MimamoBack to home

Privacy Policy

Last updated 28 September 2026.

Mimamo helps personal trainers plan workouts and run sessions, and lets their clients see exactly what to do. This policy explains what personal data we collect, why, who helps us handle it, how long we keep it, and the rights you have under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").

Who we are. Mimamo is run by Mimamo Labs ("Mimamo", "we", "us"), in India. The company, Mimamo Labs Private Limited, is being incorporated; we'll add its registered details here when it is. For your data, we are the Data Fiduciary. You can reach us at privacy@mimamoapp.com.

What this policy covers

  • The website mimamoapp.com, including the waitlist.
  • The Mimamo app for trainers and clients (iOS, Android and the web version clients open from WhatsApp), once it launches.

What we collect

When you join the waitlist

  • Your name, and your WhatsApp number or email (at least one).
  • Your city, whether you're a trainer, gym owner or client, and, for trainers, roughly how many active clients you have.
  • The page you joined from and any campaign tags in the link that brought you (for example, utm_source=instagram). We keep these tags in one first-party cookie for 30 days so we can tell which posts reach people.
  • Your IP address, used only to stop automated abuse of the form. It is kept for at most 24 hours.

Waitlist details are kept in a private spreadsheet (Google Sheets) that only we can open.

We don't use advertising cookies or trackers on the website.

When you use the app as a trainer

  • Your phone number (you sign in with a one-time code sent on WhatsApp), name, city and, if you add it, your UPI ID.
  • The gyms you train at, your exercise library (including the demo videos you upload or YouTube links you add), your clients, their schedules, the workouts you build and the sessions you run.
  • Payment requests you send your clients, and whether they were paid.
  • If you turn on travel alerts: your location, used to work out when you should leave for your next session. It is deleted after 24 hours.

When you use the app as a client

  • Your phone number and name.
  • What your trainer records to plan your training: for example your age, gender, goals and health notes (such as an injury to work around).
  • Your sessions: which ones happened, which you confirmed with a fist bump and which you couldn't make.
  • Payment claims you make to your trainer ("I've paid"), including the payment reference and, if you add one, a screenshot of the payment.
  • A push notification token for your phone, if you allow notifications.

What we never collect

Mimamo does not handle money. We never ask for or store card numbers, bank passwords or UPI PINs. Clients pay their trainers directly.

Why we use it

We use your data only to:

  • run the waitlist and tell you when Mimamo opens in your city (one message, no spam);
  • let you sign in and keep your account secure;
  • show trainers' plans to their clients, and send plan, session and payment messages by push notification or WhatsApp;
  • keep session and payment records for trainers and their clients;
  • prevent abuse and keep the service working (for example, rate limits and error logs);
  • meet our legal obligations.

We rely on your consent, which you give when you join the waitlist or sign up, and on the other lawful uses the DPDP Act allows (such as complying with the law). We don't sell your data, and we don't use it for advertising.

Health information

Health notes are sensitive. Only the client and their trainer can see them. They never appear in WhatsApp messages, notifications, logs or analytics.

Who helps us run Mimamo

We share data only with the companies that run parts of the service for us (our Data Processors), and only what each one needs:

ServiceWhat it does for usWhere data is stored
CloudflareHosts this website and our domainCloudflare's network
Google (Sheets)Keeps the waitlistGoogle's infrastructure
Fly.ioRuns our servers (the API)Singapore
SupabaseDatabase, sign-in and file storageMumbai, India
Meta (WhatsApp Business)Sends sign-in codes and messages on WhatsAppMeta's infrastructure
ExpoDelivers push notifications to your phoneExpo's infrastructure
MuxStores and streams trainers' exercise videosMux's infrastructure
Google MapsTravel times and gym searchGoogle's infrastructure

They process data under contract and on our instructions. Some of them may process data outside India, which the DPDP Act allows except to countries the Government restricts. We may also disclose data when the law requires it.

A trainer can see the data about their own clients, and a client can see their own plan and their trainer's name. Trainers never see each other's clients, and clients never see each other.

How long we keep it

DataHow long
Waitlist detailsUntil we open in your city and for 12 months after, or until you ask us to delete them
IP address used for abuse limitsUp to 24 hours
Trainer location for travel alerts24 hours
Payment screenshots90 days after the payment request is paid or closed
Sign-in links sent on WhatsAppThey stop working after 30 days, and expired links are deleted
Your accountUntil you delete it (see below)

Deleting your account. You can delete your account in the app.

  • If you're a client: your account and sign-in are deleted. Your trainer keeps the record that your sessions happened, so their own history and billing stay correct.
  • If you're a trainer: your account is deleted after a 7-day grace period, during which you can change your mind. Your clients are told that you've closed your account.

Your rights

Under the DPDP Act you can:

  • access a summary of the personal data we hold about you and how we use it;
  • correct, complete or update it;
  • ask us to erase it;
  • withdraw your consent at any time, as easily as you gave it (this stops future use; it doesn't undo past use);
  • nominate someone to exercise these rights for you if you die or can't act yourself;
  • raise a grievance with us, and, if you're not satisfied with our answer, complain to the Data Protection Board of India.

To use any of these rights, write to privacy@mimamoapp.com from the phone number or email you used with Mimamo. We'll respond within the time the law requires.

Children

Mimamo is only for people aged 18 and over. Trainers can't add clients under 18, and we don't knowingly collect data about anyone under 18. If you believe a child's data has reached us, write to privacy@mimamoapp.com and we'll delete it.

Security

Data is encrypted in transit. Access to the database is limited to our own servers, and only what each person is allowed to see is shown to them. Sign-in sessions are stored in your phone's secure storage. No system is perfectly secure. If a breach affects your data, we'll tell you and the Data Protection Board as the law requires.

Changes to this policy

If we change this policy in a way that matters, we'll update the date at the top and, where appropriate, tell you on WhatsApp, by email or in the app before the change applies.

Contact and grievances

Grievance Officer: the founder, Mimamo Labs Email: privacy@mimamoapp.com General questions: hello@mimamoapp.com