← Back to Fwrd

Privacy

Last updated August 27, 2026

In short

  • Fwrd has no account. You never sign in, and Fwrd holds no customer identity for you.
  • Your messages are processed on your iPhone and sent to the destinations you configure. Fwrd does not operate a relay or a server that receives them.
  • Neither the app nor this website runs advertising or analytics SDKs, and nothing here tracks you across apps or websites.

Message data

When a Message automation you created in Apple Shortcuts matches an incoming message, Shortcuts passes the message text and the sender value into Fwrd's Forward Message action. Fwrd uses those values to build a request for each destination you have turned on and sends it directly from your iPhone to that destination.

You choose the matching criteria in Shortcuts, so you decide which messages reach Fwrd at all. Fwrd does not request access to your Contacts or your message history, and it cannot read messages your automation does not pass in.

Where forwarded messages go

Direct destinations, such as a chat webhook or your own HTTPS endpoint, receive an HTTPS request from your iPhone containing the message text, the sender, and a timestamp. Every destination is one you own and configure; Fwrd runs no shared webhook, bot, or inbox.

Once a message reaches a destination service, that service holds it under its own privacy policy and retention rules, and Fwrd cannot reach or delete it. Some destinations are native Shortcuts actions rather than Fwrd requests — for those, Apple's or the provider's own action does the sending, under their policies.

Data stored on your iPhone

Everything the app stores stays on your device:

  • A local forwarding log containing message text, sender, destination, time, and delivery result, along with the number of send attempts and any error the destination returned. Fwrd keeps at most 500 entries and drops entries older than 30 days.
  • Your destination settings — labels, chat identifiers, recipients, and setup progress.
  • A counter of how many free forwards you have used in the current calendar month.
  • A record of whether your Fwrd Pro subscription was active the last time it could be checked, so forwarding still works when an automation runs without a network connection.

That log is stored in the app's local data on your iPhone, not on Fwrd servers, inside the app's private container with iOS file protection applied. None of the data in this section is transmitted to Fwrd.

Destination credentials

Webhook URLs and bot tokens are treated as secrets, because anyone holding one can post to your channel. Fwrd stores them in the iOS Keychain, on that device only, and does not sync them to iCloud or send them to any Fwrd system. Your saved destination settings hold only a reference to the Keychain entry, never the secret itself, and editing or deleting a destination releases the entries it no longer needs.

Subscriptions and purchases

Fwrd Pro is sold through the App Store. Apple processes the payment, and Fwrd never sees your payment method, card details, or Apple Account credentials.

Fwrd uses RevenueCat to determine whether your subscription is active. The RevenueCat SDK sends your App Store purchase and receipt information, an anonymous identifier it generates for the installation, and basic device and app metadata such as iOS version and app version to RevenueCat's servers. Fwrd does not supply your name, email address, or any message data to RevenueCat, and does not set an identifier of its own — the identifier is random and is not linked to a waitlist email address.

Your purchase belongs to your Apple Account, which is what lets Restore Purchases work without a Fwrd account. Subscriptions are managed and canceled in your Apple Account settings, not in Fwrd.

Notifications

Forwarding notifications are scheduled locally on your iPhone. There is no push server, and a notification names the destination rather than repeating your message text. Notification permission is optional and can be withdrawn at any time in iOS Settings.

Deleting app data

You can clear the forwarding log or delete individual destinations inside the app at any time. Deleting a destination also releases its stored credentials, so delete your destinations before removing the app if you want to be certain no credential remains in the Keychain.

Deleting Fwrd from your iPhone removes the forwarding log, your destination settings, the usage counter, and the stored subscription state. It does not remove anything already delivered to a destination service — remove that in the destination service itself.

Website and waitlist

When you join the waitlist on this website, Fwrd stores your email address in Supabase to send a launch notification and to deliver an eligible launch offer, and sends an internal notification containing that address to the Fwrd inbox. We do not sell your email address or use it for unrelated marketing. The waitlist email is a notification and offer-delivery channel — it is not an app account and is not linked to anything in the app.

The feedback form sends the name you provide, your reply email, the selected topic, and your message to the Fwrd inbox. Please do not put real message contents or destination credentials into any form on this website.

Waitlist email addresses are retained until the launch notification has been sent or until you ask us to delete yours.

Website analytics

This website runs no analytics. Fwrd loads no analytics or advertising script, sets no tracking cookie, and sends your visits to no measurement service.

One caveat, stated plainly: Cloudflare fronts this site and automatically inserts its own Web Analytics beacon into the page. The site's Content Security Policy blocks that script from loading, so it does not execute and does not measure your visit. Beyond that, Vercel and Cloudflare keep the operational request logs any web host keeps in order to serve and protect the site.

Service providers

The iPhone app uses Apple for App Store purchases and RevenueCat for subscription status. This website uses Vercel for hosting, Cloudflare for DNS and content delivery, Supabase to store waitlist email addresses, and Resend to deliver feedback and internal waitlist notifications. Each provider processes only the data needed to operate its service. You can read the RevenueCat privacy notice.

Changes and contact

If this policy changes materially, the date at the top of this page will change with it. To request deletion of a waitlist email address or ask a privacy question, email [email protected].