Privacy Policy
This Privacy Policy explains how Julien Pinto, a sole proprietorship governed by French law and doing business as "Pongo" ("we," "us" or "our"), collects, uses and protects your personal data when you use the Pongo mobile application and the website at usepongo.com (together, the "App").
For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller of the personal data described below.
In short. We collect what the App needs to track your training and keep it in sync across your devices. We do not sell your data, we do not use it for advertising, and we do not build advertising profiles about you. You can delete your account, and your data, from inside the App.
1. Information We Collect
1.1 Account information
When you create a Pongo account we collect the identifier returned by your chosen sign-in method. If you use Sign in with Apple, this is an Apple user identifier and an email address, which may be an Apple private relay address that forwards to you without revealing your real address. We never receive your Apple password.
1.2 Profile and training information
Information you enter yourself, including:
- onboarding answers such as your training goal, experience level, available equipment and the number of days you want to train;
- physical characteristics you choose to provide, such as age, sex, height and body weight, used to size your routine and to compute estimates;
- your routines, workout sessions, exercises, sets, repetitions, loads, rest times and notes;
- personal records and derived progress metrics;
- images you choose to attach to a workout, taken from your photo library with your permission.
1.3 Apple Health data
If you grant permission, the App reads your daily step count from Apple Health in order to display your step progress and compare it with the goal you set. Access is read-only: we never write to Apple Health.
Your step count and step goal may be stored on our servers so that they remain consistent across your devices. Health data is never used for advertising, never sold, and never shared with our analytics provider. You can revoke access at any time in the iOS Health app, under Sharing → Apps.
1.4 Subscription information
When you purchase Premium, our subscription provider records the status of your subscription, its renewal dates and an anonymous customer identifier that we link to your account. We never receive or store your payment card details — payment is handled entirely by Apple.
1.5 Technical and usage information
We collect limited technical data to keep the App working and to understand which features are used:
- device model, operating system version and App version;
- a pseudonymous installation identifier;
- in-app events, such as screens viewed and features used;
- diagnostic data, including crash reports and performance metrics reported by Apple's MetricKit;
- a push notification token, if you allow notifications.
We do not collect your precise location, your contacts, your microphone or your camera roll beyond the individual images you deliberately attach.
2. How We Use Information
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and maintain your account | Performance of a contract |
| Store your routines and workouts and synchronise them across your devices | Performance of a contract |
| Generate a training routine from the information you provide | Performance of a contract |
| Display step progress from Apple Health | Your explicit consent |
| Manage your subscription and unlock Premium features | Performance of a contract |
| Send push notifications and reminders | Your consent |
| Diagnose crashes, prevent abuse and keep the service secure | Legitimate interests |
| Understand which features are used, in aggregate, to improve the App | Legitimate interests |
| Respond to your support requests | Performance of a contract |
| Comply with legal obligations | Legal obligation |
We do not use your data for advertising, we do not sell it, and we do not share it with data brokers.
3. How We Share Information
We share personal data only with the service providers that make the App work. They act as our processors, may use the data only on our instructions, and are bound by contractual confidentiality and security obligations.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Authentication, database, backend | Account identifier, profile, routines, workouts, step goals |
| RevenueCat | Subscription management | Anonymous customer identifier, subscription status |
| Apple | Sign in with Apple, payments, App distribution, crash diagnostics | Apple identifier, purchase records, diagnostics |
| Google Firebase | Push notification delivery | Push token, device identifier |
| PostHog | Product analytics and crash reporting | Pseudonymous identifier, device and event data |
| Cloudflare | Hosting of usepongo.com | Standard web request logs |
We may also disclose data where required by law, to comply with a valid legal request, to enforce our Terms of Use, or to protect the rights and safety of our users. If the business is transferred as part of a merger or acquisition, your data may be transferred as part of that transaction; you will be notified beforehand.
4. Your Rights & Choices
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- rectify data that is inaccurate or incomplete;
- erase your data (the "right to be forgotten");
- restrict or object to certain processing, including processing based on our legitimate interests;
- portability — receive your data in a structured, machine-readable format;
- withdraw consent at any time, without affecting processing already carried out.
Deleting your account. You can delete your account and its associated data directly from within the App, in Settings. Deletion is permanent.
Permissions. You can revoke Apple Health access, photo library access and notification permissions at any time in the iOS Settings app.
To exercise any of these rights, write to hi@usepongo.com. We will respond within one month, as required by the GDPR. You also have the right to lodge a complaint with your supervisory authority — in France, the CNIL.
5. Data Retention
We keep your personal data only as long as necessary for the purposes described above:
- Account, profile and training data — for as long as your account exists;
- After account deletion — erased from our production systems without undue delay, and from encrypted backups within 30 days;
- Analytics and diagnostic data — retained in pseudonymous form for up to 12 months;
- Transaction records — retained for as long as required by accounting and tax law.
6. Security Measures
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest, row-level access controls that restrict each record to its owner, authentication managed by our identity provider, and restricted administrative access.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, you, in accordance with Articles 33 and 34 of the GDPR.
7. International Data Transfers
Some of our providers are established outside the European Economic Area, in particular in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V of the GDPR, principally the European Commission's Standard Contractual Clauses, together with any supplementary measures required.
8. Children's Privacy
The App is not intended for children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact hi@usepongo.com and we will delete it.
9. Health Data
Some of the information the App handles — body weight, training load and step count — may qualify as data concerning health, a special category of data under Article 9 of the GDPR.
We process it only on the basis of your explicit consent, given when you provide the information or grant Apple Health access, and only to provide the features you asked for. It is never used for advertising, never sold, and never disclosed to third parties other than the processors listed in Section 3. You may withdraw your consent at any time by revoking the permission or deleting your account.
Pongo is not a medical device and does not provide medical advice. See Section 3 of our Terms of Use.
10. Regional Compliance
10.1 European Economic Area and United Kingdom
The rights described in Section 4 apply to you in full under the GDPR and the UK GDPR.
10.2 California
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information is collected, to request its deletion or correction, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months.
10.3 Other jurisdictions
Wherever you live, you may contact us to ask what data we hold about you and to request its deletion, and we will honour the request to the extent applicable law allows.
11. Changes to This Policy
We may update this Privacy Policy. When we do, we will revise the effective date above, and for material changes we will give you reasonable notice in the App or by email before they take effect. Continued use after that date constitutes acceptance of the revised policy.
12. Contact Us
Julien Pinto, sole proprietorship (entreprise individuelle), France, doing business as Pongo — data controller.
Email: hi@usepongo.com
Web: usepongo.com
Supervisory authority in France: Commission Nationale de l'Informatique et des Libertés (CNIL), cnil.fr.