Health Log Local

Privacy Policy

Effective September 3, 2026

Health Log Local (the “App”) is a private, non-commercial integration operated and used by its account owner for personal health record keeping. This policy explains how the App handles data obtained through the WHOOP API.

Data the App accesses

The App may read the following data after the WHOOP member grants permission:

The App does not request WHOOP profile access and never receives the member’s WHOOP password.

How the data is used

Data is used solely for the account owner’s personal backup, longitudinal health tracking, and personal analysis. It is not used for advertising, profiling other people, or automated decisions about eligibility, employment, insurance, or credit.

Storage and security

API responses are downloaded to the account owner’s local computer. The owner may also store them in a private GitHub repository under the owner’s control. OAuth credentials are kept outside that repository with owner-only file permissions. WHOOP health records and API tokens are not submitted to or processed by this public policy website or the OAuth callback service.

A Cloudflare Worker receives the OAuth callback because the local application has no public web endpoint. It temporarily stores the one-time authorization code for no more than ten minutes, releases it only to the initiating local process using a separate random polling token, and deletes it immediately after retrieval or on expiry. The Worker does not receive the WHOOP Client Secret, access token, refresh token, password, or health records.

Sharing

The App does not sell WHOOP data or share it publicly. Data is only handled by services the owner deliberately uses to operate the App, such as WHOOP for API access and, if enabled by the owner, GitHub for private storage. Cloudflare hosts this policy page and temporarily processes the one-time OAuth authorization code as described above.

Retention, deletion, and revocation

Data is retained until the account owner deletes the local files and any private repository copies. The member may revoke the App’s WHOOP access at any time through WHOOP account settings. Revocation prevents future API access; locally retained copies can be deleted separately by the owner.

Cookies and analytics

This policy page sets no cookies, contains no analytics, and has no form or tracking script. Cloudflare may process ordinary web-request metadata as the hosting provider under its own privacy terms.

Contact

Privacy questions may be sent to the contact address displayed for Health Log Local in the WHOOP authorization screen.

Changes to this policy

Material changes will be published on this page with a revised effective date before the App requests additional categories of WHOOP data or uses existing data for a new purpose.