← forma.coach

Privacy Policy

Last updated: 20 March 2026

Forma reads your Garmin biometrics to generate recovery-adapted workouts. We collect only what we need, we never sell your data, and you can delete everything at any time.

Who we are

Forma ("we", "us") is a fitness coaching service operated by Lokh Prakash Kopparni, trading as Forma, based in the United Kingdom. Our website is forma.coach and our app is at app.forma.coach.

What we collect

Account data: Your email address, used for authentication via magic link. We do not store passwords for Forma accounts.

Garmin biometric data: When you connect your Garmin account, we access your HRV status, Body Battery, sleep score, training load, and recovery time. This data is used solely to calculate your daily readiness score and generate personalised workouts.

Garmin credentials: Your Garmin email and password are used only during the authentication handshake. Your Garmin password is never stored on our servers. We store an encrypted session token to maintain the connection.

Workout history: We store records of workouts generated and pushed to your Garmin device to improve exercise rotation and avoid repetition.

Payment data: Payments are processed entirely by Stripe. We do not see, store, or handle your card number or banking details. We store only your Stripe customer ID to manage your subscription.

How we use your data

What we never do

Third-party services

We use the following services to operate Forma:

Each service processes data under their own privacy policies. We select services that meet appropriate security and data protection standards.

Data storage and security

Your data is stored in a PostgreSQL database hosted on Railway in the EU. All connections use TLS encryption in transit. Session tokens are stored server-side with time-limited expiry.

Data retention

We retain your data for as long as your account is active. If you delete your account or request data deletion, we remove all personal data within 30 days. Anonymised, aggregated data may be retained for service improvement.

Your rights (GDPR)

Under the UK General Data Protection Regulation, you have the right to:

To exercise any of these rights, email us at privacy@forma.coach. We will respond within 30 days.

Cookies

Forma uses only essential cookies and local storage for authentication session management. We do not use analytics cookies, tracking pixels, or any third-party tracking.

Children

Forma is not intended for anyone under the age of 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated via the email address associated with your account. The "last updated" date at the top of this page reflects the most recent revision.


Contact

Data Controller: Lokh Prakash Kopparni, trading as Forma

Email: privacy@forma.coach

Website: forma.coach