Privacy Policy
Last updated: September 15, 2026
Pushup RPG is built to respect your privacy. This policy explains exactly what the app does and does not do with your data.
A note for Android users. The detail below describes the iPhone app. The substance is the same on Android — pose detection runs on your device, camera video is not uploaded for rep counting, and clips stay local — but the system prompts and integrations are Google's rather than Apple's, and Apple Health has no counterpart. Where a section names iOS specifically, read it as the iPhone behaviour. We are working through the Android specifics; until they are published here, email support@pushup.quest and we will tell you exactly what applies on your device.
Camera
The app uses your device camera to count pushups, squats, sit-ups, pull-ups and dips by detecting your body pose, and to time your plank the same way. All processing happens on-device, in real time. Pose detection never records, stores, or transmits video, images, or pose data off your device. Unless you turn on clip recording (below), the camera feed exists only in memory while a battle is active and is discarded immediately. Camera data is never uploaded to our servers or anywhere else.
Clips (optional, off by default)
If you turn on Record clips in Settings, the app records your battle or practice screen — the camera view plus the game overlays — into a video clip stored only on your device. On iPhone, iOS asks for your explicit confirmation before each session's first recording, and a REC indicator is visible whenever recording is active.
- Clips never leave your device unless you choose to share them (on iPhone, via the iOS share sheet) or save them to your Photos library.
- We never receive, upload, or process your clips — there is no server involved.
- Recording stops automatically after 3 minutes, and you can stop it any time by tapping the REC indicator.
- Unshared clips are kept temporarily on-device and cleaned up automatically.
Microphone (your choice, per the system's own prompt)
When a recording starts, iOS's own consent sheet lets you choose Record Screen and Microphone or Record Screen Only. If you allow the microphone, your clips include audio from the device microphone (your voice and the surrounding room) so shared videos carry the real moment. Like the video, this audio is recorded only on your device, only while you record, and is never uploaded to us. If you pick Screen Only, clips include only the game's own sound effects.
Photos
Two separate things, and neither gives the app the run of your library.
- Saving a clip (via Save Video on the iOS share sheet, on iPhone) uses add-only access.
- Choosing an avatar photo (a Vigil perk — see Your avatar photo below) opens Apple's own photo picker, which runs outside the app. We receive only the single image you pick; the app cannot see, browse, or search the rest of your library, and it never asks for photo-library permission.
Your avatar photo (Vigil members, optional)
With a Vigil membership you can use your own photo as your portrait instead of one of our painted ones. Because this is the one thing in the app you upload, here is exactly what happens to it.
- The image is cropped and shrunk on your device before it leaves — we never receive the full-resolution original.
- Before upload, the device screens it on-device for explicit content — on iPhone this is Apple's own analyser. This uses Apple's own analyser and, like everything else in the camera path, the picture is not sent anywhere to be checked.
- It is then stored on our servers, attached to your account.
- It is public. Your avatar is shown to other players wherever your name appears — your guild roster, the friends list, the worldwide leaderboards, duels. Anyone who can see your name can see your face. Please only upload a photo you are happy for strangers to see, and only one you have the right to use — do not upload a picture of someone else without their agreement.
- You can remove it whenever you like, from the same portrait picker you chose it in. Removing it takes it off every screen in the app immediately.
- It is deleted when you delete your account.
- Other players can report your avatar, and we can remove it — see Content moderation below.
Diagnostics you choose to send
If the camera is miscounting your reps, Settings → Reps not counting? lets you send us what the detector decided. The screen shows you the exact lines before anything is sent, and nothing goes anywhere unless you tap send. It contains the detector's own measurements — joint angles, timings, the reason each rep was accepted or refused — plus your app version, attached to your account so we can follow up. It does not include your device model.
No video, no images, and no photographs of you are ever included in that report — the camera feed never leaves your device, as described under Camera above.
The app also keeps a small tally of why reps were refused (for example "too shallow"), which rides along in your cloud save and helps us see which failures are common.
