Legal

Privacy Policy

Last updated: 5 August 2026

Effective date: 5 August 2026

1. Who we are

Pushi is a fitness challenge platform operated from Austria. We are the data controller for all personal data collected through the Pushi app and website. If you have any questions about this policy or how we handle your data, contact us at hello@pushi.fitness.

2. What data we collect

Account information

When you create an account, we collect your email address, first name, and profile avatar. This is used to identify you in challenges, display leaderboards, and connect you with friends and organisations.

Health and activity data

Pushi integrates with Apple HealthKit (iOS) and Google Health Connect (Android) to provide activity-based challenges. With your permission, Pushi may read move calories, exercise minutes, stand hours, active hours, and workout data. Pushi does not write data to HealthKit or Health Connect. We only read what is necessary for the challenges you participate in.

For challenges that use the intensity ring, Pushi reads your heart rate from HealthKit on your device only, to compute the time you spend in higher intensity zones. Your raw heart rate data is never uploaded to our servers — only the derived intensity-minutes figure is stored.

Fitness and activity data is special category personal data under Article 9 of the General Data Protection Regulation (GDPR). We process this data only with your explicit consent, which you give when you grant Pushi permission to access your health data on your device.

Personalised activity goals

To calculate a fair, personalised Move goal, Pushi reads your age, biological sex, height, and weight to compute your Basal Metabolic Rate (BMR). These underlying attributes are read on your device only and are never stored on our servers. The BMR calculation happens locally on your device; only the resulting BMR figure, your Move goal, and the time the calculation was made are uploaded to and stored on our servers.

Your daily activity data — including exercise minutes, intensity minutes, active hours, move calories, stand hours, steps, distance, your challenge score, and workout metadata (type and duration) — is uploaded to and stored on Pushi's Supabase backend so it can power challenges and leaderboards.

AI Activity Suggestions (optional)

When you enable AI Activity Suggestions, the following data, with no personally identifying information attached, is sent to Anthropic's Claude API: your workout types and durations, move calories, activity ring points, and up to 30 days of activity history. No name, email, or user ID is included. This processing is based on your explicit, separate consent (GDPR Article 9(2)(a)), which you give by tapping "Enable" on the in-app prompt or toggling the feature on in Settings. You may withdraw consent at any time by disabling "AI Activity Suggestions" in Settings, after which no further data is sent. Suggestions are advisory only and do not constitute automated decisions affecting your rights or eligibility.

Usage and technical data

We may collect basic technical information such as device type and app version to help us diagnose issues and improve the app. This data is not linked to your identity.

3. How we use your data

We use your data to:

We do not sell your data. We do not share health data with advertisers.

The lawful basis for processing your account and challenge data is your consent (GDPR Article 6(1)(a)). The lawful basis for processing health and activity data is your explicit consent (GDPR Article 9(2)(a)). Sharing your daily progress with a connected friend rests on a further, separate explicit consent, which you give when you connect with that person and can withdraw at any time in the app. You may withdraw any of these consents at any time — see Your Rights below.

4. Organisation challenges

If you join an organisation and take part in its challenges, organisation administrators can see, through the Pushi Portal: your first name and profile avatar, the email address linked to your membership (an organisation email you provide when joining, or — if you do not provide one — your account email), your role, and when you joined. They can also see your performance in the organisation's challenges — your score totals, active and rest days, and streaks — on the challenge leaderboard, the same information visible to other participants in that challenge.

For challenges based on Apple Health or Google Health Connect data, administrators can also see combined, challenge-wide statistics across all participants (such as total and average exercise minutes, move calories, stand hours, active hours, and intensity minutes). These aggregate figures are not broken down to reveal any individual's underlying health metrics.

Administrators cannot see your individual workout details (type or duration), your BMR or Move goal, your HealthKit or Health Connect permissions, or any data from challenges outside their organisation.

When you join an organisation, you are shown a clear notice explaining this before you complete the process. You can leave an organisation at any time through the app, which ends the organisation's access to your data in future challenges. Data from challenges you have already completed may remain visible to administrators as part of those challenges' historical results.

5. Friends and the friend board

Pushi lets you connect with friends in the app. Once two people are connected and have both agreed to share, each can see a weekly friend board showing how the other is getting on against their own daily activity goal.

A connected friend can see:

A connected friend cannot see any underlying health figure: no step counts, move calories, exercise minutes, distances, heart rate, workout types or durations, and no point totals or goal values. The board is assembled on our servers and only the summary figures listed above are ever sent to your friend's device. Connections are given no access to your activity records.

Because this is health-related data, we ask for your explicit consent before any of it is shared (GDPR Article 9(2)(a)). You are shown a notice setting out exactly what is and is not shared, and you confirm it as part of connecting with that person, so that you see both what you are agreeing to and what you get before you agree.

