Privacy Policy

Last updated: March 2026

    1. Data Controller

    The data controller is the individual operating Pusha ("we", "us", "our"), reachable at hello@pusha.app.

    2. Data We Collect

  • Account data: name, email address provided during registration.
  • Profile data: fitness goals, experience level, body metrics (weight, height, age), sports preferences, training constraints.
  • Training data: workout sessions, exercise logs, personal records, body measurements.
  • Nutrition data: diet plans, meal logs, hydration logs.
  • Usage data: AI interaction logs (token counts, credits used, operation type) for billing and service improvement.
  • Payment data: Stripe handles payment processing. We store only your Stripe customer ID and subscription status — we never see or store your card details.
  • Third-party integrations: if you connect Strava, we store your Strava access/refresh tokens and import activity data.
  • 3. Legal Basis for Processing

    We process your data under the following legal bases (GDPR Art. 6):

  • Contractual necessity: to provide the Pusha service.
  • Legitimate interest: to improve the service, detect abuse, and ensure security.
  • Consent: for optional features such as Strava integration and push notifications.
  • 4. Data Retention

    We retain your data as long as your account is active. You may request deletion at any time by emailing hello@pusha.app. We will delete your data within 30 days.

    5. Your Rights (GDPR)

    You have the right to: access your data, rectify inaccurate data, erase your data ("right to be forgotten"), restrict processing, data portability, and object to processing. Contact us at hello@pusha.app to exercise any of these rights.

    6. Data Sharing

    We do not sell your data. We share data only with the following sub-processors:

  • Supabase (database hosting, EU region)
  • Anthropic (AI processing — only the content of your prompts)
  • Stripe (payment processing)
  • Vercel (hosting)
  • Strava (if you connect your account)
  • 7. Cookies

    We use only technically necessary cookies (session management). We do not use tracking or advertising cookies.

    8. Security

    We use industry-standard security measures including Row Level Security (RLS) in our database, HTTPS for all communications, and secure token handling.

    9. Contact

    For any privacy-related questions, contact us at hello@pusha.app.