Privacy Policy
Effective 9 August 2026
This privacy policy applies to the Mavlo application and website (mavlo.io), operated by Mavlo Ltd, a company registered in England and Wales and based in Newcastle upon Tyne, United Kingdom ("Mavlo", "we", "us", "our"). For the purposes of UK data protection law, Mavlo Ltd is the data controller.
Mavlo is a fitness accountability service. Members create fitness commitments with an attached amount that may be charged only when Mavlo authoritatively verifies a shortfall, and Mavlo verifies completion through fitness data sources the member chooses to connect.
1. Information we collect
When you use Mavlo, we collect:
- Account information: name, email address, date of birth (collected at sign-up, including via Apple or Google Sign-In), an optional profile photo, and any phone number or postal address you choose to add for account and payment setup
- Launch-list information: the email address you submit on mavlo.io if you ask to be notified when Mavlo launches
- Website visit information: a one-way pseudonymous visitor identifier, visit date, visit count, and country code used to produce aggregate unique-visitor reporting. The raw IP address is not stored in this analytics table.
- Onboarding and commitment information: your onboarding answers, the commitments you create, weekly targets, selected amounts, results, streaks, and dispute or support history
- Connected fitness and health data: when you choose these sources, we process only the categories needed for the commitment you create. From Strava this can include activity date and time, sport type, distance, moving time, activity identifier, manual-entry and eligibility status, and Strava-provided calories only for a calorie commitment. Mavlo does not retain Strava routes, maps, coordinates or GPS geometry. Strava evidence is received through member-authorised OAuth, API requests and webhooks and is limited to the active commitment and review window. From Apple Health this is step-count data reduced on your device before upload to pledge-timezone daily totals, sample-presence signals, the covered commitment window, and latest sample time. These values produce the weekly total and let Mavlo determine whether every required date has data coverage. From Oura this can include sleep duration and timing, heart-rate variability (HRV), resting heart rate, average blood-oxygen saturation (SpO₂), and Oura's VO₂ max estimate. We do not use connected fitness or health data for advertising, marketing, profiling, or data sales.
- Payment information: your payment card is collected and stored by Stripe, our payment processor. We store only a Stripe customer reference and payment method reference — never your full card number.
- Membership information: Apple In-App Purchase or RevenueCat and Stripe product and transaction identifiers where applicable, the source of any server-granted TestFlight entitlement, and membership start and end dates
- Device and technical information: device type, operating system, IP address, push notification tokens, and server logs
2. Why we collect it and our legal basis
- To run your commitments — verifying the fitness or health data you chose against your target, and charging missed-commitment fees you have agreed to. Legal basis: performance of a contract.
- To manage your account and subscription — sign-in, billing, receipts, notifications about your commitments, and customer support. Legal basis: performance of a contract.
- To remind you about unfinished setup — after you explicitly opt in, the iPhone app may schedule up to four onboarding reminders locally on your device over one week. These reminders contain no target, amount, provider, activity, payment or health data. Mavlo does not collect a device token for this local sequence. You can disable onboarding reminders in Mavlo Settings or disable notifications in iOS Settings. Legal basis: consent.
- To keep the service safe and improve it — debugging, fraud and abuse prevention, and understanding how features are used. Legal basis: legitimate interests.
- To send the launch notification you requested — using the email address submitted on mavlo.io. Legal basis: consent, which you can withdraw at any time.
- To meet legal obligations — keeping tax and financial transaction records. Legal basis: legal obligation.
3. Third parties we work with
We share data with the following processors and service providers, solely for the purposes described:
- Stripe — stores your payment card, processes missed-commitment fee charges, and bills web Mavlo Pro subscriptions. Stripe's own privacy policy applies to data it collects as a processor.
- RevenueCat — presents the web subscription checkout and synchronises Mavlo Pro entitlement state across the web and iPhone app.
- Apple — processes subscription purchases through In-App Purchase, and provides Sign in with Apple and push notifications.
- Google — if you choose Sign in with Google, Google verifies your identity and returns your name and email to create or access your account. Google's own privacy policy applies to data it processes.
- Strava — when you explicitly connect Strava, we receive the bounded activity fields described above through OAuth-authorised API requests and webhooks solely to connect the source, show current-period progress, verify the active commitment, and complete its review. Activity-level Strava data and exact derived totals are visible only to the authenticated member, not to Mavlo administrators or support agents. We do not share Strava data with third parties or send it to artificial-intelligence systems, and we do not use it for model training, inference, advertising, historical analytics, recommendations or provider comparisons. Temporary activity evidence is deleted after review resolution and in every case within seven days of its fetch. Disconnecting in Mavlo or at strava.com/settings/apps revokes access, ends dependent commitments safely, deletes tokens and temporary Strava evidence, and produces a written confirmation. Account deletion performs the same cleanup. Strava may monitor and collect API usage data under its developer terms. Strava does not sponsor or endorse Mavlo.
