Skip to main content

Legal

Privacy policy

MFit works with some of the most personal data there is: your health, your conversations and where you train. This policy explains what we collect, why, where it is kept, who can see it, and how you stay in control.

Last updated:
24 September 2026
Version:
1.0 (draft)
Effective:
On publication after legal review

Draft under review by Mongolian counsel. Not yet in force.

Terms of service →

In short

  • Your health, message and location data are stored in Mongolia. Messages never leave the country.
  • Each use of your data has its own consent, which you can withdraw in one tap under Settings → Privacy.
  • The AI coach runs in Mongolia by default. It only uses an overseas model if you turn on “Premium AI abroad”, and then only with de-identified data.
  • We never sell your data, never use health data for advertising, and never give partners your data for their own marketing.
  • You can export, correct or delete your data at any time, and ask a person to review any automated decision.
  • If a breach affects you, we will tell you promptly and explain what to do.

This summary is here to help you find your way. It does not replace the full text below, which is what applies.

On this page

1.Who we are and what this policy covers

  1. 1.1

    MFit (“MFit”, “we”, “us”) is the controller of the personal data described in this policy. Our legal details are listed in the contact section at the end.

  2. 1.2

    This policy applies to the MFit mobile app, the MFit web portal and any MFit service that links to it (together, the “Service”). It is written to meet the Law of Mongolia on Personal Data Protection (2021) and its implementing regulations.

  3. 1.3

    Gyms, studios, kitchens, shops and coaches that you deal with through MFit are independent businesses. When they use the details we pass to them to fulfil your order or booking, they are responsible for doing so lawfully.

  4. 1.4

    The Service is for adults aged 18 and over. We do not knowingly collect data from anyone younger.

2.The data we collect

  1. 2.1

    Data you give us:

    • account details: name, phone number, email, language, and sign-in details when you use Google or Apple;
    • health and fitness details: screening answers (such as PAR-Q+), goals, body measurements, injuries and symptoms you report, food and training logs, and progress photos;
    • content: posts, comments, reviews, photos and videos, and messages to other users, coaches and partners;
    • orders and bookings: items, delivery address, your e-barimt consumer number or company TIN, and support requests.
  2. 2.2

    Data created when you use the Service:

    • training plans and the reasons behind each change, readiness scores and progress statistics;
    • your conversations with the AI coach and the outcome of safety checks;
    • venue check-ins, class bookings, run routes you choose to record, and venue searches;
    • technical data: device type, app version, crash reports and pseudonymous usage events.
  3. 2.3

    Data from others, only with your permission or when needed for a transaction:

    • Apple Health or Health Connect (steps, workouts, heart rate, sleep) when you connect them;
    • Apple or Google, to confirm your subscription status (we never receive your card details);
    • QPay and your bank, to confirm that a payment went through;
    • coaches you have shared access with, who may add notes or programmes to your plan.
  4. 2.4

    We do not collect your precise location in the background. The venue finder uses your location only while it is open.

3.Where your data is kept

  1. 3.1

    Health, correspondence and location data are stored on servers in Mongolia, together with their backups. Administrative access to production systems is only possible from within Mongolia through a secured gateway.

  2. 3.2

    The table below shows each class of data, where it is processed and whether any of it ever leaves Mongolia.

Data classes, where they are processed and whether they leave Mongolia
ClassExamplesWhere processedLeaves Mongolia?
Sensitive healthScreenings, safety state, wearable data, body measurements, food logs, progress photos, AI chatMongolia onlyOnly de-identified AI requests, if you opt in to “Premium AI abroad”
CorrespondenceDirect messages, group chats, coach chatMongolia, encrypted at restNever
LocationRun routes, venue check-ins, venue searchesMongolia onlyNo (only your district, for weather and air-quality lookups)
PersonalName, phone, email, payment referencesMongoliaEmail via Amazon SES, if you opt in; SMS via a local provider
Public contentPublic posts, comments, reviewsMongoliaNever sent raw to AI abroad
TelemetryEvent names, timings, error traces, website page views and clicksGrafana Cloud, Sentry, PostHog, Google Analytics (website and app)Yes, pseudonymous and with sensitive fields removed

