Privacy Policy

Last updated: September 15, 2026

Pushup RPG is built to respect your privacy. This policy explains exactly what the app does and does not do with your data.

A note for Android users. The detail below describes the iPhone app. The substance is the same on Android — pose detection runs on your device, camera video is not uploaded for rep counting, and clips stay local — but the system prompts and integrations are Google's rather than Apple's, and Apple Health has no counterpart. Where a section names iOS specifically, read it as the iPhone behaviour. We are working through the Android specifics; until they are published here, email support@pushup.quest and we will tell you exactly what applies on your device.

Camera

The app uses your device camera to count pushups, squats, sit-ups, pull-ups and dips by detecting your body pose, and to time your plank the same way. All processing happens on-device, in real time. Pose detection never records, stores, or transmits video, images, or pose data off your device. Unless you turn on clip recording (below), the camera feed exists only in memory while a battle is active and is discarded immediately. Camera data is never uploaded to our servers or anywhere else.

Clips (optional, off by default)

If you turn on Record clips in Settings, the app records your battle or practice screen — the camera view plus the game overlays — into a video clip stored only on your device. On iPhone, iOS asks for your explicit confirmation before each session's first recording, and a REC indicator is visible whenever recording is active.

Microphone (your choice, per the system's own prompt)

When a recording starts, iOS's own consent sheet lets you choose Record Screen and Microphone or Record Screen Only. If you allow the microphone, your clips include audio from the device microphone (your voice and the surrounding room) so shared videos carry the real moment. Like the video, this audio is recorded only on your device, only while you record, and is never uploaded to us. If you pick Screen Only, clips include only the game's own sound effects.

Photos

Two separate things, and neither gives the app the run of your library.

Your avatar photo (Vigil members, optional)

With a Vigil membership you can use your own photo as your portrait instead of one of our painted ones. Because this is the one thing in the app you upload, here is exactly what happens to it.

Diagnostics you choose to send

If the camera is miscounting your reps, Settings → Reps not counting? lets you send us what the detector decided. The screen shows you the exact lines before anything is sent, and nothing goes anywhere unless you tap send. It contains the detector's own measurements — joint angles, timings, the reason each rep was accepted or refused — plus your app version, attached to your account so we can follow up. It does not include your device model.

No video, no images, and no photographs of you are ever included in that report — the camera feed never leaves your device, as described under Camera above.

The app also keeps a small tally of why reps were refused (for example "too shallow"), which rides along in your cloud save and helps us see which failures are common.

Automatic camera-session diagnostics. Separately from the report above, and without asking you each time, the app sends us a short summary at the end of every camera session: how long the camera ran, how many reps were counted, how many were refused, how many attempts ended as neither (a rep abandoned halfway, for example), the most common refusal reason as a code, a code for how far the detector got if it never managed to start counting, which screen and which movement you were doing, whether you were on iPhone or Android, your device’s performance tier and the app build. These are numbers and codes only. They are linked to your account, batched, and sent once per session. No video, no images and no joint coordinates are included, and as everywhere else on this page the camera feed itself never leaves your device. We use this to find detection failures we would otherwise only hear about from the few people who write in. Summaries are kept for about a week, then deleted.

Automatic usage events. Also without asking you each time, the app records a handful of other moments in the same way, as numbers and codes linked to your account:

Each event also carries your device’s performance tier, the app build and whether you are on iPhone or Android. None of it includes video, images or anything you typed. This is our own record, kept on our servers, and it is separate from what AppsFlyer receives, which is described under Install measurement below. We use it to see which parts of the app work and where people give up. Usage events are deleted after about a week, and after that only daily totals with no account attached remain.

When we ask you how many you actually did. Every so often, after a session in which the camera ran for at least 40 seconds, the app shows how many reps it counted and asks whether that is right. If you say no, it asks how many you actually did. It asks at most once a day on each device, and whether it asks has nothing to do with how the set went. If you answer, we store the number the camera credited, your answer (the same number, if you said it was right), how many reps it refused, how long the camera was running, which movement it was and which screen you were on, along with your app version, attached to your account. For push-ups we also store two measurements of how you appeared in the frame, the width of your shoulders and the length of your torso as a share of the picture, which show roughly how the phone was placed. That is the whole record: no video, no images, no joint coordinates, no free text, and nothing you typed beyond the number. Answering is optional and skipping it changes nothing. We use it to measure how often the detector disagrees with the person actually doing the reps, which is the one thing the camera cannot tell us by itself.