- Apple Health — when you explicitly grant access, the Mavlo app reads step counts from HealthKit on your device and uploads reduced daily totals and sample-presence signals for the relevant commitment window, together with the latest sample time. Mavlo totals those daily values for weekly progress. A shortfall can be treated as chargeable only after every required date has sample coverage and the app completes a final post-period sync. Apple Health access is read-only, can be changed in the Health app at any time, and is not used for advertising or shared with data brokers.
- Oura — when you connect your Oura account, Oura provides the sleep or recovery measurements needed for the commitment you choose, which may include sleep duration and timing, HRV, resting heart rate, average SpO₂, and an Oura VO₂ max estimate. Disconnecting Oura stops future access. Oura data is used only for account setup, verification, progress, review, and support for your commitments.
- Hetzner — our hosting provider. Mavlo's servers and database are located in Hetzner data centres in the European Union (Germany).
- Sentry — processes minimised application error diagnostics in its European Union region so we can identify crashes and service failures. It receives only bounded technical details such as the error class, stack location, runtime version, and request method/path; request bodies, query values, cookies, authorisation headers, and provider credentials are excluded.
- PostHog — receives cookieless, personless landing-page events in its European Union region so we can understand which parts of the website are used. We do not send submitted email addresses, create PostHog person profiles, or use this data for advertising.
We require service providers that process personal data for Mavlo to use it only on our instructions and to provide protections consistent with this policy and applicable data-protection law.
We do not sell your personal data to anyone. Connected fitness and health data is never sold, never used for advertising, and never shared for third-party marketing. Strava data is used only to connect the source you chose, show current-period progress, verify the active commitment, and resolve its review. Mavlo does not use Strava data to create historical baselines, long-term analytics, customer insights or product recommendations.
4. Where your data is stored
Your data is stored on servers in the European Union (Germany). Transfers between the UK and the EU are covered by the UK's adequacy regulations for the EEA. Stripe and Apple may process data in other countries under their own safeguards.
5. How long we keep your data
- Account data: kept while your account is active. After account deletion, personal data is deleted within 30 days.
- Financial records: records of subscription transactions and missed-commitment fee charges may be retained for up to 7 years to meet UK tax and accounting obligations.
- Strava activity evidence: activity-level data, activity identifiers and exact activity-derived totals are temporary. They are deleted after review resolution, on disconnection or account deletion, and in every case no later than seven days after the applicable fetch. A review or dispute cannot extend this limit. If evidence would expire before a safe decision, Mavlo records the result as not verified and creates no charge. Final Mavlo commitment, review, dispute and payment outcomes may remain without the underlying Strava totals.
- Apple Health aggregate and Oura records: retained for up to 24 months, including a window for resolving disputes about charges. Disconnecting a source stops future collection; account deletion removes personal data within the account-deletion period, subject to the financial-record exception above.
- Launch-list email: kept until the launch notification has been sent, you ask us to delete it, or the launch list is retired.
- Server access and security logs: retained for up to 14 days. Application logs are rotated more frequently and are never retained beyond that period.
- Pseudonymous website visit aggregates: retained for up to 13 months, without the raw IP address.
6. Your rights (UK GDPR)
Under UK data protection law you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (subject to the legal retention periods above)
- Receive a copy of your data in a portable format
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, email hello@mavlo.io. We will respond within one month. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).
7. Deleting your account
You can cancel an active commitment directly in the Mavlo app at any time, without giving a reason or contacting us. Cancellation stops future reviews and future missed-commitment fees for that commitment; records of weeks already reviewed, under review, or charged remain subject to the retention periods in Section 5.
You can delete your account at any time in the Mavlo app (Settings → Delete Account), or by emailing hello@mavlo.io from your registered email address. Deletion ends your access immediately, disconnects all integrations, and removes your personal data within 30 days, except records we must keep for legal reasons (see Section 5). Mavlo sends a written confirmation when the deletion is processed.
8. Age requirement
Mavlo is only for people aged 18 or over, because the service involves financial transactions. We do not knowingly collect data from anyone under 18. If we learn that an account belongs to someone under 18, we will close it and delete its data.
9. Cookies
The Mavlo website uses only essential cookies needed for sign-in, security, and session continuity. We do not use advertising or third-party cookies. To understand aggregate interest in Mavlo, we count unique website visits and the visitor's country using a one-way pseudonymous identifier derived from network and browser information. We do not store the raw IP address for this analytics purpose, build advertising profiles, or return an analytics identifier to the browser.
10. Security
All connections use HTTPS. Integration tokens and session secrets retained for supported verification are protected at rest and never logged. Payment card data is handled entirely by Stripe and never touches our servers. Access to personal data is restricted. No system is 100% secure, but if a breach affects your data we will notify you and the ICO as required by law.
11. Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated effective date, and we will notify you of material changes in the app or by email.
12. Contact
Data controller: Mavlo Ltd, a company registered in England and Wales, Newcastle upon Tyne, United Kingdom.
Questions or data requests: hello@mavlo.io