← HomePrivacy Policy
Last updated: April 26, 2026 · Effective: April 26, 2026
This policy applies to the pushup.cc website. By using pushup.cc you agree to this policy.
Who we are
pushup.cc is operated by Jack Miller, an individual developer based in Austin, Texas. Contact: privacy@pushup.cc.
What we collect
Only what's necessary to make the app work:
- Email address: Account identity, sign-in, account recovery (Supabase Auth, encrypted)
- Display name + optional photo URL: Shown on leaderboards
- Exercise sets (rep count, exercise type, timestamp): Core app function: tracking your workouts
- Daily goals (per exercise type): Progress ring + goal-hit notifications
- Optional body metrics (height in cm, weight in lbs): Used only to calculate "weight moved" stats locally
- Friend connections: Friends-only leaderboard view
- Push notification token (future): Server-sent push alerts (when implemented)
What we DO NOT collect
- Location data
- Contacts
- Photo library access (other than the optional avatar URL you provide)
- Health / HealthKit data
- Microphone or camera
- Browsing history
- Device identifiers (other than the standard Apple-provided session token)
- Behavioral analytics or ad-tracking SDKs (no Google Analytics, Mixpanel, Firebase Analytics, Facebook SDK, etc.). We do use Sentry for crash and error reporting: technical error details only, no behavioral tracking
How we use it
- To provide the app's core function: showing your reps, calculating streaks/records/badges, ranking the leaderboard
- To authenticate you: Supabase Auth handles sign-in
- To send you notifications you've enabled: in Settings → Notifications
- To moderate the platform: the developer can hide or remove abusive accounts via the in-app admin panel
We do not sell your data. We do not share it with advertisers. We do not run ads.
Who can see what
- Public to all signed-in pushup.cc users: display name, photo URL, total reps per exercise, leaderboard standings, badge progress, daily/weekly/monthly/yearly placements
- Private to you: email address, body metrics, daily goals, notification preferences, friend requests
- Visible to your friends only: appearance on your friends' Friends leaderboard view
If you don't want your stats public, the in-app admin can mark your account as "hidden", so your reps still count for your own stats but you don't appear on anyone else's leaderboard, in records, or in friend search.
Data storage + security
- Stored in Supabase: PostgreSQL on AWS, US-East region
- All network traffic uses TLS 1.3: the site refuses non-HTTPS connections
- Row-level security policies: enforce access rules on every database table
- Authentication tokens: live in process-only memory on iOS (cleared on app kill); no passwords are persisted on device
- Encryption at rest: Supabase encrypts data at rest
Data retention
We keep your data as long as you have an account. Delete it any time:
- Self-serve (full): Settings → Danger Zone → Delete Account permanently erases your account and all associated data, instantly
- Full deletion: email privacy@pushup.cc from your account email and we'll delete your account + all associated data within 30 days
Children
pushup.cc is not directed at children under 13. We don't knowingly collect data from children under 13. If you believe a child under 13 has signed up, contact privacy@pushup.cc and we'll delete the account.
Changes to this policy
If we materially change what we collect or how we use it, we'll update the "Last updated" date and notify active users via in-app banner before the change takes effect.
Your rights
You can:
- Access your data: visible directly in the app at any time
- Correct your data: edit display name, body metrics, goals in Settings
- Delete your data: see "Data retention" above
- Export your data: email privacy@pushup.cc and we'll send a JSON export within 7 days
If you're in the EU/EEA you have rights under GDPR. If you're in California you have rights under CCPA. Both routes go through the same email contact above.
Contact
Questions about this policy: privacy@pushup.cc.