QUANTROPY PUBLIC POLICY / WHOOP

WHOOP INTEGRATION

Privacy policy

A plain account of what the private Quantropy WHOOP integration reads, why it reads it, where it goes, and how to remove it.

Consent-bound Minimum necessary data No sale of health data

01 Scope and operator

This policy covers the private WHOOP integration operated by Rudy under the Quantropy name. It applies when a person authorizes the integration through WHOOP OAuth and asks it to retrieve or summarize that person's WHOOP data.

Quantropy is the project name used for this personal integration. This page does not claim that Quantropy is a separately incorporated legal entity.

02 Data processed

With explicit WHOOP authorization, the integration may process:

  • OAuth authorization details, access tokens, refresh tokens, granted scopes, and token expiry information.
  • Physiological cycles and day strain.
  • Recovery scores and supporting recovery measurements.
  • Sleep activity, performance, and sleep-stage durations.
  • Workout activity and workout strain.

03 Authorization and purpose

The data is used only to authenticate the integration, retrieve the member's requested WHOOP records, produce requested personal wellness summaries, diagnose connection failures, and maintain reliable token refresh.

WHOOP OAuth authorization controls the integration's API access. Data is processed only after the member authorizes the requested scopes and asks to use the integration, relying on consent where that is the applicable legal basis. Authorization may be withdrawn at any time. WHOOP results are wellness information, not medical advice, diagnosis, or treatment.

04 Processors and sharing

Health data is not sold, rented, used for advertising, or shared with unrelated parties. The following services may process limited data as necessary to operate the integration:

  • WHOOP — source of authorized member data and OAuth services.
  • Hermes infrastructure and the configured AI model provider — requested measurements may enter the active model context to generate the summary the member requested. As of this policy's effective date, the active provider is OpenAI. The provider can change; the member may request the current provider before processing.
  • VPS and infrastructure providers — host the private integration and its protected token files.
  • Vercel — hosts this public policy page. This page has no analytics, advertising, or application login.
  • ImprovMX and Google Gmail — route and receive messages sent to the policy contact address.

Data may also be disclosed when required by applicable law or to protect the security and integrity of the service.

05 Storage and retention

OAuth tokens are stored server-side in a private directory with restrictive access permissions. Client secrets and tokens are not placed in this website or browser code.

WHOOP records are fetched on demand. The integration does not maintain a separate long-term health-record database by default. Requested summaries and tool results may remain in protected Hermes session history until the relevant session is deleted. If no deletion request or operator cleanup occurs, that history may be retained indefinitely.

Local OAuth tokens are retained until authorization expires, the member disconnects the integration, or deletion is requested. Deletion requests for operator-controlled tokens, session records, and exports are completed within 30 days after reasonable identity verification. Security records may be retained for up to 30 additional days, or longer when required to investigate abuse or comply with law.

Copies the member downloads or moves to member-controlled storage are controlled by that member and cannot be deleted by the operator. Operator-controlled exports are covered by the 30-day deletion commitment above.

06 Your control

The member may:

  • Decline or limit scopes during WHOOP authorization.
  • Revoke the integration in WHOOP account settings.
  • Request deletion of locally stored tokens, summaries, and exported data by emailing rudy@quantropy.co.
  • Ask what information is held and request correction or deletion where applicable.

Revoking access in WHOOP stops future API access. Removing only the local token cache does not itself revoke authorization at WHOOP.

07 Security and limits

The integration uses server-side OAuth, access controls intended to protect token files, rotating refresh tokens, and a restricted default scope set. No system can guarantee absolute security. Suspected misuse should be reported immediately to the contact below.

This integration is not directed to children and is not intended for use by anyone who cannot legally consent to the processing of their own health and wellness information.

08 Contact and changes

Privacy requests and security reports can be sent to rudy@quantropy.co. Requests will be handled after reasonable identity and account verification.

This policy may change when the integration's data use or providers change. Material changes will be published at this URL with a revised effective date before they apply to newly collected data.