Michael WHOOP Private — privacy policy

Effective when this private application is activated. Prepared 1 October 2026. Operated by Michael Browk solely for his own WHOOP account; no public sign-up or third-party users. Michael is the operator and data subject and manages support and deletion directly through his own server account. This application is independent of and is not endorsed by WHOOP.

Data and purpose

After the owner personally approves WHOOP authorization, the application reads sleep, recovery (including HRV and resting heart rate), physiological cycles/daily strain, and workouts. These records may include timestamps, activity identifiers, sleep stages, respiratory rate, oxygen saturation, skin temperature, exercise heart-rate summaries/zones and other metrics within those four WHOOP scopes. Profile and body-measurement scopes are not requested. Continuous heart-rate samples are not available. Data is used only to answer the owner's requests in dot/OpenAI; no advertising, sale, public sharing, model training by this server, diagnosis or medical recommendations.

Transfers and access

WHOOP sends requested records over HTTPS to the owner's existing DigitalOcean server. After a separate owner-approved OAuth grant, requested data is sent over HTTPS to dot/OpenAI. DigitalOcean operates the hosting infrastructure. OpenAI processes and may retain data under the owner's applicable product settings and OpenAI policies; this server cannot promise zero retention, training exclusion or deletion in OpenAI. Only the owner can authorize this private application. No other recipient is intentionally configured by this service. The owner is responsible for any subsequent sharing of responses.

Storage and security

This service keeps health records in memory only while processing a request and does not create a health-data archive, analytics database, webhook queue or payload log. WHOOP client credentials and access/refresh tokens are encrypted at rest with a dedicated encryption key. The key is stored separately with restricted permissions on the same server: this does not protect against a server administrator or full host compromise. The owner password is stored as an Argon2 hash. dot access/refresh tokens and authorization codes are stored only as cryptographic hashes; limited OAuth client/grant metadata is retained for access control. Public pages contain no trackers or external scripts. Application and virtual-host request logs are disabled. This service disables its own swapping and core dumps where the host supports these controls. Existing host-level security/SSH/network logs may record connection metadata.

Retention, withdrawal and deletion

Encrypted WHOOP credentials remain until the owner disconnects, erases or replaces them. Access can be stopped by revoking the application in WHOOP, revoking dot grants at Manage access, and removing the connector in OpenAI. The private SSH commands whoop-mcp-setup disconnect and whoop-mcp-setup erase clear local tokens or all local provider credentials and the key, respectively. Revocation in WHOOP must be completed personally first. Server snapshots/backups, if enabled independently by the owner, may contain older encrypted files and the key and require separate deletion. No additional backup service is configured here. Deleting local state does not delete source records at WHOOP or conversations/data retained by OpenAI. The owner manages those separately.

Accuracy and incidents

WHOOP records can be delayed, unscored, revised or withdrawn; missing values are not treated as zero. The service provides personal informational access, not medical care. If an incident is discovered, the operator will disable affected access, revoke/rotate credentials, investigate, and notify WHOOP as required by its API terms (within 48 hours of discovery), plus any required data-subject notifications. No automated incident reporting or monitoring guarantee is implied.

WHOOP API terms · OpenAI privacy policy · DigitalOcean privacy policy