Last updated: 24 July 2026
1.1 We are pleased that you are using our application (hereinafter "app"). In the following we inform you about the handling of your personal data when using our app. Personal data is all data with which you can be personally identified.
1.2 Responsible for data processing regarding this app within the meaning of the General Data Protection Regulation (GDPR) is David, email: [email protected]. The person responsible for the processing of personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of the processing of personal data.
1.3 PushUpLock has no user accounts. You do not create a profile, and we never ask for your name, email address, date of birth or any other directly identifying information in order to use the app.
When you contact us (e.g. by e-mail from the app's "Contact support" or "Send feedback" option), personal data is collected — at minimum your e-mail address and whatever you choose to write in the message. Some support e-mails are pre-filled with basic technical details (such as your app version and iOS version) so that we can reproduce the problem; you can see and edit the whole message before sending it. This data is stored and used exclusively for the purpose of answering your request or for contacting you and the associated technical administration. The legal basis for the processing of this data is our legitimate interest in answering your request in accordance with Article 6 (1) (f) GDPR. If your contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 (1) (b) GDPR. Your data will be deleted once your request has been processed. This is the case if it can be inferred from the circumstances that the facts in question have been finally clarified and provided that there are no legal storage obligations to the contrary.
Most of what PushUpLock does happens entirely on your iPhone and is never transmitted to us or to anyone else.
3.1 Camera and push-up detection. During a workout the app uses your camera to count repetitions. The video is analysed live on your device using Apple's and Google's on-device machine-learning frameworks. No image, video frame or photo is ever uploaded, stored on a server, or shared with us or any third party. Nothing is written to your camera roll. The camera is active only while a workout screen is open.
3.2 Blocked apps (Screen Time). If you use the app-lock feature, you choose which apps to block using Apple's Screen Time (Family Controls) picker. Apple's design means your selection is handed to the app as opaque tokens: we cannot see which apps you selected, and that selection never leaves your device. Granting Screen Time permission does not give us access to your browsing or app-usage history.
3.3 Workout history and settings. Your push-up counts, streaks, goals, ranks and app settings are stored locally on your device. If you have iPhone backups enabled, they may be included in your own iCloud or computer backup — that backup belongs to you and Apple, and we have no access to it. Deleting the app deletes this data. We are not able to recover or restore it for you, and we are not responsible for data lost this way.
If you enable voice commands ("Stop", "Finish" and similar), the app uses the microphone and Apple's speech-recognition framework while a workout is running. Depending on your device, language and Apple's own settings, the recorded audio may be sent to and processed on Apple's servers in order to be transcribed; this is Apple's standard iOS speech recognition and is subject to Apple's Privacy Policy (https://www.apple.com/legal/privacy/). We receive only the recognised command word — we never receive, store or transmit the audio itself. The microphone is used only while a workout is active and only if you have granted both microphone and speech-recognition permission. Voice commands are optional; you can decline or later revoke the permissions in iOS Settings → Privacy & Security, and the app remains fully usable. The legal basis is your consent in accordance with Art. 6 (1) (a) GDPR, given through the iOS permission prompts.
5.1 PushUpLock offers an optional paid subscription. Purchases are made through Apple's App Store. Apple processes your payment and we never see or receive your payment card details, bank details, or Apple ID password. The legal basis for processing data required to provide the subscription you bought is Art. 6 (1) (b) GDPR.
5.2 RevenueCat. Subscription entitlements are managed for us by RevenueCat Inc., 300 Euclid Avenue, San Francisco, CA 94118, USA. To check whether your subscription is active, restore purchases across your devices, and measure how our marketing performs, we transmit to RevenueCat: an anonymous app-generated user ID, your App Store purchase and subscription status, basic device and country information, device identifiers (including the advertising identifier where you have permitted tracking), and the anonymous identifiers used by our analytics and attribution providers (see sections 6 and 8) so that a purchase can be matched to the same anonymous installation. Your data is passed on in accordance with Article 6 (1) (b) and (f) GDPR for the purpose of payment and subscription processing and for measuring the performance of our app. We have concluded a data processing agreement with RevenueCat Inc. obliging the provider to protect the data of app users and not to pass it on to unauthorised third parties. Transfers to the USA are covered by the EU standard contractual clauses. Further information: https://www.revenuecat.com/privacy
6.1 To understand how PushUpLock is used, find bugs, and decide what to improve, we use PostHog, a product-analytics service provided by PostHog Inc., San Francisco, California, USA. Our PostHog project is hosted in the United States.