This Privacy Policy explains how PushWars ("we", "us", "our") collects, uses, and protects personal data when you use the PushWars iOS application and related services (the "Service").
The data controller (and, for California purposes, the business) is Triple R Ventures Ltd, registered in the United Kingdom, number 16984900, contact address Unit 6, Honeyholes Lane, Dunholme, Lincoln, LN23SU, United Kingdom.
Privacy contact: [email protected]
We are a small operation and do not carry out large-scale processing of special-category data, so we are not required to appoint a Data Protection Officer; the privacy contact above handles all data-protection matters. We comply with the EU GDPR and UK GDPR (and the UK Data Protection Act 2018) for EEA and UK users, and the California Consumer Privacy Act, as amended by the CPRA (CCPA), for California residents. This policy is privacy-by-design and data-minimizing: we collect only what we need to run the product, never "just in case."
PushWars's games are controlled by your push-ups, tracked through your device's camera. This is the most sensitive-seeming part of the product, so we're explicit about exactly what happens to that data:
| Category | Examples | Source |
|---|---|---|
| Account / contact | Email address, display name, authentication identifiers, sign-in events | You, via our sign-in provider (Apple / Google / email) |
| Fitness / gameplay data | Rep counts, session duration, workout activity, streaks, XP, tier, per-game level progress, high scores | Generated by the on-device detection engine described in §2 |
| Avatar / customization | Your selected avatar presets, outfit, and gear choices | You, in the Character customizer |
| Leaderboard data | Display name, tier, rank, score — visible to other users of the Service | Generated from your gameplay |
| Subscription data | Subscription status, plan, entitlement state, purchase receipts | Apple, via our subscription-management provider — we never see or store your card details |
| Device & diagnostics | App version, device/OS info, crash reports, performance data, product-interaction events | Automatically, via the app and our analytics/crash-reporting providers |
| Install / marketing attribution | Which marketing source or campaign led to your install, your device's vendor identifier (IDFV), and limited device/network signals used for that measurement | Automatically at install, via our attribution provider — see §6 |
| Alarm & App Blocking settings | Your chosen alarm times, which apps you've selected to block | Stored only on your device via Apple's frameworks — see §4 |
We do not collect precise GPS location, your contacts, or health/medical data. We do not use Apple's advertising identifier (IDFA) and we do not track you across other companies' apps or websites — which is why you will never see an App Tracking Transparency prompt in PushWars. We do not ask for or store your payment-card number.
If you use the push-up alarm or the app-blocking feature, your alarm schedule and your selection of which apps to block are stored only on your device, using Apple's own frameworks. We do not receive, transmit, or store this data on our servers. This is a self-directed feature you configure for yourself — not a feature we operate or monitor.
| Purpose | Data used | Lawful basis (GDPR) |
|---|---|---|
| Create and run your account; deliver the subscription you bought | Account, subscription | Contract (Art. 6(1)(b)) |
| Track your progress, XP, tier, and unlocks | Fitness/gameplay data | Contract |
| Run leaderboards | Display name, tier, score | Contract |
| Keep the Service secure, prevent cheating and abuse | Usage, device, identifiers | Legitimate interests (Art. 6(1)(f)) |
| Product analytics and error tracking to improve the app | Interaction events, crash/performance data | Legitimate interests |
| Measure which marketing source led to your install, and which campaigns work | Install/device identifiers (IDFV), campaign data, conversion milestones (e.g. that a registration or subscription happened) | Legitimate interests (Art. 6(1)(f)) |
| Send service emails (e.g. account confirmations) | Email address | Contract / Legal obligation |
We do not carry out automated decision-making producing legal or similarly significant effects on you (Art. 22). Automated anti-cheat checks may temporarily hold a leaderboard entry pending manual review, but never take a lasting action without human review. We do not sell or "share" your personal data and do not use it for cross-context behavioral advertising.
We share data only with the categories of service providers needed to run the Service. Each is bound by a data-processing agreement and processes data only on our instructions. We don't publish the specific names of every processor here — that's not required by GDPR or CCPA, which both require disclosure by category and purpose, not by vendor name — but we can tell you exactly who holds your data if you make a formal access request (§9).
