Privacy Policy

Last updated: March 19th, 2026

1. Introduction

Fork-First (fork-first.com) generates personalised nutritional and lifestyle recommendations through a proprietary algorithm applied to self-reported assessment responses. Fork-First is operated by Prompt Engine LLC, a limited liability company registered in Ohio (“we”, “us”, “our”). This policy applies to all users (“you”, “users”) of fork-first.com.

Data controller: Prompt Engine LLC
Contact: privacy@fork-first.com
Governing law: The laws of the State of Ohio, United States.

Fork-First is operated by a US company and governed by US law. Your use of Fork-First is subject to our Terms of Use.


2. Data We Collect and Why

2.1 Summary

DataPurposeLawful basis
Account data (email, Google display name, avatar URL, provider hint)Authentication and transactional communicationsContract performance
Assessment responsesDelivering personalised recommendationsExplicit consent
Payment confirmationPurchase fulfilmentContract performance
Session dataApplication security and authenticationLegitimate interest
Analytics dataService improvementLegitimate interest

2.2 Account Data

When you create a Fork-First account, we collect your email address. If you sign in using Google OAuth, we also receive and store your display name, profile picture URL, and a record that Google was used to authenticate your account. If you sign in using a magic link, we store your email address only.

2.3 Assessment Responses

The responses you provide during a Fork-First assessment cover topics including fertility patterns, menstrual health, hormonal symptoms, digestive health, and dietary status. The recommendations generated from your responses reflect your self-reported health information.

This is sensitive personal information.

Under the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), assessment responses and the recommendations derived from them constitute sensitive personal information.

Before you begin an assessment, you will be asked to provide explicit, affirmative consent to the processing of your assessment responses. This consent step is separate from accepting our Terms of Use and requires a deliberate, affirmative action. You may withdraw consent at any time (see Section 6).

2.4 Payment Data

Payment is processed by Stripe, Inc. We do not receive, store, or have access to your payment card details. We receive only a payment confirmation from Stripe. Stripe’s handling of your payment data is governed by Stripe’s Privacy Policy.

2.5 Session Data

When you log in, we set a session cookie (forkfirst_session) to keep you authenticated. This is an httpOnly cookie that cannot be read by browser scripts or third parties.

2.6 Analytics Data

We use Google Analytics to understand how users interact with fork-first.com. Google Analytics collects data through cookies and may process your IP address. Google’s handling of this data is governed by Google’s Privacy Policy. You can opt out using the Google Analytics Opt-out Browser Add-on.


3. Data Processors

The following third parties process data on our behalf under our instructions and are contractually bound to appropriate security standards.

ProcessorRoleData processedLocation
SupabaseDatabase and backend infrastructureAll personal data and assessment dataUnited States
VercelFrontend hostingIP addresses, request metadataUnited States
StripePayment processingPayment and billing dataUnited States
ResendTransactional emailEmail addresses and email contentUnited States
Google AnalyticsWebsite analyticsUsage data, cookies, IP addressUnited States

4. Data Retention

4.1 Session Cookies

Session cookies expire after seven days of inactivity and are deleted at expiry.

4.2 Sample Assessment Data

Responses submitted during a sample assessment are deleted within 24 hours of completion.

4.3 Full Assessment Data

Responses submitted to a full assessment and the recommendations generated from them are retained while your account is active, subject to the rolling window below. Responses to assessments not completed within 30 days of the first answer submitted are deleted.

180-day rolling window

Assessment responses and generated recommendations are deleted on a rolling basis 180 days from the date of your most recently completed assessment. Completing a new assessment resets this window for all prior assessment data.

4.4 Account Data

Account data is retained for as long as your account is active and deleted when you delete your account.

4.5 Payment Records

Transaction records are retained as required by applicable financial and tax regulations.

4.6 Analytics Data

Analytics data retention is configured and capped within Google Analytics.


5. Assessment Disclaimer

Results from a Fork-First assessment reflect our analysis of your self-reported answers at the time of the assessment only. They are not a medical diagnosis and do not constitute medical advice.

Recommendations are based solely on self-reported responses. We do not validate, verify, or cross-check answers provided.

Fork-First is not a substitute for consultation with a qualified healthcare provider. The material on this site is provided for educational purposes only and is not to be used for medical advice, diagnosis, or treatment.


6. Your Rights

Access: Request a copy of the personal information we hold about you by emailing privacy@fork-first.com.

Correction: Contact privacy@fork-first.com to correct inaccurate personal information.

Deletion: Users who have purchased an assessment can delete their account by logging in, selecting their profile in the navigation menu, and following the in-app instructions. Sample users must email privacy@fork-first.com. We will action all deletion requests within 30 days.

Withdraw consent: You may withdraw consent to assessment data processing at any time via your account settings or by emailing privacy@fork-first.com. Withdrawal does not affect processing that has already taken place.

Restrict processing: You may request that we restrict processing of your personal data without deleting it by contacting privacy@fork-first.com.

Sale of data: Fork-First does not sell your personal information and does not share it with third parties for cross-context behavioural advertising.

Sensitive personal information: We use your assessment responses only to provide the recommendations you requested.

No discrimination: We will not discriminate against you for exercising any of your privacy rights.

Supervisory authorities: Depending on your jurisdiction, you may have the right to lodge a complaint with a data protection authority. We welcome the opportunity to address concerns directly at privacy@fork-first.com before a formal complaint is made.

The rights described in this section apply to all users, including California residents under CCPA/CPRA.


7. Cookies

CookieTypePurposeDuration
forkfirst_sessionStrictly necessaryMaintains authenticated session7 days, rolling
_gaAnalyticsIdentifies unique visitors2 years
_ga_[ID]AnalyticsStores and counts page views2 years

The session cookie is strictly necessary for Fork-First to function and does not require consent. Analytics cookies require your consent, which is requested via our cookie consent mechanism and displayed until consent is recorded.


8. Data Security

Data is encrypted in transit and at rest. Payment card data is handled entirely by Stripe and never passes through Fork-First systems.

No internet transmission is fully secure. If you believe your account has been compromised, contact privacy@fork-first.com immediately.


9. Minimum Age

Fork-First is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under 18.


10. Changes to This Policy

We may update this policy from time to time. For material changes affecting how we process assessment data, we will notify you by email before the change takes effect.


11. Contact

Email: privacy@fork-first.com
Operator: Prompt Engine LLC, United States