Privacy Policy
How Mobr handles your information
Effective: 21 August 2026 · Last updated: 21 August 2026
1. About this policy
This Privacy Policy explains how Mobr ("Mobr", "we", "us" or "our") collects, holds, uses and discloses personal information through the Mobr app and trymobr.com. Mobr operates in Australia. Because some information you provide may concern your body, discomfort, training and recovery, we treat it with particular care and seek your consent before using it to provide Mobr.
2. Information we collect
Depending on how you use Mobr, we may collect:
- Account information: your name, email address, profile photo, user ID, authentication provider, settings, login and account timestamps. Firebase Authentication handles credentials; Mobr does not receive or store your raw Apple, Google or email-account password.
- Connected fitness-service information: after you authorise a supported service, identifiers associated with that service, authorised permissions, connection status, access and refresh tokens, and available activity information such as activity name, sport type, date, timezone, duration, distance, pace or speed, elevation, heart rate, cadence, power, effort, calories, training frequency, terrain indicators, and whether an activity is manual, indoor or a commute. The exact fields depend on the service and permissions you approve. We do not store route streams or activity start and end coordinates from connected fitness services.
- Apple Health workout information: if you connect Apple Health on iPhone, Mobr requests read-only access to workout records from the previous 30 days. For each available workout, this may include its HealthKit workout identifier, activity type and name, start and end time, duration, distance, active energy, source app name and bundle identifier, and whether the workout was indoor or manually entered. Mobr does not request heart-rate samples, route data or permission to write to or change your Apple Health data.
- Recovery and health-related information: sports, training frequency, common and same-day areas of tightness, stiffness, soreness or discomfort, equipment, routine duration and reminder preferences, generated and completed routines, and session feedback. Areas selected during a pre-session check-in are used to prioritise the routine generated for that session.
- Technical and usage information: app-session timestamps and duration, app platform and version, approximate city, region and country inferred by our hosting provider without Mobr storing your IP address, push-notification tokens, reminder time, notification permission and device timezone, device or browser information supplied in support or diagnostic records, IP address and request logs processed by our hosting and infrastructure providers, and security or error information.
- Communications and transaction information: support messages, feedback, marketing preferences and, if you subscribe, product and entitlement identifiers, subscription status, trial and renewal information, purchase or restore events, transaction identifiers, Apple receipt information or Google purchase tokens, and limited device and app information used to validate access. Apple or Google processes mobile payment details, RevenueCat manages mobile subscription status, and Stripe processes supported web payments. Mobr does not receive your complete payment-card number.
3. How we collect and use information
We collect information directly from you, automatically when you use Mobr, from fitness and health services after you authorise access, and from providers that help us operate the service. We use it to create and secure accounts; connect and sync authorised services; analyse authorised recent training; prioritise the areas you identify as stiff or sore; generate and personalise mobility and recovery routines; remember preferences; deliver reminders and activity notifications; share completed routines when you request or enable that feature; process subscriptions; provide support; prevent abuse; troubleshoot and improve Mobr; send communications you request; and comply with legal, tax and accounting obligations.
Where information is sensitive or health-related, we collect and use it with your consent and only for the purposes described above or otherwise permitted by law. You may withdraw consent by changing settings, disconnecting a service, deleting your account or contacting us. Withdrawal does not affect earlier lawful handling, and some Mobr features may no longer work.
4. Important health and fitness notice
Mobr provides general recovery and mobility suggestions based on your training data. It does not provide medical advice, diagnose injuries, or replace care from a qualified health professional. Stop any exercise that causes sharp, worsening, or unusual pain.
5. Disclosures and service providers
We do not sell personal information or data obtained from connected fitness services. We may disclose only the information reasonably needed to providers operating Mobr, including the connected services listed below; Google Firebase and Google Cloud for authentication, database, storage and messaging; Vercel for hosting and application delivery; Stripe for supported web subscription and payment processing; RevenueCat for mobile purchase validation and subscription status; Google Play and Apple for mobile purchases; Expo for push-notification delivery; and Google for business email. Each provider handles information under its own terms and privacy practices. We may also disclose information to professional advisers, regulators, courts or law enforcement where authorised or required by law, or in connection with a business restructure where appropriate privacy protections apply.
