Privacy Policy

Cleanpull is a coaching app for barbell training: coaches build programs, athletes log workouts, and both sides exchange feedback. This policy explains what data Cleanpull collects, why, where it lives, and how to get rid of it. Cleanpull is operated by CLEARTYPE SRL, Romanian tax identification number RO35033035 and Trade Registry number J1/727/2015. For anything privacy-related, write to [email protected].

What we collect

Account and profile

Your name, email address, stable internal account identifier, gender, height, body weight, and preferred unit system. Passwords are stored only as salted hashes.

Workspace plans and billing

Each workspace has its own plan and capacity. We store the plan, member allowance, subscription status, billing period, renewal or cancellation state, Stripe customer and subscription identifiers, and invoice, transaction, refund, or dispute metadata needed to administer a paid plan. When a workspace owner starts a paid plan on the web, Stripe Managed Payments Checkout collects the contact and payment information needed for the transaction and may collect a billing address or tax information based on the purchaser's location and payment method. Stripe/Link is the merchant of record for covered transactions. Cleanpull receives the resulting order, payment, and subscription status, but not the full card number.

Training data

Programs, assignments, workout sessions, sets, reps, weights, post-workout check-ins (effort, joint pain, enjoyment), and body-weight entries you or your coach record.

Generated workout cartoons

When Cleanpull generates the cartoon for a completed-workout fun-fact card, it automatically uses Google's paid Gemini Developer API. The prompt contains the gender, height, and body-weight values stored on your profile, together with a comparison derived from the total weight lifted in that workout. A stored body-weight value may have been entered manually or imported from Apple Health or Health Connect, but the prompt does not label its source. It does not contain your name, email address, Cleanpull user ID, or raw set-by-set workout log. Google processes the prompt and generated response for Cleanpull under its Data Processing Addendum and does not use paid-service prompts or responses to improve its products.

Messages and media

Private messages exchanged between athletes and authorized coaching staff inside an invitation-only workspace, including photo and video attachments. Cleanpull has no public feed, user discovery, anonymous or random matching, or messaging outside a shared workspace. Media files are stored in a private bucket under European Union jurisdiction (Cloudflare R2) and are only reachable through short-lived links issued to signed-in, authorized members of the workspace. We do not routinely review private messages, but may access specific content when you ask for support, to investigate a security or Terms issue, or when required by law.

Health Connect and Apple Health

Only with your explicit permission, granted through the operating system: Cleanpull reads recent body-weight measurements to import them into your progress tracking, and writes completed strength-training sessions back to your health record. An imported reading becomes a body-weight entry in your Cleanpull account and is stored on our server. Your latest body weight and weigh-in history may be visible to authorized coaching staff in a workspace where you are an athlete. This data is used solely to provide these features. It is never used for advertising or sold. You can revoke either permission at any time in Health Connect or the Health app, or turn off the connection in Cleanpull. That stops future reads and writes, but does not delete body-weight entries already imported into Cleanpull or workouts already written to your device's health store. You can delete individual body-weight entries in Cleanpull; records in the device health store must be managed there.

Devices and notifications

If you enable push notifications, we store a device registration tied to your account (an Apple push token or Firebase installation identifier) so our servers can hand notifications to Apple or Google for delivery. Notification content — such as a truncated message preview or a workout summary — passes through Apple's and Google's push services in transit.

Usage and diagnostics

If you choose “Allow analytics” on the public website, it sends page and product-interaction analytics to PostHog's EU Cloud. Named events record actions such as generating a calculator result or clicking a product link; calculator inputs and results are not included. You can refuse without losing access to the site and can change your choice at any time through “Analytics choices” in the footer. In the signed-in apps, product analytics such as screens visited and features used are associated with your stable internal Cleanpull user ID and, where applicable, a device or installation identifier. PostHog also derives approximate location, such as country or region, from network information for analytics. We do not send your account email address to PostHog as the telemetry identity. PostHog session replay is disabled, so Cleanpull does not use PostHog to record your screen or replay your session.

Crash and error reports from the browser, native apps, and server can include device or request information and, when you are signed in, your internal Cleanpull user ID. They go to Sentry and may be processed in the United States. We do not send your account email address to Sentry as the telemetry identity. Our servers keep standard request logs (IP address, user agent) for security and debugging, and account-deletion requests record the requesting IP address and user agent as evidence of the request.

How we use your data

To run the product: showing your program, tracking your training, letting your coaches review your sessions and reply to you, delivering notifications you asked for, enforcing workspace capacity, administering paid plans, processing payments and refunds, preventing billing fraud, meeting tax and accounting obligations, generating personalized workout cartoons, answering support requests, and keeping the service secure and working. Cleanpull shows no ads, sells no data, and shares data only with the service providers listed below, only as needed to run the service or meet their and our legal obligations.

Where the data comes from

Most data comes directly from you. Coaches and other authorized workspace members may also enter programs, assignments, session feedback, messages, and other shared-workspace content about you. We receive health data from Apple Health or Health Connect only when you grant the relevant device permission and use the connection. We receive payment and subscription status from Stripe/Link, notification-delivery information from Apple or Google, and analytics and diagnostic information from your browser, app, device, and the processors listed below. We also derive totals, progress, capacity use, and similar service information from those records.

