← Back to PushWars

PushWars — Privacy Policy

Last updated: 15 July 2026  ·  Effective date: 15 July 2026
The headline, up front: PushWars uses your camera to count your push-ups and control the game. Your camera feed never leaves your device. No video, no images, and no pose or skeleton data are ever uploaded, stored, or transmitted to us or to anyone else — not even in a de-identified form. The only thing that leaves the camera pipeline is a number: how many reps you did. Everything else in this policy is secondary to that fact.

1. Introduction and who is responsible

This Privacy Policy explains how PushWars ("we", "us", "our") collects, uses, and protects personal data when you use the PushWars iOS application and related services (the "Service").

The data controller (and, for California purposes, the business) is Triple R Ventures Ltd, registered in the United Kingdom, number 16984900, contact address Unit 6, Honeyholes Lane, Dunholme, Lincoln, LN23SU, United Kingdom.

Privacy contact: [email protected]

We are a small operation and do not carry out large-scale processing of special-category data, so we are not required to appoint a Data Protection Officer; the privacy contact above handles all data-protection matters. We comply with the EU GDPR and UK GDPR (and the UK Data Protection Act 2018) for EEA and UK users, and the California Consumer Privacy Act, as amended by the CPRA (CCPA), for California residents. This policy is privacy-by-design and data-minimizing: we collect only what we need to run the product, never "just in case."

2. The camera — what actually happens

PushWars's games are controlled by your push-ups, tracked through your device's camera. This is the most sensitive-seeming part of the product, so we're explicit about exactly what happens to that data:

  • Body-pose detection runs entirely on your device, using Apple's on-device Vision framework. Your camera feed is processed frame-by-frame in memory and is never written to disk, never uploaded, and never logged — not to our servers, not to any analytics or crash-reporting tool, not even in debug builds.
  • The only artifacts that leave the camera-processing pipeline are discrete counted events — a completed rep, a held block, a detected movement, a form/technique signal — and their aggregates (how many reps, how long a session lasted, whether you won or lost a level, general form feedback we show you).
  • What actually reaches our servers from a play session: integer counters, game results, and summarized form/technique feedback (your push-up totals, level progress, XP, leaderboard scores, coaching cues). Never anything visual, and never a skeleton/pose representation of your body — form and technique feedback is derived on-device and only the summarized result is synced, the same as a rep count.
  • This is both a product promise and an architectural fact — the camera-processing code has no network path available to it.

3. The personal data we collect

CategoryExamplesSource
Account / contactEmail address, display name, authentication identifiers, sign-in eventsYou, via our sign-in provider (Apple / Google / email)
Fitness / gameplay dataRep counts, session duration, workout activity, streaks, XP, tier, per-game level progress, high scores, summarized form/technique feedbackGenerated by the on-device detection engine described in §2
Avatar / customizationYour selected avatar presets, outfit, and gear choicesYou, in the Character customizer
Leaderboard dataDisplay name, tier, rank, score — visible to other users of the ServiceGenerated from your gameplay
Subscription dataSubscription status, plan, entitlement state, purchase receiptsApple, via our subscription-management provider — we never see or store your card details
Device & diagnosticsApp version, device/OS info, crash reports, performance data, product-interaction eventsAutomatically, via the app and our analytics/crash-reporting providers
Install / marketing attributionWhich marketing source or campaign led to your install, device/install identifiers used for that measurementAutomatically at install, via our attribution provider — see §6 for the App Tracking Transparency note
Alarm & App Blocking settingsYour chosen alarm times, which apps you've selected to blockStored only on your device via Apple's frameworks — see §4

We do not collect precise GPS location, your contacts, health/medical data, or advertising identifiers for cross-app tracking. We do not ask for or store your payment-card number.

4. Alarm & App Blocking — device-local, not ours

If you use the push-up alarm or the app-blocking feature, your alarm schedule and your selection of which apps to block are stored only on your device, using Apple's own frameworks. We do not receive, transmit, or store this data on our servers. This is a self-directed feature you configure for yourself — not a feature we operate or monitor.

