Privacy Policy for the “Outperform” App
Last updated: 3 September 2026
This Privacy Policy explains how personal data is processed when you use the “Outperform” mobile app (the “App”). The App helps users create, plan, complete and analyse workouts and training programmes and—where expressly selected—share them with other people.
1. Controller
The controller within the meaning of the General Data Protection Regulation (“GDPR”) is:
PumpMove
Pavlos Mitrou
Schloßstraße 74
70176 Stuttgart
Germany
Email: mail@pumpmove.com
2. Principles of Our Data Processing
We process personal data only to the extent necessary to provide the App, perform our contractual obligations, ensure the security of the App, provide a function you have selected, or where you have given your consent.
We do not sell personal data. We currently do not use personalised advertising in the App or technologies that track your behaviour across apps or providers for advertising purposes. The App does not access your contacts, precise location, microphone, or Apple Health/HealthKit data.
3. Technical Connection and Security Data
When the App is started and used, technically necessary data is processed. This may include in particular:
-
IP address and time of access
-
device and operating-system type, App version, language and region
-
technical identifiers, session and authentication information
-
requested functions, server responses and technical error data
-
information about the integrity of the App installation and the device
This processing is necessary to establish connections, provide content, secure sessions, prevent tampering and misuse, and identify technical faults.
The legal bases are Article 6(1)(b) GDPR, insofar as processing is necessary to provide the App, and Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and abuse-free operation of the App.
4. User Account and Sign-In
A user account is created for personalised use of the App. The following data may be processed:
-
internal user ID
-
email address and encrypted password or password managed by the authentication provider
-
display name and, where applicable, profile picture
-
selected sign-in provider
-
date and time the account was created and the most recent authentication
-
optional telephone number
Depending on the options offered, you can sign in using an email address and password, Google or Apple.
When you use “Sign in with Google”, we receive from Google the data authorised for sign-in, in particular a unique account identifier, your email address and, where applicable, your name and profile picture. When you use “Sign in with Apple”, we receive a unique identifier and—where authorised by you and provided by Apple—your name and email address. If you use Apple’s “Hide My Email” feature, we receive a relay address generated by Apple.
Signing in with Google or Apple is voluntary. Alternatively, you can use an email address and password where this option is offered. The legal basis is Article 6(1)(b) GDPR.
Further information can be found in Google’s Privacy Policy and Apple’s Privacy Policy.
5. Profile, Training and Performance Data
To provide its functions and adapt content to your settings, the App processes data you enter and data generated when you use the App. This may include:
-
date of birth or age and gender, where provided
-
training level, training goals and selected sports
-
preferred training days, training frequency and maximum training duration
-
preferences such as bodyweight training, unit of measurement and available weight increments
-
workouts and training programmes you have created, saved, favourited or received
-
exercises, repetitions, weights used, distances, times, speeds, rounds and breaks
-
training dates and times, calendar information, daily goals, reminder times and voluntary notes
-
performance levels, personal bests, progress values, statistics and use of certain training functions
This data is used to save your workouts, display training results, calculate progress and personal bests, provide calendar and reminder functions, and provide the training content you have selected.
The legal basis is Article 6(1)(b) GDPR. Where information is voluntary, the relevant function can also be used without providing it.
Outperform is not a medical application and is not intended for the diagnosis, treatment or monitoring of diseases. Please do not enter diagnoses, medical findings or other medical information in free-text fields or uploads. If voluntary information nevertheless reveals information about your health in an individual case, it is processed solely to provide the training function you have expressly chosen and is not used for advertising.
6. Community, Public Profiles and Sharing Content
The App allows you to share workouts or training programmes with other people or make content visible to the community. In particular, the following data may be processed and displayed to other users:
-
your public username or handle
-
your display name and profile picture, where provided for the selected view
-
workouts or training programmes you publish
-
associated names, descriptions, images, exercises and training parameters
-
publication time and information about the authorship or sender of shared content
Private content does not become public merely because it is stored in the App. It becomes visible to other users only when you select the relevant sharing or publication function. Review content before publishing it, and do not publish third-party personal data without that person’s permission.
