← Back to PushWars

PushWars — Privacy Policy

Last updated: 15 July 2026  ·  Effective date: 15 July 2026
The headline, up front: PushWars uses your camera to count your push-ups and control the game. Your camera feed never leaves your device. No video, no images, and no pose or skeleton data are ever uploaded, stored, or transmitted to us or to anyone else — not even in a de-identified form. The only thing that leaves the camera pipeline is a number: how many reps you did. Everything else in this policy is secondary to that fact.

1. Introduction and who is responsible

This Privacy Policy explains how PushWars ("we", "us", "our") collects, uses, and protects personal data when you use the PushWars iOS application and related services (the "Service").

The data controller (and, for California purposes, the business) is Triple R Ventures Ltd, registered in the United Kingdom, number 16984900, contact address Unit 6, Honeyholes Lane, Dunholme, Lincoln, LN23SU, United Kingdom.

Privacy contact: [email protected]

We are a small operation and do not carry out large-scale processing of special-category data, so we are not required to appoint a Data Protection Officer; the privacy contact above handles all data-protection matters. We comply with the EU GDPR and UK GDPR (and the UK Data Protection Act 2018) for EEA and UK users, and the California Consumer Privacy Act, as amended by the CPRA (CCPA), for California residents. This policy is privacy-by-design and data-minimizing: we collect only what we need to run the product, never "just in case."

2. The camera — what actually happens

PushWars's games are controlled by your push-ups, tracked through your device's camera. This is the most sensitive-seeming part of the product, so we're explicit about exactly what happens to that data:

  • Body-pose detection runs entirely on your device, using Apple's on-device Vision framework together with a machine-learning model bundled inside the app. Your camera feed is processed frame-by-frame in memory and is never written to disk, never uploaded, and never logged — not to our servers, not to any analytics or crash-reporting tool, not even in debug builds.
  • The only artifacts that leave the camera-processing pipeline are discrete counted events — a completed rep, a held block, a detected movement — and their aggregates (how many reps, how long a session lasted, whether you won or lost a level).
  • What actually reaches our servers from a play session: integer counters and game results (your push-up totals, level progress, XP, leaderboard scores). Never anything visual, and never a skeleton/pose representation of your body.
  • This is both a product promise and an architectural fact — the camera-processing code has no network path available to it.

3. The personal data we collect

CategoryExamplesSource
Account / contactEmail address, display name, authentication identifiers, sign-in eventsYou, via our sign-in provider (Apple / Google / email)
Fitness / gameplay dataRep counts, session duration, workout activity, streaks, XP, tier, per-game level progress, high scoresGenerated by the on-device detection engine described in §2
Avatar / customizationYour selected avatar presets, outfit, and gear choicesYou, in the Character customizer
Leaderboard dataDisplay name, tier, rank, score — visible to other users of the ServiceGenerated from your gameplay
Subscription dataSubscription status, plan, entitlement state, purchase receiptsApple, via our subscription-management provider — we never see or store your card details
Device & diagnosticsApp version, device/OS info, crash reports, performance data, product-interaction eventsAutomatically, via the app and our analytics/crash-reporting providers
Install / marketing attributionWhich marketing source or campaign led to your install, your device's vendor identifier (IDFV), and limited device/network signals used for that measurementAutomatically at install, via our attribution provider — see §6
Alarm & App Blocking settingsYour chosen alarm times, which apps you've selected to blockStored only on your device via Apple's frameworks — see §4

We do not collect precise GPS location, your contacts, or health/medical data. We do not use Apple's advertising identifier (IDFA) and we do not track you across other companies' apps or websites — which is why you will never see an App Tracking Transparency prompt in PushWars. We do not ask for or store your payment-card number.

4. Alarm & App Blocking — device-local, not ours

If you use the push-up alarm or the app-blocking feature, your alarm schedule and your selection of which apps to block are stored only on your device, using Apple's own frameworks. We do not receive, transmit, or store this data on our servers. This is a self-directed feature you configure for yourself — not a feature we operate or monitor.

