01 The short version
In one paragraph
Forge does not collect, transmit, sell or share any personal data. There are no accounts, no advertising, no analytics, no crash reporting and no third-party SDKs. Everything you type into Forge — your projects, tasks, session history and devlog notes — stays in the app's private storage on your own device. Deleting the app deletes all of it.
The sections that follow make the specific disclosures required by the California Online Privacy Protection Act (CalOPPA), the EU and UK General Data Protection Regulation (GDPR), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). Where a disclosure exists only because a statute asks for it, we have said so plainly rather than implying we do more with your data than we do — which is nothing.
02 Who we are
The Prodigal Developers ("TPD", "we", "us", "our") is an independent game development studio based in Olongapo City, Zambales, Philippines, and the developer and publisher of Forge.
For the purposes of the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) we would be the personal information controller for any personal data the app processed; for users in the European Economic Area or the United Kingdom the data controller under the GDPR and UK GDPR; and under the CCPA/CPRA we would be the business. As set out below, Forge processes no personal data, so in practice each of these roles carries none.
Privacy enquiries, and any request under any of the laws named in this policy, go to [email protected].
03 What this policy covers
This policy covers the Forge Android application only. It is separate from, and takes precedence for the app over, the privacy policy for theprodigaldevelopers.com, which governs our website and our early-access sign-ups. If you use both, both apply to their own subject matter.
It does not cover Google Play itself, which is operated by Google and governed by Google's own privacy policy — see Buying the app.
04 Information we collect
None. Forge collects no personal or sensitive user data of any kind.
Specifically, Forge does not collect, and has no ability to receive:
- your name, email address, phone number or any other contact detail;
- account credentials — Forge has no accounts and no sign-in;
- location data of any precision;
- your contacts, calendar, photos, camera, microphone or files;
- device identifiers, advertising IDs or installed-app lists;
- usage analytics, telemetry, event tracking or crash reports;
- payment or financial information.
Why this is verifiable, not just a promise
Forge is built without the Android INTERNET permission. An Android
app cannot open a network connection without it, so Forge has no technical means
of sending anything anywhere — to us or to anyone else — regardless of what it
might be asked to do. You can confirm this yourself: the permission list on the
app's Google Play listing, or any APK inspection tool, will show that
android.permission.INTERNET is absent.
Because there is no collection, there are no categories of sources from which we obtain personal information, and no business or commercial purpose for collecting it, in the sense those terms are used in the CCPA/CPRA. The itemised statutory categories are set out in Notice for California residents.
05 What Forge stores on your device
Forge keeps everything you create in a single file inside the app's private storage area, which on Android is readable only by the app itself:
- projects, milestones and deadlines you enter;
- tasks, their disciplines, estimates and completion state;
- your finished focus sessions, and any devlog notes you write on them;
- your settings — chosen ritual, daily goal, sound, haptics and display preferences.
This data never leaves your device. We cannot see it, and we have no server that could receive it. It is not "collected" by us under any of the laws named here, because it is never transmitted to or accessible by us.
If you use Android's own backup features, your device may include this file in a backup you control under your Google account. That is a function of your device and your Google settings, not of Forge, and is governed by Google's privacy policy.
06 Permissions and why
Forge requests only the permissions needed to be a reliable timer. None of them grants access to personal information.
| Permission | Why Forge needs it |
|---|---|
POST_NOTIFICATIONS |
To tell you a focus block or break has ended while the app is closed or your phone is face down. |
USE_EXACT_ALARM |
A block has to end at the moment it ends, not whenever the system next happens to wake. This is the alarm-and-timer permission, and exact timing is the entire function of the app. |
SCHEDULE_EXACT_ALARM |
The Android 12 equivalent of the above. Requested only on Android 12 and earlier. |
VIBRATE |
Haptic feedback when a phase changes or you complete a task. |
WAKE_LOCK |
To keep the screen awake during a focus block, so the dial stays glanceable on your desk. Optional, and off unless you enable it in Settings. |
RECEIVE_BOOT_COMPLETED |
To restore a pending end-of-block alert if your device restarts mid-session. |
Forge does not request internet access, location, contacts, storage, camera, microphone, or any other permission that touches personal data.
08 Third-party services
Forge contains no third-party analytics, advertising, attribution, crash-reporting or social SDKs. The app is built with Flutter and uses only open-source components that run entirely on-device: local notifications, audio playback for the end-of-block chimes, screen wake-lock, and local file storage. None of them communicates over a network in Forge, and none could, absent the internet permission.
For CalOPPA purposes: no third parties collect personally identifiable information about your online activities over time or across third-party websites or online services through Forge. The app contains no trackers, pixels, beacons, fingerprinting or cross-app identifiers of any kind.