The legal basis is Article 6(1)(b) GDPR because processing is necessary to perform the community or sharing function you have selected. You can remove published content in accordance with the functions available in the App. Copies that other users have previously lawfully adopted or created outside the App may not be capable of being recalled completely.
7. Photos, Camera and Photo Library
If you add a profile picture or media to a workout or training programme, you may voluntarily access your device’s camera or photo or media library. The App requests the relevant operating-system permission only when you use such a function.
Selected or captured files are processed so they can be uploaded, stored and displayed at the location you have selected in the App. Depending on the visibility you choose, published media may also be visible to other users.
The legal basis is Article 6(1)(b) GDPR. You can revoke the device permission at any time in your system settings. This does not automatically delete files that have already been uploaded; you can remove them through the App or by deleting your account.
8. Push Notifications and Reminders
If you allow push notifications, we process a device-related push token, device type, your notification setting and, where applicable, the reminder time and time zone you have selected.
This data is used to send requested notices—for example, about daily goals—to your device and to avoid duplicate delivery.
Push notifications are voluntary. The legal basis is your consent under Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future in the App or in the operating system’s notification settings.
For technical delivery, we use Firebase Cloud Messaging from Google. On iOS devices, Apple Push Notification Service is also involved in delivery.
9. Subscriptions, In-App Purchases and RevenueCat
Paid subscriptions can be purchased and restored in the App. Payment and billing are handled through the Apple App Store. We do not receive complete payment or credit-card details.
We use RevenueCat to manage offers, purchase status, term, renewal, restoration and premium entitlements. In particular, the following data may be processed:
-
an App user ID or pseudonymous subscriber identifier
-
App, device, platform and store information
-
purchased product, transaction identifier and time of purchase
-
subscription status, expiry and renewal status
-
information about restoring purchases and the active premium entitlement
Under our current integration, RevenueCat does not receive your complete payment method. The payment method is processed by Apple.
The legal basis for our processing and the transfer to RevenueCat is Article 6(1)(b) GDPR. Where data is required to comply with tax or commercial-law obligations, Article 6(1)(c) GDPR applies.
The service provider is:
RevenueCat, Inc.
1032 E Brandon Blvd #3003
Brandon, FL 33511
USA
RevenueCat processes data on our behalf under a data processing agreement. Further information can be found in RevenueCat’s Privacy Policy and Data Processing Addendum.
Apple’s information on the App Store and privacy applies to Apple’s independent processing of App Store purchases.
10. Firebase and Google Cloud
We use Google Firebase services for core App functions. These currently include in particular:
-
Firebase Authentication for user accounts and sign-in
-
Cloud Firestore for profiles, workouts, programmes, goals, calendar and performance data
-
Cloud Storage for Firebase for uploaded images and media
-
Firebase Cloud Messaging for optional push notifications
-
Firebase App Check to identify unauthorised App clients
-
Cloud Functions for Firebase for server-side functions and account deletion
Depending on the applicable contractual and service structure, the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and/or Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google generally processes customer data stored on our behalf as a processor. Google may process certain technical service and security data under its own responsibility in accordance with the applicable contractual terms.
According to the provider, Firebase Authentication processes data exclusively in data centres in the USA. Other Firebase services may process data on Google’s global infrastructure; regions can be specified in some cases for Cloud Firestore, Cloud Storage and Cloud Functions.
Google provides further information under Privacy and Security in Firebase and in the Firebase Data Processing and Security Terms.
Depending on the function, the legal bases are Article 6(1)(b) GDPR and Article 6(1)(f) GDPR. Our legitimate interest is the secure, reliable and scalable provision of the App.
11. Local Storage on the Device
The App stores certain data locally on your device, in particular sign-in status, session information, App settings and content temporarily required for display.
Where provided, security-relevant information is stored in a protected storage area of the operating system.
This storage is necessary to keep you signed in, apply your settings and provide the App efficiently. The legal basis is Article 6(1)(b) GDPR.
Local data is generally removed when you sign out, delete your account or uninstall the App. System backups may be subject to the rules of your device or cloud provider.
12. Contact and Support
If you contact us, we process the data you provide, in particular your name, email address, the content of your enquiry and, where applicable, technical information, in order to handle your request.