5. How and why we use your data, and our lawful bases

PurposeData usedLawful basis (GDPR)
Create and run your account; deliver the subscription you boughtAccount, subscriptionContract (Art. 6(1)(b))
Track your progress, XP, tier, and unlocksFitness/gameplay dataContract
Run leaderboardsDisplay name, tier, scoreContract
Keep the Service secure, prevent cheating and abuseUsage, device, identifiersLegitimate interests (Art. 6(1)(f))
Product analytics and error tracking to improve the appInteraction events, crash/performance dataLegitimate interests — opt out in Settings → Privacy
Measure which marketing source led to your installInstall/device identifiers, campaign dataConsent (via App Tracking Transparency, where applicable) / Legitimate interests
Power AI-assisted features (where used) — e.g. generating in-app content, summarizing your activity, or assisting supportOnly the specific data that feature needsContract / Legitimate interests
Send service emails (e.g. account confirmations)Email addressContract / Legal obligation

AI-assisted processing. Some features may be powered by AI/LLM technology supplied by a third-party AI processing provider — for example, generating in-app content, summarizing your activity, or assisting support. Where this is used: only the specific data a feature needs is sent, never your camera feed, video, or pose data (§2); we do not permit that data to be used to train the provider's general-purpose models; and output is never used to make a decision about you with a legal or similarly significant effect without human review.

We do not carry out automated decision-making producing legal or similarly significant effects on you (Art. 22). Automated anti-cheat checks may temporarily hold a leaderboard entry pending manual review, but never take a lasting action without human review. We do not sell or "share" your personal data and do not use it for cross-context behavioral advertising.

6. Who we share data with

We share data only with the categories of service providers needed to run the Service. Each is bound by a data-processing agreement and processes data only on our instructions. We don't publish the specific names of every processor here — that's not required by GDPR or CCPA, which both require disclosure by category and purpose, not by vendor name — but we can tell you exactly who holds your data if you make a formal access request (§9).

Category of recipientPurposeData shared
Authentication providerSign-in and account securityEmail, display name, sign-in events
Cloud hosting & database providersRunning the backend, storing your account and progressAll structured account/gameplay data in §3
Subscription-management providerProcessing your subscription via Apple's In-App PurchaseUser ID, subscription state, receipts
Product analytics providerUnderstanding how the app is used, improving itUser ID, event/device data
Crash & error monitoring providerDiagnosing and fixing bugsErrors, stack traces, anonymized user ID
Marketing-attribution providerMeasuring which install/marketing source brought you to the app, so we know what's workingDevice/install identifiers, campaign data, app-usage events tied to install source
AI data-processing provider(s)Where a feature is powered by AI/LLM technology (for example: generating in-app content, summarizing activity, or assisting with support)Only the specific data that feature needs — never your camera feed, video, or pose data (§2). We do not permit our data to be used to train a provider's general-purpose models.
Apple Inc.App Store distribution, In-App Purchase, Sign in with Apple, the on-device frameworks described in §2 and §4Standard App Store data; on-device data never reaches Apple through us

We may also disclose data where required by law, to enforce our Terms, to protect rights and safety, or in a business reorganization, merger, or sale (with your data kept protected).

Marketing attribution and App Tracking Transparency. If our attribution provider links your device or install to a marketing campaign in a way Apple classifies as "tracking," we will ask for your permission via Apple's App Tracking Transparency prompt before doing so, and you can decline. If you decline, install attribution may use Apple's privacy-preserving SKAdNetwork mechanism instead, which does not identify you individually to us.

Still absent: we do not use an advertising network, and we do not sell or share your data for cross-context behavioral advertising.

7. International data transfers

Some service providers are located in the United States. Where we transfer personal data outside the UK/EEA, we rely on appropriate safeguards — principally the EU Standard Contractual Clauses and the UK International Data Transfer Addendum — together with each provider's data-processing agreement.

