ForceIQ Privacy Policy

Last Updated and Effective: August 4, 2026

Version: 1.1

Thank you for using ForceIQ. This Privacy Policy explains how ForceIQ, LLC ("ForceIQ," "we," "us," or "our") collects, uses, discloses, and protects your information when you use our website, web application, mobile applications, and related services (collectively, the "Service").

ForceIQ processes health, fitness, and biomechanical data that is personal and sensitive. The Service is currently available in the United States and select international markets (excluding the European Economic Area and the United Kingdom). We are committed to protecting your privacy and handling your data responsibly in compliance with applicable law, including the Health Insurance Portability and Accountability Act ("HIPAA") where applicable, the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA"), and the Washington My Health My Data Act ("MHMDA").

Clinical Disclaimer: ForceIQ is not a medical device and has not been evaluated, cleared, or approved by the U.S. Food and Drug Administration or any other regulatory body. The Service is intended to provide data collection and analytical tools for use by qualified clinicians and practitioners. ForceIQ does not diagnose, treat, cure, or prevent any disease or medical condition. All clinical decisions remain the sole responsibility of the licensed clinician or practitioner using the Service.


Table of Contents

  1. Information We Collect
  2. How We Use Your Information
  3. How We Share Your Information
  4. Cookies and Tracking Technologies
  5. Data Security
  6. Data Retention
  7. Your Privacy Rights
  8. HIPAA and Protected Health Information
  9. International Data Transfers
  10. Children's Privacy
  11. Third-Party Payment Processing
  12. Changes to This Policy
  13. Contact Us

1. Information We Collect

Information You Provide

When you register for and use the Service, we collect information you provide directly, including:

Account Information

  • Name (first and last)
  • Email address
  • Password (stored only as an encrypted hash)
  • Professional credentials or license information (for clinician accounts)

Profile and Demographic Information

  • Date of birth
  • Biological sex
  • Organization or practice affiliation
  • Patient name (optional — collected only when a clinic enables PHI collection under an accepted Business Associate Agreement; by default patients are identified by a de-identified code)
  • Patient photograph (optional — a full-face photo is Protected Health Information, collected only under the same PHI opt-in; stored within our HIPAA-covered infrastructure and never shared with analytics or other third parties)

Clinical and Biomechanical Data

  • Force measurement data and biomechanical assessments
  • Range of motion and functional movement data
  • Body measurements (height, weight, body composition)
  • Injury history and rehabilitation status
  • Performance metrics and testing results
  • Session notes and clinical observations

Organization Information (for clinicians and administrators)

  • Practice, clinic, or organization name
  • Role and permissions within your organization
  • Clinician license or credential identifiers

Communications

  • Messages and notes within the Service
  • Clinician notes and patient observations
  • Support inquiries and correspondence

Information Collected Automatically

When you access or use the Service, we automatically collect:

Device and Access Information

  • Device operating system and type
  • Device identifiers
  • Browser type and version
  • IP address

Authentication Security Information

To satisfy the unique-user-identification requirement of HIPAA Technical Safeguards (45 CFR § 164.312(a)(2)(i)) and to detect credential sharing or unauthorized access, ForceIQ records:

  • A non-reversible device fingerprint hash derived from your browser, operating system, and screen attributes (generated locally — not used for cross-site tracking)
  • A list of devices on which your account has been signed in, including a short device label (e.g. "Mac", "iPad") and the most recent sign-in timestamp
  • Per-account login event records (timestamp, device fingerprint, outcome — successful sign-in, signed out due to concurrent session, signed out due to inactivity, multi-factor challenge result)

These records are visible to you and to administrators of your clinic/organization on the Team Management page. They are not shared with PostHog or any third-party analytics service. They are used solely to alert you to unrecognised sign-ins, enforce single concurrent session per User, and surface activity patterns consistent with credential sharing. See our Terms of Service § 3.3.

