PRIVACY POLICY
Last Updated 31 August 2026
Welcome to the website (the “Site”) of ManuSoft Inc. (“Company,” “we,” “us,” or “our”), the maker of Pull. Through our mobile application (the “App”), we allow users to meet people to date or to train with, ranked by where and when they actually train (such services, including pull.dating (the “Site”) and the App, are referred to collectively in this Privacy Policy as the “Service”).
This Privacy Policy explains what Personal Data (defined below) we collect, how we use and share that data, and your choices concerning our data practices. This Privacy Policy is incorporated into and forms part of our Terms of Service.
Before using the Service or submitting any Personal Data to the Company, please review this Privacy Policy carefully and contact us if you have any questions. By using the Service, you agree to the practices described in this Privacy Policy and all provisions of this Privacy Policy. If you do not agree to this Privacy Policy, please do not access the Site or otherwise use the Service.
1. PERSONAL DATA WE COLLECT
We collect information that alone or in combination with other information in our possession could be used to identify you (“Personal Data”) as follows:
Personal Data You Provide: We collect the following categories of Personal Data from you when you use our Service, including when you sign up for an account, create or share content, and message or communicate with others:
- Your account: There is one way in: your phone number and a six-digit code we text you. There is no password to set, so there is no password of yours anywhere in Pull, and there is no sign-in with Apple, Google or Facebook. Your phone number is what your account is identified by. We also keep the codes we have issued while they are still valid, and a count of how often a number has asked for one, so that the App cannot be used to text somebody repeatedly.
- Your age: Onboarding asks for your date of birth and the check that you are 18 runs on our server. The date itself is stored, because an age has to be recomputed as you get older. It is never shown to anybody: what another person sees on your profile is a whole number of years. If the date you give is under 18 the account is refused, and we keep a record of that refusal so the same account cannot simply try again with a different date.
- Your profile: Your first and last name, your date of birth, and at least one photograph are required; so are three answers to questions you pick from a list. Your gender and the genders you ask to be shown are required too, and are asked for separately with your explicit agreement, because read together they can reveal your sexual orientation. Everything else is optional: a short biography, who you are looking for, your home gym, the sports you train, which days of the week and which parts of the day you train, whether you are here to date, to train or both, what kind of relationship you are looking for, and six details other apps would call vitals - height, job, education, children, smoking and drinking. We keep your search settings too: the distance and the age range you filter to.
- Your photographs, video and voice notes: Photographs you add are stored in a private bucket, not a public one, and the App is handed a short-lived link each time it draws one. Removing a photograph deletes the stored file itself, not just the row that points at it, and a nightly job removes anything left behind. A voice note is stored with its length so the App can draw the bar.
- Your verification selfie, which is a biometric identifier: Verifying your photo is optional and nothing in Pull requires it. If you start it, the App runs a short randomised challenge - blink, smile, turn, nod - and sends one frame to our server, where two open-source models run on our own machine: a check that the frame is a live person rather than a photograph of one, and a face-recognition model that turns the frame and your profile photograph into numerical face templates and measures the distance between them. That template is a biometric identifier under the Illinois Biometric Information Privacy Act, and comparable Texas and Washington laws. We collect it for one purpose - to confirm the person in your photographs is you - and for no other. It is never sold, leased, traded or otherwise profited from, and it is disclosed to nobody: the models run on our own server in Germany, no verification vendor is called and no template is sent anywhere. Our retention and destruction schedule for it: the face template exists only in memory for the seconds the comparison takes and is never written to a database or a file; the challenge frame is written to a private bucket you cannot read back, and is deleted by the same write that records the verdict; and in every case both are destroyed when the check finishes, or within three years of your last use of Pull, whichever comes first. What survives a check is the verdict alone - verified or rejected, and when.
- Where you are: Pull asks your phone for your location during onboarding, and stores it as a single coordinate on the server. It is recorded again when you refresh it. We also store whether you granted or denied the permission, so the App knows whether to ask again. That coordinate is never sent to another person's phone, and it is never sent to yours either. Distance is computed on our server and returned as a whole number of kilometres, because an exact position is how somebody is followed home. You can decline the location permission; the App works without it, and you can set your area by hand instead.
- What you do with other people: Every like and every pass is recorded, both so that the same person is not dealt to you twice and so that a match can be created when two likes point at each other. Messages you send are stored, and so are their attachments: pictures, video and voice notes, and so is any emoji you react to a message with. Unmatching is recorded too, as is undoing a swipe - both are rationed on a free account, and a ration has to be counted against something. Blocks are stored, and so are reports: who you reported, why, anything you wrote, and how it was resolved.
