Legal
Privacy Notice
Last updated: 3 September 2026
Privacy Notice version 2026-09-03
Who we are and what this notice covers
Daily Forge is operated by NOVALK TECHNOLOGIES LTD, company number 16648348 ("we", "us", "our"). We are the controller for the personal data described here. Our registered office is 45 Blackthorn Road, Bristol, England, BS13 0AL.
For privacy questions or requests, email privacy@novalktechnologies.com. For everything else, email support@novalktechnologies.com.
This notice covers the Daily Forge web app and its public pages. It sits alongside our Terms of Use, Cookie Notice and AI Disclaimer.
The current free release
Daily Forge is currently free. There is no checkout, no subscription purchase and no trial, and we do not ask for or collect payment card details. There is no newsletter or marketing signup, and creating an account is not marketing consent.
Categories of personal data
- Account, authentication and session data: your email address, the sign-in method you use, and session tokens managed by our authentication provider. Your account's authentication metadata also stores an acceptance record: the confirmation that you are 18 or over, the Terms of Use and Privacy Notice versions you accepted, and the timestamp of that acceptance. That record is an attestation you make — it is not proof of age, and we store no date of birth.
- Profile and planning preferences: the working preferences you set during onboarding and in settings.
- Tasks, habits and Parking Lot items you create.
- Morning Forge source records, Daily Plans, Rescue sessions and Evening Reviews.
- Generated outputs and structure: the AI output saved to your history, plus dates, completion state, links between records, and operational counts of AI usage used to apply fair allowances.
- Technical, security and error data that our hosting, database and gateway providers necessarily process to serve requests and keep the service secure.
- Emails you choose to send us: if you email support or privacy, we receive your message and the address you sent it from.
Historical-only legacy billing identifiers. Some accounts created before this release may still hold a legacy subscription status record and, where a past sandbox billing test was carried out, the retained historic sandbox customer and subscription identifiers from that test. These are historical records from testing. They are not a purchase, not an active payment path, and no card number is or was stored by us.
Where the data comes from
- Mainly from you, when you create an account and use the app.
- From service and AI records created as you use features (for example a saved plan, a review, or a usage count).
- Technical data generated automatically when your browser communicates with our providers.
- Basic account information from your chosen sign-in provider, only if you use a provider sign-in instead of a password.
We do not buy data and we do not enrich your account from data brokers.
Sensitive information and legacy fields
Daily Forge is built for practical task, schedule and workload information. Please do not enter:
- Medical or mental-health information, diagnoses or treatment details
- Information revealing protected traits or other special-category data
- Biometric data
- Bank, card or other payment details
- Government-issued identifiers or identity documents
- Passwords, API keys or other secrets
- Another person's sensitive information
The current app does not ask for this information and does not intentionally use it. It applies a narrow, high-confidence phrase precaution to a small number of free-text fields before submission. That precaution is a blunt safeguard, not comprehensive crisis detection: it can miss things and can over-trigger.
Deprecated wellbeing and legacy-labelled fields. To be straightforward with you: older versions of Daily Forge used emotional_state, health_commitment, and energy/mood-labelled fields (energy / current_energy, end_mood / end_energy) as wellbeing and physical-energy inputs. Those old meanings are retired — the current app does not ask wellbeing questions — but the fields are not wholly unused: values entered under the old meanings may remain in account-scoped storage pending a controlled deletion decision, and some legacy-labelled columns are still used for compatibility. Where a compatibility column is used today, it may store only a neutral, allow-listed plan-load code (Light / Balanced / Full) describing how full a plan you asked for. Only that allow-listed workload value — never a deprecated wellbeing meaning — is eligible for the current AI payload. You can ask us to delete the historical values at any time.
Why we process data, and our lawful bases
- Performance of a contract: creating and running your account and providing the core service you ask for, including generating and saving the plans and reviews you request.
- Legitimate interests: operating the service securely and reliably, preventing abuse, applying fair operational usage allowances, and establishing, exercising or defending legal claims.
- Legal obligation: handling rights requests, complaints and records we are required to keep.
- Consent: only for optional technologies and any future marketing. Those are disabled in this release, so we are not relying on consent for them today.
AI processing
AI generation is always started by you. When you generate a Daily Plan, a Rescue session or an Evening Review, a restricted set of inputs, summaries and titles is sent through our AI gateway and model infrastructure. The relevant source record and the returned output are stored in your Daily Forge history in our database infrastructure.
What can be sent is enumerated from the exact allow-listed payload builders in the application code, so this list matches what the code can actually transmit:
- Daily Plan: your fixed-option planning preferences (planning tone, planning struggle, selected life areas) and your saved wake and sleep times where used; from the day's check-in, your selected day mode, planning notes, available hours, the selected plan load (Light / Balanced / Full), your constraints and appointments, non-negotiables, must-do items and the one win you want; your current task titles with their allow-listed priority and estimated minutes; your habit titles with their allow-listed frequency; and — only if you enable it for that plan — your open Parking Lot titles.
- Rescue: the selected operational reason, what changed, time left, the remaining plan load, what you completed so far, what still must happen, and a limited summary of the selected daily plan: its mission, priority titles, the labels of its time blocks together with the task strings listed inside those time blocks, and its final command.
