Privacy Notice
Last updated 25 August 2026
Nearly everything we hold in DIOL, you wrote: your promises, your records, your notes. This page is about what happens to them. What we collect, why, who can see it and how long we keep it, including the parts we would rather were tidier.
In short
What follows is long. Four things first.
- If all you did was join the waitlist, most of this does not apply to you: we hold your e-mail address and the record of the box you ticked. Section 3 covers that on its own.
- Some rooms are health-related. Joining a room about quitting smoking, cutting down on alcohol, a weight goal or your diet can amount to data about your health. Sections 6 and 8 cover this separately.
- Your profile is visible by default. Unless you turn it off in Settings, other signed-in users can see which rooms you are in.
- Anonymous posting hides you from other users, not from the system. A post made anonymously stays linkable to your account on our side; section 8 sets out exactly how far it goes.
This is not marketing copy. We do not tell you your data is “completely safe” or that “nobody can ever see it”.
1. Controller and contact
We run DIOL, at doitorlose.com. We are the party that decides what happens to your data and is answerable for this notice.
For anything to do with your data, write to support@doitorlose.com. A person answers.
2. Scope
This notice covers the doitorlose.com site, the iOS and Android app, and the services that run both.
It does not cover other sites we link to, or how the app stores operate; those have notices of their own.
3. The waitlist
DIOL is not open yet. Until it is, the only thing this site collects is a waitlist entry, so this section covers it on its own, and you do not have to read the rest of the notice to find out what happens to your address.
What we hold
- Your e-mail address.
- When you joined, the language you were reading in, and the page you joined from.
- A single-use confirmation token, valid for 30 minutes.
- If you ticked the box: that you ticked it, when, and which version of the sentence beside it and of this notice were on screen at that moment.
- A token that makes the unsubscribe link in our e-mails work without asking you to sign in.
Ticking the box is the consent. The confirmation e-mail that follows does not ask you again. It only checks that the address is yours. If the box is not ticked, the form does not submit and nothing is sent.
Why, on what basis, and for how long
Data
E-mail address
Purpose
Hold your place, verify the address, send the launch invitation
Legal basis
Explicit consent, KVKK art.5(1), GDPR 6(1)(a)
Retention
Deleted once the invitation has been sent
Data
Confirmation token
Purpose
Check that the address is yours
Legal basis
Explicit consent
Retention
Expires after 30 minutes; deleted with the entry
Data
Consent record, time, versions, page, language
Purpose
Be able to show what you agreed to, and when
Legal basis
Legal obligation, KVKK art.5(2)(ç), GDPR 7(1)
Retention
Kept while the consent stands, and afterwards only as long as we need it to show that we honoured your withdrawal
Data
Unsubscribe token
Purpose
Let you withdraw from any e-mail, without signing in
Legal basis
Legal obligation
Retention
Deleted with the entry
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| E-mail address | Hold your place, verify the address, send the launch invitation | Explicit consent, KVKK art.5(1), GDPR 6(1)(a) | Deleted once the invitation has been sent |
| Confirmation token | Check that the address is yours | Explicit consent | Expires after 30 minutes; deleted with the entry |
| Consent record, time, versions, page, language | Be able to show what you agreed to, and when | Legal obligation, KVKK art.5(2)(ç), GDPR 7(1) | Kept while the consent stands, and afterwards only as long as we need it to show that we honoured your withdrawal |
| Unsubscribe token | Let you withdraw from any e-mail, without signing in | Legal obligation | Deleted with the entry |
Changing your mind
Every e-mail we send carries an unsubscribe link. It opens a page with a single button, free, no sign-in, no reason required. If your mail app shows its own unsubscribe control beside our name, that one takes effect immediately. You can also write to support@doitorlose.com and we will do it for you.
Withdrawing stops the e-mails from that moment on. It cannot undo one already sent, because we cannot reach into your inbox.
Who else sees it
- The list is stored in a database, whose provider can see the entries.
- The e-mails are delivered by a sending service, which sees your address and what we send.
- The bot check on the form sees your IP address and a challenge token.