- Communication Data: We collect information when you contact us with questions or concerns and when you voluntarily respond to requests for your opinion and feedback.
- Payment Information: We offer certain portions of the Service for a fee. Payment is taken on the hosted checkout page of our payment processor, Stripe, Inc. (“Stripe”), opened in your browser, so no card number, expiry date or security code ever reaches us. Accordingly, in addition to this Privacy Policy and our Terms of Service, information related to your payments or purchases is also processed according to Stripe's services agreement and privacy policy. What we keep is the record of the charge: what it was for, the amount, the currency, Stripe's identifier for the payment, whether it succeeded, and when it settled, was refunded or was disputed, together with the customer identifier Stripe issues you.
- Device Data: If you turn on push notifications, Pull stores a push token and your platform, iOS or Android, so a notification can reach the right device. Turning notifications off removes it.
Internet Activity Data: Our servers keep ordinary request logs, which include an Internet Protocol address, the time of the request and which endpoint was called, for security and abuse prevention. We do not build browsing profiles from them.
Personal Data Collected from Third Parties/Publicly Available Sources: None. Pull has no third-party sign-in, imports nothing from any social network, and never reads your contacts, your calendar or your photo library. Adding a picture opens the phone's own photo picker, which runs outside Pull and hands back only the pictures you chose.
Derived Data: We rank the deck from what you told us - the gym you named, the sports and days you train, and how far away somebody is. We do not infer sensitive characteristics about you, and no health or fitness data is read from Apple Health, HealthKit, Health Connect or Google Fit.
Cookies: This Site sets no cookies and the App uses none. We serve no advertising, join no advertising network and hold no advertising identifier, so there is no targeted advertising to opt out of.
Analytics: There is no analytics SDK of any kind in the App, and no analytics service on this Site.
Online Tracking and Do Not Track Signals: We do not track you across other websites or services, and we serve no targeted advertising, so a “Do Not Track” signal has nothing here to switch off.
Biometrics: The optional photo verification described in section 1 is the only place Pull derives a biometric identifier, and it is governed by the retention and destruction schedule stated there. Outside it, no face template, faceprint or other biometric identifier is derived from anything you upload: your photographs are stored and displayed as pictures, no face recognition is run on them, and nobody is identified or searched for by face. A voice note is stored and played back as a recording, is never analysed to identify the person speaking, and no voiceprint is derived from it.
2. HOW WE USE PERSONAL DATA
We may use Personal Data for the following purposes:
- To provide the Service;
- To create your account, rank your deck, make a match when two likes agree, and deliver the messages you send;
- To prove that you are 18, which we are required to do;
- To respond to your inquiries, comments, feedback, or questions;
- To send administrative information to you, for example, information regarding the Service and changes to our terms, conditions, and policies;
- To maintain and improve the Service;
- To authenticate your account and keep it secure;
- To enforce our Terms of Service;
- To prevent spam, fraud, abuse, criminal activity, illegal activity, or misuses of our Service, and to ensure the security of our IT systems, architecture, and networks; and/or
- To comply with legal obligations and legal process and to protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or other third parties.
Legal bases under the GDPR. Your phone number and the codes texted to it, your profile and photographs, your location, your likes, passes and matches, your messages and their attachments, and your payment records are all processed for the performance of a contract with you. Your date of birth is processed to meet a legal obligation and to perform that contract. Two things are not covered by that and are processed only on your explicit consent, which you may withdraw at any time by clearing the field in the App: your gender together with the genders you ask to be shown, which read together can reveal your sexual orientation; and the selfie and the face template of the optional photo verification, which is biometric data processed to identify you. Both are special category data under Article 9, both are optional, and Pull works without either. A push token is processed with your consent, withdrawn by turning notifications off. Abuse counting, automated review of reported text, blocks and reports are processed in our legitimate interests in keeping the Service safe. Payment records are additionally kept to meet a legal obligation to keep records of what we are paid. Where we rely on legitimate interests you may object, as described in section 11.
Automated review. Two checks read what you write, both of them on our own server in Germany, and neither sends your words to another company. Nothing you write is sent to a text-classification service, an advertising network or a language-model API.
The first runs the moment you write. Your profile text and every message are matched against a list of patterns before they are saved, and text that matches is refused and never stored. It looks for four things: offers of paid sex, anything sexual involving somebody under 18, the payment demands romance scams are made of, and slurs. It does not moderate swearing.