8. How long we keep your data (retention)

DataRetention
Camera frames / pose dataNever stored — zero retention, by architecture
Active accountWhile your account exists, deleted within 30 days of a deletion request
Account created but never subscribedPurged after 30 days
Lapsed subscriptionPurged 180 days after it lapses
Individual workout/session records24 months, then aggregated into rollups (your lifetime totals are preserved regardless)
Progression, XP, inventory, lifetime totalsLife of the account
Leaderboard entriesLife of the account; removed on deletion
Analytics events12 months
Crash/error reports90 days
Backups30 days
Alarm configs, blocked-app selectionsOn your device only; removed when you delete the app — we hold none of this

9. Your rights

EU / UK (GDPR)

  • Access — export your data via Settings → Account → Download My Data.
  • Rectify — edit your profile in Settings; changes apply immediately.
  • Erase ("right to be forgotten") — Settings → Account → Delete Account (see §10).
  • Restrict / object — including objecting to analytics (toggle off in Settings → Privacy), or email [email protected].
  • Port — your export is machine-readable.
  • Complain to your local supervisory authority (in the UK, the ICO at ico.org.uk). We'd appreciate the chance to resolve it first.

We do not discriminate against you for exercising these rights.

California residents (CCPA/CPRA)

You have the right to know/access, delete, and correct your personal information, to opt out of the "sale" or "sharing" of it, and to limit the use of sensitive personal information. We do not sell your personal information, and we do not use it for cross-context behavioral advertising (we run no advertising network). Our marketing-attribution provider (§6) acts as our service provider for measuring install sources, not as an independent third party we sell or share data to. You may still exercise your rights via the in-app tools above or [email protected]. An authorized agent may submit a request with proof of authorization. We will not discriminate against you for exercising these rights.

10. Deleting your account

When you choose Delete Account, we:

  • Revoke your sessions and delete your authentication record, and sign you out.
  • Remove your entries from leaderboards immediately.
  • Hard-delete your account data within 24 hours — including your progress, XP, inventory, session history, and leaderboard history.
  • Propagate deletion to our service providers where applicable.

Deletion is permanent and cannot be undone. Alarm configs and blocked-app selections stored on your device are removed when you uninstall the app — we never held them to begin with. Records we must keep for legal/tax reasons, and rolling backups, age out per §8.

11. Security

We follow a privacy-by-design, minimum-data approach: per-request authentication, service-layer user isolation (every query is scoped to your account), encryption in transit, edge-level rate-limiting and bot protection, server-side-only secrets, and least-privilege access. No system is perfectly secure, but we work to protect your data and will notify you and the relevant regulator of a personal-data breach where the law requires.

12. Children

The Service is for ages 13+, matching Apple's own App Store account minimum. We do not knowingly collect data from anyone under 13. If you believe someone under 13 has given us personal data, contact [email protected] and we will delete it. Users under the digital-consent age set by their country's law (which varies, and within the EU can be as high as 16 depending on member state) must have a parent or guardian's permission to use the Service.

13. Cookies and tracking

The iOS app does not use cookies. Where our marketing-attribution provider (§6) links your device to an install source in a way Apple classifies as "tracking," we ask for your permission first via Apple's App Tracking Transparency prompt, and you can decline — see §6 for details. Any future marketing website that uses non-essential cookies will present a consent banner for EU/UK visitors.

14. Changes to this policy

We may update this policy from time to time. If a change is material we will notify you (in-app or by email). The "Last updated" date shows the latest version. Continuing to use the Service after a change takes effect means you accept the updated policy.

15. Contact

Email: [email protected]
Postal: Unit 6, Honeyholes Lane, Dunholme, Lincoln, LN23SU, United Kingdom

You also have the right to complain to your data-protection authority (in the UK, the ICO at ico.org.uk/make-a-complaint).

© 2026 Triple R Ventures Ltd. All rights reserved.  ·  pushwars.com  ·  Terms of Service