Privacy Policy

Last updated: September 23, 2026

Mobela is a fitness app for tracking workouts, syncing activities from devices and services you connect, and sharing progress with a community. This policy explains what information we collect, how we use and store it, who we share it with, and the controls you have. Jump to a section: Garmin Connect Data, Connected Services, Health & Fitness Data, Location Data, Information Visible to Others, AI Processing, Analytics & Error Tracking, and Third-Party Processors.

Information We Collect

When you use Mobela, we collect:

  • Account Information: Your name, username, email address, and password (passwords are hashed by our authentication provider and never stored in plain text).
  • Profile Content: Profile photo, hero image, bio, quote, interests, "vibes," personality prompts, social links, and your stated home city.
  • Fitness & Workout Data: Workouts, exercises, sets/reps/weights, durations, perceived exertion, notes, photos, and the activities you log or sync.
  • Connected Service Data: Activity and wellness data from Garmin Connect, Strava, Apple Health, and Google Health Connect when you connect those services.
  • Location Data: GPS coordinates and a derived city for activities, when you enable location features.
  • Usage & Device Information: Device type, operating system, app version, screens viewed, and feature interactions, collected through analytics and error-tracking tools.
  • Push Notification Tokens: A device push token used to deliver notifications.
  • Communication: Information you provide when contacting us.

How We Use Your Information

  • Create and manage your account
  • Provide workout tracking and personalized insights
  • Sync data with connected services (Garmin Connect, Strava, Apple Health, Google Health Connect)
  • Display your activities in your history and, when you choose, the community feed
  • Deliver push notifications you have enabled
  • Power optional AI features when you connect an AI assistant (see AI Processing)
  • Understand usage and diagnose errors to improve the app (see Analytics & Error Tracking)
  • Provide support and respond to your inquiries

Garmin Connect Data

If you choose to connect your Garmin Connect account, Mobela accesses Garmin data through the Garmin Connect Developer Program. This section describes exactly how that data is collected, used, processed, stored, and shared.

  • How it is collected: You authorize the connection through Garmin's official OAuth 2.0 login flow. You are never asked for your Garmin password inside Mobela. After you authorize, Garmin sends your data to Mobela using its Health and Activity APIs via secure server-to-server push notifications.
  • What we collect: Your Garmin user identifier and the activities and wellness data you have authorized, including activity type, duration, distance, pace, heart rate, GPS route, and the Garmin device the activity was recorded on.
  • How it is used: To display your activities in your Mobela history, generate fitness insights, and — only when you enable it — post selected activities to the community feed.
  • How it is processed and stored: Garmin data is received and processed by our serverless backend and stored in our database hosted on Supabase. Your Garmin access and refresh tokens are encrypted at rest. Data is transmitted over encrypted (HTTPS/TLS) connections.
  • Third-party processing, including AI: Garmin data may be processed by our infrastructure providers Supabase (database and authentication), Cloudflare (hosting and edge functions), and Mapbox (to convert an activity's GPS start point into a city name). If you use the in-app AI trainer, it may read your Garmin-derived activity data and send it to Google (Gemini). If you separately connect Mobela to an AI assistant, that data may be processed by the provider of the assistant you choose (for example Anthropic, OpenAI or xAI). Both are described in AI Processing. We do not sell Garmin data, and we do not share it with advertisers or data brokers.
  • Sharing with other users: Garmin activities are private to you by default. They become visible to other users only if you post them to the community feed or enable auto-posting, subject to the visibility you choose. See Information Visible to Others.
  • Your control: You can disconnect Garmin at any time from the Mobela app's integration settings. Disconnecting revokes Mobela's access on Garmin's side (user deregistration) and stops further data syncing. You can also revoke access from your Garmin Connect account settings.

Garmin and Garmin Connect are trademarks of Garmin Ltd. or its subsidiaries. Mobela is an independent application and is not endorsed by or affiliated with Garmin.

Connected Services

Each connection below is optional and under your control. You can disconnect any of them at any time through the Mobela app or your device settings.

  • Garmin Connect: See the dedicated Garmin Connect Data section above.
  • Strava: When connected via OAuth, we access your activity history (type, distance, duration, pace, heart rate, calories, elevation, and GPS start point). Activities of the types you opt in to are stored on our servers and may be auto-posted to your feed if you enable that. Your Strava access and refresh tokens are encrypted at rest.
  • Apple Health / Google Health Connect: With your permission, we read health metrics such as steps, distance, resting heart rate, sleep, and workouts. See Health & Fitness Data for how this data is handled.

Health & Fitness Data

Mobela can read health and fitness data from Apple Health (iOS) and Google Health Connect (Android), including daily steps, walking/running distance, resting heart rate, sleep, and workout sessions. How that data is handled depends on what it is used for:

  • Detailed daily metrics stay on your device. Individual day-by-day step counts, heart-rate readings, sleep records, and mileage that we read from Apple Health or Google Health Connect are cached locally on your device to power your dashboard and are not stored on our servers in that detailed form.
  • Weekly summaries are stored and may be shown. To display a summary on your profile, we store a rolling weekly summary on our servers: your total weekly steps and your average weekly resting heart rate and sleep. These summary values can appear on your profile to other users, and each one can be individually hidden by you in your settings.
  • Per-activity metrics are stored with workouts. When a workout is matched with device data, we store activity-level metrics on that workout record — for example steps, average and maximum heart rate, and calories during the activity — so they can appear in your history and feed.

You can revoke Mobela's access to Apple Health or Google Health Connect at any time in your device settings, and you can hide weekly summary metrics from your profile.