The second runs only after somebody reports you. What you wrote in that conversation is scored by two open-source tools we run ourselves - a language model that rates abuse, and a pattern matcher that spots a cryptocurrency address, a card number or a bank account in a message to a stranger. No account identifier and no phone number goes into either; both load from our own disk and reach no network at all.
An automated decision that can restrict your account. When three different people have reported you, or two have and one of those checks fires, your account is restricted for seven days: you leave the deck and you cannot send messages. A report of somebody being under 18 restricts on a single report, because that is the one case where being wrong in the other direction is unacceptable. Nothing you have written is deleted, the restriction lifts by itself, and no score on its own restricts anybody. You have the right to have a person review this. Write to support@pull.dating and a person will look at your account and tell you what they found.
The optional photo verification in section 1 is the other automated decision. It compares a selfie to your own photographs and answers verified or rejected; it affects a badge and nothing else, and a person will review it if you ask.
Aggregated Information. We may aggregate Personal Data and use the aggregated information to analyze the effectiveness of our Service, to improve and add features to our Service, and for other similar purposes.
3. SHARING AND DISCLOSURE OF PERSONAL DATA
In certain circumstances we may share the categories of Personal Data described above without further notice to you, unless required by the law, with the following categories of third parties. Your data is not sold, not rented, and not shared with advertisers or data brokers, and we disclose data to law enforcement only where we are legally required to, or where somebody is in immediate danger.
- Vendors and Service Providers: To assist us in meeting business operations needs and to perform certain services and functions, we share Personal Data with vendors and service providers. Ours are Supabase, in the United States, for sign-in, the database and stored photographs, video and voice notes; Twilio, in the United States, for the text message carrying your sign-in code; Hetzner, in Germany, for the server that runs notifications, the automated review described in section 2, the photo verification described in section 1 and the nightly media sweep; Stripe, in the United States, for card payments and the card details we never see; Apple and Google, in the United States, for store distribution and, in Apple's case, for delivering push notifications; and Cloudflare, in the United States, for this website, the domain and email to our published addresses. Pursuant to our instructions, these parties will access, process, or store Personal Data in the course of performing their duties to us. Three of them do not act only on our instructions, and saying otherwise would be untrue: Stripe is also a controller in its own right for fraud prevention and financial regulation, and Apple and Google are controllers in their own right for store distribution and push delivery, neither of which they offer us a processing agreement for. We take commercially reasonable steps to ensure our service providers adhere to the security standards we apply to your Personal Data.
- Business Transfers: If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of all or a portion of our assets, or transition of service to another provider (collectively a “Transaction”), your Personal Data and other information may be shared in the diligence process with counterparties and others assisting with the Transaction and transferred to a successor or affiliate as part of that Transaction along with other assets.
- Legal Requirements: If required to do so by law or in the good faith belief that such action is necessary to (i) comply with a legal obligation, including to meet national security or law enforcement requirements, (ii) protect and defend our rights or property, (iii) prevent fraud, (iv) act in urgent circumstances to protect the personal safety of users of the Service, or the public, or (v) protect against legal liability.
- Other Users: Certain actions you take are visible to other users of the Service. Anybody Pull deals you to sees your first name and the initial of your last, your age, your photographs, your biography, your answers, your gender, the sports and days you train, the gym you named, the vitals you filled in, and how far away you are in whole kilometres. That is the whole list, and it is enforced by the database rather than by the App: there is no request a client can make that returns somebody's full last name, date of birth, phone number or coordinate. Messages are visible only to you and the person you matched with. One thing reaches a third party from your own device rather than from us: when you search for the gym you train at, what you type and your device's IP address go to Nominatim, run by the OpenStreetMap Foundation in the United Kingdom and the Netherlands, and Pull never receives the search.
4. DATA RETENTION
We keep Personal Data for as long as reasonably necessary for the purposes described in this Privacy Policy, while we have a business need to do so, or as required by law (e.g. for tax, legal, accounting, or other purposes), whichever is longer. In practice, your account and everything attached to it is kept until you delete it; photographs, video and voice notes until you delete them, at which point they are removed from storage; messages until either side's account is deleted; sign-in codes for minutes, after which they expire and are cleared; a refusal of an under-18 date of birth indefinitely, so the age gate cannot be retried around; reports you filed after their resolution, so repeat behaviour is visible; a restriction on an account until it expires, and the record that it happened for as long as the account exists; the record of a permission you gave us - the photo check, or your gender and who you want to see - until you delete your account, kept even after you withdraw it because it is the proof that what we held was lawfully held while we held it; and a daily database backup, of which the two most recent stay on our own server while older copies are held off-site for about a month and then deleted. Payment records are kept for seven years from the charge even if you delete your account, because tax law requires it and a card payment can be disputed months later; deleting your account unlinks your name from the charge rather than deleting the charge, which is the exception in Article 17(3) of the GDPR for data we are required by law to keep or need in order to defend a legal claim.
