Privacy Policy
Effective Date: 18 September 2026
Last Updated: 18 September 2026
1. Data Controller
Your personal data is controlled by:
Jakub Zakrzewski Consulting
Sole Proprietorship (JDG)
Tax ID (NIP): 5213997741
Address: al. Jana Pawla II 27, 00-867 Warszawa
Email: privacy@pullyapp.com
(hereinafter: "we", "us", "Pully")
2. What Data We Collect
2.1 Account Data (legal basis: performance of contract, Art. 6.1.b GDPR)
| Data | Purpose | Source |
|---|---|---|
| Email address | Account creation, recovery | Provided by you or Apple Sign In |
| Name (optional) | Personalization (display name) | Apple Sign In (first login) |
| Apple identifier | Authentication via Apple | Apple Sign In |
| Device identifier | Device recognition for sync | Auto-generated (UUID) |
2.2 Training Data (legal basis: performance of contract, Art. 6.1.b GDPR)
- Workouts: date, duration, status, notes
- Sets: weight (kg), reps, RIR, set type
- Training plans: name, structure, exercises, goals
- Workout templates: name, exercises, usage count
- Personal records (PRs): record type, value, date achieved
- Custom exercises: name, muscle group, description (created by you)
2.3 Body Measurements (legal basis: explicit consent, Art. 9.2.a GDPR)
Body measurements are health-related data under Art. 9 GDPR. We collect them only with your explicit consent:
- Body weight, body fat percentage
- Circumferences: neck, chest, biceps (L/R), waist, hips, thigh (L/R), calf (L/R)
You can withdraw consent at any time in Settings > Privacy. Withdrawal results in deletion of all measurements from our servers.
2.4 Apple Health Data (legal basis: explicit consent, Art. 9.2.a GDPR)
If you enable Apple Health integration:
- We write: strength training workouts (date, duration)
- We do NOT read any data from Apple Health
- Apple Health data never leaves your device and is never sent to our servers
- You control permissions in iOS Settings > Health > Pully
2.5 Analytics (legal basis: consent, Art. 6.1.a GDPR)
With your consent, we collect pseudonymised usage data via PostHog (EU cloud):
- Feature usage (e.g., workouts started, screens visited)
- Device model and OS version
- App version
We do NOT collect: exercise names, weights, notes, or your conversations with the AI Assistant.
About the identifier, precisely. Analytics receives a random install identifier generated by the analytics library on first launch and stored on the device. It is not a number issued by the operating system, and not a value we hash ourselves; it is not tied to your account. Our analytics providers never receive your name, your email address or your account identifier, and we never join these events to your identity in our own database. We call this data pseudonymised rather than anonymous: the identifier is stable for a given install, so it can tell devices apart, which under the GDPR is not anonymisation.
You can disable analytics in Settings > Privacy.
2.6 Crash Reporting (legal basis: consent, Art. 6.1.a GDPR)
With your consent, we collect crash reports via Sentry:
- Automatic crash reports (stack traces)
- Diagnostic info (OS version, device model)
We never send Sentry your name, email address or account identifier - email and display name are stripped before sending. Reports carry a pseudonymous install identifier issued by Sentry. Storing of IP addresses is disabled on Sentry's side.
You can disable crash reporting in Settings > Privacy.
2.7 Subscription Data (legal basis: performance of contract, Art. 6.1.b GDPR; legitimate interest, Art. 6.1.f GDPR for revenue analytics)
- Payment processing is handled by Apple via StoreKit 2
- We do NOT receive your payment card details
- We only receive: product identifier, subscription status, expiration dates
- RevenueCat processes a pseudonymous app user identifier (it is your account identifier in our system), a device identifier and purchase information - to operate and synchronise subscriptions and for revenue analytics. This is not anonymous data: the identifier links purchase events to your account
2.8 AI Assistant Data (legal basis: performance of contract, Art. 6.1.b GDPR)
The AI Assistant ("Asystent", premium) processes your training data to answer your questions in context. When you send a message, we transmit the following to our AI sub-processor:
- Sent: a summary of your training (workout counts, weekly frequency, volume in kg, per-exercise performance including percent change and trend, exercise names, last-workout dates, a weekly activity breakdown, muscle-group distribution), your active plan name and structure (plan/day names, exercises, target sets/reps), your profile preferences (goal, experience level, units), and the message you type. Values of individual sets (weights/reps) are referenced by internal identifiers only - never sent as text.
