FitYou.do
The Problem The Solution Research
Sign in
The private bit

Privacy

Effective 14 September 2026 · Beta

This page says what FitYou.do knows about you, why, where it lives, who else can see it, and how to make it go away. It's written to be read, not skimmed past. If anything here isn't clear, that's our fault — tell us and we'll fix the wording.

The short version

  • We keep what you type in and nothing else. No tracking, no ads, no analytics.
  • Your email address, username, date of birth and notes are stored encrypted. Your measurements and bowel records are stored plainly, on a server only we can reach.
  • Nobody else sees your records. There is no sharing feature, and we don't sell or pass data on.
  • You can download everything, and you can delete everything — one metric at a time, or the whole account. Account deletion happens seven days after you ask, so you can change your mind; then it's gone.
  • Cookies: two, both boring. They're listed below, with how to clear each one.

1. Who we are

FitYou.do is run by Analytica Quality Solutions Ltd, a company registered in England and Wales (company number 16349815), registered office [registered office address]. We're the "data controller" — the legal term for the one responsible for your data. You can reach us at support@fityou.do.

We're registered with the Information Commissioner's Office (the ICO — the UK's data regulator) under number [ICO registration number].

2. What we collect, and why

Everything below is something you typed or tapped. We don't buy data, scrape data, or get it from anywhere else.

About you

  • Your email address. It's how you sign in — we send a code to it — and it's the only thing that identifies your account. Stored encrypted.
  • Your username. So the app can greet you, and so you have something to type to confirm you really mean it when you delete your account. Stored encrypted.
  • Your date of birth, and that you've confirmed you're 18 or over. FitYou.do is for adults, and the ways it interprets measurements are drawn from adult reference ranges. We ask for both when you set up your profile and take your answers on trust. Your date of birth is stored encrypted and is also used, as an age, in the basal metabolic rate estimate.
  • Your sex and height. Height feeds BMI, waist-to-height ratio and the basal metabolic rate estimate; sex is used only by that estimate, whose published equations differ by sex. Neither is stored encrypted.
  • Your preferences. Units, theme, which metrics you've chosen to track, and your weight and waist objectives. Not personal in any meaningful sense — except that which metrics you track says something about which health data you keep.

Your records

  • Measurements. Weight, waist, blood pressure and pulse: each one's value, unit and when it was taken. Where there's a gap between two real readings the app fills it with its own estimate, marked as such, so a chart has a line to draw. This is health data — the law calls it "special category" data — and it's the whole point of the app.
  • Bowel records. When it happened, the Bristol type, and any details you add: pain, urgency, blood, and anything you took for it. Health data, same as above.
  • Fasting plans. The method, days and hours you've chosen and when each fast started and ended. Dietary behaviour — we treat it as health data too.
  • Goals and achievements. The target you set, where you started, the deadline, and whether you got there.
  • Notes. Whatever you write beside a measurement, goal or bowel record. Stored encrypted.

Measurements, bowel records, fasting plans and goals are not stored encrypted. We say more about what that means, and what we're doing about it, in section 8.

Keeping your account safe

  • Sign-in sessions. When you sign in we record your IP address and browser type against that session, so we can end it after 30 minutes of inactivity and so a sign-in you didn't make would be visible. Stored encrypted.
  • A security log. One line per notable event — a sign-in, a failed sign-in, an export, a deletion — with the IP address and browser type, encrypted. We can see this log (section 7); it exists so that if something goes wrong we can work out what happened.

Before you had an account

  • The waitlist. If you asked for beta access from the landing page we keep the email address you gave, the plan you were interested in, and whether you've been invited. The address is stored encrypted.

3. What we don't collect

No location. No contacts. No device identifiers beyond the browser type above. No behavioural data — we don't record what you tap, how long you look at things, or when you open the app. There is no third-party analytics, advertising, or tracking code anywhere in the service, and every script and font is served by us, not by someone else.

4. Why the law lets us do this

Data protection law needs a reason — a "lawful basis" — for everything. Ours:

  • Your account and the service itself: the agreement between us (the Terms of Service).
  • Your measurements, bowel records, fasting plans, goals and notes: health data needs more than "by continuing you agree", so we ask for it separately — a distinct, unticked box during sign-up, apart from agreeing to these terms and confirming your age, and we record when you gave it. [Confirm this wording with legal review.] Deleting your account withdraws it — there's no way to keep the account and withdraw consent for the records, because the records are the account.
  • Sessions and the security log: our legitimate interest in keeping your account safe — which is also your interest, which is why we think it's fair.
  • The waitlist: your consent — you typed your email into a form asking to be told about the beta.

5. How long we keep things

  • Your account, profile, measurements, bowel records, fasting plans, goals, achievements and notes: until you delete your account — or, for one metric's records, until you delete that metric from your account page.
  • An account that is never set up: if you're invited (or sign up) and don't finish setting up your profile within seven days, we email you one reminder; if it's still not set up three days after that, the account and the email address it was made with are deleted.
  • Sign-in sessions: ended after 30 minutes without activity, and any leftover session records are purged after 30 days.
  • The security log: lines tied to your account are deleted with it. Lines that never belonged to an account — a failed sign-in for an address nobody registered — are deleted after 90 days.
  • Sign-in codes: 15 minutes, then useless.
  • Waitlist sign-ups: [retention period for sign-ups that are declined or never invited — none is set yet].
  • Emails we've sent you: our email provider keeps the text of each message for up to seven days (so it can retry one that didn't get through), and the delivery details — your address, the subject line and routing information — for 30 days.
  • Error reports: our error-tracking provider keeps them for 15 days (7 days for the technical logs behind them).
  • Backups: seven days, kept so we can recover everyone's data after a failure. A deleted account is never brought back from a backup — if we ever had to restore one, the deletion would be applied again before the app came back up — and it is gone from every backup within seven days of the deletion taking effect.

