Privacy Policy
Effective date: June 2, 2026 · Last updated: June 2, 2026
1. Who we are
Body-OS is a wellness and lifestyle service that analyzes user-authorized data (including WHOOP data) to provide personalized guidance for recovery, sleep, training load, and daily routines.
Body-OS is not a medical device and does not provide medical services.
For privacy law purposes, Body-OS acts as the controller of account data and user-authorized imported data.
Privacy contact: privacy@body-os.fit.
2. Wellness, not medicine
Body-OS is designed for wellness and lifestyle use only.
Body-OS does not diagnose, treat, cure, or prevent disease and does not replace professional medical advice.
WHOOP data is used only for wellness purposes and not in a clinical context.
3. WHOOP consent, access, and revocation
When you choose Connect WHOOP, you complete WHOOP OAuth 2.0 authorization and explicitly consent to importing data within authorized scopes.
We request only the minimum scopes required for service features:
- read:profile
- read:body_measurement
- read:sleep
- read:recovery
- read:cycle
- read:workout
- offline (to continue sync without repeated sign-in)
You can revoke WHOOP access at any time in Body-OS settings and/or WHOOP account settings. After revocation, new sync operations are stopped.
Body-OS is not affiliated with or endorsed by WHOOP, Inc. WHOOP is a trademark of WHOOP, Inc.
4. Data we collect
A. Account data:
- password hash
- language
- timezone
- internal identifiers
B. Wellness and usage data:
- authorized WHOOP data
- onboarding goals and user settings
- progress in missions, contracts, and protocols
- feature usage events
C. Technical and security data:
- device/app metadata
- session and security logs
- diagnostics and stability data
D. AI interaction data:
- messages sent to AI features
- metadata needed to generate and secure responses
5. How we use data
We use data only to provide, maintain, and secure the service:
- account operations, authentication, and abuse prevention
- sync and analysis of authorized WHOOP data
- personalized wellness insights and AI guidance
- subscription and access lifecycle
- customer support
- quality, anti-fraud, and reliability
We do not sell personal data.
We do not use health/wellness data for targeted advertising.
6. GDPR and UK GDPR legal bases
Depending on purpose, processing is based on:
- contract performance
- consent
- legitimate interests
- legal obligations
Where health-related processing applies, we rely on explicit consent and additional safeguards.
7. AI processing and automated decision-making
Body-OS uses AI to generate wellness insights and text guidance.
AI output is informational and not medical advice.
Body-OS does not rely on solely automated decisions that produce legal or similarly significant effects.
AI providers are governed by contractual and technical safeguards. Service configuration is intended to prevent public model training on user data where supported by provider terms.
8. Third parties and subprocessors
We use a limited set of providers strictly for service operations:
- WHOOP (OAuth and API data source)
- cloud infrastructure and hosting
- AI infrastructure
- transactional email providers
- payment and subscription providers
- privacy-safe attribution/analytics providers
We do not share personal data with data brokers for sale.
9. International data transfers
Data may be processed outside your country of residence.
Where required, we use recognized transfer mechanisms such as SCCs and equivalent EU/UK safeguards (including UK Addendum/IDTA where applicable).
10. Retention, deletion, and backups
We retain data only as long as needed for stated purposes.
- account data: while account is active
- security logs: typically up to 90 days
- support/investigation records: operational and legal necessity
- backups: removed on rolling retention cycles
After account deletion requests, primary systems are generally cleared within up to 30 days; backup copies are removed on normal backup rotation schedules.
11. Data export and account deletion
You may request:
- machine-readable data export
- full account deletion
- WHOOP disconnection and sync stop
Requests: privacy@body-os.fit.
12. Data subject rights
Depending on jurisdiction, you may have rights of access, correction, deletion, restriction, objection, portability, and consent withdrawal.
To exercise rights, contact privacy@body-os.fit. Identity verification may be required.
13. Cookies, SDKs, and similar technologies
We use cookies/SDKs/local storage for authentication, security, preferences, subscriptions, and limited analytics/attribution.
We do not send health/wellness data to ad networks for ad personalization.
14. Security measures
We apply reasonable technical and organizational safeguards including encryption in transit, access controls, logging, and incident monitoring.
No security system is perfect, but we continuously improve protection measures.
15. Children's privacy
Body-OS is not intended for children. If you believe a child has provided personal data, contact us at privacy@body-os.fit.
16. California privacy rights
California residents may have additional rights (including rights to know, delete, and correct data, and non-discrimination when exercising privacy rights).
Body-OS does not sell personal data.
17. Apple App Store and Google Play disclosures
We maintain disclosures required by Apple App Privacy and Google Play Data Safety and update them when SDKs or features change.
18. Policy updates and contact
We may update this policy from time to time. The current version is always posted on this page.
For privacy requests, account deletion, data export, and WHOOP consent revocation: privacy@body-os.fit.