doItOrLose

Privacy Notice

Last updated 25 August 2026

Nearly everything we hold in DIOL, you wrote: your promises, your records, your notes. This page is about what happens to them. What we collect, why, who can see it and how long we keep it, including the parts we would rather were tidier.

In short

What follows is long. Four things first.

  • If all you did was join the waitlist, most of this does not apply to you: we hold your e-mail address and the record of the box you ticked. Section 3 covers that on its own.
  • Some rooms are health-related. Joining a room about quitting smoking, cutting down on alcohol, a weight goal or your diet can amount to data about your health. Sections 6 and 8 cover this separately.
  • Your profile is visible by default. Unless you turn it off in Settings, other signed-in users can see which rooms you are in.
  • Anonymous posting hides you from other users, not from the system. A post made anonymously stays linkable to your account on our side; section 8 sets out exactly how far it goes.

This is not marketing copy. We do not tell you your data is “completely safe” or that “nobody can ever see it”.

1. Controller and contact

We run DIOL, at doitorlose.com. We are the party that decides what happens to your data and is answerable for this notice.

For anything to do with your data, write to support@doitorlose.com. A person answers.

2. Scope

This notice covers the doitorlose.com site, the iOS and Android app, and the services that run both.

It does not cover other sites we link to, or how the app stores operate; those have notices of their own.

3. The waitlist

DIOL is not open yet. Until it is, the only thing this site collects is a waitlist entry, so this section covers it on its own, and you do not have to read the rest of the notice to find out what happens to your address.

What we hold

  • Your e-mail address.
  • When you joined, the language you were reading in, and the page you joined from.
  • A single-use confirmation token, valid for 30 minutes.
  • If you ticked the box: that you ticked it, when, and which version of the sentence beside it and of this notice were on screen at that moment.
  • A token that makes the unsubscribe link in our e-mails work without asking you to sign in.

Ticking the box is the consent. The confirmation e-mail that follows does not ask you again. It only checks that the address is yours. If the box is not ticked, the form does not submit and nothing is sent.

Why, on what basis, and for how long

Data

E-mail address

Purpose

Hold your place, verify the address, send the launch invitation

Legal basis

Explicit consent, KVKK art.5(1), GDPR 6(1)(a)

Retention

Deleted once the invitation has been sent

Data

Confirmation token

Purpose

Check that the address is yours

Legal basis

Explicit consent

Retention

Expires after 30 minutes; deleted with the entry

Data

Consent record, time, versions, page, language

Purpose

Be able to show what you agreed to, and when

Legal basis

Legal obligation, KVKK art.5(2)(ç), GDPR 7(1)

Retention

Kept while the consent stands, and afterwards only as long as we need it to show that we honoured your withdrawal

Data

Unsubscribe token

Purpose

Let you withdraw from any e-mail, without signing in

Legal basis

Legal obligation

Retention

Deleted with the entry

Changing your mind

Every e-mail we send carries an unsubscribe link. It opens a page with a single button, free, no sign-in, no reason required. If your mail app shows its own unsubscribe control beside our name, that one takes effect immediately. You can also write to support@doitorlose.com and we will do it for you.

Withdrawing stops the e-mails from that moment on. It cannot undo one already sent, because we cannot reach into your inbox.

Who else sees it

  • The list is stored in a database, whose provider can see the entries.
  • The e-mails are delivered by a sending service, which sees your address and what we send.
  • The bot check on the form sees your IP address and a challenge token.

We do not store your IP address against your waitlist entry. Forms are rate-limited by IP, but that is held in server memory and expires; it is never written to the list.

4. The personal data we process

Your account

  • E-mail address, username and an optional profile photo.
  • Optionally, your date of birth and gender.
  • We never see your password; it is stored hashed by our authentication provider. Your session is held in a cookie.

Your promises and records

  • The goal text, your reason, the rhythm, rest days, start and end dates.
  • The rooms you join and your day count in them.
  • Check-in dates and the measures you choose yourself: time, pages, repetitions, steps, weight and the like.
  • Your exam-preparation entries.
  • Your private daily notes, which only you can see.
  • Your coin balance and coin history. Coins are an in-app token, never real money.

What you post in the community

  • Your room notes, the advice you leave after finishing a room, and your check-in photos.
  • The rockets you give, the users you block and the reports you submit.
  • Which posts you have seen. We record this so the feed can put the unseen ones first.

Your settings

  • Notification preferences, reminder hour, language and privacy toggles.
  • If you allow notifications, a notification token for your device.

What you agreed to when you signed up

  • That you accepted the Terms of Service and this Privacy Policy, and the moment you did. We keep the time because we have to be able to show what you agreed to, and when.
  • Whether you asked us to e-mail you about new features and tips. This is off unless you tick it.

The two boxes at sign-up are separate on purpose. Accepting the Terms carries no permission to e-mail you, and refusing the e-mails does not stop you creating an account. Product e-mail is off unless you tick it, and you can turn it off again at any time in Settings, Privacy. Withdrawing stops them from that moment on; it cannot undo one already sent.

