Privacy Policy
Last updated 28 September 2026.
Mimamo helps personal trainers plan workouts and run sessions, and lets their clients see exactly what to do. This policy explains what personal data we collect, why, who helps us handle it, how long we keep it, and the rights you have under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
Who we are. Mimamo is run by Mimamo Labs ("Mimamo", "we", "us"), in India. The company, Mimamo Labs Private Limited, is being incorporated; we'll add its registered details here when it is. For your data, we are the Data Fiduciary. You can reach us at privacy@mimamoapp.com.
What this policy covers
- The website mimamoapp.com, including the waitlist.
- The Mimamo app for trainers and clients (iOS, Android and the web version clients open from WhatsApp), once it launches.
What we collect
When you join the waitlist
- Your name, and your WhatsApp number or email (at least one).
- Your city, whether you're a trainer, gym owner or client, and, for trainers, roughly how many active clients you have.
- The page you joined from and any campaign tags in the link that brought you (for example,
utm_source=instagram). We keep these tags in one first-party cookie for 30 days so we can tell which posts reach people. - Your IP address, used only to stop automated abuse of the form. It is kept for at most 24 hours.
Waitlist details are kept in a private spreadsheet (Google Sheets) that only we can open.
We don't use advertising cookies or trackers on the website.
When you use the app as a trainer
- Your phone number (you sign in with a one-time code sent on WhatsApp), name, city and, if you add it, your UPI ID.
- The gyms you train at, your exercise library (including the demo videos you upload or YouTube links you add), your clients, their schedules, the workouts you build and the sessions you run.
- Payment requests you send your clients, and whether they were paid.
- If you turn on travel alerts: your location, used to work out when you should leave for your next session. It is deleted after 24 hours.
When you use the app as a client
- Your phone number and name.
- What your trainer records to plan your training: for example your age, gender, goals and health notes (such as an injury to work around).
- Your sessions: which ones happened, which you confirmed with a fist bump and which you couldn't make.
- Payment claims you make to your trainer ("I've paid"), including the payment reference and, if you add one, a screenshot of the payment.
- A push notification token for your phone, if you allow notifications.
What we never collect
Mimamo does not handle money. We never ask for or store card numbers, bank passwords or UPI PINs. Clients pay their trainers directly.
Why we use it
We use your data only to:
- run the waitlist and tell you when Mimamo opens in your city (one message, no spam);
- let you sign in and keep your account secure;
- show trainers' plans to their clients, and send plan, session and payment messages by push notification or WhatsApp;
- keep session and payment records for trainers and their clients;
- prevent abuse and keep the service working (for example, rate limits and error logs);
- meet our legal obligations.
We rely on your consent, which you give when you join the waitlist or sign up, and on the other lawful uses the DPDP Act allows (such as complying with the law). We don't sell your data, and we don't use it for advertising.
Health information
Health notes are sensitive. Only the client and their trainer can see them. They never appear in WhatsApp messages, notifications, logs or analytics.
Who helps us run Mimamo
We share data only with the companies that run parts of the service for us (our Data Processors), and only what each one needs:
| Service | What it does for us | Where data is stored |
|---|---|---|
| Cloudflare | Hosts this website and our domain | Cloudflare's network |
| Google (Sheets) | Keeps the waitlist | Google's infrastructure |
| Fly.io | Runs our servers (the API) | Singapore |
| Supabase | Database, sign-in and file storage | Mumbai, India |
| Meta (WhatsApp Business) | Sends sign-in codes and messages on WhatsApp | Meta's infrastructure |
| Expo | Delivers push notifications to your phone | Expo's infrastructure |
| Mux | Stores and streams trainers' exercise videos | Mux's infrastructure |
| Google Maps | Travel times and gym search | Google's infrastructure |
They process data under contract and on our instructions. Some of them may process data outside India, which the DPDP Act allows except to countries the Government restricts. We may also disclose data when the law requires it.
A trainer can see the data about their own clients, and a client can see their own plan and their trainer's name. Trainers never see each other's clients, and clients never see each other.
How long we keep it
| Data | How long |
|---|---|
| Waitlist details | Until we open in your city and for 12 months after, or until you ask us to delete them |
| IP address used for abuse limits | Up to 24 hours |
| Trainer location for travel alerts | 24 hours |
| Payment screenshots | 90 days after the payment request is paid or closed |
| Sign-in links sent on WhatsApp | They stop working after 30 days, and expired links are deleted |
| Your account | Until you delete it (see below) |
Deleting your account. You can delete your account in the app.
- If you're a client: your account and sign-in are deleted. Your trainer keeps the record that your sessions happened, so their own history and billing stay correct.
- If you're a trainer: your account is deleted after a 7-day grace period, during which you can change your mind. Your clients are told that you've closed your account.
Your rights
Under the DPDP Act you can:
- access a summary of the personal data we hold about you and how we use it;
- correct, complete or update it;
- ask us to erase it;
- withdraw your consent at any time, as easily as you gave it (this stops future use; it doesn't undo past use);
- nominate someone to exercise these rights for you if you die or can't act yourself;
- raise a grievance with us, and, if you're not satisfied with our answer, complain to the Data Protection Board of India.
To use any of these rights, write to privacy@mimamoapp.com from the phone number or email you used with Mimamo. We'll respond within the time the law requires.
Children
Mimamo is only for people aged 18 and over. Trainers can't add clients under 18, and we don't knowingly collect data about anyone under 18. If you believe a child's data has reached us, write to privacy@mimamoapp.com and we'll delete it.
Security
Data is encrypted in transit. Access to the database is limited to our own servers, and only what each person is allowed to see is shown to them. Sign-in sessions are stored in your phone's secure storage. No system is perfectly secure. If a breach affects your data, we'll tell you and the Data Protection Board as the law requires.
Changes to this policy
If we change this policy in a way that matters, we'll update the date at the top and, where appropriate, tell you on WhatsApp, by email or in the app before the change applies.
Contact and grievances
Grievance Officer: the founder, Mimamo Labs Email: privacy@mimamoapp.com General questions: hello@mimamoapp.com