- Never sent: email, name, Apple/device identifiers, body measurements, body weight, Apple Health data, payment data, or workout notes.
Your data is processed by Google Cloud Poland Sp. z o.o. (Gemini API services) as our sub-processor (Art. 28 GDPR); processing may also be carried out by other Google group entities and their sub-processors outside the EEA, under the Data Processing Addendum and Standard Contractual Clauses. Google does not use your prompts or responses to improve its products (we use the paid Gemini API). Google may log prompts and responses for a limited period, solely to detect and prevent violations of its safety policies and to meet legal obligations. This data may be stored transiently in any country where Google or its agents maintain facilities.
When you report a response from the Assistant (the report-response feature), we store the reported message together with the conversation context in order to review it for moderation and to improve the quality of the Assistant (Art. 6.1.f GDPR - our legitimate interest in service safety and quality). Access to reported content is limited to authorised team members; we retain it until the report has been resolved.
Buddy is not designed to process information about your health. Messages recognised as concerning pain, injury or other health problems are refused and are neither stored nor passed to the AI model provider.
The AI Assistant is part of your Premium subscription. It is informational only and is not a medical or mental-health tool. You can stop using it at any time; deleting a conversation or your account erases the conversation history from our systems. That covers the data we control, and there are two exceptions described above in this section: the safety logs kept by our AI sub-processor are subject to its own limited retention periods, and any reply you report for moderation is kept until the report has been dealt with.
3. Where We Store Data
| Location | Data | Encryption |
|---|---|---|
| Your device (SwiftData) | All data - source of truth | iOS device encryption |
| iOS Keychain | Apple identifier, device ID | OS hardware encryption |
| Supabase (EU, region eu-central-1) | Account backup (sync) | TLS 1.2+ (transit), AES-256 (rest) |
| PostHog (EU cloud - servers in Frankfurt) | Random install identifier (SDK-generated) + events | TLS (transit) |
| Sentry (EU region - Germany; US company, SCCs) | Crash reports | TLS (transit) |
| Google Cloud Poland Sp. z o.o. (Google group; processing also outside the EEA under SCCs) | AI Assistant request data (training summary + message) | TLS (transit) |
Pully is offline-first - your data is always available on your device, even without internet. Sync is a background process.
4. Who We Share Data With
We do not sell your data. Ever.
We use the following sub-processors:
| Service | Data | Purpose | DPA |
|---|---|---|---|
| Supabase (Singapore Pte. Ltd.) | Account + training data | Sync and backup | Yes |
| PostHog (EU cloud - Frankfurt; PostHog Inc., USA) | Random install identifier (SDK-generated) + events | Usage analytics and onboarding funnel | Yes (signed 2026-08-26) |
| Sentry - Functional Software, Inc. (USA, SCCs; data in the EU region) | Crash reports | App stability | Yes |
| RevenueCat (USA, SCCs) | Pseudonymous account identifier + device identifier + purchase events | Subscription handling and revenue analytics | Yes |
| Google Cloud Poland Sp. z o.o. (Google group; transfers outside the EEA under SCCs) | Training summary, plan structure, profile, messages | AI Assistant (Gemini) | Yes (incorporated by reference in the paid Gemini API terms) |
| Apple Inc. | Payment data, Apple Health | Payments, health | Independent controller |
For data transfers outside the EEA (Sentry, RevenueCat, Google), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
5. How Long We Keep Data
| Data | Retention Period |
|---|---|
| Account and training data | Until account deletion |
| AI Assistant conversations | Until you delete the conversation or your account |
| Reported AI Assistant responses | Until the report is resolved |
| AI request data (at Google) | Logged for a limited period (safety, legal obligations); Google publishes no specific term |
| Body measurements | Until consent withdrawal or account deletion |
| Analytics (PostHog) | 12 months |
| Crash reports (Sentry) | Auto-deleted after 90 days |
| Backups | Deleted within 30 days of account deletion |
6. Your Rights (GDPR Art. 15-22)
You have the following rights:
6.1 Right of Access (Art. 15)
You can download a copy of all your data in JSON or CSV format. Go to Settings > Export.