6. Overseas storage and processing
Mobr is operated from Australia, but our providers use global infrastructure. Information may be stored in or accessed from countries outside Australia, including the United States and other countries where our connected services and infrastructure, payment or platform providers and their subprocessors operate. The exact locations may change with provider infrastructure. Where required, we take reasonable steps to use reputable providers, appropriate contractual and technical protections, and settings that limit access and disclosure. Overseas recipients may be subject to different privacy laws, and in some circumstances we may remain accountable under Australian privacy law for their handling.
7. Connected fitness and health services
The integrations currently offered by Mobr are:
- Strava: activity import and, if you choose, manual or automatic sharing of completed Mobr recovery routines.
- Google Health API: import of authorised activity and fitness data, including supported Fitbit and Pixel data available through your Google account.
- Apple Health: read-only import of the specific recent workout fields described in section 2, available only after you grant HealthKit permission on your iPhone.
We will update this list when we add or remove an integration. Connecting a service is optional. Mobr accesses its data only after you authorise the requested permissions and uses that data only to provide, secure, support and improve your personal Mobr experience. We do not sell connected-service data, use it for advertising or marketing, publicly display it, disclose it to other Mobr users, or use it to train or evaluate artificial-intelligence or machine-learning models. Mobr's recovery engine applies rules directly for the authenticated user.
Mobr's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
8. Provider-specific controls and restrictions
Apple Health and HealthKit
- Apple Health access is optional and begins only when you choose Connect Apple Health and approve the HealthKit permission requested by iOS.
- Mobr reads workout records only. It does not write to, edit or delete information in the Health app. Disconnecting Mobr therefore does not delete the original data held by Apple Health on your device.
- When you connect or refresh, the approved workout fields are sent securely through Mobr's Vercel-hosted service and stored with your Mobr account in Google Cloud and Firebase so the Service can analyse recent training and generate your recovery experience. Those providers process the information only as infrastructure providers acting for Mobr.
- Mobr does not use HealthKit data for advertising, marketing, profiling for marketing, sale, data-broker activity or other use-based data mining. We do not share HealthKit data with RevenueCat, Stripe, advertising networks or other Mobr users, and do not use it to train or evaluate artificial-intelligence or machine-learning models.
- Where the same workout is available from Apple Health and Strava, Mobr compares basic workout details to avoid duplicates and gives priority to the Strava copy.
- You can change Health permissions in iOS Settings or the Health app. Disconnecting in Mobr stops future syncing and deletes Apple Health workouts imported into systems under our control, together with recovery routines derived from them.
Strava
- Mobr accesses Strava data only after you authorise Mobr through Strava OAuth.
- We request scopes needed for Mobr's features and use Strava data only to provide, secure, support and improve your personal Mobr recovery experience as permitted by Strava's developer terms.
- If you choose manual or automatic sharing, Mobr sends the completed routine's title, start time, duration and exercise summary to your Strava account. Automatic sharing is off by default and can be disabled at any time in Strava connection settings.
- We do not use Strava data for aggregate or de-identified analytics.
- Mobr respects Strava privacy changes and webhook notices. When an activity is deleted or becomes unavailable to Mobr, we remove the corresponding cached data from systems under our control.
- You can disconnect inside Mobr or revoke access in Strava's connected apps settings. Disconnecting removes stored tokens and cached Strava-derived records under our control.
Strava may collect API usage metadata under its own legal terms and privacy practices.
9. Data retention
- Account and preference information is retained while your account is active.
- Imported activities and recovery sessions derived from connected services are retained only for the period needed to provide recent recovery features. Retention may differ by integration; Strava-derived records are temporary and marked with a five-day expiry.
