Privacy Policy
Effective September 1, 2026
Cleanpull is a coaching app for barbell training: coaches build programs, athletes log workouts, and both sides exchange feedback. This policy explains what data we collect, how we use and store it, and your choices. Cleanpull is operated by CLEARTYPE SRL, Romanian tax identification number RO35033035 and Trade Registry number J1/727/2015. For anything privacy-related, write to [email protected].
What we collect
Account and profile
Your name, email address, account ID, password, gender, height, body weight, and preferred units. We do not store readable passwords.
Workspace plans and billing
Your workspace plan, member allowance, subscription and billing details, and records of payments, invoices, refunds, and disputes. Stripe/Link collects the contact, payment, billing-address, and tax information needed for a purchase and acts as the merchant of record for covered transactions. We receive order, payment, and subscription information, but not your full card number.
Coach referrals and account credit
If you use the referral program, we record your referral code, the accounts and workspaces involved, referral dates, and payment and credit records needed to administer the program. We do not show the referrer the referred coach's plan, payment amount, invoices, or billing details.
Training data
Programs, assignments, workout sessions, sets, reps, weights, post-workout check-ins (effort, joint soreness, enjoyment), and body-weight entries you or your coach record.
Generated workout cartoons
To generate a completed-workout cartoon, Cleanpull automatically sends Google Gemini your profile gender, height, body weight, profile photo if you have uploaded one, and a comparison based on the total weight you lifted. Body weight may include a reading imported from Apple Health or Health Connect. We do not send your name, email address, account ID, or detailed workout log. Google processes this information for Cleanpull and does not use it or the generated cartoon to improve its products.
Messages and media
Private messages exchanged between athletes and authorized coaching staff inside an invitation-only workspace, including photo and video attachments. Messages and media are available only to authorized members of a shared workspace. Media is stored privately under European Union jurisdiction. We do not routinely review private messages, but may access specific content when you ask for support, to investigate a security or Terms issue, or when required by law.
Health Connect and Apple Health
Only with your explicit permission through your device: Cleanpull reads recent body-weight measurements to import them into your progress tracking, and writes completed strength-training sessions back to your health record. Imported readings are stored by us as body-weight entries in your Cleanpull account. Your latest body weight and weigh-in history may be visible to authorized coaching staff in a workspace where you are an athlete. This data is used solely to provide these features. It is never used for advertising or sold. You can revoke either permission at any time in Health Connect or the Health app, or turn off the connection in Cleanpull. That stops future reads and writes, but does not delete body-weight entries already imported into Cleanpull or workouts already written to your device's health record. You can delete individual body-weight entries in Cleanpull; records in Apple Health or Health Connect must be managed there.
Devices and notifications
If you enable notifications, we store a device identifier linked to your account. Apple or Google delivers the notifications and receives their content, such as message previews or workout summaries.
Tips and product news
If you opt in at sign-up or in Settings, we may email you occasional tips and product news. We record your choice, when it changed, and whether it changed at sign-up, in Settings, through an unsubscribe link, or because a message bounced or was reported as spam. We also record which message in a sequence you have received, so you never get the same one twice. These emails carry your first name and a link into the app, not your training, body, health, or billing data. Postmark records when you click a link in one of them. You can unsubscribe with the link in any of these emails or in Settings.
Usage and diagnostics
The public website uses PostHog to measure page views and clicks. Until a regional default or your choice applies, we count these without saving tracking identifiers on your device or linking visits across browser sessions. Based on your country, identified by Cloudflare, analytics that recognize repeat visits and advertising measurement are enabled by default for US visitors for the current browser session, unless Global Privacy Control is enabled. Elsewhere, or when your country cannot be identified, we ask first. Your saved choice takes priority over this default.
When enabled, repeat-visit analytics can link a website visit to an account you create. Advertising identifiers can pass to the app to connect a signup to an ad. To measure and improve our advertising, Meta and Google Ads may use measurement cookies and receive page URLs, advertising identifiers, browser and device information, IP addresses, and basic activity such as page views. Google personalized-ad signals remain disabled. We do not send Meta or Google Ads your email, workout, body, health, media, or payment data. Calculator inputs and results are excluded from analytics.
Website session recordings capture clicks, scrolling, and navigation only when repeat-visit analytics is enabled. Typed information and calculator results are hidden before recording. You can opt out without losing access to the site through “Analytics choices” in the footer. Choosing “No thanks” stops recording; earlier recordings remain for the retention period below.
In the signed-in apps, PostHog records screens visited and features used, linked to your account and device identifiers, email address, and workspace names. Your email is removed from that analytics profile when you delete your account. PostHog also estimates your country or region from network information. App session recordings capture how you use the app, with names, messages, training and health data, photos, videos, and billing details hidden before anything is sent.
Sentry receives crash and error reports, including device information, request details, and your account ID when signed in, but not your email as an account identifier. These reports may be processed in the United States. We also log IP addresses and browser information for security, troubleshooting, and evidence of account-deletion requests.
How we use your data
To run the product: showing your program, tracking your training, letting your coaches review your sessions and reply to you, delivering notifications you asked for, enforcing workspace capacity, administering paid plans, processing payments and refunds, preventing billing fraud, meeting tax and accounting obligations, administering referral credit and preventing referral abuse, generating personalized workout cartoons, sending tips and product news you opted in to, answering support requests, and keeping the service secure and working. Cleanpull shows no ads, sells no data, and shares data only with the service providers listed below, only as needed to run the service or meet their and our legal obligations.
