Privacy Policy — Personal WHOOP Integration
Last updated: July 2, 2026
Overview
This application is a personal, single-user integration built by Mark Hobson to access his own WHOOP health and fitness data through the official WHOOP Developer API. It is not a commercial product, is not offered to other users, and does not onboard or serve any third parties.
What data is accessed
With the data owner's explicit OAuth authorization, the application reads the following from the WHOOP API:
Recovery metrics (recovery score, heart rate variability, resting heart rate)
Sleep data (duration, stages, efficiency, performance, respiratory rate)
Strain and physiological cycle data
Workout records
Basic profile and body-measurement data
The application requests read-only access. It does not write to, modify, or delete any data in the user's WHOOP account.
How the data is used
Data is used solely to display and analyze the account owner's own health trends. Processing happens locally on the account owner's personal computer.
How the data is stored and shared
OAuth tokens and any cached health data are stored locally on the account owner's own device, protected by restrictive file permissions.
Data is not sold, rented, shared, transmitted to, or disclosed to any third party.
No analytics, advertising, or tracking services are used.
Data retention and deletion
The account owner controls all stored data and may delete the local token store and any cached data at any time. Access can be revoked at any time from the WHOOP Developer Dashboard or the WHOOP account settings, which immediately ends the application's ability to read data.
Contact
For any questions about this application, contact: mark@markhobson.net
Paste that wherever you host it, then drop the resulting URL into the Whoop app's privacy policy field. Once the app is created and you've got your Client ID and Secret, ping me and we'll pick back up at installing the server.