We do not store your IP address against your waitlist entry. Forms are rate-limited by IP, but that is held in server memory and expires; it is never written to the list.
4. The personal data we process
Your account
- E-mail address, username and an optional profile photo.
- Optionally, your date of birth and gender.
- We never see your password; it is stored hashed by our authentication provider. Your session is held in a cookie.
Your promises and records
- The goal text, your reason, the rhythm, rest days, start and end dates.
- The rooms you join and your day count in them.
- Check-in dates and the measures you choose yourself: time, pages, repetitions, steps, weight and the like.
- Your exam-preparation entries.
- Your private daily notes, which only you can see.
- Your coin balance and coin history. Coins are an in-app token, never real money.
What you post in the community
- Your room notes, the advice you leave after finishing a room, and your check-in photos.
- The rockets you give, the users you block and the reports you submit.
- Which posts you have seen. We record this so the feed can put the unseen ones first.
Your settings
- Notification preferences, reminder hour, language and privacy toggles.
- If you allow notifications, a notification token for your device.
What you agreed to when you signed up
- That you accepted the Terms of Service and this Privacy Policy, and the moment you did. We keep the time because we have to be able to show what you agreed to, and when.
- Whether you asked us to e-mail you about new features and tips. This is off unless you tick it.
The two boxes at sign-up are separate on purpose. Accepting the Terms carries no permission to e-mail you, and refusing the e-mails does not stop you creating an account. Product e-mail is off unless you tick it, and you can turn it off again at any time in Settings, Privacy. Withdrawing stops them from that moment on; it cannot undo one already sent.
Subscription
- The status of your Pro subscription and when it renews.
- Apple or Google take the payment; your card details never reach us. All we receive is whether the subscription is valid.
If you joined the waitlist
Your e-mail address, the time you joined, and a single-use confirmation token.
Data created automatically
- IP address and device string, when you sign in, the session record keeps the IP address you signed in from and your browser or device string, and it keeps them for as long as that session exists.
- IP address, again, for rate-limiting forms and sign-in endpoints and for the bot check. That use is separate: it is held in server memory, expires quickly, and is never written to a table.
- Rate-limit records, your account identifier, the kind of action, and the time.
- Crash reports, from release builds of the app only: a stack trace, device and OS details, and your account identifier. The identifier is a random UUID, attached so one person hitting the same error 500 times can be told apart from 500 people hitting it once. Your e-mail, username and IP address are never attached, and screenshots are switched off.
- Your language and theme preference. The theme preference never leaves your device.
5. Our purposes and legal bases
Purpose
Create your account and sign you in
Data
e-mail, username, session
KVKK
Performance of a contract
GDPR
6(1)(b)
Purpose
Hold your promises and records and show them to you
Data
promise, record, measure, note
KVKK
Performance of a contract
GDPR
6(1)(b)
Purpose
Publish what you post in a room
Data
note, tip, photo
KVKK
Performance of a contract
GDPR
6(1)(b)
Purpose
Process health-related room membership
Data
the room you joined
KVKK
Explicit consent (art.6)
GDPR
9(2)(a)
Purpose
Send your reminders and notifications
Data
reminder hour, notification token
KVKK
Performance of a contract
GDPR
6(1)(b)
Purpose
Run your Pro subscription
Data
subscription status
KVKK
Performance of a contract
GDPR
6(1)(b)
Purpose
Screen photos for inappropriate content
Data
photo
KVKK
Legitimate interests and legal obligation
GDPR
6(1)(f)
Purpose
Prevent abuse and bot traffic
Data
IP, rate-limit record
KVKK
Legitimate interests
GDPR
6(1)(f)
Purpose
Fix crashes
Data
stack trace, device details, account identifier
KVKK
Legitimate interests
GDPR
6(1)(f)
Purpose
Send the waitlist invitation
Data
KVKK
Explicit consent
GDPR
6(1)(a)
| Purpose | Data | KVKK | GDPR |
|---|---|---|---|
| Create your account and sign you in | e-mail, username, session | Performance of a contract | 6(1)(b) |
| Hold your promises and records and show them to you | promise, record, measure, note | Performance of a contract | 6(1)(b) |
| Publish what you post in a room | note, tip, photo | Performance of a contract | 6(1)(b) |
| Process health-related room membership | the room you joined | Explicit consent (art.6) | 9(2)(a) |
| Send your reminders and notifications | reminder hour, notification token | Performance of a contract | 6(1)(b) |
| Run your Pro subscription | subscription status | Performance of a contract | 6(1)(b) |
| Screen photos for inappropriate content | photo | Legitimate interests and legal obligation | 6(1)(f) |
| Prevent abuse and bot traffic | IP, rate-limit record | Legitimate interests | 6(1)(f) |
| Fix crashes | stack trace, device details, account identifier | Legitimate interests | 6(1)(f) |
| Send the waitlist invitation | Explicit consent | 6(1)(a) |
We do not rely on vague purposes such as “improving the service”.
