Effective Date: July 11, 2026 · Last Updated: August 29, 2026
Beyond basic account info, we keep almost nothing: your name, email address, and the date you joined. Everything you type into a tool, your experience, your details, the finished resume, cover letter, landlord letter, petition, or any other document, is processed in memory in real time and never written to persistent storage. Close the tab and it's gone. Two narrow exceptions, a short optional coach note and a point-in-time review snapshot, are listed in Sections 2 and 6 below.
| Category | What we keep | What we never keep |
|---|---|---|
| Account basics | Name, email, join date, password hash | N/A |
| Documents you generate | Nothing | Full content of any resume, letter, petition, or other document |
| Information you type into tools | Nothing | All form inputs and personal details used to generate documents |
| Milestone progress | Status only (not started / pending / approved) | Content of any related document or story |
| Notes to your coach | Short optional note you choose to attach | Full documents or detailed history |
| Review meeting snapshots | A point-in-time copy of your milestone status and any notes attached, saved each time a review meeting completes | New document content, only what's already visible to your organization's staff elsewhere |
| Organization funder / Second Chance Act reports | Nothing extra, generated live from aggregate milestone data your organization's staff can already see | A copy of the report itself, or your individual documents |
| CSBG grant-reporting worksheets (orgs using this feature only) | Certain federally required intake fields entered by staff, encrypted, in a separate database — see our Consumer Health Data Privacy Policy | Diagnoses, prescriptions, insurance ID numbers, or any narrative medical record |
| Payment details | Confirmation of payment and plan type | Full card numbers, CVV, or bank account details |
| Usage | Basic technical logs for security | Browsing history or detailed activity profiles |
Forzara ("we," "us," or "our") operates the service available at forzara.ai. Forzara is a privacy first reentry support platform that provides clear tools, ordered milestones, and two kinds of AI assistance for people navigating life after a criminal conviction: (1) AI assisted generation of draft documents such as resumes, cover letters, landlord letters, and other correspondence; and (2) AI assisted identification of the correct official government or court form for processes such as expungement, record sealing, early termination, and appeals, together with step by step guidance on completing those forms. Forzara does not draft, generate, or file court or government forms on a user's behalf.
We built Forzara around a deliberate privacy principle: hold as little of your information as possible so there is almost nothing that can be lost, sold, subpoenaed, or held over you.
We collect only what is necessary to operate the service:
If you use the Recovery Finder tool's check-in log, we store one of three fixed status values you choose ("Attended a session," "Just checking in," or "Having a hard week") with the date, tied to your account. There is no free text field, entirely optional, never scheduled or required, and not part of the milestone program described above. See Section 5 for who can see it, and our separate Consumer Health Data Privacy Policy for full detail on this and the other health-related data described there.
Processed entirely by our third party payment processor. We receive only confirmation of successful payment, plan type, billing email, and subscription status. We never receive or store full payment card numbers, CVV codes, or bank account details.
IP address, browser type, device type, and server logs required for security, fraud prevention, and reliable operation of the service.
When you use any AI powered tool:
Under Google's paid Gemini API terms:
You control what you put into any form. We recommend never pasting highly sensitive identifiers (full Social Security numbers, exact case numbers, etc.) unless necessary for the specific document you are generating.
We use the limited information we hold only to:
We do not use your data for advertising. We do not build behavioral profiles. We do not sell, rent, or trade personal information.
We share information only in these narrowly defined cases:
Authorized staff can see only:
They cannot view, download, open, or access the content of any document you generate. This separation is enforced at the product level.
If your organization generates a program outcome report, a Second Chance Act compliance packet, or another funder facing export, that report is assembled at the moment it's requested from the same aggregate milestone and service data your organization's staff already have access to. It is branded with your organization's own logo and is not separately stored by us afterward. We do not send these reports to any funder, grantor, or third party ourselves, your organization controls if, when, and to whom a report is shared.