Usage Information

  • Sign-in timestamps and frequency
  • Features accessed and actions taken
  • Session duration
  • Referring URLs

Analytics Data (PostHog)

ForceIQ uses PostHog for product analytics, collecting pseudonymous usage data to improve the Service:

  • Pages visited and features used (e.g., "uploaded assessment," "generated PDF report")
  • Session frequency, duration, and navigation patterns
  • Error rates and performance metrics
  • Browser type, operating system, and screen resolution

ForceIQ does NOT collect the following in analytics:

  • Patient names, dates of birth, email addresses, or any Protected Health Information
  • Force/torque measurement data, metric values, or clinical notes
  • Assessment file contents or session-level clinical data
  • Precise geolocation (only general location derived from IP address)

Analytics collection requires your consent (provided during onboarding) and can be disabled at any time in Settings. ForceIQ respects the browser Do Not Track (DNT) signal — when enabled, PostHog is not initialized.

Information from Third Parties

We may receive information from third-party services connected to ForceIQ by you or your organization, such as:

  • Bluetooth-connected isometric dynamometers (e.g., Tindeq Progressor, PitchSix Force Board, Squegg) via the Web Bluetooth API
  • CSV data exports from isokinetic dynamometers and other force measurement devices

Future integrations (such as electronic health record systems) will be disclosed here as they become available.


2. How We Use Your Information

We use the information we collect to:

Provide and Operate the Service

  • Create and maintain your account
  • Deliver biomechanical assessment and force measurement tools
  • Enable communication between clinicians and their patients or clients
  • Process transactions and manage subscriptions

Support Clinical Workflows

  • Present assessment data and analytics dashboards to authorized clinicians
  • Generate reports and progress summaries for clinical review
  • Enable data export for integration into clinical records

Improve the Service

  • Analyze usage patterns to enhance features and performance
  • Diagnose technical problems and monitor system health
  • Conduct internal research and development

Product Analytics (PostHog)

We use pseudonymous analytics data to:

  • Identify which features clinicians use most and least frequently
  • Detect upload failures and parsing errors to improve CSV compatibility
  • Measure activation rates (time from signup to first assessment)
  • Monitor free-to-paid conversion signals
  • Diagnose performance issues and user-facing errors

Analytics data is pseudonymized (user IDs are hashed) and is never combined with PHI. Analytics data is not used for advertising, marketing targeting, or behavioral profiling.

Communicate with You

  • Send transactional emails (account verification, password resets, session notifications)
  • Provide customer support
  • Send product updates and announcements (with your consent where required)

Ensure Safety and Security

  • Detect and prevent fraud, abuse, and security incidents
  • Enforce our Terms of Service
  • Comply with legal obligations

3. How We Share Your Information

We do not sell your personal information. We will never sell your personal information. We do not share your personal information for cross-context behavioral advertising.

We share your information only in the following circumstances:

Within Your Organization

If you are part of an organization (clinic, practice, or facility) on ForceIQ:

  • Patients/Clients: Your clinician and authorized administrators can view your assessment data, metrics, session history, and (where authorized) injury and health information.
  • Clinicians: Patients or clients assigned to you can see your name and professional role; administrators can view your activity within the organization.

With Service Providers

We engage third-party companies to perform services on our behalf. These providers are contractually obligated to protect your information and use it only for the services we specify. We maintain data processing agreements with our service providers as required by applicable law.

CategoryProvider(s)PurposeHealth Data Access
Infrastructure & HostingGoogle Firebase / Google Cloud PlatformApplication hosting, data storage, authentication, HIPAA-compliant infrastructureYes — primary infrastructure
Payment ProcessingStripe, Inc.Subscription billing and payment processingNo
Email DeliveryResend (Resend, Inc.)Transactional email delivery (account notifications, report delivery)No
AnalyticsPostHogPseudonymous product usage analytics and event trackingNo
Error TrackingGoogle Cloud LoggingServer-side error detection and debugging (within our HIPAA-covered Google Cloud infrastructure)No

A current list of our sub-processors is available upon request by emailing support@forceiq.app.

With Third-Party Integrations

When you or your organization connects third-party services (such as EHR systems or wearable devices), data may be shared with those services according to their privacy policies and your organization's configuration.

For Legal and Safety Reasons

We may disclose information when we believe it is necessary to:

  • Comply with applicable law, regulation, or legal process
  • Protect the rights, property, or safety of ForceIQ, our users, or others
  • Enforce our Terms of Service
  • Respond to lawful requests from public authorities

Business Transfers

If ForceIQ is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or control of your personal information.


4. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve the Service. For detailed information, please see our separate [Cookie Policy].

