Legal
Privacy Policy
nof1.fit · operated by DIVEX · last updated 2026-08-26
In plain language
N of 1 is an invite-only instrument for single-subject experiments. It processes health and fitness data that a subject explicitly connects or types in, for one purpose: showing that subject their own experiment.
The data is never sold, never shared with advertisers, never used to train models, and never merged with anyone else’s. There is no analytics script and no tracking cookie on this site. Everything held about you can be exported or deleted on request, and disconnecting a provider stops the flow immediately.
1. Who is responsible
The controller of the personal data described here, in the sense of the GDPR (Regulation (EU) 2016/679), is:
- DIVEX
- office@divex.ai
Write to that address for anything in this policy: access, correction, deletion, an export, or a question about how something works. A human answers.
2. What this policy covers
The public website at nof1.fit — including the waitlist form — and the N of 1 application behind the sign-in page. It does not cover the third-party services a subject may connect (WHOOP, Apple Health and similar); those are governed by their own privacy policies, and connecting one is always a choice made by the subject.
3. What is collected, and why
3.1 Waitlist
The form on the landing page stores exactly three things: the email address you type, the optional line of text you write, and the date. No IP address, no browser fingerprint, no referrer. It is used only to write to you when a cohort seat opens, and for nothing else — there is no newsletter and no third-party mailing service.
3.2 Account
For a subject with an account: name, email address, timezone, and a password stored only as a scrypt hash. Sessions are recorded as the SHA-256 of the session token, never the token itself, so a database copy cannot be replayed as a login.
3.3 Health and fitness data
This is the substance of the product, and all of it arrives because a subject connected a source or typed a value in:
- WHOOP — recovery scores, heart-rate variability, resting heart rate, sleep stages and durations, physiological cycles and strain, workouts, and basic profile and body-measurement fields.
- Apple Health — steps, heart rate, active energy and workouts, pushed from the subject’s own device.
- Nutrition apps — calories, macronutrients and weight trends from an export file the subject uploads.
- Clinical and device measurements — DEXA scans, blood panels and bio-impedance scale readings, entered by the subject.
- Logged by hand — subjective check-ins, training sets, meals, supplements, interventions and work sessions.
3.4 Technical data
The hosting and database providers that run this application keep ordinary server logs (request, timestamp, IP address) for security and troubleshooting. There is no analytics product, no advertising technology, no session recording and no third-party script on any page of this site.
4. Cookies
Two, both strictly necessary, neither used for tracking:
- Session cookie — set after sign-in,
httpOnly, expires after 30 days. Without it the application cannot know who is signed in. - OAuth state cookie — a short-lived random value that protects the provider connection flow against cross-site request forgery. It is deleted as soon as the connection completes.
Because no cookie here is used for analytics or advertising, this site shows no consent banner: there is nothing to consent to.
5. Legal bases
- Performance of a contract (Art. 6(1)(b)) — operating the account and showing a subject their own data.
- Explicit consent (Art. 9(2)(a)) — health data is a special category of personal data. It is processed only because a subject explicitly connects a source or enters a value, and that consent can be withdrawn at any time by disconnecting the source or deleting the data.
- Consent (Art. 6(1)(a)) — waitlist signups.
- Legitimate interest (Art. 6(1)(f)) — keeping the service secure and available, which is what the server logs exist for.
6. WHOOP data specifically
When a subject connects WHOOP, N of 1 requests read-only access to recoveries, cycles, sleeps, workouts, profile and body measurements, plus offline access so that the connection can refresh itself without asking again. It requests no write scope and never sends anything back to WHOOP.
What happens to that data:
- The API response is stored as received, then translated into the application’s own vocabulary. Both copies live in the same private database as everything else.
- It is shown only to the subject whose account it belongs to. It is not sold, not shared with any third party, not used for advertising, and not used to train machine-learning models.
- The access and refresh tokens are encrypted with AES-256-GCM before they are written. There is no column in this database that holds a token in plaintext.
Revoking access. A subject can disconnect WHOOP from the application’s settings page, which deletes the stored credentials and stops every future sync, or revoke N of 1 from their WHOOP account, which has the same effect from the other side. Data already synced stays until it is deleted — ask at office@divex.ai and it is removed within 30 days, or immediately along with the account.
7. Who else sees it
Nobody buys it, and nobody is given it for their own purposes. Data is handled by processors that are strictly necessary to run the service:
- the hosting provider and managed database provider the application runs on, who store it under contract and never use it;
- an AI provider, used for exactly one optional feature: transcribing a photo of a body-composition scale report that a subject uploads. Only that image is sent, only when that feature is used, and the provider does not use it for training. Every value it extracts is confirmed by the subject before it is stored.
A current list of processors is available on request. Where a processor operates outside the European Economic Area, the transfer relies on the European Commission’s Standard Contractual Clauses. Data may additionally be disclosed where the law requires it.
8. How long it is kept
- Experiment data — for as long as the account exists. The point of the product is a record that stays interpretable years later, so nothing is silently expired. Deleting the account deletes it all.
- Waitlist entries — until you ask to be removed, or 24 months after signup, whichever comes first.
- Sessions — 30 days, then they expire.
- Server logs — the retention window of the hosting provider, typically counted in days.
9. Security
- All traffic runs over TLS.
- Passwords are stored as scrypt hashes; session tokens only as SHA-256.
- Integration credentials are encrypted at rest with AES-256-GCM under a key that is not stored in the database.
- Machine ingestion endpoints require a separate bearer token, compared in constant time.
- Access to the production database is limited to the operator. No perfect security exists, and this claims none.
10. Your rights
Under the GDPR you can request access to your data, correction, erasure, restriction of processing, portability in a machine-readable format, and you can object to processing or withdraw consent at any time — withdrawing it does not affect processing that already happened. Write to office@divex.ai; requests are answered within 30 days.
You also have the right to complain to a supervisory authority. In Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP), dataprotection.ro.
11. Children
N of 1 is not intended for anyone under 18 and no account is knowingly created for one.
12. Changes
If this policy changes, the date at the top changes with it, and anyone with an account or on the waitlist is told by email before a material change takes effect.
13. Contact
office@divex.ai — or see the Terms of Service.