5. UPDATE YOUR INFORMATION
You can see and change your profile in the App at any time, and you can delete your account from inside the App, in Settings: it removes your sign-in, your profile, your photographs and your messages, it is immediate, and it cannot be undone. Copies already written to a backup disappear when that backup is overwritten. Deleting your account does not by itself cancel a subscription bought through Stripe - cancel that too, or write to us and we will. You can download a copy of your data from Settings in the App, without asking us. Please contact us at privacy@pull.dating if you need to change or correct your Personal Data, or if you wish us to delete your account for you.
6. CALIFORNIA PRIVACY RIGHTS DISCLOSURES
Where provided for by law and subject to any applicable exceptions, California residents may have the right:
- To know the categories of Personal Data that Company has collected about you, the business purpose for collecting your Personal Data, and the categories of sources from which the Personal Data was collected;
- To access the specific pieces of Personal Data that Company has collected about you;
- To know whether Company has disclosed your Personal Data for business purposes, the categories of Personal Data so disclosed, and the categories of third parties to whom we have disclosed your Personal Data;
- To have Company, under certain circumstances, delete your Personal Data; and
- To be free from discrimination related to the exercise of these rights; and
- To limit our use and disclosure of your sensitive personal information. Two things we hold are sensitive personal information: your gender together with the genders you ask to be shown, which read together can reveal sexual orientation, and the selfie and face template of the optional photo verification. We use each only to perform the Service you asked for - to deal you the people you asked to see, and to answer whether the person in your photographs is you - and for no other purpose; we infer no characteristics about you from either, and we disclose neither to anybody. Both are optional and either can be removed in the App at any time.
Section 1 describes what we collect in plain words. California asks for the same list in its own categories, so here it is again in the categories section 1798.140(v) of the Civil Code names, with what we actually hold under each, why, and how long it stays. Every category is collected from you, directly, when you use the Service; nothing comes from a data broker or a public source. The categories of third parties we disclose to are in section 3, and we sell and share none of it.
| Category | What we hold | Why | Kept |
|---|---|---|---|
| Identifiers | Your phone number, your first and last name, the identifier your account is keyed on, and the IP address in a request log | To create and secure your account, and to prevent abuse | Until you delete your account; logs are short-lived |
| Customer records (1798.80(e)) | Your name, phone number and the record of what you paid | To run the Service and to be able to prove what we charged | Payment records seven years; the rest until you delete |
| Protected classifications | Your date of birth and the age computed from it, and your gender | To prove you are 18, which the law requires of us, and to decide who you are shown to | Until you delete your account |
| Commercial information | Which subscription or Lift pack you bought, when, for how much, and whether it settled, was refunded or disputed | To give you what you paid for, and for tax | Seven years from the charge |
| Biometric information | Only the optional photo check: a selfie and the face template computed from it | To confirm the person in your photographs is you | The template is never written down; the selfie is deleted when the check finishes |
| Internet activity | Ordinary server request logs - an IP address, a time, an endpoint | Security and abuse prevention | Short-lived, and no browsing profile is built from them |
| Geolocation | One coordinate, on our server. It is never sent to any phone, including yours | To work out how far away somebody is, returned as whole kilometres | Until you delete your account |
| Audio and visual | Your photographs, your voice notes, and pictures or video you send in a message | To draw your profile and deliver your messages | Until you delete them |
| Professional or employment | The job field on your profile, if you fill it in | It is shown on your profile | Until you delete it |
| Education | The education field on your profile, if you fill it in | It is shown on your profile | Until you delete it |
| Inferences | None. The deck is ranked from what you told us - your gym, your sports, your days, the distance - and we infer no characteristic you did not state | - | - |
| Sensitive personal information | Your precise location; your gender together with the genders you ask to be shown, which can reveal sexual orientation; and the biometric information above | Only to provide the Service you asked for, which is the use the statute permits without a limitation right | As above, per item |
We have not sold or shared Personal Data in the twelve months preceding the date above, and we do not sell or share it now. If you would like to exercise any or all of these rights, you may do so by contacting us at privacy@pull.dating. Your authorized agent may submit requests in the same manner. Once we receive your request, we will verify your identity by sending a code to the phone number on the account.
