This Privacy Policy explains how PushWars ("we", "us", "our") collects, uses, and protects personal data when you use the PushWars iOS application and related services (the "Service").
The data controller (and, for California purposes, the business) is Triple R Ventures Ltd, registered in the United Kingdom, number 16984900, contact address Unit 6, Honeyholes Lane, Dunholme, Lincoln, LN23SU, United Kingdom.
Privacy contact: [email protected]
We are a small operation and do not carry out large-scale processing of special-category data, so we are not required to appoint a Data Protection Officer; the privacy contact above handles all data-protection matters. We comply with the EU GDPR and UK GDPR (and the UK Data Protection Act 2018) for EEA and UK users, and the California Consumer Privacy Act, as amended by the CPRA (CCPA), for California residents. This policy is privacy-by-design and data-minimizing: we collect only what we need to run the product, never "just in case."
PushWars's games are controlled by your push-ups, tracked through your device's camera. This is the most sensitive-seeming part of the product, so we're explicit about exactly what happens to that data:
| Category | Examples | Source |
|---|---|---|
| Account / contact | Email address, display name, authentication identifiers, sign-in events | You, via our sign-in provider (Apple / Google / email) |
| Fitness / gameplay data | Rep counts, session duration, workout activity, streaks, XP, tier, per-game level progress, high scores, summarized form/technique feedback | Generated by the on-device detection engine described in §2 |
| Avatar / customization | Your selected avatar presets, outfit, and gear choices | You, in the Character customizer |
| Leaderboard data | Display name, tier, rank, score — visible to other users of the Service | Generated from your gameplay |
| Subscription data | Subscription status, plan, entitlement state, purchase receipts | Apple, via our subscription-management provider — we never see or store your card details |
| Device & diagnostics | App version, device/OS info, crash reports, performance data, product-interaction events | Automatically, via the app and our analytics/crash-reporting providers |
| Install / marketing attribution | Which marketing source or campaign led to your install, device/install identifiers used for that measurement | Automatically at install, via our attribution provider — see §6 for the App Tracking Transparency note |
| Alarm & App Blocking settings | Your chosen alarm times, which apps you've selected to block | Stored only on your device via Apple's frameworks — see §4 |
We do not collect precise GPS location, your contacts, health/medical data, or advertising identifiers for cross-app tracking. We do not ask for or store your payment-card number.
If you use the push-up alarm or the app-blocking feature, your alarm schedule and your selection of which apps to block are stored only on your device, using Apple's own frameworks. We do not receive, transmit, or store this data on our servers. This is a self-directed feature you configure for yourself — not a feature we operate or monitor.
| Purpose | Data used | Lawful basis (GDPR) |
|---|---|---|
| Create and run your account; deliver the subscription you bought | Account, subscription | Contract (Art. 6(1)(b)) |
| Track your progress, XP, tier, and unlocks | Fitness/gameplay data | Contract |
| Run leaderboards | Display name, tier, score | Contract |
| Keep the Service secure, prevent cheating and abuse | Usage, device, identifiers | Legitimate interests (Art. 6(1)(f)) |
| Product analytics and error tracking to improve the app | Interaction events, crash/performance data | Legitimate interests — opt out in Settings → Privacy |
| Measure which marketing source led to your install | Install/device identifiers, campaign data | Consent (via App Tracking Transparency, where applicable) / Legitimate interests |
| Power AI-assisted features (where used) — e.g. generating in-app content, summarizing your activity, or assisting support | Only the specific data that feature needs | Contract / Legitimate interests |
| Send service emails (e.g. account confirmations) | Email address | Contract / Legal obligation |
AI-assisted processing. Some features may be powered by AI/LLM technology supplied by a third-party AI processing provider — for example, generating in-app content, summarizing your activity, or assisting support. Where this is used: only the specific data a feature needs is sent, never your camera feed, video, or pose data (§2); we do not permit that data to be used to train the provider's general-purpose models; and output is never used to make a decision about you with a legal or similarly significant effect without human review.
We do not carry out automated decision-making producing legal or similarly significant effects on you (Art. 22). Automated anti-cheat checks may temporarily hold a leaderboard entry pending manual review, but never take a lasting action without human review. We do not sell or "share" your personal data and do not use it for cross-context behavioral advertising.