Subscription

  • The status of your Pro subscription and when it renews.
  • Apple or Google take the payment; your card details never reach us. All we receive is whether the subscription is valid.

If you joined the waitlist

Your e-mail address, the time you joined, and a single-use confirmation token.

Data created automatically

  • IP address and device string, when you sign in, the session record keeps the IP address you signed in from and your browser or device string, and it keeps them for as long as that session exists.
  • IP address, again, for rate-limiting forms and sign-in endpoints and for the bot check. That use is separate: it is held in server memory, expires quickly, and is never written to a table.
  • Rate-limit records, your account identifier, the kind of action, and the time.
  • Crash reports, from release builds of the app only: a stack trace, device and OS details, and your account identifier. The identifier is a random UUID, attached so one person hitting the same error 500 times can be told apart from 500 people hitting it once. Your e-mail, username and IP address are never attached, and screenshots are switched off.
  • Your language and theme preference. The theme preference never leaves your device.

5. Our purposes and legal bases

Purpose

Create your account and sign you in

Data

e-mail, username, session

KVKK

Performance of a contract

GDPR

6(1)(b)

Purpose

Hold your promises and records and show them to you

Data

promise, record, measure, note

KVKK

Performance of a contract

GDPR

6(1)(b)

Purpose

Publish what you post in a room

Data

note, tip, photo

KVKK

Performance of a contract

GDPR

6(1)(b)

Purpose

Process health-related room membership

Data

the room you joined

KVKK

Explicit consent (art.6)

GDPR

9(2)(a)

Purpose

Send your reminders and notifications

Data

reminder hour, notification token

KVKK

Performance of a contract

GDPR

6(1)(b)

Purpose

Run your Pro subscription

Data

subscription status

KVKK

Performance of a contract

GDPR

6(1)(b)

Purpose

Screen photos for inappropriate content

Data

photo

KVKK

Legitimate interests and legal obligation

GDPR

6(1)(f)

Purpose

Prevent abuse and bot traffic

Data

IP, rate-limit record

KVKK

Legitimate interests

GDPR

6(1)(f)

Purpose

Fix crashes

Data

stack trace, device details, account identifier

KVKK

Legitimate interests

GDPR

6(1)(f)

Purpose

Send the waitlist invitation

Data

e-mail

KVKK

Explicit consent

GDPR

6(1)(a)

We do not rely on vague purposes such as “improving the service”.

6. Data that may relate to your health

DIOL is not a health service or a medical device, and it is not built to collect health data. But by the nature of the product, some data can be linked to your health.

  • Room membership: rooms for quitting smoking, cutting down on alcohol, quitting vaping, quitting gambling and quitting pornography, along with nutrition, weight and sleep rooms.
  • Measures you enter yourself: weight, steps, sleep and the like.
  • Free-text fields: your promise text, your daily notes and what you post in rooms.

Data of this kind may be special-category personal data under KVKK art.6 and GDPR art.9. For that reason we ask for your explicit consent the first time you join such a room. You can withdraw it at any time in Settings. When you do, you leave the health rooms you are in, any coins you had staked in them come back to you, and no new join is possible until you consent again. Your own record of what you promised and what came of it stays as it is; a promise that ended this way is marked as ended rather than kept or broken.

Please do not upload medical reports, test results, diagnoses or comparable sensitive health information to DIOL. The app was not designed for it and we do not undertake a level of protection suitable for it.

7. How we collect it

  • Directly from you: what you type into forms, and the records and posts you create.
  • Automatically from use: sign-in session records (IP address and device string), rate-limit records, crash reports, language and theme preference.
  • We do not buy personal data and we do not take profiles from advertising networks.

8. Community posts and anonymity

Who sees what

  • What you post in a room is visible to the other participants in that room.
  • Your public profile, username, number of active and completed promises, and the rooms you are in, is visible to every signed-in user. This is on by default and can be turned off in Settings.
  • Your private daily notes are never shared.

What anonymous posting is, and what it is not

When you post anonymously, other users see a stable pseudonym instead of your username. We state its limits plainly.

  • Your pseudonym is stable per person. Anonymous posts from the same account can be connected to each other, and if you post once under your username in the same feed, the two can be connected as well.
  • On our side the post remains linkable to your account. Anonymity is towards other users, not towards someone with technical access to the database.
  • That link is used only for moderation, security, prevention of abuse, and compliance with legal obligations.

We do not claim that “not even we can see it”, because that would not be true.

Moderation

Accounts with administrator rights can review reported posts and posts not yet screened, photos included. Check-in photos also pass through automated content screening.