6. Data that may relate to your health
DIOL is not a health service or a medical device, and it is not built to collect health data. But by the nature of the product, some data can be linked to your health.
- Room membership: rooms for quitting smoking, cutting down on alcohol, quitting vaping, quitting gambling and quitting pornography, along with nutrition, weight and sleep rooms.
- Measures you enter yourself: weight, steps, sleep and the like.
- Free-text fields: your promise text, your daily notes and what you post in rooms.
Data of this kind may be special-category personal data under KVKK art.6 and GDPR art.9. For that reason we ask for your explicit consent the first time you join such a room. You can withdraw it at any time in Settings. When you do, you leave the health rooms you are in, any coins you had staked in them come back to you, and no new join is possible until you consent again. Your own record of what you promised and what came of it stays as it is; a promise that ended this way is marked as ended rather than kept or broken.
Please do not upload medical reports, test results, diagnoses or comparable sensitive health information to DIOL. The app was not designed for it and we do not undertake a level of protection suitable for it.
7. How we collect it
- Directly from you: what you type into forms, and the records and posts you create.
- Automatically from use: sign-in session records (IP address and device string), rate-limit records, crash reports, language and theme preference.
- We do not buy personal data and we do not take profiles from advertising networks.
8. Community posts and anonymity
Who sees what
- What you post in a room is visible to the other participants in that room.
- Your public profile, username, number of active and completed promises, and the rooms you are in, is visible to every signed-in user. This is on by default and can be turned off in Settings.
- Your private daily notes are never shared.
What anonymous posting is, and what it is not
When you post anonymously, other users see a stable pseudonym instead of your username. We state its limits plainly.
- Your pseudonym is stable per person. Anonymous posts from the same account can be connected to each other, and if you post once under your username in the same feed, the two can be connected as well.
- On our side the post remains linkable to your account. Anonymity is towards other users, not towards someone with technical access to the database.
- That link is used only for moderation, security, prevention of abuse, and compliance with legal obligations.
We do not claim that “not even we can see it”, because that would not be true.
Moderation
Accounts with administrator rights can review reported posts and posts not yet screened, photos included. Check-in photos also pass through automated content screening.
10. Service providers and recipient groups
We do not run DIOL on our own. Seven jobs are done for us by other companies, and each of them sees only as much as its job needs. We are not hiding who sees what:
- Your account, promises, records and files live in a database. That provider can see everything the app can see.
- The website is hosted on a server, which sees requests to the site, your IP address and the session cookie.
- Your e-mails are delivered by a sending service, which sees your address and the contents of what we send.
- The bot check on our forms is run by a security service, which sees your IP address and the challenge token.
- Check-in photos you share are screened automatically for inappropriate content; the service that screens them sees the photo itself.
- When the app crashes, the error goes to an error-tracking service, which sees the stack trace and your device details, but not your identity.
- Subscription payments and notification delivery are handled by the app stores, which see the purchase record; your card details never reach us. (Apple and Google)
We describe each of these by the job it does rather than by name. If you want to know which companies they are, write to support@doitorlose.com and we will tell you. That is your right, and this paragraph is not a way around it.
We do not sell personal data and we do not share it with anyone for advertising. We may share data with competent public authorities where we are legally required to.