What you need to provide

Cleanpull requires your name, email address, password, gender, height, body weight, and preferred unit system to create and operate your account and personalize its training features. This is a service requirement, not a statutory one; without those details, we cannot create the account. Workspace and billing details are required only when you create or administer a workspace or buy a paid plan. Health connections, push notifications, media uploads, public-website analytics, and other optional fields can be refused or left blank; the related optional feature will then be unavailable, but the rest of the service remains available.

Who processes it

For Managed Payments transactions, Stripe/Link processes billing information under its own duties as merchant of record as well as to provide services to Cleanpull. Stripe publishes its own privacy and transaction terms, which apply alongside this policy.

International transfers

Some providers may process data outside Romania or the European Economic Area, including in the United States. Where the destination is not covered by a European Commission adequacy decision, we use an Article 46 transfer mechanism such as the European Commission's Standard Contractual Clauses through the provider's data-processing terms, together with appropriate supplementary safeguards where required. Contact [email protected] to ask about the safeguard used for a particular provider or to request a copy of the relevant terms.

How long we keep it

Account, profile, training, and message records are normally kept while the relevant account or shared workspace content exists. Attached photo and video objects are scheduled for automatic expiry 90 days after upload; Cloudflare normally removes expired objects within the following 24 hours. Media uploads that are never attached to a message are deleted automatically within roughly a day.

PostHog retains analytics while our account is active or as needed to provide its service and meet contractual or legal obligations. At the end of its service, we can request return or deletion; PostHog may retain data required by law, to resolve a dispute, or to combat harmful use. Sentry retains event data for 30 to 90 days depending on data and plan type and deletes its event-data backups 90 days after creation. Postmark retains email content and delivery metadata for 45 days; suppression records for bounces, spam complaints, and unsubscribed recipients are retained indefinitely for delivery safety and list hygiene. We may ask these processors to delete account-linked records sooner where their services support it and no overriding obligation applies.

For the paid Gemini Developer API, Google does not use prompts or responses to improve its products. Google may log them for a limited period solely to detect and prevent prohibited use and make required legal or regulatory disclosures. The model may also use project-isolated, in-memory caching with a time-to-live of up to 24 hours. Cleanpull does not use Gemini search or maps grounding, the Interactions API, the Live API, the File API, or explicit context caching for workout cartoons.

Billing, invoice, transaction, refund, and dispute records are kept for the periods needed for subscription administration, tax and accounting law, payment disputes, and fraud prevention. You can contact us about the period that applies to a particular record.

Standard server request logs are kept under a rolling operational retention period based on what is reasonably needed to investigate security events, abuse, and service failures, then deleted or anonymized. The period may be extended for a specific log entry when it is needed to investigate an incident, establish or defend a legal claim, or meet a legal obligation.

When you delete your account, its active database records are removed promptly and removal of your profile avatar from storage is scheduled. Cached avatar copies may persist temporarily. Message attachments are no longer available through the Service after their database links are removed and their storage objects follow the 90-day expiry schedule above. Processor records, limited billing records, and backup copies may also remain under the retention settings of those systems or where a legal, tax, accounting, payment-dispute, or security obligation requires retention. We restrict those residual copies and do not use them to provide the deleted account.

Your rights

Under the GDPR, depending on the circumstances, you may ask us for access to and a copy of your personal data; correction; deletion; restriction of processing; or delivery of data you provided in a portable format. You may object to processing based on legitimate interests and withdraw consent at any time, without affecting processing that was lawful before withdrawal. You may also lodge a complaint with a supervisory authority, particularly in the country where you live, work, or believe an infringement occurred. CLEARTYPE SRL is established in Romania, whose supervisory authority is the ANSPDCP. Cleanpull does not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

You can access and correct your profile in the app, delete your profile avatar and individual body-weight entries while keeping your account, withdraw health permissions in the operating system, disable notifications, change public-website analytics through “Analytics choices,” and delete your account entirely. For an export or any other rights request, email [email protected]. We may need to verify your identity before completing the request.

Deleting your account

Follow the steps on the account deletion page — either directly in the app or by email. Deletion removes the active records for your account, profile, training history, messages directly tied to your account, body-weight entries, and device registrations, and schedules removal of your profile avatar. Any remaining message-attachment objects follow the 90-day expiry schedule above. Processor or backup records are handled under the residual-retention rules above. A program stored in a shared workspace may remain available to its other members after your account is removed. Cancelling a paid workspace plan is separate from deleting an account; manage the plan on the web or contact support. Limited billing and transaction records may remain where required under the retention rules above. Workouts already written to Apple Health or Health Connect remain in that health store until you manage them there.

Children

Cleanpull is for adults aged 18 or older. We do not knowingly collect data from anyone under 18. Write to us if you believe a minor has created an account so we can close it and remove the associated data.

Changes

If this policy changes materially, we will note it here with a new effective date and point it out in the app.