- Evening Review: your completed summary, misses, what changed, wins, lessons, carryovers, tomorrow's first move and completion score; the same limited plan summary; a limited rescue summary (the one saving action and the new final command) when a rescue exists; and your task and habit titles grouped by completed, incomplete or missed status.
The app excludes the following from the AI payload:
- Your name and email address
- Database identifiers
- Your free-text main_goal
- Task descriptions and task categories
- Parking Lot notes
- Any deprecated wellbeing or mood meaning of the legacy-labelled fields — from the compatibility column used today, only the neutral allow-listed plan-load value can be included
Who receives data, and why
We describe our providers by the specific role they perform rather than by brand name:
- Hosting and application runtime infrastructure, which serves the Daily Forge web app and runs its server-side code.
- Database and authentication infrastructure, which stores your account and app records and handles sign-in and session handling.
- AI gateway and model infrastructure, which receives the restricted payload described above only when you invoke a generation.
- Business email infrastructure, only when you choose to email our support or privacy mailbox.
- Payment infrastructure, only in respect of the retained historic sandbox identifiers described above. No payment is taken in this release.
Optional analytics, advertising and marketing tools are disabled in this release, so no data goes to any analytics, advertising or marketing provider. See the Cookie Notice.
International transfers, described honestly
Our providers, and their own subprocessors, may process data outside the United Kingdom. We do not claim a guaranteed processing country or region for any of them, and we will update this notice as our provider arrangements are confirmed.
We would rather say less than overstate. We therefore do not claim UK-only or EU-only hosting, we do not claim a completed transfer-safeguard package or data processing agreement for this route, we do not claim enterprise-grade or full legal compliance, and we do not make claims on our providers' behalf about how prompts are handled or how long they are kept. Where a provider publishes such information in its own notice, that statement is theirs, not a contractual assurance from us. If you want to know which categories of provider are involved before you use a feature, the list above is the complete picture, and you can ask us at privacy@novalktechnologies.com for more detail.
Required and optional information
An email address and password (or a provider sign-in), and the 18+ and legal acceptance confirmation, are required — without them we cannot create or operate an account.
Onboarding is also required before you can use the protected app, and each of its current fields is required: your name, a main goal, a typical wake time, a typical sleep time, a planning struggle, a planning tone, at least one life area, and a default day mode. If you do not complete onboarding, you cannot reach the dashboard or the planning features. Your free-text main goal stays in your profile and is excluded from the AI payload.
Optional: tasks, habits, Parking Lot items, the planning text you put into Morning Forge, Rescue and Evening Review, and the AI-generation actions themselves — you can leave those fields out or simply not generate. If you omit them, those features have less to work with and the AI output will be more generic; nothing else is withheld.
No sale, no active direct marketing
We do not sell your personal data. We do not run direct marketing in this release and we do not send marketing email.
How long we keep data
We keep data against criteria rather than fixed invented periods:
- Account, app content, generated outputs and usage counts: while your account is active and while they are needed to provide the service.
- If you ask us to delete your data or close your account, we act on it, subject to narrow legal, security and legal-claims exceptions and to our providers' backup cycles, which take time to roll over.
- Sessions: until they expire or you sign out.
- Support and privacy emails: while we handle your request, and afterwards only for as long as needed (for example to show how a request was resolved).
- Technical and security logs: on our providers' own schedules.
- Deprecated wellbeing fields and historic sandbox identifiers: only pending our controlled review, unless you ask for deletion sooner or a legal hold applies.
Security
We use authentication, row-level access rules that scope records to your account, transport encryption provided by our platforms, and restricted administrative access. We keep AI payloads to a restricted, allow-listed set of fields. No service can promise perfect security, and we do not claim any certification or audit we have not obtained.
Automated processing
Daily Forge produces automated AI suggestions and keeps automated usage counters. These do not make legal or similarly significant decisions about you, and no such decision is made about you solely by automated means. You decide what to act on.
Your rights
Subject to UK data protection law, you can ask us to:
- Give you access to the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Delete your data
- Restrict how we process it
- Provide portability of data you gave us, where that right applies
- Withdraw consent, where we rely on consent
Email privacy@novalktechnologies.com. We normally respond within one month, and will tell you if we need a lawful extension because a request is complex.
Your right to object
You have the right to object to our processing that relies on legitimate interests, including secure and reliable operation, abuse prevention, fair operational allowances and legal claims.
Tell us at privacy@novalktechnologies.com and explain your situation. We will stop that processing unless we have compelling legitimate grounds that override your rights, or we need to keep processing for legal claims.
Your right to object to direct marketing is absolute. If we ever introduce direct marketing and you object, we will stop entirely, with no balancing test.
Complaints
If you are unhappy with how we have handled your personal data, email privacy@novalktechnologies.com. We will acknowledge your privacy complaint within 30 days, investigate it, keep you informed of progress, and tell you the outcome without undue delay.
You can also complain to the UK Information Commissioner's Office at https://ico.org.uk/make-a-complaint/ or on 0303 123 1113. You do not have to come to us first.
Changes to this notice
We will update this notice as the service and our provider arrangements are finalised, and before we introduce any optional technology or marketing. The version identifier and "last updated" date at the top of this page tell you which version you are reading.
Contact
NOVALK TECHNOLOGIES LTD, 45 Blackthorn Road, Bristol, England, BS13 0AL. Privacy: privacy@novalktechnologies.com. Support: support@novalktechnologies.com.