4.Why we use your data

  1. 4.1

    We use personal data only for the purposes below, and only on the legal basis shown:

    • to provide the Service you signed up for (account, plans, logs, messaging, orders): your consent to the core service and our agreement with you;
    • to process health data and personalise coaching safely: your separate, explicit consent to health data processing;
    • to share data with a coach you choose: your consent, limited to the scope you select;
    • to issue receipts, keep accounting records and meet tax, consumer-protection and law-enforcement obligations: our legal obligations;
    • to keep the Service secure, prevent fraud and moderate content: our legal obligations and the protection of users;
    • to send marketing or partner offers: your optional consent, which you can refuse without losing any feature.
  2. 4.2

    If we want to use data for a new purpose, we will ask for your consent again first.

  3. 4.3

    We do not sell personal data. We do not use health, food or body data to target advertising, and sponsored listings are never chosen using that data.

6.The AI coach and automated decisions

  1. 6.1

    Your training and nutrition targets are calculated by a rules-based engine with built-in safety limits. The AI coach explains and suggests; it cannot invent numbers, change a plan without your confirmation, or lift a safety restriction.

  2. 6.2

    By default, the AI coach runs on servers in Mongolia. Only if you turn on “Premium AI abroad” are requests routed through OpenRouter, after your name, phone number, exact date of birth and location are removed, and only to providers that have agreed not to retain or train on the data. If you withdraw that consent, the coach switches back to in-country processing immediately.

  3. 6.3

    Direct messages, group chats and coach chats are never sent to any AI service outside Mongolia.

  4. 6.4

    Every plan change comes with a plain-language reason. You can ask for any automated decision to be reviewed by a person, and we will re-examine it.

7.Who we share data with

  1. 7.1

    We share personal data only as follows:

    • Coaches: only the data you have agreed to share, with the coach you named. Every coach read of your health data is logged.
    • Partners: when you order or book, the partner receives what it needs to fulfil it, such as your name, phone number, delivery address and the items ordered. Partners do not receive your health data.
    • Service providers acting on our instructions: hosting in Mongolia, SMS verification (verify.mn), email (Amazon SES, with your consent), overseas AI (OpenRouter, with your consent), and error and usage monitoring (Grafana Cloud, Sentry, PostHog) using pseudonymous data with sensitive fields removed.
    • Google, for analytics and advertising measurement in the MFit app and on the MFit website and web portal (Google Analytics with Google Signals; Firebase Analytics in the app): the pages and app screens you visit and the buttons you use, your MFit user ID when you are signed in, and the device and approximate location data Google collects itself. Health data, messages, names, phone numbers and email addresses are never sent, and the admin consoles are not measured.
    • Payment and receipt systems: Apple, Google, QPay and the national e-barimt system receive what is needed to take payment and issue receipts.
    • Authorities: when Mongolian law requires it, or to protect someone’s life or safety. Reports of child sexual abuse material are made to the competent authorities.
  2. 7.2

    If MFit is reorganised, merged or sold, personal data may pass to the new operator, which will remain bound by this policy. We will notify you before that happens.

8.Transfers outside Mongolia

  1. 8.1

    Data leaves Mongolia only in the cases shown in the table in section 3: de-identified AI requests if you opt in, email through Amazon SES if you opt in, and scrubbed technical telemetry.

  2. 8.2

    Correspondence and location data are never transferred abroad, and neither is sensitive health data, except for the de-identified AI requests you have opted into.

9.Location and activity privacy

  1. 9.1

    Maps of shared activities are hidden by default, and start and end points are always trimmed.