Location Data

When you record an outdoor walk or enable location tagging, Mobela collects location data with your permission:

  • GPS routes and coordinates, including background location during an active walk so your route stays accurate when the screen is off.
  • A derived city, obtained by converting an activity's start coordinate into a city name using Mapbox. This city, and the activity's start coordinate, are stored with the activity.
  • Your stated home city from your profile, which you provide and which is separate from activity locations.

Location tagging is a setting you can turn off, and you can deny or revoke location permission in your device settings at any time. An activity's location may be visible to others if you post the activity — see Information Visible to Others.

Information Visible to Others

Mobela includes social features. The following information can be visible to other users, governed by the visibility settings you choose:

  • Your profile — name, username, photo, hero image, bio, quote, interests, vibes, social links, stated home city, and aggregate stats (such as activity count, streak, and friend count) are viewable by other users.
  • Weekly health summary — weekly steps, average resting heart rate, and average sleep can appear on your profile. Each can be individually hidden by you.
  • Posted activities — workouts and synced activities you post, including exercise details, duration, pace, per-activity heart rate and calories, the device/service used, the activity's city, route maps, photos, and captions.
  • Social interactions — comments and reactions you make, your participation in group challenges, and habit milestones, along with your name and avatar.

You control visibility per post (public, friends-only, or just you), choose what your friends and followers can see, and can remove content you have shared.

AI Processing

In-app AI trainer (Google Gemini)

Mobela's AI trainer runs on Gemini, a model provided by Google through its API. When you chat with the trainer, we send Google your messages and the Mobela data the trainer needs to answer. That can include your profile, workout history and exercise records, runs and other activities (including data synced from Garmin Connect, Strava and Apple Health), your calendar, your saved routes, and notes the trainer has saved about you. It is sent only when you use the trainer. Google processes it to generate the trainer's replies, under Google's terms for the Gemini API. Your conversation is stored in your Mobela account so you can come back to it.

Connecting your own AI assistant (MCP)

Mobela offers an optional integration that lets you connect your own AI assistant account to your Mobela account. It uses the open Model Context Protocol (MCP), so it works with any assistant that supports it — for example Claude (Anthropic), ChatGPT (OpenAI) or Grok (xAI). Each connection is off by default and only becomes active if you explicitly authorize it. Mobela acts as a data source: when connected, your assistant reads data from your Mobela account on your request. Mobela does not send your data to any AI provider on its own.

  • What it can access: When connected, the AI assistant can read your workout history, runs and other activities (including data synced from Garmin Connect and Strava), your exercise library, and your profile, and can create workout templates on your behalf.
  • How it is processed: The data your assistant reads is processed by that assistant's provider to generate responses, under the terms of your own account with that provider — not under a Mobela business agreement. Depending on the provider, your plan and your settings, the provider may retain that data and use it to improve its models. Mobela does not control any AI provider's data practices. Please review your provider's privacy policy and account settings to understand and control how your data is used.
  • Your control: You can revoke the AI assistant's access at any time, which immediately stops further data from being shared with it.

Analytics & Error Tracking

We use PostHog for product analytics and Sentry for error and crash reporting to understand how the app is used and to fix problems.

  • What is collected: Your user ID and email address (to associate activity and errors with your account), events such as screens viewed and features used, app lifecycle events, and device information such as device model, operating system, and app version. Error reports also include exception messages, stack traces, and diagnostic breadcrumbs.
  • What is not collected by these tools: We do not send your health metrics or precise location to these analytics tools, and we do not use session replay, screen recording, or advertising identifiers.

Push Notifications

With your permission, we use Expo's notification service to deliver push notifications for rest timers and social activity (comments, reactions, friend requests, challenges, and shared workouts). We store a device push token associated with your account and platform. The token for a device is removed when you log out on that device or revoke notification permission.

Third-Party Processors & Information Sharing

We do not sell, trade, or rent your personal information. We share information only with the service providers that operate Mobela, and only as needed to run the service:

  • Supabase — database, authentication, and file storage
  • Cloudflare — website hosting and serverless edge functions
  • Mapbox — converting activity GPS coordinates into city names
  • Expo — push notification delivery and app updates
  • PostHog and Sentry — analytics and error/crash reporting
  • Google (Gemini) — the in-app AI trainer, only when you use it (see AI Processing)
  • The AI assistant provider you choose (for example Anthropic, OpenAI or xAI) — only when you connect an optional AI assistant (see AI Processing)

These providers may store data in the United States or other countries. We may also disclose information if required by law. We do not share data from connected services such as Garmin with advertisers or data brokers.

Data Security

We implement appropriate security measures to protect your information against unauthorized access, alteration, disclosure, or destruction. Data is transmitted over encrypted (HTTPS/TLS) connections, third-party access tokens (such as Garmin and Strava) are encrypted at rest, and database access is governed by row-level security so users can only access data they are authorized to see.

Data Retention & Deletion

You can delete your account and all associated data at any time:

  • Through the Mobela app in your account settings
  • By emailing us at [email protected] to request deletion

We will process your deletion request within 30 days. Once deleted, your data cannot be recovered. Disconnecting a service such as Garmin stops further syncing and revokes Mobela's access on that service's side.

Your Rights & Choices

  • Access, correct, or update your personal information
  • Delete your account and all associated data
  • Disconnect connected services (Garmin Connect, Strava, Apple Health, Google Health Connect)
  • Revoke the optional AI assistant's access to your data
  • Control who can see your activities and hide weekly health summary metrics from your profile
  • Turn off location tagging and revoke device permissions (location, health, notifications, photos)
  • Opt out of non-essential communications from us

International Users

Mobela is available worldwide. Your information may be transferred to and stored on servers located in different countries, including outside your country of residence. By using Mobela, you consent to such transfers.

Contact Us

If you have questions about this Privacy Policy, please contact us at [email protected]