Privacy Policy
The short version
- Future Forward is a private team tool. Accounts are created by your organisation's administrator — there is no public sign-up.
- We collect the information needed to run your account, your position in the team structure, and the activity you record in the app.
- We do not sell your personal data, and we do not use it for advertising. There are no advertising or third-party analytics SDKs in the app.
- The app does not collect your device's GPS location, your contacts, or your advertising ID.
- You can request deletion of your account and data at any time — see Account and data deletion.
1. Who we are
This policy is issued by Future Forward ("Future Forward", "we", "us", "our"), the provider of the Future Forward Android application and web portal (together, the "Service").
Future Forward is supplied to organisations. Your organisation's administrator decides who gets an account, what is recorded, and how the Service is used within their team. For that reason, your organisation and Future Forward both play a part in handling your information: your organisation decides why data is collected about you, and we provide and operate the platform that stores it. If you have a question about why particular information is held about you, please contact your administrator first; you can always reach us at the address in section 17.
2. Scope of this policy
This policy covers:
- the Future Forward Android app distributed on Google Play under the package name cloud.futureforward.app; and
- the Future Forward web portal used by administrators, leaders and members.
It does not cover any third-party website or service that the Service may link to, which is governed by that party's own privacy policy.
3. Information we collect
Almost everything in Future Forward is entered deliberately — by you, or by an administrator or leader in your organisation. We do not build hidden profiles, and we do not track you across other apps or websites.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Name, username, email address, phone number, profile photo, company/member ID, rank, role, joining date and last sign-in time. | Created by your administrator; you can update parts of it. |
| Team structure | Your position in the binary tree — the member you sit under, your left/right placement, your assigned leader, and which organisation tree you belong to. | Set by your administrator or leader. |
| Extended profile (optional) | Gender, date of birth, marital status, marriage date, postal address, employment status, employer name, job title and place of work. | Provided by you or your administrator. These fields are optional and can be left blank. |
| Activity you record | Guest and prospect records, event attendance, daily feedback notes you write, and which training videos you have viewed. | Entered by you in the app or portal. |
| Messages | The content of direct and group chat messages you send, with sender and timestamp. | Written by you. |
| Photos and files | A profile photo, and any video or file you choose to upload. | Selected by you from your device. |
| Authentication | Your password (stored only as a salted one-way hash, never in readable form), session tokens, and a Firebase account identifier used for chat. | Generated when you sign in. |
| Technical | A push-notification token for your device, app version, and standard server logs including IP address and request times. | Collected automatically when the app connects to our servers. |
What we do not collect
- Precise or background location. The app does not request GPS or location permissions. Where you see a "location" field on a guest record, it is a free-text note typed by a user, not a device reading.
- Your contacts, call logs, SMS, calendar, microphone or camera roll at large. Media access is limited to files you pick yourself.
- Advertising identifiers. The app contains no advertising SDK and serves no ads.
- Third-party behavioural analytics. The app does not embed an analytics or crash-reporting SDK.
4. Information you enter about other people
Future Forward lets you record details of prospects and guests — their name, contact details, a location note, their area of interest, the date you approached them and their current stage in your follow-up pipeline.
This is personal data about someone who is not a user of the Service. If you enter it, you are responsible for having a lawful basis to do so — in most cases, telling that person you are recording their details and obtaining their agreement. Do not record sensitive information about a prospect, and remove records on request.
If you are a prospect whose details are held in Future Forward and you want them removed, contact the member who recorded them, or write to us at privacy@futureforward.cloud and we will pass the request to the relevant organisation and act on it.
5. Device permissions
The Android app requests only the permissions it needs to function:
| Permission | Why |
|---|---|
| Internet / Network state | To communicate with our servers and to tell you when you are offline. |
| Notifications | To alert you to new messages, events and follow-ups. You may decline this, and the rest of the app still works. |
| Photos and media | Only when you tap to choose a profile picture or upload a file. We receive the file you pick, nothing else. |
| Vibrate | To accompany notification alerts. |
| Run at startup / Wake lock | So scheduled reminders and notifications are delivered reliably. |
6. How we use information
We use the information described above to:
- create your account, sign you in, and keep your session secure;
- show your team structure, downline and binary chart, and let authorised people manage placement;
- let you record and track guests, events, attendance and daily feedback;
- deliver chat messages and push notifications;
- host and play training videos and record view counts;
- produce the reports and statistics your role is entitled to see;
- keep the Service secure — detecting abuse, debugging faults and maintaining audit logs; and
- comply with legal obligations.
We do not use your personal data for automated decisions that produce legal or similarly significant effects about you, and we do not sell or rent it to anyone.
