ForceIQ Privacy Policy
Last Updated and Effective: August 4, 2026
Version: 1.1
Thank you for using ForceIQ. This Privacy Policy explains how ForceIQ, LLC ("ForceIQ," "we," "us," or "our") collects, uses, discloses, and protects your information when you use our website, web application, mobile applications, and related services (collectively, the "Service").
ForceIQ processes health, fitness, and biomechanical data that is personal and sensitive. The Service is currently available in the United States and select international markets (excluding the European Economic Area and the United Kingdom). We are committed to protecting your privacy and handling your data responsibly in compliance with applicable law, including the Health Insurance Portability and Accountability Act ("HIPAA") where applicable, the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA"), and the Washington My Health My Data Act ("MHMDA").
Clinical Disclaimer: ForceIQ is not a medical device and has not been evaluated, cleared, or approved by the U.S. Food and Drug Administration or any other regulatory body. The Service is intended to provide data collection and analytical tools for use by qualified clinicians and practitioners. ForceIQ does not diagnose, treat, cure, or prevent any disease or medical condition. All clinical decisions remain the sole responsibility of the licensed clinician or practitioner using the Service.
Table of Contents
- Information We Collect
- How We Use Your Information
- How We Share Your Information
- Cookies and Tracking Technologies
- Data Security
- Data Retention
- Your Privacy Rights
- HIPAA and Protected Health Information
- International Data Transfers
- Children's Privacy
- Third-Party Payment Processing
- Changes to This Policy
- Contact Us
1. Information We Collect
Information You Provide
When you register for and use the Service, we collect information you provide directly, including:
Account Information
- Name (first and last)
- Email address
- Password (stored only as an encrypted hash)
- Professional credentials or license information (for clinician accounts)
Profile and Demographic Information
- Date of birth
- Biological sex
- Organization or practice affiliation
- Patient name (optional — collected only when a clinic enables PHI collection under an accepted Business Associate Agreement; by default patients are identified by a de-identified code)
- Patient photograph (optional — a full-face photo is Protected Health Information, collected only under the same PHI opt-in; stored within our HIPAA-covered infrastructure and never shared with analytics or other third parties)
Clinical and Biomechanical Data
- Force measurement data and biomechanical assessments
- Range of motion and functional movement data
- Body measurements (height, weight, body composition)
- Injury history and rehabilitation status
- Performance metrics and testing results
- Session notes and clinical observations
Organization Information (for clinicians and administrators)
- Practice, clinic, or organization name
- Role and permissions within your organization
- Clinician license or credential identifiers
Communications
- Messages and notes within the Service
- Clinician notes and patient observations
- Support inquiries and correspondence
Information Collected Automatically
When you access or use the Service, we automatically collect:
Device and Access Information
- Device operating system and type
- Device identifiers
- Browser type and version
- IP address
Authentication Security Information
To satisfy the unique-user-identification requirement of HIPAA Technical Safeguards (45 CFR § 164.312(a)(2)(i)) and to detect credential sharing or unauthorized access, ForceIQ records:
- A non-reversible device fingerprint hash derived from your browser, operating system, and screen attributes (generated locally — not used for cross-site tracking)
- A list of devices on which your account has been signed in, including a short device label (e.g. "Mac", "iPad") and the most recent sign-in timestamp
- Per-account login event records (timestamp, device fingerprint, outcome — successful sign-in, signed out due to concurrent session, signed out due to inactivity, multi-factor challenge result)
These records are visible to you and to administrators of your clinic/organization on the Team Management page. They are not shared with PostHog or any third-party analytics service. They are used solely to alert you to unrecognised sign-ins, enforce single concurrent session per User, and surface activity patterns consistent with credential sharing. See our Terms of Service § 3.3.
Usage Information
- Sign-in timestamps and frequency
- Features accessed and actions taken
- Session duration
- Referring URLs
Analytics Data (PostHog)
ForceIQ uses PostHog for product analytics, collecting pseudonymous usage data to improve the Service:
- Pages visited and features used (e.g., "uploaded assessment," "generated PDF report")
- Session frequency, duration, and navigation patterns
- Error rates and performance metrics
- Browser type, operating system, and screen resolution
ForceIQ does NOT collect the following in analytics:
- Patient names, dates of birth, email addresses, or any Protected Health Information
- Force/torque measurement data, metric values, or clinical notes
- Assessment file contents or session-level clinical data
- Precise geolocation (only general location derived from IP address)
Analytics collection requires your consent (provided during onboarding) and can be disabled at any time in Settings. ForceIQ respects the browser Do Not Track (DNT) signal — when enabled, PostHog is not initialized.