Automatic camera-session diagnostics. Separately from the report above, and without asking you each time, the app sends us a short summary at the end of every camera session: how long the camera ran, how many reps were counted, how many were refused, how many attempts ended as neither (a rep abandoned halfway, for example), the most common refusal reason as a code, a code for how far the detector got if it never managed to start counting, which screen and which movement you were doing, whether you were on iPhone or Android, your device’s performance tier and the app build. These are numbers and codes only. They are linked to your account, batched, and sent once per session. No video, no images and no joint coordinates are included, and as everywhere else on this page the camera feed itself never leaves your device. We use this to find detection failures we would otherwise only hear about from the few people who write in. Summaries are kept for about a week, then deleted.
Automatic usage events. Also without asking you each time, the app records a handful of other moments in the same way, as numbers and codes linked to your account:
- Opening the app: how long since you last opened it and since you installed it, and a rough band for your lifetime reps.
- Finishing onboarding: how long it took and which steps you saw.
- Your first counted rep: how long after you installed the app it came.
- A membership screen closing: how long it was open, which screen and which version of it, what opened it, which price tiers it showed, and whether you closed it, started a trial or bought.
- Being refused a place in a guild: the reason, such as the guild being full or you being below its minimum level.
- Battle clips, only if you turned clip recording on: how many seconds of clip were captured, how long the camera ran, which screen you were on, how the recording ended, and whether you went on to share it.
- Your difficulty baseline changing: the old and new value, and whether onboarding, Settings or a suggestion in the app changed it.
- Accepting the offer to count knee push-ups: how many reps had counted by then, what prompted the offer, and which screen you were on.
Each event also carries your device’s performance tier, the app build and whether you are on iPhone or Android. None of it includes video, images or anything you typed. This is our own record, kept on our servers, and it is separate from what AppsFlyer receives, which is described under Install measurement below. We use it to see which parts of the app work and where people give up. Usage events are deleted after about a week, and after that only daily totals with no account attached remain.
When we ask you how many you actually did. Every so often, after a session in which the camera ran for at least 40 seconds, the app shows how many reps it counted and asks whether that is right. If you say no, it asks how many you actually did. It asks at most once a day on each device, and whether it asks has nothing to do with how the set went. If you answer, we store the number the camera credited, your answer (the same number, if you said it was right), how many reps it refused, how long the camera was running, which movement it was and which screen you were on, along with your app version, attached to your account. For push-ups we also store two measurements of how you appeared in the frame, the width of your shoulders and the length of your torso as a share of the picture, which show roughly how the phone was placed. That is the whole record: no video, no images, no joint coordinates, no free text, and nothing you typed beyond the number. Answering is optional and skipping it changes nothing. We use it to measure how often the detector disagrees with the person actually doing the reps, which is the one thing the camera cannot tell us by itself.
Automatic error reports. Also without asking you first, the app records a short note when something fails in a way it recovered from quietly, such as a camera session that was interrupted or a save that had to be retried. Each note is a short label for what happened, a technical detail such as an error code, your app version and your account, and at most one of each kind is recorded per hour. Our servers write a note of the same shape in three situations, and those carry more: renaming a guild you captain records the old and new names, so a moderation takedown has a trail; a day's reps going past the leaderboard cap records that day's count and your lifetime total; and a friend addition that trips our flood or consent checks records both players' account identifiers, on the account that made the addition. These notes contain no video, no images and no location. Each is deleted when the account it is recorded on is deleted.
Apple Health (iPhone only, optional)
Only pushup and squat sessions are written to Apple Health — sit-ups and planks are not, and nothing about them reaches Health at all. If you turn on Sync to Apple Health in Settings, Pushup RPG saves your battles and practice sessions to Apple Health as workouts (with an estimated active-energy value and your rep count) so they count toward your Activity rings. This is opt-in and write-only: we only add workouts to your Health data — we never read any of your health information, it never leaves your device to our servers, and we never sell it, use it for advertising, or share it. You can turn this off anytime in Settings, and manage or delete the data in the Health app.
Accounts and cloud sync
To back up your progress across devices and to power the friends leaderboard, the app uses a cloud account (provided by Supabase). You can sign in with:
- Sign in with Apple, Google, or email (a one-time code / magic link), or
- Continue as a guest — an anonymous account is created so your save still backs up, with no name or email attached.
