Legal

Privacy Policy

Last updated: July 15, 2026

This Privacy Policy explains how Dual-Forge collects, uses, stores, and protects information when you visit the website, create an account, or use Dual-Forge features.

1. About Dual-Forge

Dual-Forge is a habit-building and habit-breaking platform currently available in Open Beta.

2. Information you provide

Depending on how you use Dual-Forge, information you provide may include:

  • Your email address, used to create and sign in to your account.
  • A password you choose during sign-up. Passwords are processed by our authentication provider and Dual-Forge staff cannot view your password.
  • Profile fields you fill in, such as a display name or timezone, where offered.
  • Messages, feedback, bug reports, or privacy and account requests you voluntarily send to Dual-Forge Support.

3. Authentication and account information

Dual-Forge uses Supabase to handle account creation, email confirmation, sign-in sessions, password recovery, and the internal identifiers that tie your account to your profile. Your email and hashed authentication credentials, along with a short profile record, are stored in the Dual-Forge database operated on Supabase.

Google Sign-In is offered as an optional way to create or access your Dual-Forge account. If you choose Continue with Google, Google shares your email address, basic profile information, and a stable provider identifier with Dual-Forge through Supabase Auth so we can create or sign you in. We do not receive your Google password. Google's handling of your information is governed by Google's own privacy practices.

4. Your habit data

Your habits, check-ins, and daily notes are stored in the Dual-Forge cloud database against the currently signed-in account and are synchronized across every device you sign in on.

What that means in practice during Open Beta:

  • Signing in on any browser or device will show the same habits, check-ins, and notes tied to your account.
  • Signing out of Dual-Forge does not delete your habits — they remain in your account and reappear when you sign back in.
  • When your Dual-Forge account is deleted, its habits, check-ins, and notes are removed from the cloud database automatically.
  • Your browser is not the authoritative source of your habit data — it may be used internally for temporary caching or one-time migration of data created before cloud sync launched.

5. Community progress totals

When you complete a successful daily check-in — a Build habit marked completed, or a Break habit marked avoided — Dual-Forge records a protected event in its database. These raw event records are not shown publicly.

Public "Habits Built" and "Habits Broken" totals on the site are calculated as aggregate counts across all users. Duplicate events for the same habit and date do not increase the totals.

Public totals reflect activity inside Dual-Forge and do not independently verify real-world behavior. If you delete your account, the association between historical counter events and your user ID may be removed while a de-identified record of the event is retained so that lifetime aggregate totals remain accurate. Because events are tied to a user ID before deletion, they are pseudonymous rather than anonymous.

6. Automatically processed technical information

When you use Dual-Forge, limited technical information is processed to make the service work and to keep it secure. This may include:

  • Authentication session data stored in your browser so you stay signed in.
  • Limited local browser storage used internally for performance, cached community totals, and a queue of pending counter events. This local storage is not the authoritative source of your habit data.
  • Essential technical information — such as your IP address, browser type, and request logs — that our hosting, authentication, and database providers process to deliver and secure the service.

Dual-Forge does not currently use advertising cookies, third-party analytics trackers, tracking pixels, or cross-context behavioral advertising technologies, so no consent banner is shown for those categories.

7. How information is used

Dual-Forge uses information to:

  • Create and maintain your account.
  • Authenticate you and keep sessions secure.
  • Send confirmation and password-reset emails.
  • Provide habit-tracking features.
  • Calculate aggregate community progress totals.
  • Secure and troubleshoot the service.
  • Respond to your support and privacy requests.
  • Improve the Open Beta based on real-world usage and feedback.

8. Service providers

Dual-Forge relies on the following third-party providers to deliver core functionality:

  • Supabase — hosted authentication, database, and transactional authentication email delivery (such as confirmation and password-reset emails).
  • Our hosting provider — serves the Dual-Forge website and processes standard request information such as IP addresses in the ordinary course of delivering web traffic.

These providers process information under their own terms and privacy practices. Dual-Forge does not share your personal information with providers beyond what is necessary to run the service.

9. Advertising and sale of personal information

Dual-Forge does not sell personal information and does not currently use personal information for cross-context behavioral advertising.

10. Data retention

Different types of information are retained differently:

  • Account and profile information is retained while your account exists.
  • Authentication and security logs kept by our providers are retained according to those providers' policies.
  • Transactional email records (such as confirmation and password-reset emails) are retained by our email provider as needed to deliver messages and troubleshoot delivery issues.
  • Cloud habit data (habits, check-ins, and daily notes) is retained while your account exists.
  • Any local browser cache of your habit data is short-lived and refreshed from the cloud on each page load.
  • Support correspondence is retained as needed to answer your question and keep a record of the request.
  • Aggregate community counter events may be retained indefinitely; if your account is deleted, the association between those events and your user ID may be removed while the de-identified events remain so lifetime totals stay accurate.

11. Account deletion and privacy requests

Self-service account deletion is not yet available in the Dual-Forge interface. To request deletion of your Dual-Forge account, or to make another privacy request, contact Dual-Forge Support (see Get Support).

When your account is deleted:

  • Your account and profile records are removed from the Dual-Forge database.
  • Historical community counter events tied to your user ID may be updated to remove that association, leaving a de-identified record so aggregate totals remain accurate.
  • Your habits, check-ins, and daily notes stored against your account are removed from the Dual-Forge cloud database.
  • Any cached copy on your device is not affected by cloud deletion; clearing your Dual-Forge site data in your browser removes any residual local cache on that device.
  • Limited records may be retained where necessary for security, fraud prevention, or to comply with legal obligations.

Dual-Forge does not promise immediate deletion. Requests are processed manually during Open Beta.

12. Security

Dual-Forge uses reasonable technical and organizational safeguards, including authentication and database access controls provided by Supabase, to help protect account information. No online service can guarantee perfect security, and Dual-Forge does not claim end-to-end encryption or immunity from breaches.

13. Children's privacy

Dual-Forge is not directed to children under 13. Users under 13 may not create an account or provide personal information through the service. If you are between 13 and the age of legal majority in your location, you should use Dual-Forge only with the permission of a parent or guardian where required by law.

A parent or guardian who believes a child under 13 has submitted personal information may contact Dual-Forge Support so the information can be removed.

14. International users

Dual-Forge is operated from the United States. If you access the service from another country, your information may be processed in the United States or in other locations where our service providers operate.

You may submit access, correction, deletion, or other privacy questions through Get Support.

15. Changes to this Privacy Policy

Dual-Forge may update this Privacy Policy as the Open Beta, data practices, providers, or legal requirements evolve. When changes are made, the "Last updated" date at the top of this page will be revised.

16. Contact

For privacy questions or requests, please use Get Support. You can also review the Terms of Service for how Dual-Forge is provided during Open Beta.