5. How and why we use your data, and our lawful bases

PurposeData usedLawful basis (GDPR)
Create and run your account; deliver the subscription you boughtAccount, subscriptionContract (Art. 6(1)(b))
Track your progress, XP, tier, and unlocksFitness/gameplay dataContract
Run leaderboardsDisplay name, tier, scoreContract
Keep the Service secure, prevent cheating and abuseUsage, device, identifiersLegitimate interests (Art. 6(1)(f))
Product analytics and error tracking to improve the appInteraction events, crash/performance dataLegitimate interests
Measure which marketing source led to your install, and which campaigns workInstall/device identifiers (IDFV), campaign data, conversion milestones (e.g. that a registration or subscription happened)Legitimate interests (Art. 6(1)(f))
Send service emails (e.g. account confirmations)Email addressContract / Legal obligation

We do not carry out automated decision-making producing legal or similarly significant effects on you (Art. 22). Automated anti-cheat checks may temporarily hold a leaderboard entry pending manual review, but never take a lasting action without human review. We do not sell or "share" your personal data and do not use it for cross-context behavioral advertising.

6. Who we share data with

We share data only with the categories of service providers needed to run the Service. Each is bound by a data-processing agreement and processes data only on our instructions. We don't publish the specific names of every processor here — that's not required by GDPR or CCPA, which both require disclosure by category and purpose, not by vendor name — but we can tell you exactly who holds your data if you make a formal access request (§9).

Category of recipientPurposeData shared
Authentication providerSign-in and account securityEmail, display name, sign-in events
Cloud hosting & database providersRunning the backend, storing your account and progressAll structured account/gameplay data in §3
Subscription-management providerProcessing your subscription via Apple's In-App PurchaseUser ID, subscription state, receipts
Product analytics providerUnderstanding how the app is used, improving itUser ID, event/device data
Crash & error monitoring providerDiagnosing and fixing bugsErrors, stack traces, anonymized user ID
Marketing-attribution providerMeasuring which install/marketing source brought you to the app, so we know which campaigns are worth runningIDFV, campaign/install data, and a small set of conversion milestones (registration, subscription, tutorial completion) tied to an opaque account identifier — never your email, name, camera data, or body/pose data
Apple Inc.App Store distribution, In-App Purchase, Sign in with Apple, the on-device frameworks described in §2 and §4Standard App Store data; on-device data never reaches Apple through us

How our attribution works, and what it deliberately does not do. To know which adverts and channels actually bring people to PushWars, we use a mobile-measurement provider. It runs on your device's vendor identifier (IDFV — an identifier that is specific to us and cannot be used to follow you into other companies' apps), together with Apple's own privacy-preserving SKAdNetwork mechanism, which reports campaign performance to us in aggregate rather than identifying you individually. We have deliberately chosen not to use Apple's advertising identifier (IDFA) and not to request tracking permission, because we do not need cross-app tracking to run our marketing. The only behavioural information shared is a short list of conversion milestones — for example, that an account was registered or a subscription started — attached to an opaque account identifier. No email address, no display name, and nothing whatsoever from the camera pipeline described in §2.

We may also disclose data where required by law, to enforce our Terms, to protect rights and safety, or in a business reorganization, merger, or sale (with your data kept protected).

Still absent: we do not use the IDFA advertising identifier, we do not use any AI/LLM provider to process your data, and we do not sell or share your data for cross-context behavioral advertising.

7. International data transfers

Some service providers are located in the United States. Where we transfer personal data outside the UK/EEA, we rely on appropriate safeguards — principally the EU Standard Contractual Clauses and the UK International Data Transfer Addendum — together with each provider's data-processing agreement.

