Privacy Policy
Last updated: September 25, 2026
Pump is a tempo training fitness app that helps you control the speed of your lifts for better muscle gains. It also tracks outdoor activities such as runs and rides, coaches you with PumpIQ, and lets you share workouts with people you choose. This policy explains what data we collect, how we use it, and the choices you have.
Pump (listed as "Pump Fit" in the app stores) is operated by Riker Tech, LLC ("we", "us"). This policy covers the Pump apps for iOS, watchOS and Android, the Pump App Clip, the website at www.pumpfitness.app, and the Pump services behind them. Questions: help@pumpfitness.app.
Information we collect
Account and profile
- Name: your display name, shown on your profile and your activity.
- Email address: used to identify and verify your account, and to send you a sign-in, verification or password reset code.
- User ID: a unique identifier for your account.
- Profile photo, if you add one.
- Sign-in credentials: the public key of your passkey or, if you set one, a salted hash of your password (see Security).
- Settings and time zone: your units, default exercise settings and time zone, so the app behaves the same on every device.
Fitness data
- Workouts: the workouts, exercises, folders, sets, reps, weights, tempos, durations and notes you create or log.
- Training profile: answers you give during onboarding or in PumpIQ settings, such as your training goal and age range, and, only if you choose to enter them, your body weight, height and maximum heart rate. Onboarding can be skipped.
- Imported history: if you import your workout history from another app (for example a Strong, Hevy or Fitbod export file), the file and the workouts in it.
Location
When, and only when, you record an outdoor activity such as a run or a ride, the app reads your device's precise location to measure distance and pace and to draw your route. Location keeps updating while that activity is running, including if you switch away from the app (your device shows its location indicator while it does). The route is saved with the completed workout. The app does not track your location when no outdoor activity is running.
Health data
- Apple Health (iOS and watchOS): with your permission, Pump reads workouts and workout routes you record in other apps, heart rate, active energy, walking, running, cycling and swimming distance, VO2 max, body weight, height and date of birth. It uses these to show heart rate on your workout summaries, to bring workouts from other apps into your history and activity feed, and to estimate your maximum heart rate. Your date of birth is used on your device only and is never sent to our servers. On Apple Watch, Pump also saves the workouts you record to Apple Health so they count toward your Activity rings.
- Health Connect (Android): where the Android app offers it, and only with your permission, Pump reads exercise sessions, heart rate, VO2 max, weight and height from Health Connect for the same purposes. Pump does not write to Health Connect.
- Heart rate summaries, calories, distance, routes and similar metrics from a workout are stored with that workout so they can be shown on your devices and on your workout summary.
Photos, videos and files
Your profile picture; any photo or video you attach to a workout, exercise or set (including form videos recorded with your camera and microphone); photos and covers for groups you manage; files you attach in PumpIQ; and any screenshot or screen recording you attach to a bug report. Pump only accesses your camera, microphone or photo library when you choose to use a feature that needs them.
Social activity
The people you follow and who follow you, follow requests, likes and comments, blocks, groups you join, and workouts you share.
PumpIQ conversations
The messages you send to PumpIQ, its replies, and any files you attach. See PumpIQ below.
Device, diagnostics and usage
- Crash and diagnostic data: see Crash Reporting and Bug Reports below.
- Product interaction: usage events such as opening the app, starting or completing a workout and sharing, so we can measure active and returning users and understand which features are used. Before you create an account, these events are keyed to a randomly generated device identifier rather than to you.
- Push notification tokens: an identifier your device gives us so we can send you notifications.
How we use your data
Your data is used to:
- Provide workout tracking, tempo training and outdoor activity features
- Measure distance, pace and elevation, and draw the route map, for outdoor activities
- Sync your workouts across your devices
- Display your heart rate and other health metrics on your workouts
- Power PumpIQ, and the AI apps you choose to connect
- Show your activity to the people you have chosen to share it with
- Send you the notifications and account emails described below
- Keep the service secure, and improve app stability through crash reporting and bug reports
- Understand how features are used, and measure how well our ads work (see Our Website and Ads)
We do not sell your personal data, and we do not use it to build advertising profiles.
