Pump — Privacy Policy

Last updated: 18 August 2026

Pump is a workout and nutrition tracking app. This policy explains what the app records, what leaves your phone, and how to get your data back or removed.

The app is developed and operated by PumpHQ, contactable at support@pumphq.app. For the purposes of the UK/EU GDPR, PumpHQ is the data controller for the information described below.

The short version. Pump has no advertising, no analytics, and no third-party trackers of any kind. If you use the app without an account, everything you log stays on your phone. Data is only uploaded to the cloud if you sign in and have an active Premium subscription.

1. Information Pump records

CategoryWhat it includesWhy
Account details Your email address, display name, and — if you use Google Sign-In — your Google account profile picture. To create your account, sign you in, and restore your data on a new device.
Health and fitness information Age, sex, height, weight, body-fat percentage and body measurements; your workouts (exercises, sets, reps and weights); food and calorie logs; water intake; daily step counts; and the goals you set. This is the content of the app — it is what Pump exists to record and show back to you.
Photos Progress check-in photos you take, images you attach to custom exercises, and your profile picture. Only stored if you choose to add them. Used solely to display them back to you in the app.
Subscription status Whether you hold an active Premium subscription. To unlock Premium features.

Pump requests the ACTIVITY_RECOGNITION permission to read your phone's built-in step counter, and the CAMERA permission if you take a progress photo or an exercise photo from within the app. Both are optional — decline them and the rest of the app works normally.

2. What Pump does not collect

3. When your data leaves your phone

Without an account, Pump stores everything in a database on your device only. Nothing is uploaded.

With an account but without Premium, only your sign-in details are held by Firebase Authentication. Your workouts, meals, measurements and photos stay on your device.

With an account and an active Premium subscription, the app synchronises your data so you can move to a new phone without losing it. Synchronisation runs automatically when you open and close the app, and you can trigger it manually from Profile → Settings → Backup & Sync.

Uploaded data is stored in your own private area of Google Firebase (under a path keyed to your account ID) using Cloud Firestore and Cloud Storage for Firebase. Google acts as our processor and operates the servers; see the Firebase privacy documentation. Data may be processed on Google servers outside your country, protected by Google's standard contractual clauses.

Regardless of subscription, you can export everything Pump holds locally as a JSON file at any time, free of charge, from Profile → Settings → Backup & Sync → Export data.

4. Legal basis for processing (UK/EU users)

5. How long data is kept

Data stays on your device until you delete it or uninstall the app. Uninstalling removes the local database and any photos stored inside the app's private storage.

Data synchronised to the cloud is retained until you delete it or delete your account. Deleting it from within the app removes that data immediately; an emailed request is actioned within 30 days. You can delete individual items without deleting your account — see section 7.

6. Deleting your account and data

In the app. Go to Profile → Account → Delete account. You will be asked to confirm your password (or to re-confirm with Google), and then the following are erased immediately:

This is immediate and irreversible — there is no recovery window and no backup we can restore from. If you want to keep a copy, export your data first from Profile → Settings → Backup & Sync → Export data.

By email. If you cannot access the app, write to support@pumphq.app from the address registered to your account with the subject "Delete my account". We will delete the account and all associated cloud data within 30 days and confirm once it is done.

Uninstalling the app removes the local copy but does not delete your account or anything already synchronised to the cloud — use one of the two routes above for that.

Premium subscriptions are separate. Deleting your Pump account does not cancel a Google Play subscription. Cancel it in Google Play under Payments & subscriptions, otherwise billing continues.

7. Deleting your data without deleting your account

You do not have to delete your Pump account to remove data from Pump. Everything you log can be deleted item by item, from inside the app, at any time, and your account stays exactly as it is.

Steps. Open the item you want to remove and choose Delete:

What is deleted. Deleting an item removes it from your device straight away. If you have Premium and cloud sync is switched on, the same item is removed from our cloud copy on the next sync and disappears from your other devices when they next sync. Without Premium nothing was ever uploaded, so deleting on the device is the whole deletion.

What is kept, and for how long. When a synced item is deleted we keep a small deletion marker so your other devices can learn that the item is gone. A marker holds only a random identifier and the time of deletion — no workout, food, measurement or photo content, and nothing that describes you or your body. Markers are stored inside your own area of our database and are destroyed completely when you delete your account (see section 6). Apart from those markers we keep nothing: deleted content is not archived, not backed up, and cannot be recovered by you or by us.

By email. If you would rather we did it for you, write to support@pumphq.app from the address registered to your account, describing what you want removed. We will action it within 30 days and confirm once it is done. To delete your whole account instead, see section 6.

8. Your rights

If you are in the UK, EU, or another region with comparable law, you have the right to access, correct, export, restrict, or delete your personal data, and to withdraw consent. Use the export feature in the app, or write to support@pumphq.app and we will respond within 30 days. You also have the right to complain to your local data protection authority.

9. Children

Pump is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has provided data to us, contact us and we will delete it.

10. Security

Traffic between the app and Firebase is encrypted in transit (TLS), and stored data is encrypted at rest by Google. Access rules restrict every account to its own data. No system is perfectly secure, but we take reasonable measures to protect your information.

11. Changes to this policy

If this policy changes materially, the date at the top will be updated and, where the change is significant, we will note it in the app. Continued use after an update means you accept the revised policy.

12. Contact

Questions, requests, or complaints: support@pumphq.app