CSBG grant-reporting worksheets work differently, because the underlying data does. If your organization uses our CSBG worksheets, staff enter federally required intake data about you (see our Consumer Health Data Privacy Policy for the specific fields) directly into a worksheet. It's encrypted and stored individually, in a database physically separate from the rest of Forzara, as a new record created at intake rather than assembled from data staff already had access to elsewhere. It's retained afterward as a permanent, dated record for the organization's own grant-audit purposes. Your organization's own authorized staff can view individual worksheet answers. When your organization's admin certifies a report to send to a funder, only the certified aggregate totals across all its worksheets are included, never any individual's answers, and that send still only happens at your organization's own direction, the same as any other funder report.
Providers who perform necessary functions on our behalf (hosting, payment processing, email delivery, AI generation) are contractually obligated to protect the data and may use it only to provide services to us.
If we receive a valid subpoena, court order, or other legal process, we will disclose only the limited account information we actually hold. Because we do not store documents or detailed personal histories, there is very little information available to produce.
If Forzara is acquired, merged, or sold, your account data would transfer under the same privacy commitments. We will notify you in advance of any material change.
We never sell personal information.
You may delete your account at any time through Account Settings or by contacting us. Upon deletion we will delete or irreversibly anonymize your personal information within a reasonable time, except for information we are legally required to retain.
You have the right to:
To exercise any of these rights, use the Account Settings page or email us at the address below. We will respond within a reasonable time and in accordance with applicable law.
If you are enrolled through a partner organization, certain milestone status information may also be visible to that organization's authorized staff under the limited rules described in Section 5.
We protect the limited data we hold with industry standard measures, including encryption of data in transit (HTTPS/TLS), hashed and salted passwords, access controls, and secure hosting practices. Because we deliberately store almost no sensitive content, the potential impact of any security incident is minimized. No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
Any account can optionally enable two factor login (a one time code sent by SMS) for extra protection, including staff and admin accounts. Recovery codes are stored as one time use hashes we cannot reverse. Anyone can also set a short PIN to quickly re lock their own session on a shared device, that PIN is hashed the same way a password is and is never visible to anyone, including us.
Forzara uses cookies only to make the service work, never for advertising, analytics, or tracking. We do not use any third party ad, analytics, or tracking cookies, and there is nothing on this site to opt out of on that front.
Several state privacy laws require honoring an opt-out preference signal, such as Global Privacy Control, sent automatically by your browser, for the right to opt out of the sale of personal information, targeted advertising, or profiling. We honor that signal by definition: we do not sell personal information, run targeted or cross-context behavioral advertising, or use automated profiling for any purpose, for anyone, regardless of any signal your browser sends. There is no opt-out action for us to take because there is nothing running that this signal would turn off.
Both are strictly necessary to operate the service, marked Secure and HttpOnly so they're never sent unencrypted or readable by page scripts, and neither requires or triggers a cookie consent banner under applicable law, since that requirement applies to non essential cookies like advertising or analytics, which Forzara does not use. See our Security page for more detail on how these cookies are hardened.
We use a small number of carefully selected third party services:
These providers process data only as necessary to provide their services to us and are bound by contractual data protection obligations. We do not allow them to use your data for their own marketing or unrelated purposes.
The service is operated from the United States. If you access Forzara from outside the United States, you understand that your information will be processed in the United States, which may have data protection laws that differ from those in your country of residence.
Forzara is intended solely for adults 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected such information, we will delete it promptly.
We may update this Privacy Policy from time to time. When we do, we will post the revised version on this page, update the "Last Updated" date, and, for material changes, provide notice by email or through a prominent notice on the service. Continued use of the service after the effective date of any update constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy, our privacy practices, or wish to exercise your rights, contact us at:
We take privacy seriously and will respond as promptly as possible.
No. Documents and the information you enter to create them are never stored on our servers. They exist only in your browser session.
No. Coaches and organization staff can see only the status of milestones you submit and any short note you choose to attach. They cannot see document content.
We can produce only the limited account information we actually hold (name, email, join date, and milestone statuses). Because we do not store documents or detailed personal histories, there is very little information available.
No. We never sell, rent, or trade personal information.
We currently use Google Gemini via the paid API. Under Google's paid terms, prompts and responses are not used to train or improve their models.
Go to Account Settings and delete your account, or email support@forzara.ai. We will delete or irreversibly anonymize your personal information within a reasonable time.
This Privacy Policy accurately describes how Forzara operates as of the effective date above. We designed the product to hold as little of your information as possible so that the path back can be yours alone.