GetFit MCP

Privacy policy

Last updated 7 August 2026

GetFit MCP stores the fitness records you choose to keep and shows them back to you. This page says exactly what that means. It is written to be read, not to be survived.

Who runs this

GetFit MCP is operated by Frank Karro, Estonia. Questions, requests and complaints: hello@getfitmcp.com.

What is stored

The beta waitlist

If you request an invite on the landing page, your email address is delivered to our inbox through Resend and kept there. It is used for exactly one thing: contacting you about beta access. It is removed when you get your invite or when you ask, whichever comes first. Email hello@getfitmcp.com to be taken off the list.

What is not stored

No advertising identifiers, no tracking pixels, no cookies beyond the one that keeps you signed in. The public pages at getfitmcp.com use Plausible, a cookieless visit counter running on our own server. It keeps aggregate visit numbers and does not follow you across other sites. The app itself has no analytics at all. Your data is not sold, rented or shared for advertising, and it is not used to train models.

Why it is stored

To provide the service you asked for: to keep your records, calculate your daily and weekly summaries, weight trend, adherence and maintenance estimate, and to make the same data available to ChatGPT when you connect it. The legal basis is performance of a contract with you, and for security records, our legitimate interest in keeping accounts safe.

Who else can reach it

Nobody, unless you connect them. Specifically:

We disclose data to nobody else, except where the law requires it.

How long it is kept

Until you delete it. Deleting a record removes it from every view, export and calculation, and its change history is kept until you delete your account, which is what makes a correction traceable. Deleting your account removes everything, permanently and immediately.

Your rights

Under the GDPR you may access, correct, export, restrict, object to and delete your data. Two of those are buttons rather than requests:

For anything else, email hello@getfitmcp.com. You also have the right to complain to your data protection authority; in Estonia that is the Andmekaitse Inspektsioon.

Security

Traffic is encrypted in transit. Sign-in sessions and OAuth tokens are stored hashed. Every query is scoped to your account, which is enforced in the database itself rather than only in code. Connected applications receive short lived tokens bound to a single service.

Children

GetFit MCP is not intended for anyone under 16.

Changes

If this policy changes in a way that affects what is stored or who can reach it, the date above changes and account holders are told by email before it takes effect.

Back to GetFit MCP ยท Terms of service