Where the law requires a legal basis for processing, we rely on the performance of the contract between your organisation and us, our legitimate interest in operating and securing the Service, your consent where we ask for it (for example, optional notifications), and compliance with legal obligations.
7. Sharing and disclosure
We share personal data only in these circumstances:
- Within your organisation. Other members see the information described in section 9.
- With service providers who host and operate parts of the Service on our behalf — see section 8. They may only use the data to provide their service to us.
- Where the law requires it — to comply with a valid legal request, or to establish, exercise or defend legal claims.
- In a business transfer. If the Service is acquired or merged, data may transfer to the successor, who will remain bound by this policy or give notice of any change.
We do not share personal data with advertisers or data brokers.
8. Third-party services
The Service relies on the following providers:
| Provider | Used for | Data involved |
|---|---|---|
| Google Firebase (Google LLC) |
Authentication for chat, the real-time message database, file storage, and push notification delivery (Firebase Cloud Messaging). | Account identifier, email address, chat messages, uploaded files, device push token. |
| Google Play (Google LLC) |
Distributing and updating the Android app. | Handled by Google under its own policy; we receive only aggregate install statistics. |
| Our hosting provider | Running the application servers and database that hold your account, team, guest, event, feedback and video data. | All data described in section 3, other than the Firebase items above. |
Google's handling of data it processes is described in the Google Privacy Policy.
9. Who can see your data
Future Forward is a shared workspace, so some of your information is visible to others in your organisation by design:
- Other members can see your name, username, profile photo, role and rank, and your position in the binary chart.
- Your leader can additionally see your guests, event attendance and daily feedback.
- Your administrator can see everything recorded within their tree, including your extended profile, and can edit your account and reset your password.
- The super administrator can see all trees on the platform.
Each administrator's tree is isolated: members of one organisation's tree cannot see members, guests or activity belonging to another.
Chat messages are visible to the people in that conversation and to administrators of the platform.
10. Data retention
- Account and profile data is kept while your account is active, and deleted or anonymised within 90 days of your account being deleted.
- Guest, event, feedback and attendance records are kept while your organisation needs them, and are removed with the account that owns them.
- Chat messages are kept until deleted by a participant or an administrator, or until the account is deleted.
- Server and security logs are kept for up to 12 months.
- Backups may retain copies for up to 35 days after deletion, after which they are overwritten.
We may keep information for longer where the law requires it, or to resolve a dispute.
11. Security
We take reasonable and appropriate measures to protect your information, including:
- encrypted connections (HTTPS/TLS) between the apps and our servers;
- passwords stored only as salted one-way hashes, never in readable form;
- session tokens held in the device's encrypted secure storage;
- role-based access controls, with each administrator's tree isolated from every other; and
- restricted administrative access to production systems.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities where the law requires it.
12. Your rights and choices
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have your data deleted (see section 13);
- restrict or object to certain processing;
- receive your data in a portable format; and
- withdraw consent where processing is based on it — for example by turning off notifications.
To exercise any of these, write to privacy@futureforward.cloud. We will respond within 30 days. Because your organisation controls your account, we may need to consult them before acting, and we will tell you if we do. You may also complain to your local data protection authority.
You can turn off push notifications at any time in your device's Android settings without affecting the rest of the app.
13. Account and data deletion
How to request deletion of your account and associated data:
Email privacy@futureforward.cloud from the address registered on your account, with the subject line "Delete my account". Include your username so we can identify the account. If you cannot email from the registered address, contact your organisation's administrator, who can raise the request on your behalf.
What is deleted: your account record, profile details, profile photo, daily feedback, chat messages, video view history, push token, and any guest records you personally created.
What may be retained, and why: records that belong to your organisation rather than to you — such as an event whose attendance list includes you, or a member who was placed beneath you in the team structure — are retained so the organisation's own records stay intact. Where this happens your entry is anonymised wherever it is not needed. We also retain what the law requires us to keep, and security logs for the period stated in section 10.
Timing: requests are actioned within 30 days, and data is fully removed from live systems and backups within 90 days.
Deleting the app from your phone does not delete your account — please use the process above.
14. Children
The Service is intended for adults working within a member organisation. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has been given an account, contact us and we will remove the account and its data.
15. International transfers
Our providers — including Google Firebase — may process and store data on servers in countries other than your own. Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission's standard contractual clauses or an adequacy decision, as applicable.
16. Changes to this policy
We may update this policy as the Service changes. The "Last updated" date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will give notice in the app or by email before it takes effect. Continuing to use the Service after a change means you accept the updated policy.
17. Contact us
Questions about this policy, or about the data we hold about you:
Future Forward
Email: privacy@futureforward.cloud
For data deletion requests, see section 13.