Push Up League
Privacy Policy
Last updated: August 20, 2026
1. Controller
The controller for personal data processed through Push Up League is 03 Studios, operated by Manuel Thurner, Weinstraße 6, 39057 Girlan BZ, Italy. You can contact us at contact@03-studios.com.
2. Scope of This Policy
This Privacy Policy covers the Push Up League iOS app, its authentication, training, camera-based repetition counting, notification, analytics, paywall, purchase, and support flows, and this public legal page.
3. Personal Data We Process
Account and authentication data. If you sign in with Apple or Google through Supabase Auth, we process a user identifier, authentication and session data, and your email address where the identity provider makes it available. Authentication tokens are stored securely in the iOS Keychain.
Cloud profile and gameplay data. When you are signed in, we store your display name, training goal, experience, focus areas, planned sessions per week, repetition counts, game progress, achievements, scores, session results, and related dates in our Supabase backend. This lets us provide your account, synchronize progress across your signed-in devices, operate game features, and protect progression from abuse. We send the display name and selected training and progress parameters to Superwall when presenting a paywall. These parameters determine which paywall variant, offer, and wording you are shown, and which paywall experiment you are assigned to.
Training and profile information stored only on your device. The app may also ask for age, gender preference, height, current and target weight, injury areas, training barriers, preferred units, reminder time, push-up ability, camera-permission state, and onboarding draft state. These fields stay in the app's local storage and are not sent to 03 Studios' backend, Supabase, Firebase, or Superwall. They are used locally to tailor the app experience.
Camera, pose, and face data. During a camera-assisted training session, the app accesses live front-camera frames, which may contain your face, and uses Google ML Kit Pose Detection to derive pose landmark positions and confidence values in memory on your device. The only face-specific landmark that Push Up League reads from the model output is the position of the nose (normalized horizontal and vertical coordinates, relative depth where available, and a detection-confidence value). It is used only to draw the live pose overlay. Push-up counting uses body landmarks such as shoulders, elbows, and wrists.
The app does not perform facial recognition or facial analysis, identify or authenticate anyone from their face, derive emotions or demographic attributes, create a face template or faceprint, or use face data for profiling, analytics, advertising, marketing, or tracking. The app does not take or save photos or videos from this flow.
Purchase and entitlement data. We and our providers may process product identifiers, subscription status, purchase and restore outcomes, entitlement state, paywall interactions, and limited transaction information needed to provide paid features. Apple processes your payment details; 03 Studios does not receive your full payment-card information.
App-integrity data. To protect account progress from abuse, we process an Apple App Attest key identifier, attestation and assertion data, a public key, a receipt, an anti-replay counter, and app-version information. This cryptographic security data is associated with your account and is not used to identify you outside Push Up League.
Device, Superwall analytics, and optional diagnostic data. We and our providers may process an app, installation, or vendor-specific user identifier, device and app information, and a country or region inferred from the network connection. From app launch, Superwall also receives SDK lifecycle and session events and placement, paywall, product, entitlement, purchase, and restore events. When you are signed in, Superwall may associate these events with your Push Up League user identifier and the limited paywall attributes described above. This Superwall collection is enabled independently of the optional analytics setting and supports paywall presentation, reporting, measurement, audience selection, and purchase and entitlement flows. Firebase Analytics and Firebase Crashlytics remain off unless you enable optional usage and diagnostics in Settings. If enabled, they may collect optional screen, feature, onboarding, training, performance, crash, error, and other diagnostic events for measurement and reliability. We do not use this information for cross-app or cross-website tracking.
Notification data. If you enable notifications, Apple and Firebase may process a device or installation identifier, push token, app information, and delivery-related technical data so that reminders and service messages can be delivered. You can disable notifications at any time in iOS Settings.
Support data. If you contact us, we process your contact details, message, and any information you choose to include so that we can respond.
Website data. This legal page does not use advertising cookies or website analytics. Our hosting provider may process standard connection and server log data, such as IP address, browser or device information, request time, and the page requested, to deliver the page, maintain security, and prevent abuse.
4. Sources of Personal Data
- directly from you when you sign in, complete onboarding, train, make a purchase, change settings, or contact us;
- from Apple or Google when you choose their authentication or platform services;
- from Apple StoreKit and Superwall for paywall, purchase, restore, and entitlement flows;
- from Firebase for analytics, diagnostics, installation, and messaging functions; and
- from your device during ordinary app, local storage, camera, and network operations.
