Privacy Policy
Last updated: August 2, 2026
Pushup RPG is built to respect your privacy. This policy explains exactly what the app does and does not do with your data.
Camera
The app uses your device camera to count pushups by detecting your body pose. All processing happens on-device, in real time. Pose detection never records, stores, or transmits video, images, or pose data off your device. Unless you turn on clip recording (below), the camera feed exists only in memory while a battle is active and is discarded immediately. Camera data is never uploaded to our servers or anywhere else.
Clips (optional, off by default)
If you turn on Record clips in Settings, the app records your battle or practice screen — the camera view plus the game overlays — into a video clip stored only on your device. iOS asks for your explicit confirmation before each session's first recording, and a REC indicator is visible whenever recording is active.
- Clips never leave your device unless you choose to share them (via the iOS share sheet) or save them to your Photos library.
- We never receive, upload, or process your clips — there is no server involved.
- Recording stops automatically after 3 minutes, and you can stop it any time by tapping the REC indicator.
- Unshared clips are kept temporarily on-device and cleaned up automatically.
Microphone (your choice, per iOS's own prompt)
When a recording starts, iOS's own consent sheet lets you choose Record Screen and Microphone or Record Screen Only. If you allow the microphone, your clips include audio from the device microphone (your voice and the surrounding room) so shared videos carry the real moment. Like the video, this audio is recorded only on your device, only while you record, and is never uploaded to us. If you pick Screen Only, clips include only the game's own sound effects.
Photos
Two separate things, and neither gives the app the run of your library.
- Saving a clip (via Save Video on the iOS share sheet) uses add-only access.
- Choosing an avatar photo (a Vigil perk — see Your avatar photo below) opens Apple's own photo picker, which runs outside the app. We receive only the single image you pick; the app cannot see, browse, or search the rest of your library, and it never asks for photo-library permission.
Your avatar photo (Vigil members, optional)
With a Vigil membership you can use your own photo as your portrait instead of one of our painted ones. Because this is the one thing in the app you upload, here is exactly what happens to it.
- The image is cropped and shrunk on your device before it leaves — we never receive the full-resolution original.
- Before upload, iOS screens it on-device for explicit content. This uses Apple's own analyser and, like everything else in the camera path, the picture is not sent anywhere to be checked.
- It is then stored on our servers, attached to your account.
- It is public. Your avatar is shown to other players wherever your name appears — your fellowship roster, the friends list, the worldwide leaderboards, duels. Anyone who can see your name can see your face. Please only upload a photo you are happy for strangers to see, and only one you have the right to use — do not upload a picture of someone else without their agreement.
- You can remove it whenever you like, from the same portrait picker you chose it in. Removing it takes it off every screen in the app immediately.
- It is deleted when you delete your account.
- Other players can report your avatar, and we can remove it — see Content moderation below.
Diagnostics you choose to send
If the camera is miscounting your reps, Settings → Reps not counting? lets you send us what the detector decided. The screen shows you the exact lines before anything is sent, and nothing goes anywhere unless you tap send. It contains the detector's own measurements — joint angles, timings, the reason each rep was accepted or refused — plus your device model and app version, attached to your account so we can follow up.
No video, no images, and no photographs of you are ever included — the camera feed never leaves your device, as described under Camera above.
The app also keeps a small tally of why reps were refused (for example "too shallow"), which rides along in your cloud save and helps us see which failures are common.
Apple Health (optional)
If you turn on Sync to Apple Health in Settings, Pushup RPG saves your battles and practice sessions to Apple Health as workouts (with an estimated active-energy value and your rep count) so they count toward your Activity rings. This is opt-in and write-only: we only add workouts to your Health data — we never read any of your health information, it never leaves your device to our servers, and we never sell it, use it for advertising, or share it. You can turn this off anytime in Settings, and manage or delete the data in the Health app.
Accounts and cloud sync
To back up your progress across devices and to power the friends leaderboard, the app uses a cloud account (provided by Supabase). You can sign in with:
- Sign in with Apple, Google, or email (a one-time code / magic link), or
- Continue as a guest — an anonymous account is created so your save still backs up, with no name or email attached.
What we store on your account:
- Game progress — level, XP, streak, gear, currencies, settings, lifetime reps.
- Profile — the display name you choose, a randomly generated friend code, your level, class, current streak, and weekly rep total. This profile is visible to friends you add and to the members of any fellowship (guild) you join — see Fellowships below.
