Legal

Privacy Policy

Last updated: 28 August 2026

This Privacy Policy explains how Oblige(“we”, “us”) processes personal data when you use our mobile app, coach admin atapp.oblige.fit, and marketing site atoblige.fit. It should be read together with ourTerms of Service.

1. Who we are

The data controller is Enrique Velasco, a natural person operating as a sole trader in Spain.

Privacy requests:hello@oblige.fit.

2. What this covers

This policy covers personal data processed through:

  • The Oblige mobile application (iOS / Android)
  • The coach authoring studio at app.oblige.fit
  • The public website oblige.fit (including waitlist and founding-coach forms)

3. Data we process

Depending on how you use Oblige, we may process:

Account and authentication

You sign in with Apple or Google via Firebase Authentication. We receive a Firebase user ID (UID) and, when the provider supplies them, an email address and display name. Your profile may also store a display name, optional avatar image URL, and bio.

Training content

Workouts, programs, session logs, and related training data you create are stored in Cloud Firestore under your user account (users/{uid}/…). This data is owner-scoped: only you can read or write it under our security rules.

Media

Optional progress photos and other images you upload are stored in Firebase Storage under your account path. Access is limited to you (owner-only), subject to our storage rules.

Apple Health (iOS, optional)

On iPhone you can turn on Settings → Apple Health → Save workouts to Apple Health. It isoff unless you turn it on, and turning it on is what asks iOS for permission. When it is on, Oblige runs a workout session on your device while you train and saves that workout — its type, start and end — to your Health app. We never write calories, distance or heart rate, and we never read anything from Health.

This data is written to Apple Health on your device.It is not sent to us and we cannot see it. You can revoke access at any time in iOS Settings → Health → Data Access, and you can delete saved workouts in the Health app itself.

Marketplace and published content

Coaches may publish programs to a storefront. Published program metadata may be visible to signed-in users. If you subscribe to or clone a published program, the copy and subscription record live under your account.

Website forms

If you join the waitlist or submit a founding-coach form, we collect your email address and any other fields you provide on that form. These submissions are handled by MailerLite on our behalf.

Analytics

We use Firebase Analytics / Google Analytics 4 on the apps and site to understand product usage (for example session starts, set logging, marketplace subscribe/unsubscribe events) and basic device or app metadata. These events carry identifiers, counts and durations, and — for session and marketplace events — thename of the workout or programinvolved, so the numbers are readable. They do not carry your notes or your photos. We do not use this data to sell advertising.

Diagnostics and crash reporting

The apps use Sentry to detect crashes and reliability problems (for example, a rest timer failing to fire or a workout failing to save). When a problem occurs, we may collect a crash or error report together with device and app metadata (device model, OS version, app version) and a short technical event trail from the current workout session. This trail containstechnical identifiers, timestamps, and counts only — never the names of your workouts or exercises, your notes, your messages, or your photos.

In the mobile app you can turn detailed diagnostics on or off at any time inSettings → Diagnostics → Share detailed diagnostics. It is off by default in App Store builds, and on by default in TestFlight beta builds. Turning it off stops the searchable logs and the screen recording described below, and takes effect immediately without restarting the app.

Crash and error reports are sent either way, including the technical event trail described above. They are the minimum we need to know the app is broken, and they carry no names, notes or images. What the toggle controls is the additional detail: searchable diagnostic logs, an on-error screen recording, and — in TestFlight beta builds only — your IP address and request headers. App Store builds never send your IP address or request headers.

The screen recording (session replay) is available in both App Store and TestFlight builds when detailed diagnostics is on. It is never continuous: a short recording of the moments leading up to an error is uploaded only when an error actually occurs, and nothing is uploaded otherwise. Images are fully masked, and text is masked apart from a small allowlist of non-personal interface labels.

4. Purposes and legal bases

We process personal data for the following purposes and GDPR legal bases (Art. 6):

  • Providing the service (accounts, workouts, sessions, storage, marketplace features) — performance of a contract (Art. 6(1)(b)).
  • Security, abuse prevention, and reliability— legitimate interests (Art. 6(1)(f)).
  • Product analytics to improve Oblige — legitimate interests (Art. 6(1)(f)).
  • Diagnostics and crash reporting(via Sentry) to find and fix defects — legitimate interests (Art. 6(1)(f)); you can turn this off in the mobile app at any time (Settings → Diagnostics).
  • Marketing emails (waitlist / coach updates via MailerLite) — consent (Art. 6(1)(a)); you can withdraw anytime.
  • Optional progress photos — provided by you for the service; where consent is required under applicable law, we rely on consent.
  • Saving workouts to Apple Health(iOS, optional) — consent (Art. 6(1)(a)), given by turning the setting on and by granting iOS permission; you can withdraw either at any time.
  • Legal compliance when we must — legal obligation (Art. 6(1)(c)).

5. Processors and subprocessors

We use trusted providers to operate Oblige:

  • Google — Firebase Authentication, Cloud Firestore, Firebase Storage, Firebase Hosting, Firebase Analytics / GA4
  • Apple — Sign in with Apple
  • Sentry (Functional Software, Inc.) — crash and error reporting for the apps
  • MailerLite — waitlist and founding-coach email capture and related email delivery

These providers may process data in the United States or other countries outside the European Economic Area. Where required, transfers rely on the providers’ contractual safeguards (such as Standard Contractual Clauses) and their published terms.

6. Retention and account deletion

We keep account and training data while your account is active. When you delete your account in the app, we permanently remove everything stored under your account — your profile, workouts, programs, session logs, subscriptions and progress photos in Cloud Firestore, every Storage object under your account path, and your Firebase Auth user — subject to short technical delays in provider systems.

One exception, stated plainly: if you are a coach and have published a program to the marketplace, the published copy and its storefront media live outside your account (other people may already have subscribed to it) and are not removed automatically by in-app deletion. Emailhello@oblige.fit and we will take published content down. Copies that trainees have already saved to their own accounts are theirs and remain with them.

You may also request deletion without the app — including after uninstalling it — atoblige.fit/delete-account, or by emailinghello@oblige.fit.

MailerLite contacts are kept until you unsubscribe or ask us to delete them. Analytics data is retained according to Google’s product retention settings for our property. Diagnostic error reports in Sentry are retained for 90 days and then deleted automatically.

7. Your rights

Under the GDPR you may have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data (“right to be forgotten”)
  • Restrict or object to certain processing
  • Data portability
  • Withdraw consent where processing is based on consent

The fastest way to erase account data is the in-app delete-account flow (Settings). For other requests, email hello@oblige.fit.

You also have the right to lodge a complaint with the Spanish data protection authority (AEPD) or your local supervisory authority in the EEA.

8. Children

Oblige is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a minor has created an account, contact us and we will delete it.

9. Security and international transfers

We use Firebase security rules, authentication, and owner-scoped paths to limit access to your data. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.

As described above, some processing occurs outside the EEA under provider safeguards. See Section 5.

10. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of Oblige after an update means you accept the revised policy, where permitted by law.

11. Contact

Questions about privacy:hello@oblige.fit. For product help, seeSupport.