BeBest+

Privacy Policy

Last updated · October 2, 2026

This policy explains what BeBest does with your personal data: what we collect, why, who else sees it, how long we keep it and how you get it erased. It covers the BeBest mobile app, the web version of the app at app.bebestplus.com, and this website. There is a single account, used from both the mobile app and the web version, so everything below about accounts and their data applies to both. This website itself has no accounts and no sign-in.

It describes what the product does today, not what it might do. Every item below was checked against the database and the API before it was written down.

Who is responsible for your data

BeBest is run by Federico Di Natale, a private individual, who is the data controller for the personal data described here.

You can reach the controller at federico.dinatale.bebest@gmail.com. That address is the single channel for anything to do with your data: questions, corrections, access requests and account deletion.

What we collect

All of it comes from you using the app. We do not buy personal data and we do not obtain it from anyone else.

Account
Your email address, and the display name you typed when you signed up.
Sign-in credentials
Your password, stored only as a hash — we never hold the password itself and cannot read it. Plus the session tokens that keep you signed in, and the one-hour token created when you ask to reset your password.
Training data
Your sport; your goals (skill, goal types, priority, start and target dates, target score, notes up to 10,000 characters); your sessions (date, title, type — training, match, tournament or camp — indoor or outdoor, place, game category picked from a list, the recurring training you link it to, notes up to 10,000 characters); the recurring trainings you create to recognise your sessions: a name, in free text, and, if you pick them, a game category and the type, place and court to prefill, with the history of their name and category changes; the places you create to pick a session’s place from: a name and, if you write one, an address, as free text (on sessions logged before, the place stays the free text you wrote then); the notes you write on a skill within a session, and those you write on a whole area outside any session, each with its type (positive, negative, coach feedback, idea); and your skill self-assessments, scored 1 to 10.
Abuse prevention
Counters of recent attempts. One is keyed by the action and the email address used, for four actions: signing in, requesting a password reset, resending the confirmation email, and signing up with an address that is already registered. Another, built into the authentication library, is keyed by the endpoint and the IP address the request came from.

Cloudflare and Vercel, which host the service, also process the technical data that any web request carries — your IP address and browser user agent among them — in order to route it and keep the service available. We build no profile from it.

What we do not collect

  • No location. A place is a name and, if you want, an address, both typed by you, up to 200 characters each. Neither app asks for the location permission, and neither reads GPS.
  • No analytics and no advertising. There is no analytics SDK, no advertising SDK and no third-party tracker in either app. We do not profile you, and we sell nothing.
  • No payment data. BeBest has no purchases.
  • No access to your contacts, photos, files, microphone or camera.
  • No health or fitness data from your device. Nothing is read from Apple Health, Google Fit or a wearable.
  • No automated decision-making or profiling in the sense of Article 22 GDPR.

One thing worth naming rather than omitting: Google Play collects crash and ANR reports from installed Android apps through Android vitals. Google collects those as the distributor of the app; they reach us aggregated and we cannot tie them to your account.

Why we process it, and on what legal basis

Running your account and the service — goals, sessions, observations, assessments
Performance of the contract between you and us, Article 6(1)(b) GDPR. Without this data the app has nothing to show you.
Signing you in and keeping the account secure — password hashing, sessions, address confirmation, password reset
Performance of the contract, and our legitimate interest in keeping accounts secure, Article 6(1)(b) and (f).
Preventing abuse — rate limits on sign-in and on the emails we send (confirmation, password reset, notice)
Our legitimate interest in stopping brute-force attempts, and in stopping our own email being used to flood somebody else, Article 6(1)(f).
Answering a request you send us about your data
Our legal obligation to respond, Article 6(1)(c).

Who else processes your data

Four providers, each acting as a processor on our instructions. Nobody else receives your data. It is never sold, rented or shared for advertising.

Cloudflare, Inc.
Hosts the API and the database. Everything listed above is stored there.
Vercel Inc.
Hosts this website — the pages you are reading — and the web version of the app, at app.bebestplus.com. For the web version it forwards your requests to the API and relays the API’s responses back: your email, password and name when you sign in or sign up, the session cookie, and the account data the API returns all pass through Vercel. It forwards them without storing them. This website, by contrast, forwards nothing to the API.
Resend
Sends the account emails: the one that confirms your address when you sign up, the password-reset email, and a notice if someone tries to sign up again with your address. It receives your email address and the contents of those messages.
Google (Google Play)
Distributes the Android app and collects crash and ANR reports through Android vitals.

