WHOOP INTEGRATION
Privacy policy
A plain account of what the private Quantropy WHOOP integration reads, why it reads it, where it goes, and how to remove it.
01 Scope and operator
This policy covers the private WHOOP integration operated by Rudy under the Quantropy name. It applies when a person authorizes the integration through WHOOP OAuth and asks it to retrieve or summarize that person's WHOOP data.
Quantropy is the project name used for this personal integration. This page does not claim that Quantropy is a separately incorporated legal entity.
02 Data processed
With explicit WHOOP authorization, the integration may process:
- OAuth authorization details, access tokens, refresh tokens, granted scopes, and token expiry information.
- Physiological cycles and day strain.
- Recovery scores and supporting recovery measurements.
- Sleep activity, performance, and sleep-stage durations.
- Workout activity and workout strain.
03 Authorization and purpose
The data is used only to authenticate the integration, retrieve the member's requested WHOOP records, produce requested personal wellness summaries, diagnose connection failures, and maintain reliable token refresh.
WHOOP OAuth authorization controls the integration's API access. Data is processed only after the member authorizes the requested scopes and asks to use the integration, relying on consent where that is the applicable legal basis. Authorization may be withdrawn at any time. WHOOP results are wellness information, not medical advice, diagnosis, or treatment.
05 Storage and retention
OAuth tokens are stored server-side in a private directory with restrictive access permissions. Client secrets and tokens are not placed in this website or browser code.
WHOOP records are fetched on demand. The integration does not maintain a separate long-term health-record database by default. Requested summaries and tool results may remain in protected Hermes session history until the relevant session is deleted. If no deletion request or operator cleanup occurs, that history may be retained indefinitely.
Local OAuth tokens are retained until authorization expires, the member disconnects the integration, or deletion is requested. Deletion requests for operator-controlled tokens, session records, and exports are completed within 30 days after reasonable identity verification. Security records may be retained for up to 30 additional days, or longer when required to investigate abuse or comply with law.
Copies the member downloads or moves to member-controlled storage are controlled by that member and cannot be deleted by the operator. Operator-controlled exports are covered by the 30-day deletion commitment above.
06 Your control
The member may:
- Decline or limit scopes during WHOOP authorization.
- Revoke the integration in WHOOP account settings.
- Request deletion of locally stored tokens, summaries, and exported data by emailing rudy@quantropy.co.
- Ask what information is held and request correction or deletion where applicable.
Revoking access in WHOOP stops future API access. Removing only the local token cache does not itself revoke authorization at WHOOP.
07 Security and limits
The integration uses server-side OAuth, access controls intended to protect token files, rotating refresh tokens, and a restricted default scope set. No system can guarantee absolute security. Suspected misuse should be reported immediately to the contact below.
This integration is not directed to children and is not intended for use by anyone who cannot legally consent to the processing of their own health and wellness information.
08 Contact and changes
Privacy requests and security reports can be sent to rudy@quantropy.co. Requests will be handled after reasonable identity and account verification.
This policy may change when the integration's data use or providers change. Material changes will be published at this URL with a revised effective date before they apply to newly collected data.