Privacy policy
Version 1, draft of September 22, 2026
Get Fit Or ___ is a place to set a deadline, post a photo a day and keep your numbers together. Some of that is health data and photos of your body, so this page tries to say plainly what happens to it. It applies to the site getfitor.fabiocrestoni.it and to the emails it sends.
The short version
- Everything you add is private by default. Nobody sees your challenge unless you choose to share it by link or make it public, and you can undo that at any time.
- Photos lose their GPS position and other metadata as soon as you upload them.
- No ads, no analytics, no tracking pixels. Your data is never sold and never used to train AI models.
- The administrator can see that your account exists and how your challenge is going in numbers of days, but not your photos, your journal or your measurements.
- You can download everything (ZIP) or delete your account at any time.
Who is responsible
The data controller is Fabio Crestoni, a private individual based in Italy, who runs Get Fit Or ___ as a personal project. It is not a company. Contact for anything about your data: privacy@fabiocrestoni.it.
No data protection officer has been appointed: it is not required for a project of this size. Write to the address above and you will get an answer from the person who runs the service.
The service is a closed, free beta: access is by invitation only, and nothing is paid.
What we collect
If you join the waitlist: your email address, your language, the optional answer to "what's your deadline?", and the status of your request (waiting, invited, joined, rejected).
If you have an account:
- Account: email address, the name on your account, and, if you sign in with Google, the name and profile picture address Google shares with us.
- Profile: handle, display name, language, time zone, the date you declared you are 18 or older, the date and version of your health-data consent, your email preferences (daily reminder hour, cheers digest).
- Sign-in: the one-time sign-in links we email you (stored only as a hash) and your sessions. A session is stored as an opaque id with its expiry and timestamps: we record neither your IP address nor your browser.
- Your challenge: the phrase you complete, dates, goal, the name of your 0 to 10 scale, visibility settings and the secret sharing link.
- Photos you take or upload, with the day and pose you choose and the capture time read from the photo.
- Measurements and scores: weight, waist, body fat, muscle mass, your 0 to 10 scale, and the data from connected devices (see below).
- Your journal, one short text per day.
- Your answer to the one-question survey at the midpoint of your challenge, if you give one.
- For each connected service: the account id it gives us, the access keys (encrypted), and a log of each synchronisation (time, outcome, number of rows).
If you visit a shared or public challenge and tap a cheer: the cheer, the day it is for, and a keyed hash of a random id stored in a cookie on your device. Details in "Visitors and cheers".
Everyone: the web server keeps technical logs of requests (IP address, date and time, page requested, browser) for security and troubleshooting. The application itself never stores your IP address.
Health data and body photos
Body photos, body measurements, sleep, heart rate, recovery and similar figures are "special categories" of personal data under article 9 of the GDPR. We only process them with your explicit consent (article 9(2)(a)), which onboarding asks for separately from everything else, with its own checkbox. We store the date and the version of the text you agreed to. Without that consent you can keep an account, but you cannot start a challenge.
You can withdraw consent at any time by deleting your account or by writing to privacy@fabiocrestoni.it. We then stop processing that data and delete your photos, measurements, journal and connected-device data. Withdrawal does not make earlier processing unlawful.
Photos: when you upload a photo we remove its GPS position and every other metadata tag (camera, device, and so on), keeping only the capture date, time and time-zone offset, which decide the day the photo counts for. The copy we store in private storage therefore holds no location. What is shown, to you or to anyone else, and what goes into your export are copies with no metadata at all.
Why, and on what legal basis
- Running the service you signed up for (account, sign-in, your challenge, the pages you share, service emails such as sign-in links): performance of a contract, article 6(1)(b) GDPR. For health data and body photos, on top of that, your explicit consent, article 9(2)(a).
- Waitlist: your consent, confirmed through the link we email you (double opt-in), article 6(1)(a).
- Daily reminder and cheers digest emails: only if you switch them on; one click in any email switches them off. Article 6(1)(a).
- Connected devices (WHOOP, Withings, Oura): only if you connect them, and covered by your explicit consent for health data.
- Security and abuse prevention (rate limits, server logs, backups): our legitimate interest in keeping the service and your data safe, article 6(1)(f).
- Understanding whether the beta works (counts of done days, the optional midpoint survey): our legitimate interest in deciding whether the project should continue, article 6(1)(f). These figures are looked at in aggregate. Answering the survey is optional.
We make no automated decisions about you and do no profiling. There is no advertising of any kind.
What is public
Nothing, unless you decide otherwise. Every challenge starts as private: only you can see it. You can change that in two ways:
- Link: anyone with the secret link can see the challenge page. The page is hidden from search engines. You can generate a new link at any time, and the old one stops working.
- Public: the page is at /@your-handle, anyone can see it and search engines can index it. Switching needs your explicit opt-in: we remind you that your body photos will be visible to anyone and record the date and time you opted in. Switching back to link or private withdraws the opt-in.