| Category of recipient | Purpose | Data shared |
|---|---|---|
| Authentication provider | Sign-in and account security | Email, display name, sign-in events |
| Cloud hosting & database providers | Running the backend, storing your account and progress | All structured account/gameplay data in §3 |
| Subscription-management provider | Processing your subscription via Apple's In-App Purchase | User ID, subscription state, receipts |
| Product analytics provider | Understanding how the app is used, improving it | User ID, event/device data |
| Crash & error monitoring provider | Diagnosing and fixing bugs | Errors, stack traces, anonymized user ID |
| Marketing-attribution provider | Measuring which install/marketing source brought you to the app, so we know which campaigns are worth running | IDFV, campaign/install data, and a small set of conversion milestones (registration, subscription, tutorial completion) tied to an opaque account identifier — never your email, name, camera data, or body/pose data |
| Apple Inc. | App Store distribution, In-App Purchase, Sign in with Apple, the on-device frameworks described in §2 and §4 | Standard App Store data; on-device data never reaches Apple through us |
How our attribution works, and what it deliberately does not do. To know which adverts and channels actually bring people to PushWars, we use a mobile-measurement provider. It runs on your device's vendor identifier (IDFV — an identifier that is specific to us and cannot be used to follow you into other companies' apps), together with Apple's own privacy-preserving SKAdNetwork mechanism, which reports campaign performance to us in aggregate rather than identifying you individually. We have deliberately chosen not to use Apple's advertising identifier (IDFA) and not to request tracking permission, because we do not need cross-app tracking to run our marketing. The only behavioural information shared is a short list of conversion milestones — for example, that an account was registered or a subscription started — attached to an opaque account identifier. No email address, no display name, and nothing whatsoever from the camera pipeline described in §2.
We may also disclose data where required by law, to enforce our Terms, to protect rights and safety, or in a business reorganization, merger, or sale (with your data kept protected).
Still absent: we do not use the IDFA advertising identifier, we do not use any AI/LLM provider to process your data, and we do not sell or share your data for cross-context behavioral advertising.
Some service providers are located in the United States. Where we transfer personal data outside the UK/EEA, we rely on appropriate safeguards — principally the EU Standard Contractual Clauses and the UK International Data Transfer Addendum — together with each provider's data-processing agreement.
| Data | Retention |
|---|---|
| Camera frames / pose data | Never stored — zero retention, by architecture |
| Active account | While your account exists, deleted within 30 days of a deletion request |
| Account created but never subscribed | Purged after 30 days |
| Lapsed subscription | Purged 180 days after it lapses |
| Individual workout/session records | 24 months, then aggregated into rollups (your lifetime totals are preserved regardless) |
| Progression, XP, inventory, lifetime totals | Life of the account |
| Leaderboard entries | Life of the account; removed on deletion |
| Analytics events | 12 months |
| Attribution / install-source records | 12 months |
| Crash/error reports | 90 days |
| Backups | 30 days |
| Alarm configs, blocked-app selections | On your device only; removed when you delete the app — we hold none of this |
We do not discriminate against you for exercising these rights.
You have the right to know/access, delete, and correct your personal information, to opt out of the "sale" or "sharing" of it, and to limit the use of sensitive personal information. We do not sell your personal information, and we do not use it for cross-context behavioral advertising. Our marketing-attribution provider (§6) acts as our service provider for measuring install sources — it is not an independent third party we sell or share data to, and it does not receive your advertising identifier. You may still exercise your rights via the in-app tools above or [email protected]. An authorized agent may submit a request with proof of authorization. We will not discriminate against you for exercising these rights.
When you choose Delete Account, we:
Deletion is permanent and cannot be undone. Alarm configs and blocked-app selections stored on your device are removed when you uninstall the app — we never held them to begin with. Records we must keep for legal/tax reasons, and rolling backups, age out per §8.
We follow a privacy-by-design, minimum-data approach: per-request authentication, service-layer user isolation (every query is scoped to your account), encryption in transit, edge-level rate-limiting and bot protection, server-side-only secrets, and least-privilege access. No system is perfectly secure, but we work to protect your data and will notify you and the relevant regulator of a personal-data breach where the law requires.
The Service is for ages 13+, matching Apple's own App Store account minimum. We do not knowingly collect data from anyone under 13. If you believe someone under 13 has given us personal data, contact [email protected] and we will delete it. Users under the digital-consent age set by their country's law (which varies, and within the EU can be as high as 16 depending on member state) must have a parent or guardian's permission to use the Service.
The iOS app does not use cookies. It also does not track you across other companies' apps or websites: we do not use Apple's advertising identifier, so PushWars does not trigger — and does not need — an App Tracking Transparency prompt. Our install-attribution measurement (§6) uses only an identifier specific to us plus Apple's aggregate SKAdNetwork reporting. Any future marketing website that uses non-essential cookies will present a consent banner for EU/UK visitors.
We may update this policy from time to time. If a change is material we will notify you (in-app or by email). The "Last updated" date shows the latest version. Continuing to use the Service after a change takes effect means you accept the updated policy.
Email: [email protected]
Postal: Unit 6, Honeyholes Lane, Dunholme, Lincoln, LN23SU, United Kingdom
You also have the right to complain to your data-protection authority (in the UK, the ICO at ico.org.uk/make-a-complaint).