1. Who is responsible
The pushup.group team is responsible for the processing described on this page. Privacy and data requests can be sent to hello@pushup.group.
2. Camera analysis and workout video
We ask for camera permission only after showing an explanation. The live camera image is analyzed on your device with MediaPipe to recognize your pose and count repetitions. Raw frames are not sent to our server for pose recognition.
When you start a set, your device also creates a short, sped-up replay. After you confirm the set, that replay and a smaller preview are uploaded to private Cloudflare storage. They appear in your timeline and may be shown to members of the group you selected. Each replay has an unlisted share link: it is hard to guess, but anyone who receives the link can open the video without signing in.
Your device temporarily records an unedited version while you train. It is discarded when you accept the automatic count. If you manually correct the count, the unedited recording may be uploaded as private correction evidence so administrators can improve and evaluate the counter. It is not shown to group members or through a replay link.
You can deny or revoke camera access in your browser or device settings. Without camera access, the automated counter and replay flow cannot run.
3. Other data we process
- Account and profile: Firebase user ID, email address, name, optional date of birth, profile photo and sign-in provider.
- Groups and workouts: memberships, roles, invitations, goals, repetitions, timestamps, duration, streaks, rewards and replay references.
- Coarse location: Cloudflare-derived country code and, where available, a coarse region code for an account's first activity, completed sets and support reports. We do not request GPS access or store coordinates or the source IP in the application database.
- Device and counter diagnostics: broad device, operating system and browser details, language, screen size, camera resolution and performance measurements for a completed set. We do not store a camera ID or raw user-agent string with the workout.
- Notifications: a device push endpoint and encryption keys after you opt in, your category preferences, timezone and quiet hours, short-lived in-app reactions, and targeted root-admin campaign reminders using the selected audience limit.
- Product analytics: page views, feature and install events, scroll depth, a random analytics session ID, browser, device class, operating system, language and external referrer hostname. The event payload contains no account ID, email address or raw invite token.
- Support and payments: feedback you submit with basic device context, and payment status, amount, currency and provider references for purchases. Full payment credentials are handled by the payment provider, not stored by pushup.group.
For a category-by-category view, including visibility and retention, see Your data.
4. Why we use this data
We process data to:
- create and secure your account;
- count sets, keep workout history and update group goals;
- create and share the replay you choose to submit;
- send the notification categories you enable after you opt in, respect your timezone and quiet hours, and show targeted campaign reminders using the selected audience limit;
- operate purchases and provide support;
- protect, diagnose and improve the service and counter.
The proposed legal bases are performance of the service agreement, consent for device permissions, legitimate interests in operating and improving the service, and legal obligations for financial records. These bases require confirmation during legal review.
5. Who receives data
- Your groups: members can see your display name, photo, contributions, stats and submitted replays within the product.
- Cloudflare: hosting, API execution, database, private object storage, email delivery and coarse request location.
- Google Firebase: account authentication, including optional Google sign-in.
- Danno Events: pseudonymous product-event ingestion when analytics is configured.
- Mollie: payment processing when you choose a paid feature.
- Administrators: limited account, support, diagnostic and private correction-evidence access needed to run and improve the product.
We do not sell personal data. Providers may process data outside your country; the legal reviewer must confirm the applicable transfer safeguards and processor terms before publication.
6. How long data is kept
- Account, profile, workout history, diagnostic snapshots, submitted replays and private correction evidence are kept until the account is permanently deleted, unless removed earlier for a valid request or operational reason.
- Push subscriptions remain until you disable them, the endpoint becomes invalid or the account is deleted.
- In-app reactions are removed after display or after at most 30 days.
- Expired unused invitations are removed by the scheduled cleanup; accepted invitations are removed after 30 days.
- Feedback remains linked to your account until account deletion unless removed earlier. Financial records may be retained for the period required by law.
- Analytics events and infrastructure logs are retained only as long as needed for product measurement, security and reliability under the configured provider retention. The exact analytics and log periods must be confirmed during legal review.
7. Your controls and rights
You can change your name, optional birth date, profile photo, camera guide and notifications in the app. Notification and camera permission can also be revoked in browser or device settings.
In Profile & settings → Danger zone, you can permanently delete the account after a fresh sign-in and two confirmations. This removes the application account, Firebase sign-in, profile media, workouts, replays, private correction evidence, memberships and push subscriptions. Groups you own and their group-scoped history are also deleted for every member. Contributions are removed from groups you do not own and their totals are recalculated.
For access, correction, deletion, restriction, portability or an objection, use the contact page. You may also complain to the competent data-protection authority.
8. Changes to this policy
We will update the date above when this policy changes. Material changes should be communicated in the product before they take effect.