Moe Talaat
8:00AM - 6:00PM
Monday to Saturday
hello@moetalaat.com
Email me directly
+1 (707) 706-0501
Let's talk
HomeServicesPricingBlogAboutSupport

← Back to Margo

Privacy Policy

Last updated: August 13, 2026

1. Introduction

Margo ("we," "our," or "us") is a women's workout app for iPhone. This Privacy Policy explains what data we collect, what we don't, and how your data flows between your device, Firebase, OpenAI, RevenueCat, and PostHog.

Margo is built by one developer. We don't sell your data, we don't run third-party ads, and we don't track you across other companies' apps or websites.

2. How Your Data Flows

The cleanest way to understand Margo's privacy model is to follow the data:

  • Device ↔ Firebase Auth (sign-in): You sign in with Apple, Google, or an email address and password, handled by Firebase Authentication over HTTPS. If you use Apple or Google, that provider authenticates you and returns a token; we never see your Apple or Google password. Passwords for email accounts are handled by Firebase and never stored by us in plaintext.
  • Device ↔ Firestore (your account data): Your onboarding answers (fitness level, training days per week, session length), your current plan, workout history, streak, and app settings are stored in Google Firestore under your user ID (UID). Firestore security rules scope every document to your own UID; no other user can read or write your data.
  • Device ↔ Firebase Storage (profile picture): If you set a profile picture, the image is stored in Firebase Storage under a path keyed to your UID, readable only by your signed-in account.
  • Device ↔ Cloud Function ↔ OpenAI (Ask Margo): When you message Ask Margo, your message, recent messages from that conversation, your language, and light workout context (such as which workout you're in) are sent to a Firebase Cloud Function, which asks OpenAI's API (currently gpt-4o-mini) to write the coach's reply. Data sent through OpenAI's API is not used to train OpenAI's models, per their API data usage policy. Your conversation history itself is saved on your device, not on our servers. To keep costs and abuse bounded, Ask Margo is capped at 30 messages per hour and 100 per day per account.
  • Device → PostHog (analytics):Margo sends a small set of usage events (for example: onboarding step completed, workout started, workout finished) to PostHog, hosted in the US, so we can see what's working. Events are tied to your random Firebase UID, never to your email, name, or any body data. Session replay is disabled.
  • Device ↔ RevenueCat ↔ Apple (Margo Pro): If you subscribe to Margo Pro, Apple processes the purchase. RevenueCat sits between the app and Apple to report whether your Pro entitlement is active; it receives your UID and the subscription data Apple returns. We never see your Apple ID or payment method.
  • On-device only: Workout reminders are local notifications scheduled on your phone. Ask Margo conversation history, voice cue and playback preferences, and downloaded workout media live on your device.

3. Information We Collect

Account information

  • Email address (from email sign-up or Google; Apple may relay a private address) and the display name your sign-in provider shares
  • A Firebase Authentication user ID (UID)
  • The sign-in provider you used (Apple, Google, or email)

Fitness profile and activity

  • Your onboarding answers: fitness level, how many days a week you train, and preferred session length
  • Your current plan and where you are in it
  • Workout history: which workouts you completed and when, and your streak
  • App settings: units, language, reminder time, and toggles
  • An optional profile picture, if you choose to set one

Ask Margo messages

  • The messages you send to the coach, processed to generate a reply as described above; the conversation itself is stored on your device

Usage analytics

  • App events (screens viewed, onboarding progress, workouts started and finished), identified by UID only

4. What We Don't Collect

  • No location data
  • No contacts, camera roll scanning, or microphone recording
  • No Apple Health / HealthKit data
  • No body measurements, weight logs, or photos of you (beyond the optional profile picture)
  • No advertising identifiers used for cross-app tracking, and no data sold or shared for advertising

5. Third-Party Services

Margo relies on these processors, each receiving only what's described above:

  • Google Firebase (Authentication, Firestore, Cloud Functions, Storage): accounts and app data
  • OpenAI: generates Ask Margo replies; API data not used for model training
  • RevenueCat and Apple: subscription status and billing
  • PostHog: first-party usage analytics

6. Data Retention and Deletion

Your data is kept while your account exists. To delete everything, open Settings inside the app and tap Delete account. A Cloud Function permanently removes your Firestore data, your profile picture from Storage, and your Firebase Auth record. This is irreversible. Deleting the app from your phone removes on-device data (including Ask Margo conversations) but not your account; use Delete account for that, or email us and we'll do it for you.

7. Children

Margo is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we'll delete it.

8. Changes to This Policy

If this policy changes materially, we'll update this page and the "Last updated" date above.

9. Contact

Questions about privacy or your data: support@moetalaat.com

See also: Terms of Service · Support

Got an app idea?

Let’s ship it.

I take on a couple of client projects at a time alongside my own apps. Tappable prototype in about a week, App Store in weeks not months.

Get in touchSee what I do
MOE TALAAT

Solo builder. iOS, Android, and the small backends that hold them up. Each app gets its own page, real legal copy, and a support inbox that goes to me.

Site

  • Home
  • Services
  • Pricing
  • About
  • Blog
  • Contact
  • Support

Contact

  • hello@moetalaat.com
  • support@moetalaat.com

© 2026 Mohamed Talaat. All rights reserved.

Built solo. Hosted on Vercel.