Information from Third Parties
We may receive information from third-party services connected to ForceIQ by you or your organization, such as:
- Bluetooth-connected isometric dynamometers (e.g., Tindeq Progressor, PitchSix Force Board, Squegg) via the Web Bluetooth API
- CSV data exports from isokinetic dynamometers and other force measurement devices
Future integrations (such as electronic health record systems) will be disclosed here as they become available.
2. How We Use Your Information
We use the information we collect to:
Provide and Operate the Service
- Create and maintain your account
- Deliver biomechanical assessment and force measurement tools
- Enable communication between clinicians and their patients or clients
- Process transactions and manage subscriptions
Support Clinical Workflows
- Present assessment data and analytics dashboards to authorized clinicians
- Generate reports and progress summaries for clinical review
- Enable data export for integration into clinical records
Improve the Service
- Analyze usage patterns to enhance features and performance
- Diagnose technical problems and monitor system health
- Conduct internal research and development
Product Analytics (PostHog)
We use pseudonymous analytics data to:
- Identify which features clinicians use most and least frequently
- Detect upload failures and parsing errors to improve CSV compatibility
- Measure activation rates (time from signup to first assessment)
- Monitor free-to-paid conversion signals
- Diagnose performance issues and user-facing errors
Analytics data is pseudonymized (user IDs are hashed) and is never combined with PHI. Analytics data is not used for advertising, marketing targeting, or behavioral profiling.
Communicate with You
- Send transactional emails (account verification, password resets, session notifications)
- Provide customer support
- Send product updates and announcements (with your consent where required)
Ensure Safety and Security
- Detect and prevent fraud, abuse, and security incidents
- Enforce our Terms of Service
- Comply with legal obligations
3. How We Share Your Information
We do not sell your personal information. We will never sell your personal information. We do not share your personal information for cross-context behavioral advertising.
We share your information only in the following circumstances:
Within Your Organization
If you are part of an organization (clinic, practice, or facility) on ForceIQ:
- Patients/Clients: Your clinician and authorized administrators can view your assessment data, metrics, session history, and (where authorized) injury and health information.
- Clinicians: Patients or clients assigned to you can see your name and professional role; administrators can view your activity within the organization.
With Service Providers
We engage third-party companies to perform services on our behalf. These providers are contractually obligated to protect your information and use it only for the services we specify. We maintain data processing agreements with our service providers as required by applicable law.
| Category | Provider(s) | Purpose | Health Data Access |
|---|---|---|---|
| Infrastructure & Hosting | Google Firebase / Google Cloud Platform | Application hosting, data storage, authentication, HIPAA-compliant infrastructure | Yes — primary infrastructure |
| Payment Processing | Stripe, Inc. | Subscription billing and payment processing | No |
| Email Delivery | Resend (Resend, Inc.) | Transactional email delivery (account notifications, report delivery) | No |
| Analytics | PostHog | Pseudonymous product usage analytics and event tracking | No |
| Error Tracking | Google Cloud Logging | Server-side error detection and debugging (within our HIPAA-covered Google Cloud infrastructure) | No |
A current list of our sub-processors is available upon request by emailing support@forceiq.app.
With Third-Party Integrations
When you or your organization connects third-party services (such as EHR systems or wearable devices), data may be shared with those services according to their privacy policies and your organization's configuration.
For Legal and Safety Reasons
We may disclose information when we believe it is necessary to:
- Comply with applicable law, regulation, or legal process
- Protect the rights, property, or safety of ForceIQ, our users, or others
- Enforce our Terms of Service
- Respond to lawful requests from public authorities
Business Transfers
If ForceIQ is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or control of your personal information.
4. Cookies and Tracking Technologies
We use cookies and similar technologies to operate and improve the Service. For detailed information, please see our separate [Cookie Policy].
Summary of Cookie Usage:
- Strictly Necessary Cookies: Required for the Service to function (authentication, session management, security). You cannot opt out of these cookies.
- Performance and Analytics Cookies: Help us understand how the Service is used so we can improve it. These collect aggregated usage data.