Summary of Cookie Usage:

  • Strictly Necessary Cookies: Required for the Service to function (authentication, session management, security). You cannot opt out of these cookies.
  • Performance and Analytics Cookies: Help us understand how the Service is used so we can improve it. These collect aggregated usage data.
  • Functionality Cookies: Remember your preferences and settings.

We do not use advertising or marketing cookies. We do not serve targeted advertisements.

Do Not Track: ForceIQ respects the "Do Not Track" (DNT) browser signal. When DNT is enabled, ForceIQ will not initialize PostHog analytics or set any performance/analytics cookies.


5. Data Security

We implement comprehensive security measures to protect your information, leveraging Google Firebase's HIPAA-eligible infrastructure.

Encryption

  • In Transit: All data transmitted to and from the Service is encrypted using TLS 1.2 or higher (HTTPS).
  • At Rest: All data stored in Google Firebase/Cloud is encrypted at rest using AES-256 encryption, including database records, file storage, and backups.
  • Passwords: Stored only as cryptographic hashes using Firebase Authentication; we cannot access your actual password.

Access Controls

  • Role-based access controls ensure users can only access data appropriate to their role
  • Multi-tenant architecture with strict data isolation between organizations
  • Administrative access limited to authorized personnel on a need-to-know basis
  • Audit logging of all access to protected health information

Infrastructure Security

  • Hosted on Google Cloud Platform, which maintains SOC 1, SOC 2, SOC 3, ISO 27001, and HIPAA compliance certifications
  • Automated security patching and updates
  • Regular security assessments and vulnerability scanning
  • Automated encrypted backups with geographic redundancy

Health Information Safeguards

For health-related data, we implement additional safeguards consistent with HIPAA requirements for protected health information (PHI), including access controls, audit logging, encryption, and breach notification procedures. ForceIQ maintains a Business Associate Agreement (BAA) with Google for Firebase services.

Security Incident Response

In the event of a data breach that affects your personal information or PHI, we will:

  • Investigate and contain the incident promptly
  • Notify those we are required to notify under applicable law, including:
    • HIPAA: Where ForceIQ acts as a Business Associate, we notify the affected customer (the Covered Entity) without unreasonable delay and no later than 60 days after discovery, as provided in the applicable Business Associate Agreement; the Covered Entity is responsible for notifying affected individuals unless otherwise agreed
    • MHMDA and other applicable state laws: We notify affected individuals and authorities as required by applicable state breach notification statutes, where that obligation falls on ForceIQ
  • Take steps to prevent future incidents

6. Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Policy.

Retention Periods

Data TypeRetention Period
Account informationDuration of account plus 30 days after deletion request
Clinical and assessment dataDuration of account; or as required by applicable medical records retention laws
Session notes and observationsDuration of account
Communication messagesDuration of account
Analytics dataAggregated data retained indefinitely; identifiable data retained up to 2 years
De-identified assessment dataRetained indefinitely; no longer PHI or personal information, retained after account deletion (see Account Deletion below)
Server and access logs180 days
Billing and transaction recordsAs required by applicable tax and financial reporting laws (typically 7 years)

Account Deletion

When you request account deletion:

  • Your personal information will be deleted or anonymized within 30 days
  • Direct identifiers and Protected Health Information — including patient names, dates of birth, contact details, injury descriptions, and all clinical notes — are destroyed when a clinic account is deleted
  • Before destroying the identifiable records, ForceIQ de-identifies the assessment measurements (per 45 CFR 164.514(b)) and retains the resulting de-identified data, which is no longer PHI or personal information and cannot be linked back to you or any patient. ForceIQ may retain and use this de-identified data indefinitely for quality improvement and research, as described in the Terms of Service (Section 8.4). This retention is not affected by account deletion
  • Clinical data associated with your account may be retained for a longer period if required by applicable healthcare records retention laws, or as necessary for legal, security, or legitimate business purposes (e.g., resolving disputes, enforcing agreements)
  • Backup copies may persist for a limited time as part of our disaster recovery processes
  • Where ForceIQ operates as a Business Associate, data retention and deletion will be governed by the applicable BAA and Covered Entity's instructions

7. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information.