What we store on your account:
- Game progress — level, XP, streak, gear, currencies, settings, lifetime reps.
- Profile — the display name you choose, a randomly generated friend code, your level, class, current streak, and weekly rep total. This profile is visible to friends you add and to the members of any guild you join — see Guilds below.
- Contact identifier — if you sign in with email, your email address; with Apple or Google, the identifier they return. Used only to authenticate your account.
- A push token, so the app can send you notifications. See Notifications below.
- Your avatar photo, if you are a Vigil member and chose to upload one. See Your avatar photo above — it is public to other players.
- Detection diagnostics, if you sent a report. See Diagnostics you choose to send.
We do not collect contacts, and no health/fitness data beyond the rep counts that are part of your game progress. The app never asks for GPS or precise location, and there is no location permission prompt. There is one coarse exception, and we would rather name it than bury it: your country is derived on our server from the IP address your device connects from, so that country leaderboards can exist. Your country below explains exactly what is stored and what it is used for.
Notifications
To send you notifications, the app needs a push token: an identifier that Apple (on iPhone) or Google (on Android) issues so that a notification can reach the app on your phone. The app stores it on our servers against your account, a guest account included, together with which platform it came from, when it was last registered and, from recent versions of the iPhone app, the app version. On iPhone, the app only asks Apple for a token after you have allowed notifications.
We use it to tell you when a friend cheers you on or challenges you to a duel, when a referral you made pays out, when your streak is about to lapse, when another player starts searching the Arena while you are waiting in it, and, if you run a guild, when someone applies to join. If a different account later signs in on the same phone, the token moves to that account. When Apple or Google tells us a token no longer works, we delete it. You can turn notifications off at any time in your phone's settings.
Install measurement
The app includes AppsFlyer for install attribution and product analytics. It is not limited to aggregate counts, and we would rather describe it accurately than reassure you: alongside Apple’s SKAdNetwork on iPhone, the app sends AppsFlyer an event stream tied to your account — app opens and activation, onboarding steps (including whether you allowed notifications and camera access), paywall views and dismissals, trial starts, level milestones, and completed purchases with the amount, currency, product and Apple transaction id. Your Pushup RPG account id is passed to AppsFlyer as the customer identifier, so those events are linked to your account rather than being anonymous.
We also use RevenueCat to manage subscriptions and entitlements. It receives your account id and your purchase and subscription history, and our server asks it whether your account has an active membership.
What we can still tell you plainly: the app never shows an App Tracking Transparency prompt and does not use the ATT advertising identifier, and there are no ad-serving SDKs — you will not see ads in Pushup RPG. We do not sell your data. AppsFlyer is nonetheless an attribution vendor with its own tracking capabilities, so if that matters to you, treat this as a real third-party disclosure rather than a formality.
Friends
Adding a friend is mutual and is done by exchanging friend codes. A friend code only resolves to a profile when entered exactly — profiles cannot be browsed or listed. Removing a friend removes the connection for both people and revokes their access to your profile.
Guilds
You can join a guild — a small team that shares a weekly goal — or, with a Vigil membership, create one. This makes some information visible more widely than Friends:
- Your profile (display name, class, level, streak, weekly reps) is visible to the other members of any guild you join, who may not be your friends.
- A guild name and motto you create, and the guild names shown in the public browse directory, are visible to all players and may appear on images you choose to share.
- Content moderation. Guild names/mottos, display names and avatar photos are all content players create. Names are filtered against a blocklist, and avatar photos are screened on-device before upload by Apple's analyser, which catches sexually explicit imagery — other objectionable content, including a photo of someone who did not consent, is caught by the report path rather than the filter. You can report an offensive name or picture from inside the app — the ⋯ button beside any player, on every screen that shows one. We review reports and remove violating content, and may remove an offending account's ability to upload a picture at all — there is zero tolerance for objectionable content.
Your country
Country leaderboards need to know which country you belong to. Two separate things do that, and only one of them involves your IP address.
- A country code we derive (not chosen by you). When your profile is written, our server reads the two-letter country code that our network provider attaches to the request — a value derived from the IP address your device is connecting from — and stores that code on your profile. Your IP address itself is not stored on your profile; only the two-letter country code. (Every internet service processes IP addresses in order to route traffic at all, and our hosting providers are no exception.)