11. International transfers
Every provider in section 10 is a company established outside Türkiye, so some of your data is processed abroad. The database, your account, your promises, your records and the files you upload, is hosted in Frankfurt, Germany. Our error reports are also received in Germany. Where the remaining providers hold their servers depends on each one's own infrastructure.
Data that goes abroad goes only for the jobs described in section 10, and only as far as those jobs require. If that scope or our providers change, we update this section and change the date at the top.
If you do not want your data processed outside Türkiye, DIOL is not for you: we do not offer a version that runs on domestic infrastructure alone.
12. Retention and deletion
Data
Account and profile
How long we keep it
Until you delete it
Data
Promises, records, notes and coin history
How long we keep it
Until your account is deleted
Data
Check-in photos
How long we keep it
24 hours, then deleted automatically
Data
Your room notes and tips
How long we keep it
Kept after deletion, with the author removed
Data
Post-view records
How long we keep it
With the post itself, at 24 hours
Data
Rate-limit records
How long we keep it
Kept until we prune them; there is no automatic schedule yet, so some are older than a month
Data
Waitlist entry
How long we keep it
Deleted once the launch invitation has been sent
Data
Crash reports
How long we keep it
For as long as the error-tracking service keeps them
Data
Backups
How long we keep it
Deleted data may remain in system backups for a short while
| Data | How long we keep it |
|---|---|
| Account and profile | Until you delete it |
| Promises, records, notes and coin history | Until your account is deleted |
| Check-in photos | 24 hours, then deleted automatically |
| Your room notes and tips | Kept after deletion, with the author removed |
| Post-view records | With the post itself, at 24 hours |
| Rate-limit records | Kept until we prune them; there is no automatic schedule yet, so some are older than a month |
| Waitlist entry | Deleted once the launch invitation has been sent |
| Crash reports | For as long as the error-tracking service keeps them |
| Backups | Deleted data may remain in system backups for a short while |
When you delete your account
- You request deletion in Settings, under Danger zone.
- Your account waits 30 days. You can change your mind during that time.
- When the window closes, your account, promises, records, coins, avatar and photos are deleted.
- Notes and tips you left in rooms are not deleted; they remain with the author removed, so that other people's conversation is not torn apart. Content that was reported, and all content from an author someone had blocked, is deleted outright.
To change your mind you must open the app and tap the cancel control. Simply signing in does not cancel the deletion.
13. Security
- All traffic is encrypted in transit.
- We never see your password; it is stored hashed by our authentication provider.
- Row-level access rules apply in the database; as a rule, users reach only their own rows.
- Write endpoints are rate-limited.
- Administrator rights can only be granted through direct database access, never from inside the app.
No system is completely secure, and we are not going to tell you otherwise.
14. Children's privacy
DIOL is not designed for anyone under 13, and we do not knowingly collect data from people below that age. If you believe a child has created an account, write to support@doitorlose.com and we will remove it.
15. Your rights under KVKK and GDPR
Under KVKK art.11 you have the right to:
- Learn whether your personal data is processed, and request information about it.
- Learn the purpose of processing and whether the data is used accordingly.
- Know the third parties it is transferred to, at home or abroad.
- Request correction if it is incomplete or inaccurate.
- Request erasure or destruction.
- Request that any correction or erasure be notified to the third parties it was transferred to.
- Object to a result against you produced solely by automated analysis.
- Claim compensation for damage caused by unlawful processing.
Where GDPR applies you also have the rights of access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent. You may lodge a complaint with your supervisory authority.
16. How to make a request, and how long we take
Send your request to support@doitorlose.com. Under KVKK we will conclude it within 30 days at the latest. We may ask for further information to verify your identity.
You do not need to wait for us in order to delete your account: you can start it yourself in the app, under Settings, Danger zone.
17. Changes to this notice
If what we collect or who can see it changes, we update this page and change the date at the top. If the change matters and we have your e-mail address, we write to you. We do not quietly edit the page and move on.
18. Contact
For privacy, data requests and anything else: support@doitorlose.com. A person reads and answers everything sent there.
