Privacy Policy

Last updated August 2, 2026

This Privacy Policy explains what data Mtieli collects across the mobile app and this web portal, why we collect it, and the choices you have. Mtieli is built on Google Firebase, and the app and web portal share the same backend and account.

1. Information we collect

  • Account info: your email address and password, or your name, email and profile photo if you sign in with Google. You may add a display name, bio and profile photo yourself.
  • Content you create: posts, photos, comments, community posts, direct messages, trip plans, gear lists, saved places and condition reports.
  • Precise location: if you allow it, your device location is used to centre the map, show spots near you, and produce live condition reports and weather forecasts for where you are. Deny the permission prompt and no location is collected — the rest of the app still works.
  • Purchase data: if you subscribe to Plus or Pro, or buy a Tourist Pass, our billing provider tells us which plan you hold and when it expires. We never see or store your card details — payment is handled entirely by Apple, Google, and our billing provider.
  • Advertising identifiers:the free tier shows ads, which use your device's advertising ID and, on this website, advertising cookies. Paid members see no ads.
  • Diagnostics: if the app crashes we receive a crash report containing the error, the device model, the OS version and the app version. It is not linked to your posts or messages.
  • Usage data: counters for metered features (for example how many live condition reports you have generated this month) so we can apply the limits your plan includes.
  • Product analytics: in the mobile app, which screens and features get used — for example which activity categories are opened, and whether a purchase was started or completed. These events carry categories and outcomes only. They never include your posts, messages, names, email address or the coordinates of places you view. You can turn this off entirely in Settings → Privacy → "Share anonymous usage data", which stops collection at the source rather than merely hiding it.

2. How we use it, and our legal basis

Under the GDPR we rely on the following legal bases. We do not sell your personal data.

  • To perform our contract with you: running your account, showing your posts to people who follow you, syncing your Passport progress and saved routes, delivering the features your plan includes, and applying metered limits.
  • With your consent:precise location, and personalised advertising where required by law. You can withdraw either at any time — location through your device settings, ad personalisation through the "Ad privacy choices" option in the app's Privacy settings.
  • Our legitimate interests: keeping the service secure and abuse-free, diagnosing crashes, and preventing automated abuse of our backend.
  • Legal obligation: retaining records we are required to keep, and responding to lawful requests.

3. Who processes your data

We use the following providers. Each receives only what it needs to do its job.

  • Google Firebase (Authentication, Firestore, Storage, App Check, Crashlytics, Analytics) — accounts, your content, crash reports, and app usage events.
  • Google Maps — map rendering in the app.
  • Google AdMob and AdSense — ads on the free tier, in the app and on this site respectively.
  • RevenueCat — subscription status for Plus, Pro and the Tourist Pass.
  • Vercel — hosting for this website.
  • Open-Meteo — weather and condition forecasts. Receives coordinates only, never your identity.
  • OpenStreetMap Nominatim — turning coordinates into place names. Receives coordinates only.
  • Esri (ArcGIS World Imagery) — satellite imagery of places you view. Receives coordinates only.

4. International transfers

Our providers are largely US-based, so your data is transferred outside Georgia and the European Economic Area. Those transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard offered by the provider.

5. What's visible to other members

Your display name, profile photo, bio, and anything you post to the public feed or a community are visible to other signed-in Mtieli members. Direct messages are private between you and the recipient. Your saved posts, gear list, blocked list, and private trip details are visible only to you.

6. Cookies and local storage

This site stores your language choice and your ambient-video preference in your browser's local storage so the site behaves the way you left it. Signing in sets a session cookie. On the free tier, Google AdSense sets advertising cookies; paid members are served no ads and no advertising cookies. This website itself runs no analytics trackers — the product analytics described in section 1 are in the mobile app only.

7. How long we keep it

  • Account and content: for as long as your account exists. Deleting your account removes them (see below).
  • Crash reports: retained by Firebase Crashlytics for up to 90 days.
  • Abuse reports: kept while we investigate and for a reasonable period afterwards, so repeat behaviour can be recognised. These are never readable by other members.
  • Purchase records: retained as long as required for tax and accounting purposes.

8. Deleting your account

You can delete your account yourself, at any time — in the app under Settings → Delete Account, or from the delete account page on this site. This removes your profile, posts, comments, photos, trips, gear lists, saved places and messages. Content already delivered to another member's device, and abuse reports filed about your account, may persist. An active subscription must be cancelled separately in your App Store or Google Play account — deleting your Mtieli account does not cancel store billing.

9. Your rights

You have the right to access your data, correct it, delete it, receive a portable copy, object to or restrict processing, and withdraw consent at any time. Most of this you can do directly in the app — edit your profile, delete individual posts, or delete your account outright. For anything else, email us and we will respond within 30 days. If you are in the EEA and believe we have handled your data improperly, you may complain to your national data protection authority.

10. Children

Mtieli is not directed at children under 16, and we don't knowingly collect data from them. If you believe a child has given us personal data, email us and we will delete it.

11. Changes

We'll update the date at the top of this page whenever this policy changes, and tell you in the app if the change is significant.

12. Contact

Questions about this policy or a data request? Email hello@mtieli.ge or use the Support page.

This policy describes Mtieli's actual data practices accurately, but it has not yet been reviewed by a lawyer. It will be reviewed by counsel before Mtieli is generally available.