Privacy Policy
Last updated: March 2026
- Account data: name, email address provided during registration.
- Profile data: fitness goals, experience level, body metrics (weight, height, age), sports preferences, training constraints.
- Training data: workout sessions, exercise logs, personal records, body measurements.
- Nutrition data: diet plans, meal logs, hydration logs.
- Usage data: AI interaction logs (token counts, credits used, operation type) for billing and service improvement.
- Payment data: Stripe handles payment processing. We store only your Stripe customer ID and subscription status — we never see or store your card details.
- Third-party integrations: if you connect Strava, we store your Strava access/refresh tokens and import activity data.
- Contractual necessity: to provide the Pusha service.
- Legitimate interest: to improve the service, detect abuse, and ensure security.
- Consent: for optional features such as Strava integration and push notifications.
- Supabase (database hosting, EU region)
- Anthropic (AI processing — only the content of your prompts)
- Stripe (payment processing)
- Vercel (hosting)
- Strava (if you connect your account)
1. Data Controller
The data controller is the individual operating Pusha ("we", "us", "our"), reachable at hello@pusha.app.
2. Data We Collect
3. Legal Basis for Processing
We process your data under the following legal bases (GDPR Art. 6):
4. Data Retention
We retain your data as long as your account is active. You may request deletion at any time by emailing hello@pusha.app. We will delete your data within 30 days.
5. Your Rights (GDPR)
You have the right to: access your data, rectify inaccurate data, erase your data ("right to be forgotten"), restrict processing, data portability, and object to processing. Contact us at hello@pusha.app to exercise any of these rights.
6. Data Sharing
We do not sell your data. We share data only with the following sub-processors:
7. Cookies
We use only technically necessary cookies (session management). We do not use tracking or advertising cookies.
8. Security
We use industry-standard security measures including Row Level Security (RLS) in our database, HTTPS for all communications, and secure token handling.
9. Contact
For any privacy-related questions, contact us at hello@pusha.app.