- Functionality Cookies: Remember your preferences and settings.
We do not use advertising or marketing cookies. We do not serve targeted advertisements.
Do Not Track: ForceIQ respects the "Do Not Track" (DNT) browser signal. When DNT is enabled, ForceIQ will not initialize PostHog analytics or set any performance/analytics cookies.
5. Data Security
We implement comprehensive security measures to protect your information, leveraging Google Firebase's HIPAA-eligible infrastructure.
Encryption
- In Transit: All data transmitted to and from the Service is encrypted using TLS 1.2 or higher (HTTPS).
- At Rest: All data stored in Google Firebase/Cloud is encrypted at rest using AES-256 encryption, including database records, file storage, and backups.
- Passwords: Stored only as cryptographic hashes using Firebase Authentication; we cannot access your actual password.
Access Controls
- Role-based access controls ensure users can only access data appropriate to their role
- Multi-tenant architecture with strict data isolation between organizations
- Administrative access limited to authorized personnel on a need-to-know basis
- Audit logging of all access to protected health information
Infrastructure Security
- Hosted on Google Cloud Platform, which maintains SOC 1, SOC 2, SOC 3, ISO 27001, and HIPAA compliance certifications
- Automated security patching and updates
- Regular security assessments and vulnerability scanning
- Automated encrypted backups with geographic redundancy
Health Information Safeguards
For health-related data, we implement additional safeguards consistent with HIPAA requirements for protected health information (PHI), including access controls, audit logging, encryption, and breach notification procedures. ForceIQ maintains a Business Associate Agreement (BAA) with Google for Firebase services.
Security Incident Response
In the event of a data breach that affects your personal information or PHI, we will:
- Investigate and contain the incident promptly
- Notify those we are required to notify under applicable law, including:
- HIPAA: Where ForceIQ acts as a Business Associate, we notify the affected customer (the Covered Entity) without unreasonable delay and no later than 60 days after discovery, as provided in the applicable Business Associate Agreement; the Covered Entity is responsible for notifying affected individuals unless otherwise agreed
- MHMDA and other applicable state laws: We notify affected individuals and authorities as required by applicable state breach notification statutes, where that obligation falls on ForceIQ
- Take steps to prevent future incidents
6. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Policy.
Retention Periods
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account plus 30 days after deletion request |
| Clinical and assessment data | Duration of account; or as required by applicable medical records retention laws |
| Session notes and observations | Duration of account |
| Communication messages | Duration of account |
| Analytics data | Aggregated data retained indefinitely; identifiable data retained up to 2 years |
| De-identified assessment data | Retained indefinitely; no longer PHI or personal information, retained after account deletion (see Account Deletion below) |
| Server and access logs | 180 days |
| Billing and transaction records | As required by applicable tax and financial reporting laws (typically 7 years) |
Account Deletion
When you request account deletion:
- Your personal information will be deleted or anonymized within 30 days
- Direct identifiers and Protected Health Information — including patient names, dates of birth, contact details, injury descriptions, and all clinical notes — are destroyed when a clinic account is deleted
- Before destroying the identifiable records, ForceIQ de-identifies the assessment measurements (per 45 CFR 164.514(b)) and retains the resulting de-identified data, which is no longer PHI or personal information and cannot be linked back to you or any patient. ForceIQ may retain and use this de-identified data indefinitely for quality improvement and research, as described in the Terms of Service (Section 8.4). This retention is not affected by account deletion
- Clinical data associated with your account may be retained for a longer period if required by applicable healthcare records retention laws, or as necessary for legal, security, or legitimate business purposes (e.g., resolving disputes, enforcing agreements)
- Backup copies may persist for a limited time as part of our disaster recovery processes
- Where ForceIQ operates as a Business Associate, data retention and deletion will be governed by the applicable BAA and Covered Entity's instructions
7. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information.