Rights for All Users

  • Access: View the personal information we hold about you through your account settings
  • Correction: Update inaccurate information through your account or by contacting us
  • Deletion: Request deletion of your account and personal information (subject to legal retention requirements)
  • Data Export: Request a copy of your data in a portable format

California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: Request information about the categories and specific pieces of personal information we have collected, the sources, purposes, and third parties with whom we share it
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sharing: We do not sell or share your personal information for cross-context behavioral advertising
  • Right to Limit Use of Sensitive Personal Information: Request limits on the use of sensitive personal information (such as health data) beyond what is necessary to provide the Service
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

Categories of Personal Information Collected (preceding 12 months):

  • Identifiers (name, email, IP address, device identifiers)
  • Personal information under California Civil Code Section 1798.80 (name, physical characteristics)
  • Protected classification characteristics (age, sex)
  • Commercial information (subscription history)
  • Internet or network activity (usage data within the Service)
  • Geolocation data (general location from IP)
  • Professional or employment-related information (organization role, credentials)
  • Sensitive personal information (health data)

To exercise your California privacy rights, contact us at support@forceiq.app or submit a request through your account settings.

Washington State Residents (My Health My Data Act)

If you are a Washington State resident, you have rights under the Washington My Health My Data Act (MHMDA, RCW 19.373), effective March 31, 2024.

Consumer Health Data We Collect:

ForceIQ collects "consumer health data" as defined by the MHMDA, including personal information linked or reasonably linkable to you that identifies your past, present, or future physical or mental health status. This includes:

  • Force measurement data and biomechanical assessments
  • Range of motion and functional movement data
  • Body measurements (height, weight, body composition)
  • Injury history and rehabilitation status
  • Performance metrics and testing results
  • Session notes and clinical observations

Purposes for Collection and Use:

We collect and use consumer health data for the following purposes:

  • Providing our biomechanical assessment and force measurement services
  • Supporting clinical workflows (presenting assessment data, generating reports, enabling data export)
  • Maintaining and securing your account
  • Complying with legal obligations

Third Parties with Whom Consumer Health Data Is Shared:

We share consumer health data only with the service providers identified in Section 3 of this Policy, and only as necessary to provide the Service. We do not sell consumer health data. Our sub-processor relationships are contractual processing arrangements — our service providers process data solely on our behalf and under our instructions, and do not receive consumer health data in exchange for monetary or other valuable consideration.

Service ProviderPurposeConsumer Health Data Shared
Google Firebase / Google Cloud PlatformInfrastructure and hostingYes — as necessary to host and operate the Service
PostHogProduct analyticsNo — receives only pseudonymized usage data, not health data
Resend (Resend, Inc.)Transactional emailNo — emails contain only generic notifications
Stripe, Inc.Payment processingNo — processes payment data only

Your Rights Under the MHMDA:

  • Right to Confirm: You may confirm whether we are collecting, sharing, or selling your consumer health data.
  • Right to Access: You may request access to the consumer health data we have collected about you.
  • Right to Delete: You may request deletion of your consumer health data, subject to applicable exceptions (including legal retention obligations and data subject to HIPAA governance).
  • Right to Withdraw Consent: You may withdraw your consent to the collection and sharing of your consumer health data at any time. Withdrawal of consent may affect our ability to provide the Service.

How to Exercise Your Rights:

To exercise your rights under the MHMDA, contact us at support@forceiq.app. We will respond to verified requests within 30 days.

Separate Authorization:

Before collecting your consumer health data, we will obtain your authorization through a separate and distinct consent mechanism, as required by the MHMDA. This authorization is separate from our Terms of Service and general privacy consents.

Geofencing:

ForceIQ does not implement geofencing technology around any healthcare facility or health care services provider for the purpose of identifying or collecting data from consumers.

HIPAA-Governed Data:

To the extent that any data processed by ForceIQ constitutes Protected Health Information ("PHI") governed by HIPAA pursuant to a valid Business Associate Agreement, such data may be exempt from certain MHMDA requirements as provided by RCW 19.373.010(10)(a). However, ForceIQ applies the MHMDA's protections to all consumer health data of Washington residents as a baseline, regardless of whether a HIPAA exemption may apply.

Exercising Your Rights

To submit a privacy request:

We will verify your identity before processing requests. You may designate an authorized agent to make requests on your behalf. We will respond to verified requests within 30 days (MHMDA) or 45 days (CCPA/CPRA), or notify you if an extension is needed.


