// mirrormov

Privacy Policy

Effective 21 July 2026

MirrorMov is a GPS activity recorder for Pebble smartwatches. Your activity data stays on your phone. It is not uploaded to our servers, not sold, not shared, and not used for advertising.

This policy explains exactly what the app touches and where it goes. If you connect Strava, the section on that is below.

What the app records, and where it lives

Location / GPS

MirrorMov records your GPS position roughly once per second, only while you are actively recording an activity — and not while the recording is paused. The trace is used to build your activity track and the resulting FIT file. It is stored locally on your phone and is not sent to our servers.

Heart rate, cadence and step data

Captured from the watch during an activity, stored locally alongside the GPS trace, and embedded in the FIT file. Not sent to our servers.

Activity history

Completed activities — up to the 20 most recent — are stored locally on your phone with their full track and sensor data, so you can re-export them later. You can delete any activity from inside the app at any time.

Imported GPX routes

Routes you import are your own files. They are stored locally on your phone and persist until you delete them.

Map tiles

Map tiles are fetched by your phone directly from the map providers (Google, and CyclOSM/OpenStreetMap). They do not pass through our servers. Standard provider request data applies under those providers’ own terms.

Subscription

The app validates your MirrorMap subscription code against api.mirrormap.app. This checks entitlement only — it confirms whether a code is active. No activity, location or sensor data is involved.

If you connect Strava

Strava is entirely optional. MirrorMov records, stores and exports your activities without it. If you do choose to connect it:

Your Strava access and refresh tokens are held on your phone. Token exchange and refresh pass through our backend (api.mirrormap.app) purely so the Strava client secret never has to ship inside the app. That backend is stateless: it does not store your tokens, your activities, or any Strava data.

Strava data is never disclosed to any third party, is never used for advertising or profiling, and is never used to train or evaluate any AI or machine-learning model.

What we never do

Retention

Your choices and your rights

Withdrawing Strava consent

Tap Disconnect in the app’s Strava settings. This revokes MirrorMov’s access and deletes cached Strava data and tokens from the app.

Deleting your data

You can delete individual activities and imported routes yourself, inside the app, at any time — those deletions are immediate and local. For anything else, or for a written request, contact hello@mirrormap.app. We respond to requests within 30 days. Because the backend is stateless and holds no activity data, there is in practice very little held server-side to remove.

Access, correction, portability

If you are in the UK, EU or another region with equivalent rights, you have the right to access, correct, erase and port your data, and to object to or restrict processing. Portability is largely self-service: you can export any stored activity as a standard FIT file from within the app and take it wherever you like. For anything else, email the address above.

Children

MirrorMov is not directed to children under 13, and we do not knowingly collect data from them. If you are below the age of digital consent in your country (13–16 depending on jurisdiction), please only use the app with the involvement of a parent or guardian. If you connect Strava, Strava’s own minimum-age terms apply separately.

Changes to this policy

If this policy changes in a way that matters, we will update the effective date at the top of this page. Because it describes how MirrorMov handles categories of data rather than listing every feature, most app updates will not require a change here.

Contact

Questions about this policy, or any data request: hello@mirrormap.app.