09 Buying the app
Forge is a paid app with no in-app purchases, subscriptions or advertising. Your purchase is processed entirely by Google Play. We never see your payment details; we receive only aggregate sales and payout reporting from Google, which does not identify individual buyers to us.
Google's handling of your purchase — including any personal and payment data you give it — is governed by the Google Privacy Policy, not by this one. Requests about that data should be directed to Google.
10 Do Not Track and Global Privacy Control
California law (Cal. Bus. & Prof. Code § 22575(b)(5), added by AB 370) requires us to disclose how we respond to "Do Not Track" browser signals and to other mechanisms that give you a choice about the collection of personally identifiable information across sites and over time. Our answer:
Nothing to honour, nothing to ignore
Forge does not track you, in any sense — not within the app, not across apps, and not across websites. It has no browser component, no web view used for content, no network access, and no mechanism that could receive or act on a Do Not Track (DNT) or Global Privacy Control (GPC) signal. Because the app never engages in the tracking those signals are designed to switch off, there is no behaviour for them to change. We do not treat the absence of a signal as consent to anything, because we ask for nothing.
Our website is a separate matter and does respond to your cookie choices; see the Cookie Policy.
11 International transfers
Forge performs no international transfers of personal data. Your data does not leave your device, so it is never exported to the Philippines — where we are based — or anywhere else, and no transfer mechanism is engaged.
For GDPR purposes this means Chapter V (Articles 44 to 49) is not triggered by the app: there is no transfer to a third country, and therefore no adequacy decision, no Standard Contractual Clauses and no derogation to rely on. Should that ever change, we would identify the recipient country and the safeguard relied upon in this policy before the change took effect.
12 Automated decisions and profiling
Forge does not carry out automated decision-making producing legal or similarly significant effects, and does not profile you, within the meaning of Article 22 of the GDPR. It performs no advertising profiling and draws no inferences about you for any purpose outside the app.
The statistics Forge shows you — your discipline split, your peak working hours, your estimate drift — are computed on your device, from your own entries, and shown only to you. They are not transmitted, not used to make decisions about you, and not seen by us.
13 Retention and deletion
Because we hold no data about you, there is nothing for us to retain or delete on our side, and no retention period for us to specify — no personal information is ever in our custody, for any length of time.
You control the data on your own device completely:
- Clear your history — open Settings inside Forge and choose Clear history. This deletes every logged session, note and streak, and cannot be undone.
- Delete everything — Android Settings → Apps → Forge → Storage → Clear storage removes all app data including projects and tasks.
- Uninstall — removing the app deletes its private storage, and with it everything Forge ever held.
Forge itself keeps your entries for as long as you keep them. It never expires, archives or silently prunes your history.
14 How your data is protected
Forge's data lives in the app's private storage directory, which Android isolates from other applications at the operating-system level. It is additionally protected by whatever device encryption, screen lock or biometric you have enabled — modern Android encrypts app storage at rest by default.
Because nothing is transmitted, there is no network channel to intercept and no server of ours to breach. The strongest privacy guarantee we can offer is the one we chose: not to build the pipe in the first place. It also means there is no scenario in which a breach of our systems could expose your Forge data, and so no breach-notification duty could arise in respect of it.
15 Your rights and choices
Privacy laws give you rights that operate against organisations holding your personal data. We hold none from Forge, so in practice there is nothing for you to request from us and no identity for us to verify. Your data is already entirely in your possession, on your own device, and you can inspect or destroy it at any time using the steps in Retention and deletion.
You are welcome to write to us anyway, and we will answer. Region-specific rights and how to exercise them are set out in Notice for California residents and Notice for the EEA and the UK.
How to make a request. Email [email protected] with what you want to know or done. We aim to acknowledge within 10 business days and to respond substantively within 30 days (or 45 days under the CCPA/CPRA, which we may extend once by a further 45 days where permitted, telling you why). There is no charge for a request unless it is manifestly unfounded or excessive, in which case we will tell you before doing anything.
16 Notice for California residents
This section is provided under CalOPPA and the CCPA as amended by the CPRA. We provide it to every California resident who uses Forge, whether or not we meet the CCPA's business thresholds — as a small independent studio we do not currently believe we do, and we make these disclosures regardless rather than rely on that.
