Back to home
Privacy-first

Privacy Policy

Effective date: June 2, 2026 · Last updated: June 2, 2026

1. Who we are

Body-OS is a wellness and lifestyle service that analyzes user-authorized data (including WHOOP data) to provide personalized guidance for recovery, sleep, training load, and daily routines.

Body-OS is not a medical device and does not provide medical services.

For privacy law purposes, Body-OS acts as the controller of account data and user-authorized imported data.

Privacy contact: privacy@body-os.fit.

2. Wellness, not medicine

Body-OS is designed for wellness and lifestyle use only.

Body-OS does not diagnose, treat, cure, or prevent disease and does not replace professional medical advice.

WHOOP data is used only for wellness purposes and not in a clinical context.

3. WHOOP consent, access, and revocation

When you choose Connect WHOOP, you complete WHOOP OAuth 2.0 authorization and explicitly consent to importing data within authorized scopes.

We request only the minimum scopes required for service features:

  • read:profile
  • read:body_measurement
  • read:sleep
  • read:recovery
  • read:cycle
  • read:workout
  • offline (to continue sync without repeated sign-in)

You can revoke WHOOP access at any time in Body-OS settings and/or WHOOP account settings. After revocation, new sync operations are stopped.

Body-OS is not affiliated with or endorsed by WHOOP, Inc. WHOOP is a trademark of WHOOP, Inc.

4. Data we collect

A. Account data:

  • email
  • password hash
  • language
  • timezone
  • internal identifiers

B. Wellness and usage data:

  • authorized WHOOP data
  • onboarding goals and user settings
  • progress in missions, contracts, and protocols
  • feature usage events

C. Technical and security data:

  • device/app metadata
  • session and security logs
  • diagnostics and stability data

D. AI interaction data:

  • messages sent to AI features
  • metadata needed to generate and secure responses

5. How we use data

We use data only to provide, maintain, and secure the service:

  • account operations, authentication, and abuse prevention
  • sync and analysis of authorized WHOOP data
  • personalized wellness insights and AI guidance
  • subscription and access lifecycle
  • customer support
  • quality, anti-fraud, and reliability

We do not sell personal data.

We do not use health/wellness data for targeted advertising.

6. GDPR and UK GDPR legal bases

Depending on purpose, processing is based on:

  • contract performance
  • consent
  • legitimate interests
  • legal obligations

Where health-related processing applies, we rely on explicit consent and additional safeguards.

7. AI processing and automated decision-making

Body-OS uses AI to generate wellness insights and text guidance.

AI output is informational and not medical advice.

Body-OS does not rely on solely automated decisions that produce legal or similarly significant effects.

AI providers are governed by contractual and technical safeguards. Service configuration is intended to prevent public model training on user data where supported by provider terms.

8. Third parties and subprocessors

We use a limited set of providers strictly for service operations:

  • WHOOP (OAuth and API data source)
  • cloud infrastructure and hosting
  • AI infrastructure
  • transactional email providers
  • payment and subscription providers
  • privacy-safe attribution/analytics providers

We do not share personal data with data brokers for sale.

9. International data transfers

Data may be processed outside your country of residence.

Where required, we use recognized transfer mechanisms such as SCCs and equivalent EU/UK safeguards (including UK Addendum/IDTA where applicable).

10. Retention, deletion, and backups

We retain data only as long as needed for stated purposes.

  • account data: while account is active
  • security logs: typically up to 90 days
  • support/investigation records: operational and legal necessity
  • backups: removed on rolling retention cycles

After account deletion requests, primary systems are generally cleared within up to 30 days; backup copies are removed on normal backup rotation schedules.

11. Data export and account deletion

You may request:

  • machine-readable data export
  • full account deletion
  • WHOOP disconnection and sync stop

Requests: privacy@body-os.fit.

12. Data subject rights

Depending on jurisdiction, you may have rights of access, correction, deletion, restriction, objection, portability, and consent withdrawal.

To exercise rights, contact privacy@body-os.fit. Identity verification may be required.

13. Cookies, SDKs, and similar technologies

We use cookies/SDKs/local storage for authentication, security, preferences, subscriptions, and limited analytics/attribution.

We do not send health/wellness data to ad networks for ad personalization.

14. Security measures

We apply reasonable technical and organizational safeguards including encryption in transit, access controls, logging, and incident monitoring.

No security system is perfect, but we continuously improve protection measures.

15. Children's privacy

Body-OS is not intended for children. If you believe a child has provided personal data, contact us at privacy@body-os.fit.

16. California privacy rights

California residents may have additional rights (including rights to know, delete, and correct data, and non-discrimination when exercising privacy rights).

Body-OS does not sell personal data.

17. Apple App Store and Google Play disclosures

We maintain disclosures required by Apple App Privacy and Google Play Data Safety and update them when SDKs or features change.

18. Policy updates and contact

We may update this policy from time to time. The current version is always posted on this page.

For privacy requests, account deletion, data export, and WHOOP consent revocation: privacy@body-os.fit.

For account deletion, data export, WHOOP consent revocation, and all privacy requests, contact: privacy@body-os.fit.
Body-OS · body-os.fit · All rights reserved