PumpIQ
PumpIQ is Pump's AI coach. To answer you, PumpIQ sends your message, the files you attach, and the context it needs to an AI model provider. That context can include your exercise library, your saved workouts, your recent completed workouts (including average heart rate and calories), your settings, and your training profile (goal, age range and, if you entered them, weight and height). PumpIQ can also create and change workouts and settings in your account when you ask it to.
Our current provider is OpenAI. We send these requests with OpenAI's response storage turned off. We may instead use Google's Gemini models, through Google Cloud, as an alternative provider. The same providers help match exercise names when you import workout history from another app.
Your PumpIQ conversations and attached files are stored on our servers so you can come back to them. We may review conversations to troubleshoot and improve PumpIQ. When you delete a conversation, it disappears from your history, but we keep a copy until you delete your account. PumpIQ is an automated tool and can make mistakes.
Connected AI apps
You can connect third-party AI apps, such as ChatGPT, Claude or Meta's AI apps, to your Pump account. Nothing is shared until you approve the connection, either in the Pump app or on Pump's sign-in page, and the approval screen shows which app is asking. A connected app can:
- Read your workout templates and folders; your exercise library, yours and Pump's built-in exercises; your workout settings and training goal; your time zone; and your full workout history: each completed session's name, date and time, and duration, and each set's reps, weight, time and tempo. It does not receive heart rate, calories or routes.
- Change your workout templates and folders, your exercise defaults, and your workout settings and training goal, and delete workouts after you confirm.
A connected app cannot see or change your profile, followers, social or privacy settings, or anything in your feed.
Once data reaches a connected app, that app's own terms and privacy policy govern how it uses the data, not this policy. You can disconnect an app at any time in Pump under Settings → Connected Apps, which immediately revokes its access.
Sharing and visibility
We do not share your personal data with third parties for their own purposes. Within Pump, your data is shared only as you direct it:
- Your completed workouts, including any route map and any photos or videos you attached, are visible to your followers, along with the likes and comments on them.
- You can make your account private, so that people must ask before they can follow you, and you can limit your activity to a list of approved followers. You can also make an individual workout private, hide the route map on any outdoor workout, remove followers and block people.
- Your name, profile photo, and follower and workout counts can appear on your profile's share page, which anyone with the link can open.
- When you share a workout by link, anyone with the link can preview that workout: its exercises, sets, reps and weights, but not your notes.
- Activity you post in a group is visible to that group's members.
- Deleting a workout removes it for everyone. Workout notes are personal and are never included when a workout is shared.
We may also disclose information if required by law, to protect the safety of our users or others, or as part of a merger, acquisition or sale of our business, in which case this policy continues to apply to your data.
Notifications and email
With your permission, Pump sends push notifications, for example about activity from people you follow, likes and comments, requests to connect an AI app, and reminders to come back and train. If you install the app but have not yet created an account, we may send a few reminders to finish signing up. You can turn notifications off at any time in your device's settings.
We send email only for your account: sign-in, verification and password reset codes. We do not send marketing email.
Crash reporting and bug reports
On iOS, Pump uses Firebase Crashlytics to collect crash reports automatically, so we can find and fix bugs.
On Android, there is no automatic crash reporting service of our own. When the app crashes, the stack trace is written to the app's own storage on your device; Google Play may also collect crash reports under your device's settings.
If you send us a bug report (from Settings, or by shaking your phone), it includes your account ID, device model, OS version, app version, a few display and app settings, the state of any workout in progress, the app's recent diagnostic logs and recent network errors, and any screenshot or recording you add. On Android, the stack trace of a recent crash is attached as well.
Our website and ads
Our website at www.pumpfitness.app uses the Meta Pixel, which lets Meta (Facebook and Instagram) record that you visited the site and tapped a download button, and sets Meta cookies in your browser. The site also records these visits on our own servers using a random identifier stored in your browser.
