Atlas is a personal application operated by and for a single user (the owner of this application). This policy describes how health data from connected services — including the WHOOP API — is collected, stored, and used within the Vitals module of Atlas.
1. Who operates this application
Atlas is a private, single-user application. It is not a commercial product or public service. No third parties have access to this application or the data it contains. The operator can be reached at [email protected].
2. What data is collected
When connected to WHOOP via OAuth, this application collects the following data on your behalf:
- Recovery data — recovery score, HRV, resting heart rate
- Sleep data — sleep duration, sleep score, start and end times
- Workout data — activity type, duration, strain, accumulated load
- Cycle data — day strain, average heart rate during a cycle
- Profile data — basic profile information
- Body measurements — height, weight, max heart rate
Additionally, this application may collect manually entered health data including bloodwork results, nutrition logs, supplement tracking, and workout logs.
3. How data is used
All data collected is used solely for:
- Displaying personal health metrics on the dashboard
- Calculating composite health scores (Live Forever Score, biological age estimation)
- Tracking trends over time for personal insight
Data is never used for advertising, sold, or shared with any third parties.
4. Data storage
Health data collected by this application is stored in a private Supabase-hosted PostgreSQL database (US region). The database is accessed only from the application server, using a service-role credential that is never exposed to the browser or to any third party — the database is not publicly readable or writable. This application does not use any third-party analytics, advertising, or tracking services that could read this data.
OAuth tokens from WHOOP are stored in this same database and used only to authenticate requests to the WHOOP API on your behalf. They are never logged or transmitted to any party other than WHOOP.
5. Data sharing
No data collected by this application is shared with any third parties. This application is not connected to analytics services, advertising networks, or data brokers.
6. Your rights
As the sole user of this application, you have full control over all data. You may disconnect your WHOOP account at any time through the Whoop page within the application, which will revoke stored tokens and delete synced data. You may also delete manually entered data at any time.
7. Third-party services
This application connects to the WHOOP Developer API to retrieve your health data on your behalf. WHOOP’s own privacy practices are governed by WHOOP’s Privacy Policy. Data retrieved from WHOOP is subject to the WHOOP API Terms of Use.
8. HIPAA
This application is not a covered entity or business associate under HIPAA and is not intended for use in any clinical or healthcare context. It is a personal wellness tracking tool only.
9. Changes to this policy
This policy may be updated as the application evolves. The “last updated” date at the top of this page reflects the most recent revision.
10. Contact
Questions regarding this privacy policy can be directed to [email protected].