PUSHON

Legal

Privacy Policy

Effective · Applies to the PushOn app for Android and iOS (app id io.appflare.pushup) and the website pushon.pages.dev

PushOn counts your pushups. Your workouts stay on your phone. Only if you choose to sign in, to race friends and groups, does a small set of numbers go to a server. This page says exactly which, who can see them, and how to delete them.

The short version

1. Who is responsible

PushOn is developed and operated by Asaf Cohen, an individual developer (“I”, “me”). I am the controller of the personal data described here. Contact: asafcoheng@gmail.com.

2. What stays on your device

Everything you do in a workout is stored locally, on your phone only:

I cannot see, access or recover this local data. If you uninstall the app or clear its storage, it is gone. On Android, if device backup is turned on, Android may include the app’s local data in your Google backup; that is controlled by Google and your device settings, not by me.

3. If you sign in: what is stored on the server

Signing in is optional. When you do, the app creates an account and stores the following in a database hosted by Supabase (see service providers):

DataWhyWho can see it
Email address, name and account ID from Google (or Apple on iOS). Google may also include a profile picture link, which is kept in your sign-in record but is not used or shown. Apple may give a private relay email instead of your real one.Create your account, sign you in, keep it secure.Only you and me (as the database administrator). Never shown to other users.
Your @username (you choose it)Let friends find you and show you on leaderboards.Other signed-in users who search for it, your friends and group members, and anyone who opens your invite link.
Display name (copied from your Google or Apple profile)Show a friendly name next to your @username.Same as your @username.
Invite code (random, generated by the server)Let people add you by link or code.Whoever you give it to. Opening it shows your @username.
Daily pushup totals: a date and the total for that dayRace Home and leaderboards (today, week).You, your friends and your group members.
Streak, best day, best plank hold, all-time totalShow your stats and bests on leaderboards.You, your friends and your group members.
Friendships (including pending requests) and group memberships, plus the names and codes of groups you createRun friends and groups.The other person, or the other members of the group.
Technical logs: IP address, time and type of requestOperate and secure the service, fix problems.My hosting providers, and me if I need to investigate a problem. Not used for tracking or profiling.

A sign-in session is also stored on your device so you stay signed in until you sign out.

What I never collect

Individual sets or rep timing, your location, contacts, camera or microphone input, photos or files, advertising ID, health or fitness platform data (no Health Connect, Google Fit or Apple Health), payment information, or any analytics or crash-tracking identifiers. The app has no ads and no third-party analytics or advertising SDKs.

4. What other people can see

You can remove a friend or leave a group at any time in the app. Choose your @username and display name accordingly: they are visible to others.

5. How I use your data

I do not sell your data, share it for advertising, build advertising profiles, or use it to train AI models. The “AI coach” counts out loud with voice clips that were recorded once and are bundled inside the app. Nothing you do is sent to any AI service.

Legal bases (where GDPR or UK GDPR applies): providing the service you asked for (contract), keeping it secure and preventing abuse (legitimate interests), and your choices to sign in and to allow notifications (consent, which you can withdraw at any time).

6. Service providers and where data is stored

I use a few providers to run PushOn. They process data only to provide their service to me, under their own terms and privacy policies. I do not use any other third parties.

ProviderRoleData involved
SupabaseDatabase and sign-in service. Hosted in Seoul, South Korea.Everything listed in section 3.
Google“Sign in with Google”; on Android also Google Play services and Google Play (distribution, Android vitals).Your Google sign-in details. Google may give me aggregated crash and performance reports from devices that chose to share diagnostics with Google. They contain no personal data.
Apple“Sign in with Apple” (iOS only).Your Apple sign-in details (name and email, or a private relay email).
CloudflareHosts the website pushon.pages.dev (Cloudflare Pages).Standard web server logs such as IP address when you visit the website.

International transfers. Your server data is stored in South Korea, and my providers may process data in other countries, including the United States. Where the law requires a transfer mechanism, I rely on the safeguards in the providers’ data-processing terms, such as standard contractual clauses.

I may also disclose data if the law requires it, or to protect the rights, safety or security of users or the service.

7. How long I keep it

8. Your choices and rights

If you are in the EEA, UK or Switzerland, you have the rights above under GDPR or UK GDPR, and you can complain to your local data protection authority. If you are in California or another US state with a privacy law, you can ask what personal data I hold, ask me to delete it or correct it, and you will not be treated differently for asking. I do not sell or share personal information for advertising. Rights under other local laws are honoured the same way, through the same email address.

9. Children

PushOn is not directed to children. You must be at least 13 to use it, and old enough under your local law to agree to this processing where that age is higher (up to 16 in some countries), or have a parent’s permission. I do not knowingly collect personal information from children under 13. If you believe a child has signed in, email me and I will delete the account.

10. Security

All traffic between the app and the server uses HTTPS (TLS encryption in transit), and the database is encrypted at rest by my hosting provider. Row-level security means a signed-in user can read only their own stats rows, and can see others only through the limited fields described in section 4. The app contains only a public client key, no server secrets, and I never see or store a password for Google or Apple sign-in. No system is perfectly secure, so I cannot guarantee absolute security.

11. App permissions

The app does not request camera, microphone, location, contacts, photos or storage permissions. The nose-tap counter uses the touch screen, not the camera.

12. This website

The website (pushon.pages.dev) is hosted on Cloudflare Pages. It has no cookies, no analytics and no trackers. Two things to know: it loads the Unbounded font from Google Fonts, so your browser contacts Google when a page opens; and an invite page (a link ending in /f/CODE or /g/CODE) sends the code to my Supabase database to show who invited you. Cloudflare and Supabase may log your IP address as part of normal operation.

13. Changes to this policy

If I change what I collect or how I use it, I will update this page and its effective date, and for significant changes I will tell you in the app or on the website before they take effect.

14. Contact

Questions, requests or complaints: asafcoheng@gmail.com. Developer: Asaf Cohen.

Delete your account