Transfers outside the EU

All four providers are United States companies, so your data may be processed outside the European Economic Area. Those transfers rest on the safeguards in each provider’s data processing agreement: the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework.

How long we keep it

  • Your account and your training data: for as long as the account exists. There is no automatic expiry, and we do not delete inactive accounts on our own initiative.
  • Session tokens: until you sign out or they expire. Password-reset tokens: one hour. Resetting a password signs out every other session.
  • Abuse-prevention counters keyed to your email address: removed when your account is deleted. The counters keyed to an IP address are not tied to any account, are not removed with it, and are overwritten by normal use of the limit.

One honest limit. Our database provider keeps its own point-in-time backups for a limited window that it defines, so a copy of a deleted row can survive there for a short time after we have erased it. We cannot reach into those backups, and they are overwritten on the provider’s own schedule.

What “delete” actually means here

Two different things, and it is worth being precise about which is which.

Deleting a goal, a session, an observation or an assessment inside the app
It disappears from every screen and from every API response immediately, and it does not come back: there is no bin and no restore. The row itself, however, stays in the database flagged as deleted until the account is deleted. We would rather write that down than let you assume it is already gone.
Deleting your account
A hard delete. Your user record, your sport, your goals, your sessions, your places, your recurring trainings, your observations, your assessments, your session notes, your sign-in credentials and sessions, and the abuse counters tied to your email address are removed from the database in a single transaction — including every row you had already deleted inside the app. Nothing is flagged and kept.

There is no deleted-account state and no recovery period. Once the account is deleted we cannot restore it, and neither can you.

Your rights

Under the GDPR you can ask for access to your data, correction of it, erasure, restriction of processing and portability of the data you gave us, and you can object to the processing we base on our legitimate interest.

Write to federico.dinatale.bebest@gmail.com to exercise any of them. We answer within one month of the request, as Article 12(3) requires.

Being straight about correction: your email address and your display name cannot be changed from inside the app. No screen and no API endpoint updates them. If either is wrong, writing to the address above is the only way to correct it — we are not going to point you at a self-service option that does not exist.

If you believe we have handled your data badly you can complain to the Italian supervisory authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or to the authority of the EU country you live in.

How it is protected

  • Passwords are stored only as hashes. Nobody, ourselves included, can read them.
  • All traffic runs over HTTPS.
  • Every API call is checked for a valid session and for ownership of the data it touches. A request for someone else’s goal is refused exactly as a request for a goal that does not exist is, so nothing can be learned by asking.
  • Sign-in attempts, password-reset requests, resends of the confirmation email and sign-ups with an already registered address are rate limited.

No system is perfectly secure, and we do not claim otherwise.

Cookies and local storage

This website sets no cookies at all. There is no sign-in here, so there is no session to keep.

It also keeps your language choice in your browser’s local storage, under the key bebest.language. That value never leaves your device and is never sent to us.

The web version of the app, at app.bebestplus.com, does set one cookie: __Secure-better-auth.session_token, the session cookie that keeps you signed in. It is a technical cookie, needed to stay signed in once you have signed in. It is httpOnly, so no script on the page can read it. It lasts seven days, renewed as you use the app, and it is deleted when you sign out. In your browser’s local storage the web version keeps two things only, both chosen in the Profile: the language, under the key bebest.language, and the theme (system, light or dark), under the key bebest.theme. Those values never leave your device and are never sent to us.

There are no analytics cookies, no advertising cookies and no third-party cookies. That is why you see no cookie banner: the only cookie is the session cookie, which is technical and needs no consent. The bebest.language and bebest.theme keys are choices you make yourself, used only to show you the language and the theme you asked for, and need no consent either. There is nothing else to consent to.

Changes to this policy

If this policy changes, the new version is published at this address and the date at the top changes with it. A material change is reflected here before it takes effect in the product.

Questions about any of the above: federico.dinatale.bebest@gmail.com.