Rights for All Users
- Access: View the personal information we hold about you through your account settings
- Correction: Update inaccurate information through your account or by contacting us
- Deletion: Request deletion of your account and personal information (subject to legal retention requirements)
- Data Export: Request a copy of your data in a portable format
California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request information about the categories and specific pieces of personal information we have collected, the sources, purposes, and third parties with whom we share it
- Right to Delete: Request deletion of your personal information, subject to certain exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sharing: We do not sell or share your personal information for cross-context behavioral advertising
- Right to Limit Use of Sensitive Personal Information: Request limits on the use of sensitive personal information (such as health data) beyond what is necessary to provide the Service
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
Categories of Personal Information Collected (preceding 12 months):
- Identifiers (name, email, IP address, device identifiers)
- Personal information under California Civil Code Section 1798.80 (name, physical characteristics)
- Protected classification characteristics (age, sex)
- Commercial information (subscription history)
- Internet or network activity (usage data within the Service)
- Geolocation data (general location from IP)
- Professional or employment-related information (organization role, credentials)
- Sensitive personal information (health data)
To exercise your California privacy rights, contact us at support@forceiq.app or submit a request through your account settings.
Washington State Residents (My Health My Data Act)
If you are a Washington State resident, you have rights under the Washington My Health My Data Act (MHMDA, RCW 19.373), effective March 31, 2024.
Consumer Health Data We Collect:
ForceIQ collects "consumer health data" as defined by the MHMDA, including personal information linked or reasonably linkable to you that identifies your past, present, or future physical or mental health status. This includes:
- Force measurement data and biomechanical assessments
- Range of motion and functional movement data
- Body measurements (height, weight, body composition)
- Injury history and rehabilitation status
- Performance metrics and testing results
- Session notes and clinical observations
Purposes for Collection and Use:
We collect and use consumer health data for the following purposes:
- Providing our biomechanical assessment and force measurement services
- Supporting clinical workflows (presenting assessment data, generating reports, enabling data export)
- Maintaining and securing your account
- Complying with legal obligations
Third Parties with Whom Consumer Health Data Is Shared:
We share consumer health data only with the service providers identified in Section 3 of this Policy, and only as necessary to provide the Service. We do not sell consumer health data. Our sub-processor relationships are contractual processing arrangements — our service providers process data solely on our behalf and under our instructions, and do not receive consumer health data in exchange for monetary or other valuable consideration.
| Service Provider | Purpose | Consumer Health Data Shared |
|---|---|---|
| Google Firebase / Google Cloud Platform | Infrastructure and hosting | Yes — as necessary to host and operate the Service |
| PostHog | Product analytics | No — receives only pseudonymized usage data, not health data |
| Resend (Resend, Inc.) | Transactional email | No — emails contain only generic notifications |
| Stripe, Inc. | Payment processing | No — processes payment data only |
Your Rights Under the MHMDA:
- Right to Confirm: You may confirm whether we are collecting, sharing, or selling your consumer health data.
- Right to Access: You may request access to the consumer health data we have collected about you.
- Right to Delete: You may request deletion of your consumer health data, subject to applicable exceptions (including legal retention obligations and data subject to HIPAA governance).
- Right to Withdraw Consent: You may withdraw your consent to the collection and sharing of your consumer health data at any time. Withdrawal of consent may affect our ability to provide the Service.
How to Exercise Your Rights:
To exercise your rights under the MHMDA, contact us at support@forceiq.app. We will respond to verified requests within 30 days.
Separate Authorization:
Before collecting your consumer health data, we will obtain your authorization through a separate and distinct consent mechanism, as required by the MHMDA. This authorization is separate from our Terms of Service and general privacy consents.
Geofencing:
ForceIQ does not implement geofencing technology around any healthcare facility or health care services provider for the purpose of identifying or collecting data from consumers.
HIPAA-Governed Data:
To the extent that any data processed by ForceIQ constitutes Protected Health Information ("PHI") governed by HIPAA pursuant to a valid Business Associate Agreement, such data may be exempt from certain MHMDA requirements as provided by RCW 19.373.010(10)(a). However, ForceIQ applies the MHMDA's protections to all consumer health data of Washington residents as a baseline, regardless of whether a HIPAA exemption may apply.
Exercising Your Rights
To submit a privacy request:
- Email: support@forceiq.app
We will verify your identity before processing requests. You may designate an authorized agent to make requests on your behalf. We will respond to verified requests within 30 days (MHMDA) or 45 days (CCPA/CPRA), or notify you if an extension is needed.
8. HIPAA and Protected Health Information
Applicability
ForceIQ may process Protected Health Information ("PHI") as defined under HIPAA when the Service is used by or on behalf of a Covered Entity (such as a healthcare provider) or Business Associate. In such cases, ForceIQ acts as a Business Associate under HIPAA.