- It is recorded once and never updated. The first value seen is kept, and later connections do not move it. That is deliberate: re-reading it on every write would turn a single coarse attribute into a running record of where you have been, and we did not want to hold that. The practical consequence is that it reflects where you were when you first played — a VPN, a trip or a move will not change it, and you cannot edit it. It is deleted with your account.
- Where it is used. It decides which country's leaderboard you appear on, and it can be counted in country-level figures we publish, which never identify you (see Statistics we publish). If your country cannot be determined — including connections our provider reports as unknown, and traffic arriving over Tor — nothing is stored, and you simply do not appear on a country board.
- A flag you pick (optional). Separately, you can choose a flag in the app. That one is your choice, it is shown publicly next to your name, and you can change or clear it whenever you like. We suggest a likely country when you open the picker, but nothing is saved unless you tap it.
Live duels and the Arena
You can duel a friend, or enter the Arena and be matched with another player you have not met. There is no chat and no messaging in a duel — two cameras and a timer.
- While you are searching, we hold a short-lived queue entry with your account id, your level and which exercise you picked, so the matchmaker can pair you with someone at a similar level. It is removed the moment a match is made, and it is ignored after 90 seconds.
- During a bout, your opponent sees your display name, class, level, your portrait or avatar, and your rep count as it climbs. They do not see your camera: pose detection stays on your device, and only the number of reps is sent. Nothing about your opponent's video reaches you either.
- Blocking. You can block a player from the result card. We store that as a pair of account ids and the time it was made, and it stops the two of you being matched again. You can undo a block you made, from Settings — you cannot remove someone else's block on you, which is the point of the feature.
- Reporting. Reporting a player sends their account id and your reason to our moderation queue, along with context we use to judge the report — their level, lifetime reps, best day, and how deep they have gone in Endless Descent. See Content moderation above for how reports are handled.
- Recording a bout is optional and off by default. A clip stays on your device until you choose to share it. See Clips above.
Data we share
We do not sell or share your data with advertisers or data brokers. Your profile is shared with the friends you add and the members of any guild you join, and a guild name or motto you create, and an avatar photo you upload, are public to other players. Be aware it also goes wider than that: if you rank on the worldwide daily or weekly rep ladders, on your country's ladder, or on the Endless Descent board, your display name, class, level and the ranked figure are visible to every signed-in player — together with the flag you picked, if you picked one. Entering the Arena shows your display name, class, level and portrait to the player you are matched with; see Your country and Live duels and the Arena above. Three processors handle data on our behalf: Supabase (hosting, accounts and cloud saves), RevenueCat (subscriptions and entitlements — it receives your account id and purchase history), and AppsFlyer (install attribution and product analytics — see Install measurement above for what it receives).
Statistics we publish
We may publish figures calculated across many players, such as the total number of push-ups counted in the app, or how players in different countries compare. A published figure never includes your name, your account or anything else that identifies you, and we do not publish a figure about any group of fewer than 30 players, because a figure drawn from that few people can amount to one person's result. This is separate from the leaderboards, which do show individual players, as described under Data we share above.
Who is responsible for your data
Pushup RPG is made by Yerasyl Amanbek, who is the data controller for the information described on this page. The contact address is support@pushup.quest, or use the contact page and put Privacy in the subject.
Your rights over your data
If you are in the UK or the EEA, data protection law gives you the rights below. We apply them to everyone, wherever you live, because splitting them by country would be more work than honouring them.
- Access. Ask what we hold about you and we will send it.
- Rectification. Correct anything wrong. Your display name and flag you can change yourself in the app.
- Erasure. Delete your account from Settings → Delete account, or ask us. Read Deleting your data below first, because a few records survive and we would rather you knew which.
- Portability. Ask for a copy of your account data in a machine-readable format.
- Objection and restriction. Object to, or ask us to pause, processing that rests on our legitimate interests.
- Withdrawing consent. Where something is optional and you turned it on, you can turn it off: clip recording, the avatar photo, sending a detector report, and Apple Health.