6.2 Right to Rectification (Art. 16)
You can edit your data directly in the app (workouts, plans, measurements, profile).
6.3 Right to Erasure (Art. 17)
You can delete your account and all associated data in Settings > Account > Delete Account. Deletion is:
- Immediate on your device (all local data)
- Immediate on the server (cascade delete across all tables)
- Irreversible - we recommend exporting your data first
6.4 Right to Data Portability (Art. 20)
Export in JSON and CSV formats is always free (including free-tier users). Settings > Export.
6.5 Right to Restriction of Processing (Art. 18)
Contact us at: privacy@pullyapp.com
6.6 Right to Object (Art. 21)
You can disable analytics and crash reporting in Settings > Privacy.
6.7 Right to Withdraw Consent (Art. 7.3)
You can withdraw consent for:
- Body measurements - Settings > Privacy (data will be deleted)
- Analytics - Settings > Privacy
- Crash reporting - Settings > Privacy
- Apple Health - iOS Settings > Health > Pully
Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6.8 Right to Lodge a Complaint
You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, www.uodo.gov.pl - or with the supervisory authority of your EU member state of residence.
7. Data Security
We implement the following technical and organizational measures:
- Row Level Security (RLS) - each user can only access their own data on the server
- Encryption in transit - TLS 1.2+ for all network communication
- Encryption at rest - AES-256 on the server, device encryption on iOS
- Keychain - sensitive identifiers stored in iOS Keychain
- Soft delete - data is marked as deleted first, then permanently removed
- Data minimization - we only collect what is necessary for the app to function
- No cross-app tracking - we do not use IDFA or device fingerprinting
8. Notifications
All notifications are local (UNUserNotificationCenter). We do not send server-side push notifications.
Notification types:
- Rest timer completed
- Unfinished workout reminder
- Body measurement reminder
- Personal record celebration (premium)
- Subscription reminders (trial expiry, grace period)
You can manage notifications in Settings > Notifications.
9. Cookies and Tracking
Pully does not use cookies. The app contains no web browser or web components. We do not use:
- Tracking pixels
- IDFA
- Device fingerprinting
- Cross-app tracking
10. Children
Pully is not intended for persons under 18 years of age. This threshold follows from the terms of the language-model provider used by the AI Assistant (Buddy) and is higher than the consent threshold in Art. 8 GDPR. We do not knowingly collect data from persons under 18 and we do not collect dates of birth. If you learn that a person under 18 is using the app, please contact us - we will promptly delete their data.
11. Changes to This Privacy Policy
We will notify you of material changes via:
- In-app notification
- Email (if we have your address)
Continued use of Pully after publication of changes constitutes acceptance. Previous versions of this policy are available upon request.
12. Contact
For data protection inquiries:
- Email: privacy@pullyapp.com
- Response time: within 30 days (per Art. 12.3 GDPR)
13. Automated Decision-Making
Pully does not employ automated decision-making or profiling within the meaning of Art. 22 GDPR. Calculations displayed in the app (estimated 1RM, personal records, session comparisons) are mathematical computations for display purposes only - they do not make decisions affecting your rights.
The AI Assistant generates informational, advisory observations and answers using a language model. This is not automated decision-making under Art. 22 GDPR - its outputs do not produce legal effects or similarly significantly affect you, and no decisions about your account, subscription, or feature access are made based on them.
14. What We Do NOT Collect
For clarity - Pully never collects:
- Location / GPS data
- Phone contacts
- Photos or media
- Biometric data (Face ID/Touch ID is used for device unlock, we do not collect this data)
- Browsing history
- Audio/video recordings
- Data from other apps