Automatic error reports. Also without asking you first, the app records a short note when something fails in a way it recovered from quietly, such as a camera session that was interrupted or a save that had to be retried. Each note is a short label for what happened, a technical detail such as an error code, your app version and your account, and at most one of each kind is recorded per hour. Our servers write a note of the same shape in three situations, and those carry more: renaming a guild you captain records the old and new names, so a moderation takedown has a trail; a day's reps going past the leaderboard cap records that day's count and your lifetime total; and a friend addition that trips our flood or consent checks records both players' account identifiers, on the account that made the addition. These notes contain no video, no images and no location. Each is deleted when the account it is recorded on is deleted.

Apple Health (iPhone only, optional)

Only pushup and squat sessions are written to Apple Health — sit-ups and planks are not, and nothing about them reaches Health at all. If you turn on Sync to Apple Health in Settings, Pushup RPG saves your battles and practice sessions to Apple Health as workouts (with an estimated active-energy value and your rep count) so they count toward your Activity rings. This is opt-in and write-only: we only add workouts to your Health data — we never read any of your health information, it never leaves your device to our servers, and we never sell it, use it for advertising, or share it. You can turn this off anytime in Settings, and manage or delete the data in the Health app.

Accounts and cloud sync

To back up your progress across devices and to power the friends leaderboard, the app uses a cloud account (provided by Supabase). You can sign in with:

What we store on your account:

We do not collect contacts, and no health/fitness data beyond the rep counts that are part of your game progress. The app never asks for GPS or precise location, and there is no location permission prompt. There is one coarse exception, and we would rather name it than bury it: your country is derived on our server from the IP address your device connects from, so that country leaderboards can exist. Your country below explains exactly what is stored and what it is used for.

Notifications

To send you notifications, the app needs a push token: an identifier that Apple (on iPhone) or Google (on Android) issues so that a notification can reach the app on your phone. The app stores it on our servers against your account, a guest account included, together with which platform it came from, when it was last registered and, from recent versions of the iPhone app, the app version. On iPhone, the app only asks Apple for a token after you have allowed notifications.

We use it to tell you when a friend cheers you on or challenges you to a duel, when a referral you made pays out, when your streak is about to lapse, when another player starts searching the Arena while you are waiting in it, and, if you run a guild, when someone applies to join. If a different account later signs in on the same phone, the token moves to that account. When Apple or Google tells us a token no longer works, we delete it. You can turn notifications off at any time in your phone's settings.

Install measurement

The app includes AppsFlyer for install attribution and product analytics. It is not limited to aggregate counts, and we would rather describe it accurately than reassure you: alongside Apple’s SKAdNetwork on iPhone, the app sends AppsFlyer an event stream tied to your account — app opens and activation, onboarding steps (including whether you allowed notifications and camera access), paywall views and dismissals, trial starts, level milestones, and completed purchases with the amount, currency, product and Apple transaction id. Your Pushup RPG account id is passed to AppsFlyer as the customer identifier, so those events are linked to your account rather than being anonymous.

We also use RevenueCat to manage subscriptions and entitlements. It receives your account id and your purchase and subscription history, and our server asks it whether your account has an active membership.

What we can still tell you plainly: the app never shows an App Tracking Transparency prompt and does not use the ATT advertising identifier, and there are no ad-serving SDKs — you will not see ads in Pushup RPG. We do not sell your data. AppsFlyer is nonetheless an attribution vendor with its own tracking capabilities, so if that matters to you, treat this as a real third-party disclosure rather than a formality.

Friends

Adding a friend is mutual and is done by exchanging friend codes. A friend code only resolves to a profile when entered exactly — profiles cannot be browsed or listed. Removing a friend removes the connection for both people and revokes their access to your profile.

Guilds

You can join a guild — a small team that shares a weekly goal — or, with a Vigil membership, create one. This makes some information visible more widely than Friends:

Your country

Country leaderboards need to know which country you belong to. Two separate things do that, and only one of them involves your IP address.