8. HIPAA and Protected Health Information

Applicability

ForceIQ may process Protected Health Information ("PHI") as defined under HIPAA when the Service is used by or on behalf of a Covered Entity (such as a healthcare provider) or Business Associate. In such cases, ForceIQ acts as a Business Associate under HIPAA.

Business Associate Agreement

ForceIQ will enter into a Business Associate Agreement ("BAA") with any Covered Entity or Business Associate that uses the Service to process PHI. The BAA governs ForceIQ's obligations with respect to PHI, including:

  • Permitted uses and disclosures of PHI
  • Safeguards to protect PHI
  • Breach notification obligations
  • Obligations upon termination

ForceIQ maintains a BAA with Google for its Firebase and Google Cloud Platform services, ensuring that PHI processed through our infrastructure is covered by appropriate HIPAA safeguards.

PHI Safeguards

ForceIQ implements administrative, physical, and technical safeguards as required by the HIPAA Security Rule, including:

  • Encryption of PHI in transit and at rest
  • Access controls and authentication requirements
  • Audit logging and monitoring of PHI access
  • Workforce training on HIPAA requirements
  • Incident response and breach notification procedures

Minimum Necessary Standard

ForceIQ limits access to PHI to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request.

No Use of PHI for Marketing or AI Training

ForceIQ does not use PHI for marketing purposes, sale of data, AI model training, or any purpose other than (a) providing and securing the Service as described in the applicable BAA, and (b) de-identifying PHI as permitted by the BAA and 45 CFR 164.514(b). Data that ForceIQ has de-identified is no longer PHI and is governed by Section 8.4 ("Aggregated and De-Identified Data") of the Terms of Service rather than by this HIPAA section.

De-Identification and Research Use

ForceIQ creates and retains de-identified data derived from assessment measurements for its own internal quality improvement and for potential research and publication. This de-identified data contains no direct identifiers, no free-text notes, and no dates other than a within-subject day-offset and year, and cannot be linked back to a clinic, clinician, or patient. Because it is not PHI or personal information, ForceIQ may retain it after an account, its PHI, and its identifiable records are deleted (see Section 6, Data Retention).

To request a BAA, contact us at support@forceiq.app.


9. International Data Transfers

ForceIQ is based in the United States, and your information is processed and stored in the United States via Google Cloud Platform infrastructure.

If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country. Your data is processed and stored solely within the United States.


10. Children's Privacy

The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.

Users must be at least 18 years old to create a clinician account. Patient or client profiles may be created for minors only by an authorized clinician or administrator with appropriate parental or guardian consent as required by applicable law.

ForceIQ does not offer direct account registration or self-service access to individuals under 18. Patient profiles for minors are created and managed exclusively by authorized clinicians or administrators. ForceIQ does not directly collect personal data from minors — all data for minor patients is submitted by the clinician on behalf of the minor, with appropriate consent obtained by the clinician.

If we learn that we have collected personal information from a child under 13 without appropriate consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected information from a child under 13, please contact us at support@forceiq.app.


11. Third-Party Payment Processing

All payment processing for ForceIQ subscriptions is handled by Stripe, Inc. ForceIQ does not directly collect, store, or process credit card numbers, bank account information, or other payment card data.

When you provide payment information, it is transmitted directly to and processed by Stripe in accordance with Stripe's privacy policy and PCI-DSS compliance standards.

ForceIQ receives from Stripe only limited transaction information necessary to manage your subscription (such as transaction confirmation, last four digits of card, expiration date, and billing address).


12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law.

When we make material changes, we will:

  • Update the "Last Updated" date at the top of this Policy
  • Notify you by email or through a notice within the Service
  • Where required by law, obtain your consent to material changes

We encourage you to review this Policy periodically.

Revision History

VersionEffectiveChange
1.1August 4, 2026Corrected the Security section to describe our encryption practices accurately. The prior text stated that sensitive information received "additional application-level encryption" beyond encryption at rest. That was inaccurate: data is protected by AES-256 encryption at rest, in transit encryption, and access controls, without a separate field-level encryption layer. Also clarified that encryption at rest covers backups. No change to how your data is handled; this is a correction to the description.
1.0July 7, 2026Initial version.

13. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

For HIPAA-related inquiries or to request a Business Associate Agreement, please email support@forceiq.app with the subject line "HIPAA/BAA Request."

For Washington MHMDA rights requests, email support@forceiq.app with the subject line "Washington Health Data Request."