We share data only with the categories of service providers needed to run the Service. Each is bound by a data-processing agreement and processes data only on our instructions. We don't publish the specific names of every processor here — that's not required by GDPR or CCPA, which both require disclosure by category and purpose, not by vendor name — but we can tell you exactly who holds your data if you make a formal access request (§9).
| Category of recipient | Purpose | Data shared |
|---|---|---|
| Authentication provider | Sign-in and account security | Email, display name, sign-in events |
| Cloud hosting & database providers | Running the backend, storing your account and progress | All structured account/gameplay data in §3 |
| Subscription-management provider | Processing your subscription via Apple's In-App Purchase | User ID, subscription state, receipts |
| Product analytics provider | Understanding how the app is used, improving it | User ID, event/device data |
| Crash & error monitoring provider | Diagnosing and fixing bugs | Errors, stack traces, anonymized user ID |
| Marketing-attribution provider | Measuring which install/marketing source brought you to the app, so we know what's working | Device/install identifiers, campaign data, app-usage events tied to install source |
| AI data-processing provider(s) | Where a feature is powered by AI/LLM technology (for example: generating in-app content, summarizing activity, or assisting with support) | Only the specific data that feature needs — never your camera feed, video, or pose data (§2). We do not permit our data to be used to train a provider's general-purpose models. |
| Apple Inc. | App Store distribution, In-App Purchase, Sign in with Apple, the on-device frameworks described in §2 and §4 | Standard App Store data; on-device data never reaches Apple through us |
We may also disclose data where required by law, to enforce our Terms, to protect rights and safety, or in a business reorganization, merger, or sale (with your data kept protected).
Marketing attribution and App Tracking Transparency. If our attribution provider links your device or install to a marketing campaign in a way Apple classifies as "tracking," we will ask for your permission via Apple's App Tracking Transparency prompt before doing so, and you can decline. If you decline, install attribution may use Apple's privacy-preserving SKAdNetwork mechanism instead, which does not identify you individually to us.
Still absent: we do not use an advertising network, and we do not sell or share your data for cross-context behavioral advertising.
Some service providers are located in the United States. Where we transfer personal data outside the UK/EEA, we rely on appropriate safeguards — principally the EU Standard Contractual Clauses and the UK International Data Transfer Addendum — together with each provider's data-processing agreement.
| Data | Retention |
|---|---|
| Camera frames / pose data | Never stored — zero retention, by architecture |
| Active account | While your account exists, deleted within 30 days of a deletion request |
| Account created but never subscribed | Purged after 30 days |
| Lapsed subscription | Purged 180 days after it lapses |
| Individual workout/session records | 24 months, then aggregated into rollups (your lifetime totals are preserved regardless) |
| Progression, XP, inventory, lifetime totals | Life of the account |
| Leaderboard entries | Life of the account; removed on deletion |
| Analytics events | 12 months |
| Crash/error reports | 90 days |
| Backups | 30 days |
| Alarm configs, blocked-app selections | On your device only; removed when you delete the app — we hold none of this |
We do not discriminate against you for exercising these rights.
You have the right to know/access, delete, and correct your personal information, to opt out of the "sale" or "sharing" of it, and to limit the use of sensitive personal information. We do not sell your personal information, and we do not use it for cross-context behavioral advertising (we run no advertising network). Our marketing-attribution provider (§6) acts as our service provider for measuring install sources, not as an independent third party we sell or share data to. You may still exercise your rights via the in-app tools above or [email protected]. An authorized agent may submit a request with proof of authorization. We will not discriminate against you for exercising these rights.
When you choose Delete Account, we:
Deletion is permanent and cannot be undone. Alarm configs and blocked-app selections stored on your device are removed when you uninstall the app — we never held them to begin with. Records we must keep for legal/tax reasons, and rolling backups, age out per §8.
We follow a privacy-by-design, minimum-data approach: per-request authentication, service-layer user isolation (every query is scoped to your account), encryption in transit, edge-level rate-limiting and bot protection, server-side-only secrets, and least-privilege access. No system is perfectly secure, but we work to protect your data and will notify you and the relevant regulator of a personal-data breach where the law requires.
The Service is for ages 13+, matching Apple's own App Store account minimum. We do not knowingly collect data from anyone under 13. If you believe someone under 13 has given us personal data, contact [email protected] and we will delete it. Users under the digital-consent age set by their country's law (which varies, and within the EU can be as high as 16 depending on member state) must have a parent or guardian's permission to use the Service.
The iOS app does not use cookies. Where our marketing-attribution provider (§6) links your device to an install source in a way Apple classifies as "tracking," we ask for your permission first via Apple's App Tracking Transparency prompt, and you can decline — see §6 for details. Any future marketing website that uses non-essential cookies will present a consent banner for EU/UK visitors.
We may update this policy from time to time. If a change is material we will notify you (in-app or by email). The "Last updated" date shows the latest version. Continuing to use the Service after a change takes effect means you accept the updated policy.
Email: [email protected]
Postal: Unit 6, Honeyholes Lane, Dunholme, Lincoln, LN23SU, United Kingdom
You also have the right to complain to your data-protection authority (in the UK, the ICO at ico.org.uk/make-a-complaint).