- Apple Health sync requests a rolling 30-day workout window. Imported copies remain until a later sync removes workouts no longer in that window, you disconnect Apple Health, you delete your account, or you request deletion. Disconnecting removes Apple Health-derived recovery routines as well as imported workouts.
- Recovery history and feedback that is not subject to a shorter provider-specific retention period is retained until you delete your account or request deletion.
- Security, hosting and diagnostic logs are retained for the period reasonably needed for security, troubleshooting and provider operations.
- Subscription, transaction and accounting records may be kept for the period required by tax, accounting, fraud-prevention and other laws.
Deleted information may remain temporarily in encrypted backups, provider logs or disaster-recovery systems until overwritten in the ordinary backup cycle, and may be retained where legally required. We do not use residual copies for ordinary product purposes.
10. Access, correction, account and data deletion
You may access or update key profile settings in Mobr. You can disconnect integrations from Account → Connections and permanently delete your Mobr account from Account → Delete account. Account deletion removes your authentication account and user-scoped profile, activity, recovery, reminder, connection and stored integration-token records from active systems under our control, subject to the retention exceptions above.
Revoking Apple Health permission is managed separately by Apple in iOS Settings or the Health app. Disconnecting or deleting your Mobr account does not change or delete the original health information held in Apple Health on your device.
You may also ask us for access to or correction of personal information, withdrawal of consent, or deletion of particular information by emailing trymobr@gmail.com. We may need to verify your identity. We will respond within a reasonable period and explain any lawful reason we cannot fulfil a request.
11. Security
We use safeguards appropriate to the information we hold, including encrypted network connections, Firebase authentication, user-scoped database access rules, server-only storage of integration tokens and service secrets, restricted administrative access, secure cloud infrastructure, and dependency and security maintenance. No internet service is completely secure, so we cannot guarantee absolute security. You are responsible for protecting your login credentials and telling us promptly about suspected unauthorised access.
12. Data breaches
We investigate suspected data breaches and take reasonable steps to contain, assess and remedy them. Where the Privacy Act 1988 (Cth) or another law requires it, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.
If an incident affects data from a connected service, Mobr will comply with applicable provider notification and remediation requirements. For a Strava data incident, this includes notifying Strava without undue delay and within 24 hours of discovery.
13. Cookies, local storage and analytics
Mobr uses browser storage and similar essential technologies to keep you signed in, secure the service, remember preferences and support app functionality. Firebase, Vercel and related infrastructure may use essential identifiers and request logs for security and delivery. Mobr does not currently use third-party advertising cookies or behavioural advertising. We measure limited in-app usage such as session timing to understand and operate the product, but do not use HealthKit data or the contents of your connected workouts for advertising, marketing or general-purpose analytics. You can clear or block browser storage in your browser, but doing so may sign you out or prevent features from working. If we introduce non-essential analytics or advertising technologies, we will update this policy and seek consent where required.
14. Marketing communications
If you opt in, we may email product news, new features and price-discount offers. You can withdraw consent at any time using the unsubscribe option in a marketing message or by contacting us. We may still send non-marketing service messages necessary for your account, such as security, billing or material service notices. We do not require marketing consent to create an account and never use HealthKit or connected health and fitness data to select or target marketing.
15. Age requirement
Mobr is only for people aged 18 or older. We do not knowingly permit anyone under 18 to create an account. If you believe a person under 18 has provided information to Mobr, contact us so we can investigate and delete it where appropriate.
16. Privacy complaints
Email trymobr@gmail.com with enough detail for us to investigate. We will acknowledge and assess the complaint, may ask for further information, and aim to respond within 30 days. If you are not satisfied, you may complain to the OAIC.
17. Changes to this policy
We may update this policy to reflect changes to Mobr, providers or legal requirements. We will publish the updated policy and change the “Last updated” date. If a change materially affects how we handle information, we will provide reasonable notice and seek fresh consent where required by law.
18. Contact
Privacy enquiries: trymobr@gmail.com
Website: trymobr.com
Country of operation: Australia