6. Cookies, sessions, and what's stored on your device

A cookie is a small piece of text the site asks your browser to hold and send back with each request. We use two, neither of them for tracking. Here they are, and how to be rid of each.

Cookies

  • session_id — "you're signed in". Set when you sign in. It holds a random token that matches a session record on our server; it doesn't contain your email or anything about you. It's signed so it can't be forged, marked so JavaScript can't read it, and only sent over HTTPS. It has no expiry date, which means your browser drops it when you close the browser. On our side the session is ended after 30 minutes without activity whatever the cookie says. Cleared by: signing out (which also deletes the session on our server), closing your browser, or 30 minutes of doing nothing.
  • _fityou_session — the plumbing. A general-purpose cookie the site itself uses. It carries the one-line messages that appear after you do something ("Saved!") and a token that stops other websites submitting forms as you. It's encrypted, so you can't read it and neither can anyone else. It has no expiry date either. Cleared by: closing your browser.

That's all of them. There's no cookie banner because there's nothing to consent to: both cookies are strictly necessary for the thing you asked for.

Stored on your device, not in a cookie

  • Your theme. If you pick "Light" or "Dark", that one word is kept in your browser's local storage so the page can paint the right colours before it has heard from us, and saved to your profile so other devices follow it. Choosing "System" removes it.
  • Nothing else. The app registers a "service worker" so your browser will offer to install it like an app, but it deliberately caches nothing — not a page, not a record — because your browser's cache is unencrypted storage on your device and this is a health tracker.

Clearing everything at once

Every browser has a "clear site data" option for a single website (usually in the padlock or "site settings" menu). Doing that for FitYou.do removes both cookies and the theme setting in one go. It doesn't touch your account or your records on our server — for that, see section 9.

7. Who else can see your data

  • Us. The app holds the keys to the encrypted fields so it can show your data back to you, which means the person running it could in principle read it. There's no admin screen for browsing anyone's measurements or records, and we don't look. There is an admin screen for the security log — sign-ins, failed sign-ins and the like, with the email address, IP address and browser type behind each — and a weekly summary of it is emailed to us, because that's how we'd notice someone trying to get into accounts. We're not going to pretend encryption we hold the keys to is the same as encryption we don't — it isn't "end-to-end", and we don't claim it is.
  • The company that hosts our server: Hetzner, in Nuremberg, Germany. They can see the server, its disk, and the backup copies of the database we keep in their storage. Encrypted fields are gibberish to them; measurements and records are not. Germany is in the EU, which the UK treats as giving your data equivalent protection. [Confirm Hetzner's data-processing agreement is accepted.]
  • The company that delivers our email: Mailgun, in their EU region. They see the address the email is going to and what's in it: a sign-in code, or a notice about your account. Never your records — nothing you've recorded is ever emailed, not even when you delete your account (you download a copy on the page instead). [Confirm Mailgun's data-processing agreement.]
  • The company that collects our error reports: Honeybadger, in their EU region. When something in the app breaks, it receives the error, where in the code it happened, and the address of the page — with anything that could be a measurement, an email address or a sign-in code stripped out first. It's never told which account was affected. [Confirm Honeybadger's data-processing agreement is accepted.]
  • Nobody else. We don't sell data, we don't pass it to advertisers, and there's no one to "partner" with. If the law ever forces us to hand something over, we'll tell you unless we're legally forbidden to.

8. How it's protected

  • Everything between your device and our server travels over HTTPS.
  • Your email address, username, date of birth, notes, and every IP address and browser type we hold are encrypted in the database. Your measurements, bowel records, fasting plans and goals are stored as plain rows, on a server only we can reach. We're working on encrypting those too; it's a trade-off with what the dashboard can calculate, and we'll update this page when it's done.
  • There's no password to steal. Sign-in is a one-time code that expires in 15 minutes and can only be used once.
  • Sign-in attempts are rate-limited and capped, and every one is logged.
  • The export you download from your account page never contains your name or email, so a stray CSV can't be tied to you by anyone who finds it.

9. Your rights — and the buttons that do them

  • See it all. The app shows you everything. For a copy, use Export on your account page — it's a CSV file of every measurement, bowel record and note. It doesn't include your goals, fasting plans, sessions or security log; if you want those too, email us and we'll send them.
  • Fix it. Every measurement, bowel record, note, goal and fast can be edited.
  • Take it with you. The same export re-imports cleanly, here or anywhere that reads CSV.
  • Delete some of it. Your account page lets you delete all of one metric's records — every weight reading, say — without touching anything else.
  • Delete it all. Delete my account on your account page. We schedule the deletion for seven days later and show you the date; until then you can cancel with one tap. That week exists so that someone who got into your account can't wipe it out from under you before you notice. We email you a CSV copy when you ask, so you have it regardless. When the day comes, everything — profile, measurements, bowel records, fasting plans, goals, notes, sessions, the security log — is deleted. Nothing is kept for analytics.
  • Complain. Tell us first at support@fityou.do and we'll sort it. If we don't, you can complain to the ICO at ico.org.uk/make-a-complaint.

10. Children

FitYou.do is for adults. You must be 18 or over to have an account, and we ask for your date of birth and a confirmation when you set up your profile. There's nothing here for anyone younger, and we don't knowingly hold any data about them. If you think someone under 18 has made an account, tell us and we'll remove it.

11. Changes to this page

If we change what we collect or who sees it, we'll change this page, move the date at the top, and email you before it takes effect. Small wording fixes won't get an email.

12. Contact

support@fityou.do — for anything on this page, or anything that should be.

© 2026 FitYou.do. All rights reserved.
Terms Privacy