5. Purposes and Legal Bases
- Provide the app. We authenticate users, personalize training locally, count repetitions, maintain progress, provide paid features, restore purchases, and secure progression against abuse. Legal basis: Article 6(1)(b) GDPR, performance of a contract or steps requested before entering into a contract.
- Camera-assisted repetition counting. We process live camera frames and on-device pose data, including the limited face data described in Section 6, only after you choose to use the camera feature and grant iOS camera permission. The purpose is to show the live pose overlay and count push-ups. Legal basis: your consent under Article 6(1)(a) GDPR. You may withdraw consent at any time by revoking camera permission in iOS Settings.
- Paywalls, subscriptions, and Superwall measurement. We process lifecycle, session, placement, paywall, product, entitlement, purchase, and restore events to present and operate paid features, report paywall outcomes, measure performance, and select relevant paywall experiences. Legal basis: Article 6(1)(b) GDPR where processing is necessary to provide requested paid features or manage purchases, and Article 6(1)(f) GDPR for our legitimate interests in measuring and improving our paywall and subscription flows. Selecting a paywall variant on the basis of these attributes is profiling within the meaning of Article 4(4) GDPR. It is not automated decision-making producing legal effects concerning you or similarly significantly affecting you under Article 22(1) GDPR: it affects only how an optional subscription offer is presented, the available products and prices are the same, and access to the app's free functionality does not depend on it. You may object to processing based on legitimate interests by contacting us.
- Optional Firebase analytics and diagnostics. We use Firebase Analytics and Firebase Crashlytics only after your consent to understand feature use and improve reliability. Legal basis: Article 6(1)(a) GDPR. You may withdraw consent in the app's Settings.
- Notifications. We send reminders or service messages when you enable notifications. Legal basis: your consent under Article 6(1)(a) GDPR or performance of the service you request under Article 6(1)(b) GDPR, depending on the message.
- Security and troubleshooting. We use limited operational and diagnostic data to secure, debug, and prevent abuse of the service. Legal basis: Article 6(1)(f) GDPR, our legitimate interests in a safe and reliable service.
- Purchases and legal obligations. We process purchase and entitlement records to provide subscriptions, handle requests, meet accounting or legal duties, and defend legal claims. Legal basis: Articles 6(1)(b), 6(1)(c), and 6(1)(f) GDPR, as applicable.
- Support and rights requests. We process messages to answer you and comply with applicable law. Legal basis: Articles 6(1)(b), 6(1)(c), and 6(1)(f) GDPR, as applicable.
6. Face Data and On-Device Camera Processing
Camera access is optional and requires the iOS permission prompt. If you use the camera-assisted repetition counter, Push Up League uses Google ML Kit Pose Detection in stream mode to locate pose landmarks and estimate movement. The model is included with the app and processing occurs on the device. Live frames may show your face. The only face-specific model output read by Push Up League is the nose landmark described in Section 3; the app does not read eye, ear, mouth, face-mesh, or facial-geometry outputs.
Use and disclosure. Camera frames, pose landmarks, and the nose landmark are used only to provide the live pose overlay, assess body visibility and movement, and count push-ups. They are not used for identification, authentication, profiling, analytics, advertising, marketing, tracking, or any unrelated purpose. They are not sold, shared, disclosed, or transferred to any third party, including Google, and are not sent to 03 Studios, Supabase, Firebase, or Superwall.
Storage, retention, and deletion. Camera frames and landmark data exist only temporarily in volatile memory on your device while the camera session is active. Frames are discarded after processing, and short-lived landmark values are replaced as new frames are analyzed. They are never written to persistent device storage, logs, backups, or any server or cloud storage, and are not retained after the camera session ends. Because no face data is retained, there is no stored face data to delete later. Ending the camera session discards the transient data; revoking camera permission in iOS Settings prevents future access.
This feature is pose and movement analysis, not facial recognition or biometric identity processing. You can decline or revoke camera access in iOS Settings, although the camera-assisted counter will then be unavailable.
7. Analytics, Consent, and Tracking
Superwall event collection is active from app launch. It includes SDK lifecycle and session events and placement, paywall, product, entitlement, purchase, restore, and related interaction events used for paywall analytics, reporting, measurement, and audience selection. Superwall collection is not controlled by the optional usage and diagnostics setting. Firebase Analytics and Firebase Crashlytics default to off and are enabled only after you opt in through Settings; you can withdraw that choice there at any time. Firebase Cloud Messaging registration defaults to off and is enabled only while iOS notification authorization is active. We do not sell or share personal information for cross-context behavioural advertising, run third-party advertising, or use app data for cross-app or cross-website tracking.