9. Cookies, local storage and technical data

What

diol-lang

Where

Cookie

Purpose

Language preference

Lifetime

365 days

What

diol-theme

Where

Local storage

Purpose

Light/dark theme

Lifetime

Indefinite, never leaves your device

What

Session cookie

Where

Cookie

Purpose

Keeping you signed in

Lifetime

Duration of your session

What

Bot check

Where

Cookie and local storage

Purpose

Telling a person from a script on our forms

Lifetime

Set by the security provider that runs the check

We run no advertising cookies, analytics pixels, session recorders or marketing trackers. Because we set no non-essential cookies, we do not present a cookie consent banner. If that changes we will update this section and add a Cookie Policy.

10. Service providers and recipient groups

We do not run DIOL on our own. Seven jobs are done for us by other companies, and each of them sees only as much as its job needs. We are not hiding who sees what:

  • Your account, promises, records and files live in a database. That provider can see everything the app can see.
  • The website is hosted on a server, which sees requests to the site, your IP address and the session cookie.
  • Your e-mails are delivered by a sending service, which sees your address and the contents of what we send.
  • The bot check on our forms is run by a security service, which sees your IP address and the challenge token.
  • Check-in photos you share are screened automatically for inappropriate content; the service that screens them sees the photo itself.
  • When the app crashes, the error goes to an error-tracking service, which sees the stack trace and your device details, but not your identity.
  • Subscription payments and notification delivery are handled by the app stores, which see the purchase record; your card details never reach us. (Apple and Google)

We describe each of these by the job it does rather than by name. If you want to know which companies they are, write to support@doitorlose.com and we will tell you. That is your right, and this paragraph is not a way around it.

We do not sell personal data and we do not share it with anyone for advertising. We may share data with competent public authorities where we are legally required to.

11. International transfers

Every provider in section 10 is a company established outside Türkiye, so some of your data is processed abroad. The database, your account, your promises, your records and the files you upload, is hosted in Frankfurt, Germany. Our error reports are also received in Germany. Where the remaining providers hold their servers depends on each one's own infrastructure.

Data that goes abroad goes only for the jobs described in section 10, and only as far as those jobs require. If that scope or our providers change, we update this section and change the date at the top.

If you do not want your data processed outside Türkiye, DIOL is not for you: we do not offer a version that runs on domestic infrastructure alone.

12. Retention and deletion

Data

Account and profile

How long we keep it

Until you delete it

Data

Promises, records, notes and coin history

How long we keep it

Until your account is deleted

Data

Check-in photos

How long we keep it

24 hours, then deleted automatically

Data

Your room notes and tips

How long we keep it

Kept after deletion, with the author removed

Data

Post-view records

How long we keep it

With the post itself, at 24 hours

Data

Rate-limit records

How long we keep it

Kept until we prune them; there is no automatic schedule yet, so some are older than a month

Data

Waitlist entry

How long we keep it

Deleted once the launch invitation has been sent

Data

Crash reports

How long we keep it

For as long as the error-tracking service keeps them

Data

Backups

How long we keep it

Deleted data may remain in system backups for a short while

When you delete your account

  • You request deletion in Settings, under Danger zone.
  • Your account waits 30 days. You can change your mind during that time.
  • When the window closes, your account, promises, records, coins, avatar and photos are deleted.
  • Notes and tips you left in rooms are not deleted; they remain with the author removed, so that other people's conversation is not torn apart. Content that was reported, and all content from an author someone had blocked, is deleted outright.

To change your mind you must open the app and tap the cancel control. Simply signing in does not cancel the deletion.

13. Security

  • All traffic is encrypted in transit.
  • We never see your password; it is stored hashed by our authentication provider.
  • Row-level access rules apply in the database; as a rule, users reach only their own rows.
  • Write endpoints are rate-limited.
  • Administrator rights can only be granted through direct database access, never from inside the app.

No system is completely secure, and we are not going to tell you otherwise.

14. Children's privacy

DIOL is not designed for anyone under 13, and we do not knowingly collect data from people below that age. If you believe a child has created an account, write to support@doitorlose.com and we will remove it.

15. Your rights under KVKK and GDPR

Under KVKK art.11 you have the right to:

  • Learn whether your personal data is processed, and request information about it.
  • Learn the purpose of processing and whether the data is used accordingly.
  • Know the third parties it is transferred to, at home or abroad.
  • Request correction if it is incomplete or inaccurate.
  • Request erasure or destruction.
  • Request that any correction or erasure be notified to the third parties it was transferred to.
  • Object to a result against you produced solely by automated analysis.
  • Claim compensation for damage caused by unlawful processing.

Where GDPR applies you also have the rights of access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent. You may lodge a complaint with your supervisory authority.

16. How to make a request, and how long we take

Send your request to support@doitorlose.com. Under KVKK we will conclude it within 30 days at the latest. We may ask for further information to verify your identity.

You do not need to wait for us in order to delete your account: you can start it yourself in the app, under Settings, Danger zone.

17. Changes to this notice

If what we collect or who can see it changes, we update this page and change the date at the top. If the change matters and we have your e-mail address, we write to you. We do not quietly edit the page and move on.

18. Contact

For privacy, data requests and anything else: support@doitorlose.com. A person reads and answers everything sent there.