, user profiling, model training, or public examples.
Foreshape retains the selected reference photo and generated previews until you delete your account; there is no separate face template or biometric record. You may withdraw permission for any new remote photo processing in My → Privacy & Data. Withdrawing permission stops new uploads but does not delete previously generated content. To delete stored photos and previews, use My → Delete Account or contact support@getforeshape.com. Account deletion removes the account and associated forecast records, reference photos, and generated images from systems controlled by Foreshape on a best-effort basis. Limited provider security logs and routine backups expire under the applicable provider retention schedules.
How your data is processed
- Most of your body/activity data stays on your device until you explicitly request a remote preview render.
- When you request a preview, your photo and a structured summary of your data are sent over an encrypted (HTTPS/TLS) connection to our backend, which generates the comparison image using a third-party AI image model (Google Gemini). Generated images and your reference photo are stored in a private storage bucket and served to your app via short-lived signed URLs.
- Foreshape's backend and private application storage are located in the United States. Our service providers may process limited data in other locations where they operate, as described in their terms and privacy documentation.
How we use your data
Only to: create/secure your account; compute your forecast; generate and show your before/after preview; process subscription and purchase entitlements; and operate, debug, and secure the service.
We never use your body photos or personal data for advertising, for training AI models, or as public examples.
Who we share it with (sub-processors)
We share data only with service providers that help us run the app, under their terms:
- Supabase (United States, us-west-2) — authentication, database, and image storage.
- Google (Gemini API) — generates the preview image from your photo + forecast and performs image-safety review. We use the paid Gemini API; under Google's paid API terms, your inputs are not used to train or improve Google's models. Google may retain limited API logs for a limited period for abuse monitoring, safety, and legal compliance.
- Alibaba Cloud (United States) — hosts our backend application.
- Apple — processes subscription and in-app purchases; we receive purchase status but not your payment-card details.
We do not sell your personal data.
Retention & deletion
- We keep your account, selected reference photo, and generated previews until you delete your account.
- You can delete your account in-app (My → Delete Account). This permanently deletes your account and associated forecast data and images on a best-effort basis, and removes your auth user.
- Routine backups and operational logs are retained only for a limited period for security, troubleshooting, and abuse prevention, then rotated out.
Security
Data in transit is protected with HTTPS/TLS. Your session token is stored only in the device keychain. No method is 100% secure, but we take reasonable measures to protect your data.
Your choices and rights
You can access, correct, or delete your data at any time using in-app account deletion (My → Delete Account) or by contacting support@getforeshape.com. California residents may have additional rights regarding their personal information under California law; contact us at the same address to exercise them.
Where Foreshape is offered
Foreshape is offered to users in the United States. Foreshape's backend and private application storage are in the United States; service providers may process limited data in other locations where they operate, as explained above.
Changes
We may update this policy; we'll change the "Last updated" date and, for material changes, provide in-app notice.
Contact
Foreshape — an independent developer — support@getforeshape.com