pushup.group

Data transparency

What happens to your data, at a glance.

This inventory describes the current product behavior. It complements the privacy policy with practical detail about storage, visibility and deletion.

Last updated 18 August 2026

Camera and workout data

DataWhere and whyWho can see itRetention
Live camera frames and pose pointsProcessed on your device to count repetitions. The app does not send raw frames or pose landmarks to the server for recognition.You, on your screen.Live processing only; discarded when the camera stops.
Short replay and previewCreated on your device after a set and uploaded to private Cloudflare R2 storage.You, selected group members, and anyone who receives the unlisted replay URL.Until account deletion or an earlier valid deletion action.
Unedited corrected-set evidenceTemporarily captured on-device; uploaded only when the automatic count is manually corrected, to evaluate the counter.Authorized administrators only. Never shown in group timelines or through a replay URL.Until account deletion or earlier administrative removal.
Workout recordRepetitions, recognized count, manual-correction flag, duration and times are stored in Cloudflare D1 to build personal and group progress.You, relevant group members in aggregated views, and administrators.Until account deletion.

Account, device and communication data

DataWhere and whyVisibilityRetention
Login and profileEmail and identity are managed with Firebase. Name, optional birth date and metadata-free profile images support your app profile.Email is limited to you and administrators; name and photo are visible to your groups.Until account deletion.
Groups and invitationsCloudflare D1 stores names, memberships, owner roles, targets, progress and invite records.Group participants and administrators, depending on the field.Group history lasts until group or owner-account deletion. Expired invites are cleaned up; accepted invites after 30 days.
Country, region and device diagnosticsCloudflare derives country and coarse region from the request. A completed set stores broad device, browser, screen, camera and counter-performance data for support and improvement.Authorized administrators.Workout-linked data lasts until account deletion.
Push subscriptionYour push endpoint and encryption keys are stored only after opt-in so group notifications can reach this device.Service infrastructure and administrators; other members cannot see the endpoint.Until disabled, invalidated or account deletion.
Notification preferences and eventsYour notification categories, timezone and quiet hours control delivery. We store minimal notification lifecycle events so permission and delivery flows can be measured.Preferences are private to you and authorized administrators; event data is available to product administrators.Until account deletion, subject to configured operational retention.
Campaign reminder and dismissalA root-admin campaign can target people without their own group, people without a logged push-up, or everyone. An in-app reminder stores a campaign/user dismissal so it stays dismissed.The targeted user sees the reminder; campaign content and publication state are available to authorized administrators.Until account deletion, or campaign revocation for an active reminder.
Product analyticsDanno Events receives pseudonymous feature events, a random session ID and broad browser/device context. The app payload excludes account ID, email and raw invite tokens.Product administrators and the analytics provider.Provider retention must be confirmed before legal publication.
Feedback and paymentsFeedback text and diagnostic context are stored in D1. Mollie handles payment details; the app keeps status, amount, currency and references.Administrators and, for payments, Mollie.Feedback lasts until deletion unless removed earlier. Financial records follow legal requirements.

Deletion: what actually happens

Account deletion requires a fresh sign-in, the exact account email and a second confirmation. The server removes database records and media, recalculates shared totals, then deletes the Firebase login. A temporary retry marker prevents a partial failure from recreating already-deleted app data. The marker is removed after Firebase confirms deletion.

Deleting a group removes group settings, membership, progress, invitations and group links to sessions. Members keep their personal accounts and workout history. Deleting the owner's account also deletes every group that person owns.

Start in Profile & settings → Danger zone, or use the contact page if you cannot sign in.