PPumpy

Privacy Policy

This policy explains what Pumpy collects, how it is used, and the choices you have. We collect the minimum needed to run a great training app - no ads, no data selling.

1. Data we collect

Account: email, name, and authentication data (password hash, passkeys, or OAuth identifiers). Profile & training: your goals, experience, units, gyms and equipment, workouts and logged sets, activities, records, and derived statistics. Optional health-related data you choose to enter, such as bodyweight or body measurements - provided by you, used to personalize your training, and treated with heightened care. Technical: an offline cache (IndexedDB) on your device so logging works without a connection, and standard server logs for security and reliability.

2. How we use it

To operate and improve the Service: generating your workouts, computing your statistics and records, syncing across your devices, and powering the social features you opt into. We do not sell personal data and do not run third-party advertising or ad trackers.

3. Sharing - always at your direction

Your training data is private by default. It becomes visible to others only when you act: members of a group you join can see your completed workouts, records, and stats; people you share a workout with receive a copy; contributions to public gyms are visible to that gym’s users. Leaving a group stops future sharing. We also use infrastructure providers (hosting, backups) bound to processing data only on our behalf, and we may disclose data when required by law.

4. Retention & deletion

We keep your data while your account exists. Deleting your account (Settings → Data) permanently and immediately removes your personal data from the Service. Copies of workouts you explicitly shared with other users remain theirs, without your account attached beyond the sharer name they saved.

5. Your rights

You can access and export all of your data (JSON) or delete your account at any time from Settings → Data - no email required. Depending on your jurisdiction (e.g. GDPR or the Israeli Privacy Protection Law), you may also have rights to rectification, restriction, and complaint to a supervisory authority. Contact us for anything you cannot do in-app.

6. Security

Traffic is encrypted in transit (HTTPS); passwords are stored hashed; passkeys use WebAuthn. No system is perfectly secure - use a strong, unique password and keep your devices protected.

7. Children

The Service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child is using the Service, contact us and we will remove the account.

8. Changes & contact

We will announce material changes to this policy in the app. Privacy questions or requests: [email protected].

Last updated: August 2026.