No advertising identifier. Push Up League does not access the Apple Advertising Identifier (IDFA) and does not present the App Tracking Transparency prompt. Its App Store privacy manifest declares no tracking and no tracking domains. The app, installation, and vendor-specific identifiers described in Section 3 are scoped to our apps: they cannot be used to recognize you in apps published by other developers or on websites. We do not use advertising networks, attribution networks that rely on the advertising identifier, or data brokers.
8. Recipients and Service Providers
We share data only as needed to operate Push Up League:
- Supabase. Authentication, account identifiers and sessions, cloud profile and gameplay data, account deletion, and App Attest security records. Supabase Privacy Policy.
- Firebase / Google. Optional analytics and diagnostics, app-installation functions, and push messaging after notification authorization. Firebase Privacy and Security.
- Google ML Kit. A model included with the app performs pose detection locally on the device. Google does not receive camera frames, pose landmarks, or face data from this feature. Google ML Kit.
- Superwall (Nest 22, Inc., 2093 Philadelphia Pike #5307, Claymont, DE 19703, United States). Paywall presentation, lifecycle and session events, product interaction, analytics and reporting, audience selection, entitlement, and purchase orchestration. Superwall Privacy Policy.
- Apple. App Store distribution, purchases and subscription management, Sign in with Apple, notifications, and iOS platform services. Apple Privacy Policy.
- Google Sign-In. Optional Google account authentication when you select that sign-in method. Google Privacy Policy.
9. International Transfers
Some providers operate outside Italy or the European Economic Area, including in the United States. Where required, international transfers are protected by an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, or appropriate safeguards such as the European Commission's Standard Contractual Clauses and supplementary measures.
10. Retention
Camera frames, pose landmarks, and face data. As described in Section 6, these are processed only in volatile memory on your device during an active camera session. Frames are discarded after processing, short-lived landmark values are replaced as new frames arrive, and none of this data is retained after the camera session ends or stored persistently by the app.
Local profile and training data. Locally stored onboarding, preferences, and progress remain on your device until changed, reset where the app offers that option, or removed by deleting the app.
Account, cloud profile, gameplay, and App Attest data. This data is retained while your account remains active and as needed for security, support, or legal duties. Session credentials remain in the iOS Keychain while needed to maintain your authenticated session.
Purchases, Superwall paywall analytics, optional Firebase analytics and diagnostics, notifications, support, and server logs. These records are kept only as long as needed for the stated purpose, configured provider retention periods, accounting or legal requirements, fraud prevention, support, or the defense of claims. Apple retains App Store purchase records under its own policies. Provider backups and logs may expire on their normal retention cycle after deletion from active systems.
11. Account Deletion and Local Data
You can delete your Push Up League account in the app: open Settings, select Delete Account, and confirm. This removes your Supabase account and its associated cloud profile, gameplay, and App Attest records. If you cannot access the app, email contact@03-studios.com from the address connected to your account to request help. We may need to verify your identity. We will delete or anonymize data unless retention is required for legal duties, purchase proof, fraud prevention, security, or legal claims.
Deleting an account does not cancel an Apple subscription or erase purchase history held by Apple. Deleting the app removes app data stored in its local container; Apple and other providers may retain data under their own policies.
12. Your Choices and Rights
You can deny or revoke camera and notification permissions in iOS Settings and can decline or withdraw consent for optional Firebase Analytics and Firebase Crashlytics in the app's Settings. That setting does not disable Superwall paywall event collection. Revoking camera permission prevents any future camera or face-data processing; the app has no persistently stored face data requiring a separate deletion request. Subject to applicable law, you may request access, correction, deletion, restriction, objection, or portability, and may withdraw consent at any time without affecting prior lawful processing. You may object to processing based on legitimate interests by contacting us. We normally respond within one month, or explain any lawful extension or refusal.
13. Security
We use technical and organizational measures designed to protect personal data, including secure platform storage for authentication credentials and limiting camera analysis to on-device processing. No system is completely secure, and we cannot guarantee absolute security.
14. Children
Push Up League is not directed to children under 13, and we do not knowingly collect their personal data. A user below the age at which they can independently consent under applicable law may use the app only with authorization from a parent or legal guardian.
15. Complaints
You may lodge a complaint with your competent data protection authority, including the Italian Garante per la protezione dei dati personali at garanteprivacy.it.
16. Changes to This Policy
We may update this Privacy Policy to reflect changes in Push Up League, the law, or our providers. The current version and its effective date will be published on this page.
17. Contact
For privacy questions or requests, contact contact@03-studios.com.