- Complaint. You can complain to your national data protection authority. In the UK that is the ICO; in the EEA it is your country's supervisory authority. We would rather you told us first, but you do not have to.
We will not charge you for any of this and will not make you justify the request.
Why we are allowed to process it
- Running your account, syncing progress, friends, guilds, duels and leaderboards — performance of the contract you enter when you create an account and play.
- Deriving your country from the connecting IP address — legitimate interests, so that country leaderboards can exist. The IP itself is not stored on your profile.
- Install measurement and product analytics — legitimate interests in understanding which channels bring players and which features get used.
- Automatic usage events, camera-session summaries and error reports — legitimate interests in finding what is broken and which parts of the app work.
- Purchases, entitlements and accounting records — performance of the contract, and our legal obligation to keep records of sales.
- Push tokens and notifications — legitimate interests in reaching you about your game, such as a friend's challenge or a streak about to lapse. You can turn notifications off in your phone's settings.
- Statistics published across many players — legitimate interests in reporting what players achieve, limited as described under Statistics we publish.
- Security, anti-abuse and moderation — legitimate interests in keeping the boards honest and players safe.
- Clip recording, the avatar photo, detector reports and Apple Health — your consent, given by turning each one on, and withdrawable by turning it off.
How long we keep it
- Your account and game data — until you delete the account. We do not expire accounts for inactivity.
- Detector reports you send — kept while we investigate the counting problem they describe, then deleted.
- Usage events and camera-session summaries — about a week, then deleted. Only daily totals with no account attached are kept after that.
- Purchase and entitlement records — kept after deletion for as long as accounting and tax rules require.
- The referral anti-abuse hash — kept after deletion by design, because its whole purpose is to stop the same device claiming a referral repeatedly. It is one-way and cannot be turned back into a device or an account.
Where your data goes
The processors we use are named under Data we share: Supabase for accounts and cloud saves, RevenueCat for subscriptions and entitlements, and AppsFlyer for install measurement. Apple and Google hold your purchase records because they take the payment.
These are international services, so your data may be processed outside the country you live in, including outside the UK and the EEA. Each of them publishes its own data-processing terms and transfer safeguards, which are linked from their own sites.
Deleting your data
You can delete your account at any time from Settings → Account → Delete account. That removes your profile, cloud save, avatar photo, leaderboard entries and friend connections from our servers. A few things survive by necessity — a one-way referral hash, purchase and entitlement records held for accounting, and any anti-abuse record — and records held by Apple, Google Play, RevenueCat and AppsFlyer are not ours to delete. The deletion page lists each one and how to reach those providers. Uninstalling the app removes the local copy on your device.
Children
The app is designed for general audiences. Account creation (and therefore the social features) is intended for users able to consent under their local law; younger players can use the app fully in guest mode.
Android beta waitlist (closed)
Pushup RPG is now released on Google Play, so the Android beta waitlist is closed and we are no longer collecting emails for it. If you signed up while it was open, we stored only your email address in order to send you a single notification, and it was never used for anything else, sold, or shared. You can have it deleted at any time by emailing support@pushup.quest.
Website analytics
This website uses privacy-friendly, cookieless analytics (Vercel Web Analytics) that count aggregate page views. It sets no cookies and builds no advertising profile.
Advertising measurement on this website
If we are running ads, we need some way to tell which ones actually bring people here. We ask first. When advertising measurement is switched on you will see a banner offering Accept or Decline, and nothing is set until you choose Accept. Declining costs you nothing: every page works identically either way.
If you accept, we load tags from Google Ads and Meta. These are ordinary advertising trackers and we would rather say so plainly than call them something softer: they set cookies, they can recognise you on other websites that use the same networks, and they let us see that someone who clicked an ad went on to open the App Store link. They do not receive your name, your email, your account, or anything you do inside the app.
Your choice is remembered in your browser, not on our servers, and it applies until you clear your browser storage. To change it, clear site data for pushup.quest and the banner returns. If you never see a banner, no advertising tag has been loaded at all.
None of this applies to the app. Advertising measurement described here is a website matter only. What the app collects is described above, under Install measurement.
Contact
Questions or data requests: support@pushup.quest