Privacy Policy

Last updated: April 17, 2025

What pushed is

pushed is a personal social fitness app that lets you share WHOOP workout data with people you follow. It is not a commercial product and does not sell or monetise your data in any way.

Data we collect

When you use pushed, we collect and store:

  • Your email address and display name (used to create your account).
  • WHOOP biometric data pulled via the WHOOP API with your explicit consent: workout type, start/end time, strain score, average and max heart rate, kilojoules, recovery score (%), HRV, and resting heart rate.
  • WHOOP OAuth tokens (access token, refresh token, expiry) required to fetch your data on your behalf.
  • Social graph data you create: who you follow, kudos you give.

We do not collect location data, payment information, device identifiers, or any data beyond what is listed above.

How we use your data

  • To display your workouts on your profile and in your followers' feeds.
  • To authenticate you when you sign in.
  • To refresh your WHOOP access token automatically so syncing continues to work without requiring you to reconnect.

We do not use your data for advertising, profiling, or any purpose beyond operating the app.

Data sharing

We do not sell, rent, or share your personal data with third parties. The only external service your data touches is the WHOOP API, which we query on your behalf using tokens you granted. Everything else is stored locally in the app's database.

Workout data you post is visible to users who follow you. You control your follower list.

Data retention

Your data is retained for as long as your account exists. You can request deletion at any time (see below). When you disconnect your WHOOP account, we immediately remove your stored OAuth tokens.

Your rights

  • Access: you can view all your stored workouts on your profile page.
  • Deletion: email us at abhiraj9066@gmail.com to request full account and data deletion. We will action it within 30 days.
  • Revoke WHOOP access: you can revoke pushed's access to your WHOOP data at any time from your WHOOP account settings at app.whoop.com.

Security

Passwords are hashed using bcrypt. WHOOP tokens are stored in a private database and are never exposed to the client. The app is served over HTTPS in production.

Changes to this policy

If we make material changes we will update the “Last updated” date at the top of this page. Continued use of the app after changes constitutes acceptance.

Contact

Questions about this policy? Email abhiraj9066@gmail.com.