Business Associate Agreement
ForceIQ will enter into a Business Associate Agreement ("BAA") with any Covered Entity or Business Associate that uses the Service to process PHI. The BAA governs ForceIQ's obligations with respect to PHI, including:
- Permitted uses and disclosures of PHI
- Safeguards to protect PHI
- Breach notification obligations
- Obligations upon termination
ForceIQ maintains a BAA with Google for its Firebase and Google Cloud Platform services, ensuring that PHI processed through our infrastructure is covered by appropriate HIPAA safeguards.
PHI Safeguards
ForceIQ implements administrative, physical, and technical safeguards as required by the HIPAA Security Rule, including:
- Encryption of PHI in transit and at rest
- Access controls and authentication requirements
- Audit logging and monitoring of PHI access
- Workforce training on HIPAA requirements
- Incident response and breach notification procedures
Minimum Necessary Standard
ForceIQ limits access to PHI to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request.
No Use of PHI for Marketing or AI Training
ForceIQ does not use PHI for marketing purposes, sale of data, AI model training, or any purpose other than (a) providing and securing the Service as described in the applicable BAA, and (b) de-identifying PHI as permitted by the BAA and 45 CFR 164.514(b). Data that ForceIQ has de-identified is no longer PHI and is governed by Section 8.4 ("Aggregated and De-Identified Data") of the Terms of Service rather than by this HIPAA section.
De-Identification and Research Use
ForceIQ creates and retains de-identified data derived from assessment measurements for its own internal quality improvement and for potential research and publication. This de-identified data contains no direct identifiers, no free-text notes, and no dates other than a within-subject day-offset and year, and cannot be linked back to a clinic, clinician, or patient. Because it is not PHI or personal information, ForceIQ may retain it after an account, its PHI, and its identifiable records are deleted (see Section 6, Data Retention).
To request a BAA, contact us at support@forceiq.app.
9. International Data Transfers
ForceIQ is based in the United States, and your information is processed and stored in the United States via Google Cloud Platform infrastructure.
If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country. Your data is processed and stored solely within the United States.
10. Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
Users must be at least 18 years old to create a clinician account. Patient or client profiles may be created for minors only by an authorized clinician or administrator with appropriate parental or guardian consent as required by applicable law.
ForceIQ does not offer direct account registration or self-service access to individuals under 18. Patient profiles for minors are created and managed exclusively by authorized clinicians or administrators. ForceIQ does not directly collect personal data from minors — all data for minor patients is submitted by the clinician on behalf of the minor, with appropriate consent obtained by the clinician.
If we learn that we have collected personal information from a child under 13 without appropriate consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected information from a child under 13, please contact us at support@forceiq.app.
11. Third-Party Payment Processing
All payment processing for ForceIQ subscriptions is handled by Stripe, Inc. ForceIQ does not directly collect, store, or process credit card numbers, bank account information, or other payment card data.
When you provide payment information, it is transmitted directly to and processed by Stripe in accordance with Stripe's privacy policy and PCI-DSS compliance standards.
- Stripe's Privacy Policy: https://stripe.com/privacy
- Stripe's Security: https://stripe.com/docs/security
ForceIQ receives from Stripe only limited transaction information necessary to manage your subscription (such as transaction confirmation, last four digits of card, expiration date, and billing address).
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law.
When we make material changes, we will:
- Update the "Last Updated" date at the top of this Policy
- Notify you by email or through a notice within the Service
- Where required by law, obtain your consent to material changes
We encourage you to review this Policy periodically.
Revision History
| Version | Effective | Change |
|---|---|---|
| 1.1 | August 4, 2026 | Corrected the Security section to describe our encryption practices accurately. The prior text stated that sensitive information received "additional application-level encryption" beyond encryption at rest. That was inaccurate: data is protected by AES-256 encryption at rest, in transit encryption, and access controls, without a separate field-level encryption layer. Also clarified that encryption at rest covers backups. No change to how your data is handled; this is a correction to the description. |
| 1.0 | July 7, 2026 | Initial version. |
13. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
- Email: support@forceiq.app
- Mailing Address: ForceIQ, LLC, 22 Agawam Road, Acton, MA 01720
For HIPAA-related inquiries or to request a Business Associate Agreement, please email support@forceiq.app with the subject line "HIPAA/BAA Request."
For Washington MHMDA rights requests, email support@forceiq.app with the subject line "Washington Health Data Request."