Where the data comes from
Most data comes from you or authorized workspace members, such as your coach. Other sources include health services you connect, Stripe/Link for payments, referral links, Apple and Google for notification delivery, and your device and the providers below for usage and error reports. We calculate training totals, progress, and workspace usage from these records.
What you need to provide
Your name, email address, password, gender, height, body weight, and preferred units are required to create your account and personalize training features. This is a service requirement, not a legal one; without these details, we cannot create the account. Workspace and billing details are required only when you create or administer a workspace or buy a paid plan. Health connections, push notifications, media uploads, public-website analytics and advertising measurement, and other optional fields can be refused or left blank. The related optional feature will be unavailable, but the rest of the service remains available.
Who processes it
- Cloudflare — website delivery, country identification, and private media storage under EU jurisdiction.
- PostHog (EU Cloud) — usage analytics and session recordings.
- Meta Platforms — advertising measurement where enabled by the US regional default or your choice.
- Google Ads — advertising attribution and measurement where enabled by the US regional default or your choice.
- Sentry — crash and error reporting.
- Postmark — transactional email (verification, password resets, deletion confirmations) and, if you opt in, tips and product news, including link-click records for those.
- Google Gemini — workout-cartoon generation under Google's Data Processing Addendum.
- Stripe and Link — payments, subscriptions, invoices, tax, refunds, disputes, and payment security and support.
- Apple and Google — push-notification delivery on their platforms.
For covered transactions, Stripe/Link processes billing information under its own duties as merchant of record as well as to provide services to Cleanpull. Stripe publishes its own privacy and transaction terms, which apply alongside this policy.
International transfers
Some providers may process data outside Romania or the European Economic Area, including in the United States. Where the destination is not covered by a European Commission adequacy decision, we use an Article 46 transfer mechanism such as the European Commission's Standard Contractual Clauses through the provider's data-processing terms, together with appropriate supplementary safeguards where required. Contact [email protected] to ask about the safeguard used for a particular provider or to request a copy of the relevant terms.
How long we keep it
Account, profile, training, and message records are normally kept while the account or shared workspace content exists. Photo and video attachments expire 90 days after upload and are normally deleted within the following 24 hours. Uploads never attached to a message are deleted within roughly a day.
PostHog keeps analytics while we use its service or as needed to provide it, meet legal or contractual obligations, resolve disputes, or prevent abuse. Session recordings are deleted after 30 days. Google Ads data follows our account's retention settings. Sentry keeps error reports for 30 to 90 days and backups for 90 days after creation. Postmark keeps email content and delivery records for 45 days; records used to prevent unwanted or failed deliveries are kept indefinitely. We may request earlier deletion of account-linked records where supported and legally permitted.
Google may temporarily retain cartoon-generation data for up to 24 hours to provide the service, and keep limited-period logs to prevent prohibited use and meet legal or regulatory requirements.
Billing, referral-credit, invoice, transaction, refund, and dispute records are kept for the periods needed for subscription and referral-program administration, tax and accounting law, payment disputes, and fraud prevention. You can contact us about the period that applies to a particular record.
Security and troubleshooting logs are deleted or anonymized once no longer reasonably needed. Specific records may be kept longer to investigate an incident, handle a legal claim, or meet a legal obligation.
After account deletion, we promptly remove active account records and arrange to delete your profile photo; temporary copies may remain briefly. Message attachments become inaccessible and follow the 90-day expiry schedule above. Limited provider, billing, and backup records may remain under the retention periods above or for legal, tax, accounting, dispute, or security obligations. Access to these remaining copies is restricted, and we do not use them to operate the deleted account.
Your rights
Under the GDPR, depending on the circumstances, you may ask us for access to and a copy of your personal data; correction; deletion; restriction of processing; or delivery of data you provided in a portable format. You may object to processing based on legitimate interests and withdraw consent at any time, without affecting processing that was lawful before withdrawal. You may also lodge a complaint with a supervisory authority, particularly in the country where you live, work, or believe an infringement occurred. CLEARTYPE SRL is established in Romania, whose supervisory authority is the ANSPDCP. Cleanpull does not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
You can access and correct your profile in the app, delete your profile avatar and individual body-weight entries while keeping your account, withdraw health permissions in the operating system, disable notifications, turn tips and product news off in Settings, change public-website analytics through “Analytics choices,” and delete your account entirely. For an export or any other rights request, email [email protected]. We may need to verify your identity before completing the request.
Deleting your account
Follow the steps on the account deletion page to delete your account in the app or by email. This removes your account, profile, training history, body-weight entries, linked devices, and messages directly tied to your account, subject to the retention rules above. Shared workspace programs may remain available to other members. Cancelling a paid plan is separate; manage it on the web or contact support. Workouts already written to Apple Health or Health Connect must be managed in those services.
Children
Cleanpull is for adults aged 18 or older. We do not knowingly collect data from anyone under 18. Write to us if you believe a minor has created an account so we can close it and remove the associated data.
Changes
If this policy changes materially, we will note it here with a new effective date and point it out in the app.