Privacy Policy
Last updated 11 August 2026
How Gods of Pushups handles your data, written by the people who wrote the code that handles it.
The short version
The video never leaves your phone. Camera frames are analysed on the device and thrown away frame by frame. Nothing is recorded, stored or uploaded — not a video, not a still, not a skeleton.
Your account is an identifier, not a profile. Signing in with Apple or Google gives us an opaque user id. We generate your display name ourselves; we never take your real one.
We keep the numbers you earn. Reps, sets, fights, gates — the game is a record of work, and that record is what we store.
No ads, no advertising identifier, and nothing sold. We use one analytics tool — PostHog, hosted in the EU — set up so it cannot follow you: no cookies, no session recordings, no profile of you assembled anywhere.
You can delete everything from inside the app — the Codex tab, your account panel — and deletion means deletion.
- Who we are
- What the camera does
- What we store
- Analytics
- What other players see
- Why we are allowed to
- Who else touches it
- How long we keep it
- Your rights
- Children
- Security
- Changes
Who we are
Gods of Pushups is made and operated by TechForce OÜ, a company registered in Estonia. For the purposes of the EU General Data Protection Regulation, TechForce OÜ is the controller of the personal data described here.
Write to privacy@techforce.pro about anything on this page. A person reads that address.
What the camera does, and does not do
The game counts your reps by looking at you through the front camera. That happens entirely on your phone, using a pose model bundled inside the app. Each frame is turned into a set of body-joint positions, used to decide whether a rep happened, and discarded. The next frame overwrites it.
We do not record video. We do not save frames. We do not upload images, stills, thumbnails or joint positions to our servers, and there is no code in the app that could — what crosses the network during a fight is a rep count and a timestamp, and nothing else.
The app asks for camera permission for this and only this. You can refuse it: the rest of the game still works, but reps will not count themselves.
The app does not record audio. On Android the microphone permission is declared by the audio library the game uses for its sound effects; nothing in Gods of Pushups opens the microphone.
We do not read from Apple Health or Google Fit, and we do not write to them.
What we store
Your account. When you sign in, Apple or Google gives us a stable identifier for you — a long opaque string — and, if you allow it, an email address. Apple's Hide My Email relay works fine here; we never need to know your real address. We also store which provider you used, when the account was made, and when it was last active.
Your name in the game is one we generate, from a word list. We deliberately drop the real name your sign-in provider offers us, so that a leaderboard can never expose it. You can re-roll the generated name whenever you like.
Sessions. Signing in mints a random token that your phone keeps. We store only a SHA-256 hash of it, the platform it was issued to, and its timestamps. A session lasts up to 180 days, extending while you keep playing; then it dies and you sign in again.
Devices. An identifier generated by the app for your install, the platform, when it was last seen, and — if you turned notifications on — the push token Apple or Google issued for it.
The work you do. This is the game: for each attempt, which boss and which gate, how much of its health you took off, whether you won, when it started and ended, and how many people were in the party. Under that, one row per set: which exercise, how many reps, when, and per-rep timing — how long the descent took, how long you held the bottom, and whether the rep was marked short. Also your progress: which heroes and gates you own, hero levels and XP, and the cosmetic choices you have made. And a per-day total per exercise, with your time-zone offset, so that "today" means your today.
Your friends. Who you are friends with, who asked whom, whether a request is pending, accepted or blocked, and any invite links you have generated. Invite links are codes with an expiry rather than your user id, so handing one out stays a choice you make instead of something anyone can derive from a leaderboard.
Duels. Which two sets were matched against each other, and who won.
Technical data. Our server sees your IP address on every request, as any server does. We use it in memory to rate-limit abusive traffic; it is not written to the database and not attached to your account. The server keeps short-lived operational logs to diagnose faults. They are not used to build any profile of you, and they are not shared.
Cookies. There are none — not in the app, and not on this website. Our analytics is configured to keep nothing on your device at all, so there is nothing here to ask you to accept, and no banner asking you to. Apart from analytics, this website loads nothing from anywhere else: the fonts and images on it are served from this same site.
Analytics
We measure how the game and this site are used, because otherwise we are guessing at what to build. The tool is PostHog, on their EU cloud, and it is deliberately set up as the least invasive version of itself.
