Bonyo doing a pull-up

privacy

this is a small personal project about pull-ups, not an advertising business. it stores what it needs to count your reps and keep bonyo alive, and nothing else. here is all of it, in plain words.

who runs this

this site is run by Merrick Allen in Australia, who is the data controller for the information described below. you can reach a human at captain@onemillionpullups.com about anything on this page.

what gets stored

when you sign up and use the site, the database holds:

  • your email address (it is how you sign in, and the only way to reach you);
  • a display name, which starts out as the part of your email before the @ sign until you change it;
  • your pirate alias, generated for you at signup;
  • who referred you, which is permanent and cannot be changed later;
  • your pull-up logs, plans, personal goal, badges and bounty history, with the times they happened.

all of it lives in Cloudflare D1, a database hosted by Cloudflare, who host this site. there is no other copy anywhere.

what other people see

on the leaderboard, in crews and on the bounty board, other users see your pirate alias and your rep numbers. they see your chosen display name only if you have done two things: turned on the “post as my name” option and actually set a name of your own. if either is missing you stay an alias, which is what a brand-new account is by default.

your email address is never shown to anyone. not on the leaderboard, not in a crew, not on a poster, not anywhere.

cookies and storage

mp_session
the sign-in cookie, and the only one this site sets itself. it is essential: without it you cannot stay signed in. HttpOnly, Secure, SameSite=Lax, and it lasts up to a year (see retention below for the sliding part).
_ga and _ga_…
Google Analytics cookies. they are only ever set after analytics has been allowed for your browser, and you can switch that off below at any time.
browser storage
a few small preference keys kept in your own browser, including your analytics choice (mp_consent_v1) and some interface memory. they never leave your device and they track nothing.

analytics

the site uses Google Analytics 4 to count visits: which pages get looked at, a rough location worked out from your IP address, and what kind of device you are on. it never sends Google your email, your name, your alias, your user id, or any custom event about what you did. advertising features are switched off, and the ads-related consent signals are permanently denied.

how the choice is made depends on where you are. if you are in the EEA, the UK or Switzerland, nothing is sent to Google at all until you press “ok” on the small bar at the bottom of the page. everywhere else, analytics is on by default, disclosed right here, and you can turn it off with the button below, which sticks. if we cannot work out where you are, you get the bar and nothing loads.

Google's own privacy policy is at policies.google.com/privacy.

who else is involved

the complete list of third parties, and what each one actually sees:

  • Cloudflare hosts the site and the database, and keeps short-lived request logs the way every web host does.
  • Resend delivers the sign-in links and notification emails, so it sees your email address.
  • GitHub receives the feedback you send through the widget, together with your display name, filed into a private repository only the captain can read.
  • Google receives analytics only, and only under the rules above.

that is the whole list. because both webfonts and every other asset are served from this site itself, your browser makes no third-party request at all before you have agreed to analytics.

how long it is kept

honestly, rather than tidily:

  • your account and your logs are kept while the challenge runs, and after it ends they stay as its historical record.
  • your sign-in session lasts up to a year, and it renews: any visit from 30 days into a session pushes the expiry back out to a full year. so an account you keep using never gets signed out, and a session really ends about a year after your last visit, not a year after you signed in.
  • expired sessions are not automatically deleted. the rows stay in the database until the account is deleted.
  • sign-in links are good for 15 minutes and work once. only a hashed form is stored, never the link itself, and those rows are kept too.
  • server request logs are short-lived and held by Cloudflare.
  • deletion is done by hand, by email. there is no self-serve delete button, and this page will not pretend otherwise.

your rights

anyone, anywhere, can email captain@onemillionpullups.com to get a copy of their data, correct it, or have the account deleted.

if you are in the EEA or the UK you also have the rights the GDPR gives you: access, rectification, erasure, restriction of processing, portability, objection, and the right to complain to your data protection authority.

what this site never does

no advertising. no selling or sharing of personal data. no tracking you across other websites. no profiling. if that ever changes, this page changes first, and the analytics bar asks everyone again.

back to bonyo →