When you arrive from one of our ads, the site sends our servers a short-lived set of signals about your visit: your IP address, browser and device type, screen size, language and time zone, and the ad identifiers in the link. When the app is first signed in, it sends similar device signals so we can tell whether the install came from that ad. If it did, we report the sign-up, and later your first completed workout, to Meta through its Conversions API, together with the ad identifiers, IP address and browser details from your visit, so Meta can measure the ad. We do not send Meta your name, email address or workout data. The raw visit signals are deleted after 7 days; the attribution result is kept with your account and our usage records.
The Pump apps do not include the Meta SDK, do not access your device's advertising identifier, and do not track you across other companies' apps. On iOS, the app may report an anonymous conversion value through Apple's SKAdNetwork, which does not identify you.
Third-party service providers
We use these providers to run Pump. They process data on our behalf:
- Google Cloud: hosts our servers and the storage for photos, videos and files you upload
- MongoDB Atlas: hosts our database
- OpenAI, and Google (Gemini) as an alternative: AI models for PumpIQ (see PumpIQ above)
- Firebase Crashlytics and Firebase Analytics (iOS only): crash reporting, and usage data associated with a pseudonymous account identifier to understand how features are used and measure active users. Advertising features are turned off.
- Resend: delivers our account emails
- Apple: push notifications, in-app purchases where offered, and the Apple Health integration
- Google: the Health Connect integration and app updates on Android
- Meta: ad measurement, as described in Our Website and Ads
- SoundCloud: if you add a SoundCloud link for music, we look up that playlist or track on SoundCloud
The Android app uses neither Crashlytics nor Firebase Analytics; its usage events go only to our own servers.
Data storage and retention
Your workout data is stored locally on your device and synced to our servers so you can access it across devices. Your data is encrypted in transit using HTTPS.
We keep your account data for as long as your account exists. Usage events are kept for up to a year. When you delete your account, we delete your profile, workouts, exercises, folders, completed workouts, uploaded photos and videos, PumpIQ conversations and files, bug reports, followers and likes, sessions and connected-app access. Some records can remain after deletion: billing records we must keep for tax and accounting, usage events until they expire, comments you left on other people's workouts, groups you created, some records of past activity such as imports and PumpIQ usage, and backups and logs until they cycle out.
Your rights and choices
You have control over your data:
- Delete your account: you can delete your account and its data at any time from the app's settings.
- Control who sees your activity: make your account private, limit your activity to approved followers, remove or block people, make a workout private, hide the route map on any outdoor workout, and delete any workout, all from within the app.
- Connected AI apps: disconnect any app at any time in Settings → Connected Apps.
- Location access: location is only requested when you start an outdoor activity, and you can revoke it at any time in your device's settings. The rest of the app continues to work without it.
- Health data access: you can revoke Pump's access to Apple Health or Health Connect at any time in your device's settings.
- Notifications: turn them off in your device's settings.
- Delete local data: uninstalling the app removes all locally stored data.
- Access and correction: depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to how we use it. Email help@pumpfitness.app and we will respond within the time the law requires.
Security
Pump uses passkey authentication for secure, passwordless sign-in wherever your device supports it. All communication with our servers uses encrypted HTTPS connections.
Because not every device can create a passkey, you can also sign in with an email address, using a one-time code we email you or, on accounts that have one, a password. A password is salted and cryptographically hashed before it is stored. We never store it in a readable form, and neither your password nor its hash is ever returned by our API. Access granted to connected AI apps is stored only as a hash and expires unless it is renewed.
Photos and videos attached to shared workouts are served from long, unguessable addresses so the app can display them; anyone who has such an address can view that file.
Children
Pump is not directed to children, and we do not knowingly collect data from children under 13. If you believe a child under 13 has given us personal data, contact us and we will delete it.
Changes to this policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated revision date.
Contact
If you have any questions about this privacy policy or your data, email help@pumpfitness.app.
Riker Tech, LLC