Privacy

Privacy Policy

This page explains the main categories of information MAVIR uses to operate the free MVP fitness experience and how users can contact us about their data.

Last updated: July 9, 2026

Information You Provide

MAVIR may collect account information such as your name, email address, authentication method, email verification status, and login activity. If you create an email/password account, your password is stored only as a secure hash.

During onboarding and profile setup, MAVIR may collect fitness and profile information such as goal, experience level, workout location, available equipment, workout days, workout duration, injuries or limitations, height, weight, and related profile settings.

Workout, Nutrition, and Progress Data

MAVIR stores workout plans, workout logs, completed sets, exercise feedback, personal records derived from workout logs, nutrition entries, favorite foods, weight logs, lesson progress, onboarding progress, and settings needed to show your dashboard and progress views.

Nutrition logging in the MVP is manual. Barcode scanning, meal photo scanning, nutrition AI, AI Coach, weekly AI reports, and automatic progression remain disabled unless a future approved phase changes that.

Uploaded Exercise Images

Members may upload images for their own member-created exercises. Admins may upload images for global exercises. These image files are stored in a private AWS S3 bucket and are shown through short-lived signed URLs. MAVIR does not intentionally make the upload bucket public.

Authentication and Email Providers

MAVIR uses NextAuth for sessions and supports email/password login and Google Sign-In. If you use Google Sign-In, Google provides account details needed to authenticate you, such as verified email status and provider account identifiers.

MAVIR uses Resend to send transactional email such as email verification and password reset messages. These emails may include your email address, sender details, and one-time verification or reset links.

OpenAI Workout Generation

MAVIR may use OpenAI only to assist onboarding workout generation when the owner enables the approved feature flag and provider configuration. The deterministic workout generator runs first, and MAVIR falls back to that deterministic plan if AI is unavailable or invalid.

AI workout generation is designed to use workout-relevant onboarding/profile inputs and active Coaching Brain rules. MAVIR should not send member name, email, user id, admin id, API keys, raw audit logs, unpublished drafts, archived Coaching Brains, or training chat messages to OpenAI.

Storage and Service Providers

MAVIR uses PostgreSQL for app data, AWS S3 for private exercise image storage, Resend for transactional email, Google for optional Google Sign-In, and OpenAI for the approved onboarding-only AI workout generation path. Provider access is configured through owner-controlled secrets and production infrastructure.

Your Choices and Rights

You can update profile and settings information in the app where available. You can request help, account deletion, or questions about your data by emailing support@mavir.co.

Some records may be retained when required for security, fraud prevention, legal, or operational reasons. We will explain any retention that applies when responding to a deletion request.