  2. 9.2

    You can set privacy zones (minimum 400 m) around places such as your home. Distances near a zone are rounded when shown to others.

  3. 9.3

    Check-ins are private by default. If you share one, others see “trained at this venue today”, never that you are there now. There is no public heatmap.

  4. 9.4

    Venue busy-times are aggregated and hidden when too few people contribute to identify anyone.

10.Your rights

  1. 10.1

    Under Mongolian law you have the right to:

    • access your data and receive a copy: export everything as JSON (logs also as CSV) from the app; the download link is valid for 7 days;
    • correct inaccurate data: edit your profile, logs and body measurements at any time;
    • delete your data: delete your account in the app or on the web;
    • withdraw consent: in Settings → Privacy;
    • receive an explanation of, and a human review of, any automated decision;
    • complain to the National Human Rights Commission of Mongolia, which supervises personal data protection.
  2. 10.2

    We will respond to requests without undue delay and within the time limits set by law. We may need to confirm your identity first.

  3. 10.3

    When you delete your account:

    • your account, logs, health data and media are deleted;
    • your posts and comments are deleted; other people’s replies remain, shown as from a “deleted user”;
    • messages are removed from your side; the other participants see “deleted message”;
    • orders, payments and receipts are kept only as long as tax and accounting law requires, de-identified where possible;
    • moderation records are kept as long as needed to handle abuse and legal claims.

11.How long we keep data

  1. 11.1

    We keep data only as long as needed for the purpose it was collected for. Our default periods are:

    • raw wearable samples: 24 months;
    • daily summaries and training history: for the life of your account;
    • AI coach conversations: 12 months;
    • media held for moderation review: 30 days;
    • security audit log: 5 years;
    • receipts and accounting records: the period required by tax law.
  2. 11.2

    When a retention period ends, the data is deleted or irreversibly anonymised.

12.How we protect your data

  1. 12.1

    Our safeguards include:

    • encryption in transit (TLS) and at rest, including all disks and backups;
    • messages encrypted with a separate key per conversation, protected by a master key held in Mongolia;
    • least-privilege access controls, with every moderator decryption and every coach or staff read of health data recorded in an audit log;
    • notifications, SMS and emails that never contain health data or message text;
    • location and camera metadata (EXIF/GPS) removed from photos, with progress photos private by default;
    • a designated security officer, written security procedures, regular risk assessments and independent audits.
  2. 12.2

    No system is completely secure. Please use a device lock and keep your phone number up to date so that verification codes reach only you.

13.If a data breach happens

  1. 13.1

    If a breach affects your data, we will notify you promptly, telling you what happened, what data is involved and what you can do.

  2. 13.2

    We also notify the competent authorities as required by law, record every incident in our breach register, and file that register with the National Human Rights Commission each year.

14.Cookies and notifications

  1. 14.1

    The website and web portal use the cookies needed to keep you signed in, remember your language and protect against abuse, and Google Analytics cookies (_ga and related) to measure how the site is used and how well our advertising works. This includes Google Signals, which can link visits to signed-in Google accounts for cross-device reports and advertising audiences. You can opt out with Google’s browser add-on (tools.google.com/dlpage/gaoptout) or by blocking cookies in your browser.

  2. 14.2

    You can turn off push notifications in your device settings and marketing messages in Settings → Privacy at any time. Security and transaction messages cannot be turned off while you have an account.

15.Changes to this policy

  1. 15.1

    We will update this policy when our services or the law change. The date and version at the top show the current edition.

  2. 15.2

    If a change materially affects how we use your data, we will tell you in the app before it takes effect and, where the law requires, ask for your consent again.

Contact us

For questions about this policy or to exercise your rights, contact our data protection team. You can also manage most settings yourself in Settings → Privacy.

Controller
TODO: legal entity name and state registration number
Registered address
TODO: registered address, Ulaanbaatar
Security officer
TODO: named security officer
Email
TODO: privacy contact email
Back to top