Connections made before the friend board launched. If you were already connected with someone before 5 August 2026, that connection was made before this notice existed. Those connections appear on your board when the feature launches. You can turn Share my daily results off at any time — including before you first open the board — and nothing about your progress is shown to anyone.

You stay in control after connecting:

Disconnecting from someone also ends the sharing, in both directions. Withdrawing consent does not affect the lawfulness of sharing that took place beforehand.

6. Data sharing and third parties

We use the following third-party services to operate Pushi:

These services process only the data necessary to operate the app. We do not share your data with advertising networks, data brokers, or any other third parties beyond those listed above. Optional features that involve third-party processing (such as AI Activity Suggestions) require your separate, explicit consent before any data is transmitted.

Who can see your workout details

You control who can see the specific workouts that make up your score. In Settings, the Workout Details Visibility setting offers three options: Friends only (the default), Challenge participants, or Only me. Your aggregate scores remain visible to other participants in a challenge regardless of this setting; the control applies to the detailed workout list (type and duration).

International data transfers

Your account, challenge, and activity data is hosted in Supabase's European Union (EU) region, within the European Economic Area (EEA). It is not transferred outside the EEA in the normal course of operating the app.

If you opt in to AI Activity Suggestions, the activity data described above is transferred to Anthropic in the United States. This transfer is made under the EU–US Data Privacy Framework, on which Anthropic relies to provide an adequate level of protection for personal data transferred from the EEA. No transfer takes place unless you enable the feature.

7. Data retention

We retain your personal data for as long as your account is active. To delete your data, request deletion by contacting us at hello@pushi.fitness; we will permanently delete your personal data within 30 days, except where we are required to retain it for legal or compliance purposes.1

Activity data associated with completed challenges may be retained in aggregated form, with no personally identifying information attached, after deletion — this cannot be linked back to you.

1 In-app account deletion is coming in a future release. Until then, please request deletion by email as described above.

8. Your rights

Under the GDPR, you have the following rights regarding your personal data:

To exercise any of these rights, contact us at hello@pushi.fitness. We will respond within 30 days.

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Austrian data protection authority: Datenschutzbehörde (DSB), Barichgasse 40–42, 1030 Vienna, Austria — www.dsb.gv.at.

9. US privacy rights

If you are a resident of the United States, you have privacy rights under your state's laws in addition to the protections described above. This section explains those rights and how to exercise them.

All US residents

Regardless of your state, you can ask us to:

To exercise any of these rights, contact us at hello@pushi.fitness. We will respond within 30 days. We do not sell your personal data, and we do not share it with advertising networks or data brokers.

Washington residents — My Health My Data Act (MHMDA)

Your activity, exercise, fitness, and workout data, together with your intensity minutes and your Basal Metabolic Rate (BMR), is "consumer health data" under Washington's My Health My Data Act (MHMDA). We collect this data only with your separate, explicit consent. We do not sell consumer health data, and we do not use geofencing around any health facility.

We maintain a separate Consumer Health Data Privacy Policy describing how we handle consumer health data and how Washington residents can exercise their MHMDA rights, including the right to withdraw consent and to have consumer health data deleted. If you believe we have not complied with the MHMDA, you may file a complaint with the Washington State Attorney General at atg.wa.gov.

California residents — CCPA/CPRA

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, you have the right to know, delete, and correct the personal information we hold about you, and the right to limit our use of sensitive personal information (which includes health data). We do not sell your personal information and we do not share it for cross-context behavioural advertising. We use your health and activity data only to operate the features you use.

Residents of other US states

If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Florida, Indiana, Iowa, Tennessee, Montana, Delaware, New Hampshire, New Jersey, Kentucky, Rhode Island, Minnesota, or Maryland, you have the right to access your personal data, correct inaccuracies, delete it, and request a portable copy. You also have the right to opt out of profiling that produces legal or similarly significant effects — we do not engage in this kind of profiling.

To exercise any of these rights, contact us at hello@pushi.fitness.

10. Security

Your data is stored securely using Supabase infrastructure, hosted in Supabase's European Union (EU) region within the European Economic Area (EEA). We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction. No method of transmission over the internet is 100% secure, but we take reasonable steps to protect your information.

11. Children's privacy

Pushi is not intended for users under the age of 14. We do not knowingly collect personal data from children under 14. If you believe a child under 14 has created an account, please contact us at hello@pushi.fitness and we will delete the account promptly.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the date at the top of this page. For significant changes we will notify you through the app. Your continued use of Pushi after changes are posted constitutes acceptance of the updated policy.

13. Contact

If you have any questions about this Privacy Policy or how we handle your data, please contact us at hello@pushi.fitness.

Change log