ForteSet

ForteSet legal & support

Privacy Policy

How ForteSet handles account, training-plan, music-preference, playlist, subscription, and support information.

Effective: September 22, 2026 · Version 1.0

Version privacy-2026-09-22 · Effective September 22, 2026. Who operates ForteSet: ForteSet is provided by Duan Yubo (段玉波), an individual developer based in Shangrao, Jiangxi, China. Contact privacy@forteset.com for privacy matters. English is the primary version of this policy; where permitted by law, it controls if the translations conflict.

1. Scope

This policy applies to the ForteSet iOS app, forteset.com, and related support and privacy-request services. It does not govern Apple Music, the App Store, or other services under their own policies.

2. Information we process

  • Account and eligibility: account ID, email or Apple-provided relay email when shared, authentication records, age band (under 13, 13–14, 15–17, or 18+), declaration method, guardian-permission confirmation for minors, and accepted policy versions and times. We do not request a birth date.
  • Training-plan content: text, images, supplemental instructions, parsed exercises, stages, durations, corrections, and confirmation state that you submit for a Session. Avoid including unnecessary information about another person or medical details.
  • Music preferences and Apple Music data: Apple Music connection and authorization state; playlists you choose to import; your music library, Heavy Rotation, recently played content, and personalized recommendations read while you actively use ForteSet; Anchor Stage choices; catalog or library identifiers; track metadata; explicit likes, replacements, skips, and blocks. ForteSet never asks for or receives your Apple ID password.
  • Sessions and feedback: confirmed plan snapshots, generated and delivered playlists, track order, Session history, review answers, and reuse or deletion actions.
  • Subscription records: ForteSet product identifier, entitlement status, app-account association, renewal, expiration, refund, and revocation events. Apple processes payment-card and billing details; ForteSet does not receive them.
  • Device, security, and operations: app and OS version, request and operation identifiers, timestamps, network and error information, integrity or abuse signals, and limited diagnostic events. Private plan text, images, email, tokens, and full snapshots are excluded from ordinary logs.
  • Communications: information you send in support, feedback, or privacy requests.

3. How we use information

  • Provide accounts, plan analysis, playlist generation, Apple Music delivery, history, export, deletion, and support.
  • Authenticate requests, protect users, prevent abuse, investigate failures, and maintain service reliability.
  • Administer the three Included Generations and ForteSet Plus entitlement across devices.
  • Comply with law and enforce the Terms.

Where legal-basis terminology applies, core processing is necessary to perform our contract with you; safety and reliability processing supports our legitimate interests; and some records may be processed to meet legal obligations.

Apple Music use and retention

Selected playlists are strong preference evidence; Heavy Rotation and recently played content represent recent interest; library membership represents familiarity and general preference; and Apple recommendations are exploration candidates and weak interest evidence, not likes. ForteSet derives versioned song, artist, and genre weights from this evidence. Those weights cannot bypass explicit feedback, workout-stage fit, recording version, trusted duration, storefront availability, or other hard constraints.

ForteSet retains verified song and catalog identity, library relationships, anonymous connection sources, and the provenance, observation time, expiry, and algorithm version of derived weights. Recent signals use a 14-day half-life and expire after 60 days. ForteSet does not retain complete listening history or archive raw Apple recommendation responses. Music User Tokens are not written to the database, app-managed persistence, logs, analytics, or error reports.

4. AI plan analysis

When you choose cloud analysis, the plan text or image and the minimum related instructions needed to interpret it are sent through ForteSet's server to Alibaba Cloud Model Studio (Qwen). The production Qwen workspace uses a Virginia endpoint with a Global service scope, so processing is not represented as United States-only. Alibaba Cloud's applicable terms state that customer content is not used to develop or improve Model Studio models without separate consent. ForteSet does not authorize third-party model training with your plan content.

The AI result is treated as a draft. You review and correct it before it becomes a confirmed plan.

5. Service providers and disclosures

  • Supabase and its infrastructure providers: authentication, database, storage, server functions, security, and backups. The launch project is hosted in the United States.
  • Alibaba Cloud Model Studio: approved launch AI inference for plan text or images when you request cloud analysis; the configured Virginia workspace has a Global service scope.
  • Apple: Sign in with Apple, Apple Music/MusicKit, StoreKit purchases, subscription status, refunds, and App Store distribution.
  • Public music-metadata services: limited song or recording metadata may be queried without sending your account identity.
  • Professional advisers or authorities: only when reasonably necessary to obtain advice, protect rights or safety, investigate abuse, or comply with valid legal process.

We do not sell personal information, share it for cross-context behavioral advertising, display third-party advertising, or authorize service providers to use plan content to train their general models.

6. International processing

ForteSet is operated from China and uses providers that process information in the United States and other disclosed service regions. This means information may be processed outside your country. We use provider agreements, access controls, encryption in transit, data minimization, and retention limits appropriate to the service.

7. Retention

  • ForteSet's temporary private analysis copy, including a submitted image, is deleted after processing or expires within approximately 15 minutes. The AI provider's processing and retention are governed by its applicable terms and security requirements; ForteSet does not promise that the provider deletes every internal copy within 15 minutes.
  • Unconfirmed structured analysis results expire after 7 days. A confirmed result becomes part of the Session you choose to save.
  • Recommendation replay snapshots expire after 30 days. Short-lived authentication nonces expire within 24 hours.
  • Selected Apple Music preferences, Sessions, playlists, and reviews remain until you remove them or delete the account, subject to limited integrity records.
  • Security, operation, and content-free deletion evidence is generally retained for no more than 90 days unless a longer period is necessary for an active investigation or legal duty.
  • After verified account deletion, access is disabled immediately, active-system personal data is deleted within 30 days, and residual backups age out within 90 days, except narrowly limited legal, transaction-security, or fraud-prevention records.

8. Your choices and rights

You can access or change many preferences in the app; disconnect or delete Apple Music data; export account data; and request access, correction, deletion, restriction, objection, or portability where applicable. Submit a request in the app, at forteset.com/privacy-request, or by email. We respond within 30 calendar days from receipt, or sooner where applicable law requires. We verify identity using the least additional information practical and do not request government ID by default.

Local law may give you additional rights and a right to complain to your privacy regulator. We do not discriminate against you for exercising a privacy right.

9. Children and teenagers

ForteSet is not directed to children under 13, and they may not create an account. A user aged 13–17 must have permission from a parent or guardian. We collect an age band, not a date of birth. If we learn that an under-13 account was created, we will disable it and delete its personal information while preserving access to privacy-request and deletion channels.

10. Security

We use owner-scoped access controls, authenticated server functions, encrypted transport, limited secrets access, redacted logs, expiration jobs, and account export and deletion controls. No system is perfectly secure. Contact privacy@forteset.com if you believe your account or information is at risk.

11. Changes and contact

We may update this policy prospectively. Material changes are clearly notified and require renewed acceptance where appropriate; we do not silently apply material changes retroactively. Questions and complaints may be sent to privacy@forteset.com. Service provider: Duan Yubo (段玉波), Shangrao, Jiangxi, China.