The legal basis is Article 6(1)(b) GDPR for contract-related enquiries and otherwise Article 6(1)(f) GDPR. Our legitimate interest is appropriate communication and support.
Enquiries are deleted once they have been conclusively handled and there are no statutory retention obligations or legitimate grounds for further storage.
13. Recipients of Personal Data
Personal data is provided only to parties that need it for the purposes described. Recipients may include in particular:
-
Google/Firebase as a hosting, database, storage, authentication, security and push-service provider
-
Google and Apple if you select the relevant sign-in service
-
RevenueCat for managing subscriptions and premium entitlements
-
Apple for processing App Store purchases and push notifications
-
other App users when you publish or share content
-
technical advisers and support providers, where they are bound by confidentiality
-
authorities and courts where there is a legal obligation or where this is necessary to enforce legal claims
We do not disclose data for third-party advertising purposes.
14. Transfers of Data to Third Countries
Some service providers we use are based in the USA or process data there. The USA is a third country outside the European Union and the European Economic Area.
Where the relevant recipient is validly certified under the EU–US Data Privacy Framework, the transfer may be based on the European Commission’s adequacy decision under Article 45 GDPR.
Otherwise, the European Commission’s Standard Contractual Clauses under Article 46(2)(c) GDPR and supplementary technical and organisational measures are used in particular. You may request a copy of the applicable safeguards from us.
Despite these safeguards, processing in third countries may involve a residual risk that government authorities may access data under the laws applicable there.
15. Storage Period and Deletion
We store personal data only for as long as necessary for the relevant purpose or for as long as statutory obligations require continued storage.
-
account, profile, training, calendar and performance data: generally for the duration of your user account
-
publicly shared content: until you remove the content or delete your account
-
uploaded files: until the file, the associated content or the user account is removed
-
push token: until consent is withdrawn, the token becomes invalid or the account is deleted
-
subscription and entitlement data: for as long as required for management, restoration and statutory obligations
-
support enquiries: until they have been conclusively handled and, where applicable, until statutory periods have expired
-
technical security data: only for the period required for security and error analysis
If you delete your account in the App, deletion of the Firebase Authentication account and the App data associated with your account, including subcollections and user uploads, is initiated.
Data subject to statutory retention obligations is blocked and deleted only after the relevant period expires. Backups may remain until they are overwritten in the regular cycle and are not used for ongoing operations during that time.
16. Your Rights
Subject to the statutory requirements, you have the following rights in particular:
-
access to your data under Article 15 GDPR
-
rectification under Article 16 GDPR
-
erasure under Article 17 GDPR
-
restriction of processing under Article 18 GDPR
-
data portability under Article 20 GDPR
-
objection under Article 21 GDPR
-
withdrawal of consent under Article 7(3) GDPR
To exercise your rights, simply send a message to mail@pumpmove.com. To protect your data, we may request appropriate proof of your identity.
You can also delete your account directly in the App through the settings.
You have the right to lodge a complaint with a data protection supervisory authority. The following authority is responsible in particular:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart
Germany
Email: poststelle@lfdi.bwl.de
Website: baden-wuerttemberg.datenschutz.de
17. Right to Object
Where we process personal data on the basis of legitimate interests under Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation.
We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds or the processing is necessary for the establishment, exercise or defence of legal claims.
18. Minors
Outperform is not specifically directed at children. Persons under the age of 16 may use functions whose data processing is based on consent only with the consent or authorisation of the person holding parental responsibility, insofar as Article 8 GDPR applies.
Persons holding parental responsibility may contact us if they believe that a child has submitted personal data without the required authorisation.
19. Automated Decision-Making
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
Calculations of training statistics, progress values or content suggestions are used solely for display and support within the App.
20. Data Security
We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and unauthorised disclosure.
These measures include, in particular, encrypted transmission, authentication, role- and user-based access rules, protected storage of session information, App integrity checks and restricted administrative access.
However, no method of electronic transmission or storage can guarantee absolute security.
21. Changes to This Privacy Policy
We update this Privacy Policy when functions, service providers or legal requirements change.
The current version is available in the App and at outperform.fitness/data. If material changes are made, we will provide appropriate notice within the App or using the contact details on file.