Live duels and the Arena

You can duel a friend, or enter the Arena and be matched with another player you have not met. There is no chat and no messaging in a duel — two cameras and a timer.

Data we share

We do not sell or share your data with advertisers or data brokers. Your profile is shared with the friends you add and the members of any guild you join, and a guild name or motto you create, and an avatar photo you upload, are public to other players. Be aware it also goes wider than that: if you rank on the worldwide daily or weekly rep ladders, on your country's ladder, or on the Endless Descent board, your display name, class, level and the ranked figure are visible to every signed-in player — together with the flag you picked, if you picked one. Entering the Arena shows your display name, class, level and portrait to the player you are matched with; see Your country and Live duels and the Arena above. Three processors handle data on our behalf: Supabase (hosting, accounts and cloud saves), RevenueCat (subscriptions and entitlements — it receives your account id and purchase history), and AppsFlyer (install attribution and product analytics — see Install measurement above for what it receives).

Statistics we publish

We may publish figures calculated across many players, such as the total number of push-ups counted in the app, or how players in different countries compare. A published figure never includes your name, your account or anything else that identifies you, and we do not publish a figure about any group of fewer than 30 players, because a figure drawn from that few people can amount to one person's result. This is separate from the leaderboards, which do show individual players, as described under Data we share above.

Who is responsible for your data

Pushup RPG is made by Yerasyl Amanbek, who is the data controller for the information described on this page. The contact address is support@pushup.quest, or use the contact page and put Privacy in the subject.

Your rights over your data

If you are in the UK or the EEA, data protection law gives you the rights below. We apply them to everyone, wherever you live, because splitting them by country would be more work than honouring them.

We will not charge you for any of this and will not make you justify the request.

Why we are allowed to process it

How long we keep it

Where your data goes

The processors we use are named under Data we share: Supabase for accounts and cloud saves, RevenueCat for subscriptions and entitlements, and AppsFlyer for install measurement. Apple and Google hold your purchase records because they take the payment.

These are international services, so your data may be processed outside the country you live in, including outside the UK and the EEA. Each of them publishes its own data-processing terms and transfer safeguards, which are linked from their own sites.

Deleting your data

You can delete your account at any time from Settings → Account → Delete account. That removes your profile, cloud save, avatar photo, leaderboard entries and friend connections from our servers. A few things survive by necessity — a one-way referral hash, purchase and entitlement records held for accounting, and any anti-abuse record — and records held by Apple, Google Play, RevenueCat and AppsFlyer are not ours to delete. The deletion page lists each one and how to reach those providers. Uninstalling the app removes the local copy on your device.

Children

The app is designed for general audiences. Account creation (and therefore the social features) is intended for users able to consent under their local law; younger players can use the app fully in guest mode.

Android beta waitlist (closed)

Pushup RPG is now released on Google Play, so the Android beta waitlist is closed and we are no longer collecting emails for it. If you signed up while it was open, we stored only your email address in order to send you a single notification, and it was never used for anything else, sold, or shared. You can have it deleted at any time by emailing support@pushup.quest.

Website analytics

This website uses privacy-friendly, cookieless analytics (Vercel Web Analytics) that count aggregate page views. It sets no cookies and builds no advertising profile.

Advertising measurement on this website

If we are running ads, we need some way to tell which ones actually bring people here. We ask first. When advertising measurement is switched on you will see a banner offering Accept or Decline, and nothing is set until you choose Accept. Declining costs you nothing: every page works identically either way.

If you accept, we load tags from Google Ads and Meta. These are ordinary advertising trackers and we would rather say so plainly than call them something softer: they set cookies, they can recognise you on other websites that use the same networks, and they let us see that someone who clicked an ad went on to open the App Store link. They do not receive your name, your email, your account, or anything you do inside the app.

Your choice is remembered in your browser, not on our servers, and it applies until you clear your browser storage. To change it, clear site data for pushup.quest and the banner returns. If you never see a banner, no advertising tag has been loaded at all.

None of this applies to the app. Advertising measurement described here is a website matter only. What the app collects is described above, under Install measurement.

Contact

Questions or data requests: support@pushup.quest