8. How long we keep your data (retention)

DataRetention
Camera frames / pose dataNever stored — zero retention, by architecture
Active accountWhile your account exists, deleted within 30 days of a deletion request
Account created but never subscribedPurged after 30 days
Lapsed subscriptionPurged 180 days after it lapses
Individual workout/session records24 months, then aggregated into rollups (your lifetime totals are preserved regardless)
Progression, XP, inventory, lifetime totalsLife of the account
Leaderboard entriesLife of the account; removed on deletion
Analytics events12 months
Attribution / install-source records12 months
Crash/error reports90 days
Backups30 days
Alarm configs, blocked-app selectionsOn your device only; removed when you delete the app — we hold none of this

9. Your rights

EU / UK (GDPR)

  • Access — request an export via the "Export my data" option in Profile → Settings, or email us.
  • Rectify — edit your profile in Settings; changes apply immediately.
  • Erase ("right to be forgotten") — the "Delete account" option in Profile → Settings (see §10).
  • Restrict / object — including objecting to analytics: email [email protected] and we will action it.
  • Port — your export is machine-readable.
  • Complain to your local supervisory authority (in the UK, the ICO at ico.org.uk). We'd appreciate the chance to resolve it first.

We do not discriminate against you for exercising these rights.

California residents (CCPA/CPRA)

You have the right to know/access, delete, and correct your personal information, to opt out of the "sale" or "sharing" of it, and to limit the use of sensitive personal information. We do not sell your personal information, and we do not use it for cross-context behavioral advertising. Our marketing-attribution provider (§6) acts as our service provider for measuring install sources — it is not an independent third party we sell or share data to, and it does not receive your advertising identifier. You may still exercise your rights via the in-app tools above or [email protected]. An authorized agent may submit a request with proof of authorization. We will not discriminate against you for exercising these rights.

10. Deleting your account

When you choose Delete Account, we:

  • Revoke your sessions and delete your authentication record, and sign you out.
  • Remove your entries from leaderboards immediately.
  • Hard-delete your account data within 24 hours — including your progress, XP, inventory, session history, and leaderboard history.
  • Propagate deletion to our service providers where applicable.

Deletion is permanent and cannot be undone. Alarm configs and blocked-app selections stored on your device are removed when you uninstall the app — we never held them to begin with. Records we must keep for legal/tax reasons, and rolling backups, age out per §8.

11. Security

We follow a privacy-by-design, minimum-data approach: per-request authentication, service-layer user isolation (every query is scoped to your account), encryption in transit, edge-level rate-limiting and bot protection, server-side-only secrets, and least-privilege access. No system is perfectly secure, but we work to protect your data and will notify you and the relevant regulator of a personal-data breach where the law requires.

12. Children

The Service is for ages 13+, matching Apple's own App Store account minimum. We do not knowingly collect data from anyone under 13. If you believe someone under 13 has given us personal data, contact [email protected] and we will delete it. Users under the digital-consent age set by their country's law (which varies, and within the EU can be as high as 16 depending on member state) must have a parent or guardian's permission to use the Service.

13. Cookies and tracking

The iOS app does not use cookies. It also does not track you across other companies' apps or websites: we do not use Apple's advertising identifier, so PushWars does not trigger — and does not need — an App Tracking Transparency prompt. Our install-attribution measurement (§6) uses only an identifier specific to us plus Apple's aggregate SKAdNetwork reporting. Any future marketing website that uses non-essential cookies will present a consent banner for EU/UK visitors.

14. Changes to this policy

We may update this policy from time to time. If a change is material we will notify you (in-app or by email). The "Last updated" date shows the latest version. Continuing to use the Service after a change takes effect means you accept the updated policy.

15. Contact

Email: [email protected]
Postal: Unit 6, Honeyholes Lane, Dunholme, Lincoln, LN23SU, United Kingdom

You also have the right to complain to your data-protection authority (in the UK, the ICO at ico.org.uk/make-a-complaint).

© 2026 Triple R Ventures Ltd. All rights reserved.  ·  pushwars.com  ·  Terms of Service