- Contact identifier — if you sign in with email, your email address; with Apple or Google, the identifier they return. Used only to authenticate your account.
- Your avatar photo, if you are a Vigil member and chose to upload one. See Your avatar photo above — it is public to other players.
- Detection diagnostics, if you sent a report. See Diagnostics you choose to send.
We do not collect location, contacts, or any health/fitness data beyond the rep counts that are part of your game progress.
Install measurement
The app includes AppsFlyer for install attribution and product analytics. It is not limited to aggregate counts, and we would rather describe it accurately than reassure you: alongside Apple’s SKAdNetwork, the app sends AppsFlyer an event stream tied to your account — app opens and activation, onboarding steps (including whether you allowed notifications and camera access), paywall views and dismissals, trial starts, level milestones, and completed purchases with the amount, currency, product and Apple transaction id. Your Pushup RPG account id is passed to AppsFlyer as the customer identifier, so those events are linked to your account rather than being anonymous.
We also use RevenueCat to manage subscriptions and entitlements. It receives your account id and your purchase and subscription history, and our server asks it whether your account has an active membership.
What we can still tell you plainly: the app never shows an App Tracking Transparency prompt and does not use the ATT advertising identifier, and there are no ad-serving SDKs — you will not see ads in Pushup RPG. We do not sell your data. AppsFlyer is nonetheless an attribution vendor with its own tracking capabilities, so if that matters to you, treat this as a real third-party disclosure rather than a formality.
Friends
Adding a friend is mutual and is done by exchanging friend codes. A friend code only resolves to a profile when entered exactly — profiles cannot be browsed or listed. Removing a friend removes the connection for both people and revokes their access to your profile.
Fellowships (guilds)
You can join a fellowship — a small team that shares a weekly goal — or, with a Vigil membership, create one. This makes some information visible more widely than Friends:
- Your profile (display name, class, level, streak, weekly reps) is visible to the other members of any fellowship you join, who may not be your friends.
- A fellowship name and motto you create, and the fellowship names shown in the public browse directory, are visible to all players and may appear on images you choose to share.
- Content moderation. Fellowship names/mottos, display names and avatar photos are all content players create. Names are filtered against a blocklist, and avatar photos are screened on-device before upload by Apple's analyser, which catches sexually explicit imagery — other objectionable content, including a photo of someone who did not consent, is caught by the report path rather than the filter. You can report an offensive name or picture from inside the app — the ⋯ button beside any player, on every screen that shows one. We review reports and remove violating content, and may remove an offending account's ability to upload a picture at all — there is zero tolerance for objectionable content.
Data we share
We do not sell or share your data with advertisers or data brokers. Your profile is shared with the friends you add and the members of any fellowship you join, and a fellowship name or motto you create, and an avatar photo you upload, are public to other players. Be aware it also goes wider than that: if you rank on the worldwide daily or weekly rep ladders, or on the Endless Descent board, your display name, class, level and the ranked figure are visible to every signed-in player. Three processors handle data on our behalf: Supabase (hosting, accounts and cloud saves), RevenueCat (subscriptions and entitlements — it receives your account id and purchase history), and AppsFlyer (install attribution and product analytics — see Install measurement above for what it receives).
Deleting your data
You can delete your account at any time from Settings → Account → Delete account. That removes your profile, cloud save, avatar photo, leaderboard entries and friend connections from our servers. A few things survive by necessity — a one-way referral hash, purchase and entitlement records held for accounting, and any anti-abuse record — and records held by Apple, RevenueCat and AppsFlyer are not ours to delete. The deletion page lists each one and how to reach those providers. Uninstalling the app removes the local copy on your device.
Children
The app is designed for general audiences. Account creation (and therefore the social features) is intended for users able to consent under their local law; younger players can use the app fully in guest mode.
Android beta waitlist (closed)
Pushup RPG is now released on Google Play, so the Android beta waitlist is closed and we are no longer collecting emails for it. If you signed up while it was open, we stored only your email address in order to send you a single notification, and it was never used for anything else, sold, or shared. You can have it deleted at any time by emailing support@pushup.quest.
Website analytics
This website uses privacy-friendly, cookieless analytics (Vercel Web Analytics) that count aggregate page views and which buttons are tapped. It sets no cookies, builds no advertising profile, and never tracks you across other sites.
Contact
Questions or data requests: support@pushup.quest