In the app we record events like a fight being started or finished, which screen you opened, which mode you chose, the app version, and errors and crashes. Those events carry an identifier for your install so we can tell one person doing ten sessions from ten people doing one. They never carry your email address or your sign-in identifier, and the camera is not part of this in any form.
On this website we count page views and where visitors arrived from. It is configured to store nothing at all on your device — no cookies, no local storage — which means we cannot recognise you when you come back, and two visits look like two strangers. That is the trade we chose, and it is why there is no consent banner here.
We do not use session recording: nobody watches a replay of your screen. We do not use autocapture, so what you type is never collected. PostHog receives your IP address with each event, as any server does, and uses it to work out an approximate location — country, roughly a city. We do not use it for anything else, and we do not combine any of this with data from other companies.
None of it is used for advertising, and none of it is sold. Our legal basis is legitimate interest (Art. 6(1)(f)) — knowing which parts of a game people actually use. You can object: write to privacy@techforce.pro and we will exclude your account from analytics. Turning on Do Not Track in your browser also stops this site from measuring anything.
What other players can see
Gods of Pushups is competitive, so some of your data is shown to other people by design:
- Your generated display name, the hero's face you wear, and its aura.
- Your rep totals on the daily, weekly and lifetime leaderboards.
- In a duel, your live rep count — and if you fight someone's ghost, a set they recorded earlier is replayed against you as a rep-by-rep timeline. A ghost is a series of numbers, never a video.
- Your friends can see the fights you have finished.
Your email address is never shown to another player. Nor is your sign-in identifier.
Why we are allowed to do this
Under the GDPR, each thing we do with your data needs a legal basis. Ours are:
- To perform our agreement with you (Art. 6(1)(b)) — running your account, saving your progress across devices, matching you with opponents, showing leaderboards. This is the game working as described.
- Our legitimate interests (Art. 6(1)(f)) — keeping the service up, rate-limiting and blocking abuse, keeping leaderboards readable by rejecting impossible submissions, fixing bugs, and the analytics that tell us which parts of the game are used. We have weighed these against your interests and kept the data involved minimal.
- Your consent (Art. 6(1)(a)) — push notifications, which only happen after your phone asks and you agree. Withdraw it any time in your system settings; nothing else stops working.
How long we keep it
Your account and its history stay as long as the account exists. This is a game about a record over time, and a record that expires is not one.
Sessions expire after at most 180 days of inactivity and are swept from the database. Invite codes expire on their own. Devices that go quiet are cleaned up.
Deleting your account deletes it. In the app: the Codex tab, your account panel, Delete account. Every session is revoked immediately, and the account row is removed — which cascades to your identity from Apple or Google, your friendships and invites, every set you have ever done, your progress, your daily totals and your push tokens. What remains is the fight rows themselves — a boss, a gate, a result, and how many people were in the party — with no way to attribute them to you. They exist so that the other people in a raid do not lose their history when you leave.
Deletion is immediate and cannot be undone. The save on your own phone is not ours to remove: it stays on the device until you delete the app.
Your rights
If the GDPR applies to you, you have the right to ask for a copy of your data, to correct it, to have it erased, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on consent, you can withdraw it.
The fastest routes are inside the app: your name is re-rollable, your notifications are a system toggle, and deletion is a button. For anything else, email privacy@techforce.pro and we will answer within 30 days.
If you think we have got this wrong, you can complain to your local supervisory authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee.
Children
Gods of Pushups is not intended for children under 13, and in countries where the GDPR sets a higher age for consenting on your own — up to 16 — you need a parent or guardian's permission below that age.
We do not knowingly collect data from children under those ages. If you believe a child has an account, write to privacy@techforce.pro and we will delete it.
Security
Everything between the app and our servers is encrypted in transit. We never see a password, because there are none: sign-in happens through Apple or Google, and we verify the signed token they issue against the provider's published keys. Session tokens are stored only as hashes, so a copy of our database would not let anyone sign in as you. The database is not reachable from the public internet.
No system is perfect. If you find a vulnerability, please tell us at privacy@techforce.pro before telling anyone else.
Changes to this policy
When we change this document, the date at the top changes with it. If a change materially affects what we do with your data, we will say so in the app before it takes effect, rather than quietly editing this page.