Please contact us if you have questions about your rights or our disclosures under the CCPA, or to request access to an alternative format of this Privacy Policy.
7. CHILDREN
Pull is for adults. The Service is not directed to anyone under 18, the age check runs on our server at sign-up rather than in the App, and an account whose date of birth is under 18 is refused. If you have reason to believe that an individual under the age of 18 has provided Personal Data to Company through the Service please contact us and we will endeavor to delete that information from our databases.
8. LINKS TO OTHER WEBSITES
The Service may contain links to other websites not operated or controlled by Company, including Stripe's hosted checkout and the app stores (“Third Party Sites”). The information that you share with Third Party Sites will be governed by the specific privacy policies and terms of service of the Third Party Sites and not by this Privacy Policy. By providing these links we do not imply that we endorse or have reviewed these sites. Please contact the Third Party Sites directly for information on their privacy practices and policies.
9. SECURITY
You use the Service at your own risk. You agree and acknowledge that we are a small-scale startup company and implement security features that are reasonable for a company of our size and resources. We implement reasonable measures, within our commercial capabilities at any given time, to protect Personal Data both online and offline from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. What one account may read from another is enforced by row-level security in the database rather than by the App, photographs are held in a private bucket and served through short-lived links, and no exact coordinate is ever returned to a client. However, no Internet or e-mail transmission is ever fully secure or error free. Therefore, you should take special care in deciding what information you send to us via the Service or e-mail.
In addition, we are not responsible for circumvention by a third party of any privacy settings or security measures contained on the Service, or third-party websites. Finally, we cannot control the actions of users on the platform, who may seek to use third party apps or devices to record, store, or share content or communication without other users' prior consent. Please keep this in mind when using the Service.
10. INTERNATIONAL USERS
By using our Service, you understand and acknowledge that your Personal Data will be transferred from your location to our facilities and servers in the United States, and where applicable, to the servers of the technology partners we use to provide our Service, as listed in section 3. What covers each transfer differs, and the honest answer is not the same sentence for every party. The data processing agreements of Supabase, Twilio, Stripe and Cloudflare each incorporate the EU Standard Contractual Clauses and the UK International Data Transfer Addendum and take effect with their terms rather than needing a separate signature, and Stripe additionally receives EEA, UK and Swiss data under the EU-US Data Privacy Framework. No transfer out of the EEA arises for Hetzner, whose server is in Nuremberg, Germany, or for the OpenStreetMap Foundation, since the United Kingdom holds an adequacy decision and the Netherlands is in the European Union. Apple and Google are not covered by anything we hold, because neither offers a transfer agreement for store distribution; both operate as controllers under their own published terms and their own transfer mechanisms, and we are not a party to that.
11. YOUR CHOICES
In certain circumstances providing Personal Data is optional. However, if you choose not to provide Personal Data that is needed to use some features of our Service, you may be unable to use the Service. The App asks for four device permissions and no others - location, when you set where you are; the camera, if you take a photograph inside the App; the microphone, when you record a voice note; and notifications, if you turn them on - and every one of them is refusable. Depending on where you live you also have the right to ask for a copy of the data we hold about you and to know what we collect and who we disclose it to; to have inaccurate data corrected; to have your data deleted; to object to processing we base on legitimate interests; to restrict processing; to receive your data in a portable form; and to complain to your data protection authority. You can also contact us to ask us to update or correct your Personal Data, and you may delete your account. Please note that we will need to verify that you have the authority to delete the account and certain activity generated prior to deletion may remain stored by us and may be shared with third parties as detailed in this Privacy Policy.
12. CHANGES TO THE PRIVACY POLICY
The Service and our business may change from time to time. As a result, we may change this Privacy Policy at any time. When we do we will post an updated version on this page, unless another type of notice is required by the applicable law. By continuing to use our Service or providing us with Personal Data after we have posted an updated Privacy Policy, or notified you by other means if applicable, you consent to the revised Privacy Policy and practices described in it.
13. CONTACT US
If you have any questions about our Privacy Policy or information practices, please feel free to contact us anytime by e-mail at privacy@pull.dating, by telephone at +1 (464) 251-0564, or by post at ManuSoft Inc., 918 E Old Willow Rd, Unit 101, Prospect Heights, Illinois 60070, United States. ManuSoft Inc. decides why and how the data described here is handled, which under the GDPR makes it the controller and under United States state privacy laws the business.