A shared or public page shows your display name and handle, your phrase, the challenge dates and goal, your photos (without metadata), your measurements and your 0 to 10 scale, the numbers from connected devices, your journal, and how many days you have done. Choosing link or public is your explicit choice to show the data that comes from connected devices too. You can switch back to private at any time, with immediate effect on our pages.
We cannot take back what someone has already seen, saved or screenshotted while your page was visible. Share with that in mind.
Visitors and cheers
Viewing a shared or public page needs no account and leaves no trace in the application. Visitors can tap one of five fixed reactions ("cheers") on a day. There is no free text.
The first time you tap a cheer, and only then, the site sets a first-party cookie with a random id so that the same browser is counted once. We store only a keyed hash (HMAC) of that id, never your IP address. Your IP address is used for a moment to limit how many taps can come from one place, and is not stored. Deleting the cookie in your browser removes the only link between you and your taps.
Who else handles your data
We use a few service providers. Each receives only what it needs for its job:
- Hetzner Online GmbH (Germany): hosting. The server, the database, the photo storage and the backups are in Hetzner's data centre in Helsinki, Finland (EU). Processor.
- Resend (United States): sends our emails (sign-in links, invitations, reminders, digests). It receives your email address and the content of the email. Processor; see "Transfers outside the EU".
- Google: only if you choose "Sign in with Google". Google tells us your email address, your name and your profile picture address, and knows you signed in to our site. Google's privacy policy applies to your Google account.
Connected devices. If you connect WHOOP, Withings or Oura, we receive data from them through their official APIs, under their terms and your consent on their authorisation screen. We only read; we never write anything back. Each of them is an independent service with its own privacy policy for the data it holds about you. Disconnecting a service in your settings revokes our access and stops new data from arriving.
- WHOOP: recovery, strain (cycles), sleep, workouts, profile and body measurements.
- Withings: body measurements (weight, body fat, muscle mass) and activity (steps).
- Oura: sleep, readiness, activity (steps), heart rate variability, resting heart rate and workouts. Oura may not be available during the whole beta.
We do not sell your data, we do not share it for advertising, and we do not give it to anyone to train artificial intelligence models, nor do we train any. We would only disclose data if the law required it.
Transfers outside the EU
Our own data lives in the EU. Resend is based in the United States: emails go through it under the European Commission's Standard Contractual Clauses. If you sign in with Google, Google may process your sign-in data outside the EU under its own safeguards. Data you keep with WHOOP (United States) or other device makers is transferred by them under their terms, not ours.
How long we keep it
- Account and challenge data: for as long as your account exists. A finished challenge stays readable in your account until you delete it or delete the account.
- Waitlist: until you are invited and create your account, or until you ask us to remove you. If you never confirm your address, the request is deleted after 7 days.
- Sign-in links: 15 minutes, single use.
- Sessions: until you sign out, at most 30 days.
- Export files: the download link works for 24 hours, then the file is deleted automatically.
- Server logs: at most 14 days.
- Backups: a nightly backup of the database and of the photo storage, kept for 14 days; the server snapshots that carry it off the machine are kept for up to 7 more days. Data you delete therefore leaves every backup within 21 days at most, and backups are only ever used to restore the service.
Your rights
Under the GDPR you can:
- See what we hold about you (access).
- Take it with you: from your settings you can request an export, a ZIP file with every row of data you own plus your photos (without metadata). We email you a download link valid for 24 hours; after that the file is deleted.
- Correct it: most of it you can edit yourself; for the rest, write to us.
- Delete it: deleting your account signs you out immediately; your data, photos and connected-service access are erased within 24 hours, and cannot be recovered, not even by the administrator. Your waitlist entry is removed too. Any request to delete data received from a connected device is completed within 72 hours at the latest.
- Withdraw consent at any time, for health data, the waitlist or emails, without affecting what was done before.
- Object to processing based on our legitimate interest, and ask us to restrict processing.
For anything you cannot do from your settings, write to privacy@fabiocrestoni.it. We answer within one month. You also have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali, or with the authority of the EU country where you live or work.
How we protect it
- All traffic is encrypted (HTTPS).
- Access keys for connected services are stored encrypted (AES-256-GCM); those that Google sign-in gives us are encrypted too.
- Photos sit in private storage with no public access: every photo is served by the application after checking that the viewer is allowed to see it.
- Sign-in links are single use, expire after 15 minutes and are stored only as a hash.
- The administrator interface shows counts and statuses, never photos, journals or measurements.
If a breach puts your data at risk, we will notify the Garante within 72 hours as the law requires and tell you directly when the risk to you is high.
Minimum age
Get Fit Or ___ is for people aged 18 or over. Onboarding asks you to confirm it. If we learn that an account belongs to someone younger, we delete it.
Changes to this policy
The version and date are at the top of this page. We will email members before any significant change takes effect. If a change affects what you consented to for health data, we will ask for your consent again.