1. Information We Collect
Mariposas collects the following data to provide our service:
- Account Information: Email address and display name via Apple or Google Sign-In.
- Health & Fitness Data: Workout summaries (type, duration, calories) from Apple HealthKit or Google Health Connect; during outdoor runs on iOS, heart rate and walking/running distance read from HealthKit for in-run coaching and charts. Used solely to power fitness features and in-app rewards.
- Usage Data: App interactions and feature usage via Firebase Analytics to improve the experience.
- Identifiers: Device identifiers for crash reporting and analytics.
- Purchase History: In-app purchase records for receipt validation.
- Advertising Data: With your permission (via the iOS App Tracking Transparency prompt), your device's advertising identifier (IDFA) and certain app events (such as account creation and sign-in) are shared with TikTok to measure the performance of our advertising campaigns. If you decline the prompt, the advertising identifier is not used.
2. How We Use Your Data
- Authenticate your account and sync your progress.
- Detect completed workouts and award Gashapon rolls.
- Track in-app purchase receipts for validation.
- Improve app performance and user experience via anonymized analytics.
- Measure the effectiveness of our advertising campaigns.
- Send optional push notifications (reminders, rewards).
3. Health Data
We read workout data from HealthKit/Health Connect to verify exercise completion. On iOS, heart rate and distance during a run are read from HealthKit for live coaching and are stored with your saved run history in the app. We do not sell, share, or use health data for advertising. Workout summaries (type, duration, calories) may also be stored in your private Firestore document for rewards.
4. Data Sharing
We do not sell your personal data. Data is shared only with:
- Firebase/Google Cloud: For authentication, database, analytics, and hosting.
- Apple/Google: For in-app purchase receipt validation.
- TikTok: For advertising measurement and attribution, device advertising identifier (with your permission) and app events such as account creation and sign-in. We never share your health or fitness data with TikTok or any other advertising partner.
5. Advertising & Your Choices
We use the TikTok Business SDK to understand whether our ads bring new users to Mariposas. On iOS, this only uses your device's advertising identifier if you allow it in the App Tracking Transparency prompt shown when the app first launches. You can change your choice at any time in iOS Settings → Privacy & Security → Tracking. Declining does not affect any app features.
6. Data Retention & Deletion
Your data is retained as long as your account exists. You can delete your account and all associated data at any time from the Settings screen in the app. Account deletion is permanent and irreversible.
7. Security
All data is transmitted over HTTPS. Sensitive operations (Gashapon rolls, purchases) are handled server-side via Firebase Cloud Functions. Firestore Security Rules prevent unauthorized access.
8. Children's Privacy
Mariposas is rated 12+ and does not knowingly collect data from children under 13. If you believe we have inadvertently collected such data, please contact us immediately.
9. Changes to This Policy
We may update this policy. Significant changes will be communicated in-app. Continued use of Mariposas after changes constitutes acceptance of the revised policy.
10. Contact
Questions about this privacy policy? Email us at support@mariposas.fit.