Categories of personal information
The CCPA enumerates categories of personal information. For Forge, every one of them is the same answer:
| Statutory category | Collected? | Sold or shared? |
|---|---|---|
| Identifiers (name, alias, IP address, email, account name, device ID) | No | No |
| Personal records under Cal. Civ. Code § 1798.80(e) | No | No |
| Protected classifications under California or federal law | No | No |
| Commercial information (records of products or services purchased) | No | No |
| Biometric information | No | No |
| Internet or other electronic network activity | No | No |
| Geolocation data | No | No |
| Audio, electronic, visual, thermal or similar information | No | No |
| Professional or employment-related information | No | No |
| Non-public education information (FERPA) | No | No |
| Inferences drawn to create a profile | No | No |
| Sensitive personal information (CPRA) | No | No |
Because we collect no sensitive personal information, there is nothing to which the CPRA right to limit the use and disclosure of sensitive personal information could apply, and we do not use or disclose any for purposes requiring that option.
Your California rights
- Right to know — the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties to whom we disclose it. For Forge the answer to all of these is "none".
- Right to delete — to request deletion of personal information we hold about you. We hold none; you can delete your on-device data yourself at any time.
- Right to correct — to request correction of inaccurate personal information. We hold none to correct.
- Right to opt out of sale or sharing — we do neither, so there is nothing to opt out of.
- Right to limit use of sensitive personal information — we collect none.
- Right to non-discrimination — we will never deny you the app, charge you a different price, or give you a lesser experience for exercising any privacy right. Forge behaves identically for everyone.
How to exercise them
Email [email protected] with "CCPA request" in the subject. Because Forge operates exclusively online and we hold no account records, email is the sole method — there is no toll-free number and no account to verify against. We will verify a request only to the extent we can, and if we hold nothing about you we will say so rather than ask you for identifying information we do not need and would not otherwise have.
An authorised agent may make a request on your behalf with written permission signed by you; we may contact you to confirm it.
Shine the Light (Cal. Civ. Code § 1798.83): we disclose no personal information to third parties for their own direct marketing purposes.
17 Notice for the EEA and the UK
This section is provided under the GDPR and the UK GDPR.
Controller and contact
The Prodigal Developers, Olongapo City, Zambales, Philippines — [email protected]. We have not appointed a Data Protection Officer: we carry out no large-scale monitoring and process no special-category data, so Article 37 does not require one. We have not designated an Article 27 representative in the Union or the UK, because Forge processes no personal data of anyone, and so does not engage Article 3(2) through either the offering of goods or services to data subjects or the monitoring of their behaviour.
Purposes and legal bases
Article 6 requires a lawful basis for each processing operation involving personal data. Forge performs none, so no basis is engaged and none is claimed. We do not rely on legitimate interests, consent, contract or any other basis for app data, because there is no processing to justify. Providing data is neither a statutory nor a contractual requirement, and you are not obliged to provide anything to use the app.
Your rights
You have the rights of access (Art. 15), rectification (16), erasure (17), restriction (18), notification (19), data portability (20), objection (21), and not to be subject to automated decision-making (22), together with the right to withdraw consent at any time where processing is based on consent. Since we hold no personal data of yours and rely on no consent, these rights have no subject matter in respect of Forge — but you may still write to us and we will respond.
Complaints
You have the right to lodge a complaint with a supervisory authority — in the EEA, the authority in your country of residence, place of work, or place of the alleged infringement (a directory is maintained by the European Data Protection Board); in the UK, the Information Commissioner's Office; and in the Philippines, the National Privacy Commission. We would rather you told us first, at [email protected].
18 Children
Forge is a productivity tool intended for a general audience and is not directed at children. It collects no data from anyone, children included, and contains no ads, no in-app purchases, no social features, no user-to-user communication and no external links to unmoderated content.
Because nothing is collected, Forge does not knowingly or unknowingly collect personal information from children under 13 — the threshold under the US Children's Online Privacy Protection Act (COPPA) — or under 16, the threshold at which the CCPA requires opt-in consent before any sale or sharing, and at or below which Article 8 of the GDPR conditions a child's consent on parental authorisation. There is no such data for a parent or guardian to review, restrict or request the deletion of. If you believe otherwise, contact us and we will investigate.
19 Changes to this policy
If we change how Forge handles data, we will update this page and change the "last updated" date shown at the top — the method by which we notify you of changes, as CalOPPA requires us to describe.
For a material change — in particular any change that introduced collection, transmission, sale or sharing of data where there is now none — we would additionally:
- state the change in the app's release notes on Google Play before the version making it is released, so you can decide whether to update;
- surface a notice inside the app on first launch of that version;
- update the Google Play Data safety declaration to match, before publishing.
We will not apply a materially different practice to data gathered under an earlier version of this policy without telling you first. This page is the authoritative version; previous versions are not archived publicly, but we will send you one on request.
20 Contact us
Questions about Forge and privacy
The Prodigal Developers
Olongapo City, Zambales, Philippines
We answer privacy questions ourselves — there is no ticket queue. Please allow a few working days. Mark CCPA or GDPR requests as such in the subject line and we will treat them on the timelines in Your rights and choices.