Privacy policy

Privacy

Last updated 14 August 2026. H5 Innovations AS operates FitnessPeak and is the data controller.

Summary. We store your email, an encrypted WHOOP token, and a log of which tools were called. We do not store your health records, we do not sell or share your data, and we do not use it to train models. Delete your account and everything goes.

What FitnessPeak does with your WHOOP data

If you arrived here from WHOOP's authorisation screen, this is the section you want. Everything below it is the full policy.

What we ask WHOOP for

FitnessPeak requests these scopes, all of them read-only. WHOOP lists them on the consent screen before you approve, and you can decline any of them.

ScopeWhat it lets us readWhy we need it
read:recoveryRecovery score, resting heart rate, HRV, blood oxygen, skin temperatureThe whoop_recovery tool
read:sleepSleep stages, duration, performance, efficiency, respiratory rateThe whoop_sleep tool
read:workoutPer-workout sport, strain, heart rate, calories, distanceThe whoop_workouts tool
read:cyclesWhole-day strain and heart rateThe whoop_cycles tool
read:profileYour name, email and WHOOP user idShowing which WHOOP account is connected
read:body_measurementHeight, weight, max heart rateCalculations that need to normalise by body mass or heart-rate reserve
offlineNothing on its ownLets us refresh the access token so the connection survives past an hour

What we can never do

  • We cannot write to your WHOOP account. We request no write scopes, so we cannot log workouts, edit journal entries, or change any setting — regardless of what our code does.
  • We never see your WHOOP password. You authorise on WHOOP's own screen; we receive a scoped token, nothing else.
  • We do not read anything outside these scopes. WHOOP enforces that, not us.

Where your WHOOP data goes

When your AI assistant calls a tool, FitnessPeak fetches the relevant records from WHOOP, formats them as a table, and returns them to your assistant. We do not keep a copy. There is no database of your recovery scores here — only the encrypted token used to fetch them on demand, and a log of which tool was called and how long it took.

One thing worth being clear about: the data your assistant receives goes to your AI provider — Anthropic, OpenAI, or whoever you use — under their privacy policy, not ours. That is inherent to connecting any data source to an AI assistant. Choose your client accordingly.

Your explicit opt-in

Before you can connect any source, FitnessPeak asks you to tick a box confirming you understand that the data your assistant requests is transmitted to your AI provider. That is a requirement of WHOOP's developer terms, which prohibit exposing WHOOP data to a third party without the explicit opt-in of the person it belongs to — and your AI provider is a third party.

We record the exact wording you agreed to and when, not merely that you agreed. Withdrawing it from your dashboard disconnects every source immediately, because consent that does not stop the transmission is not consent.

How to disconnect

Two independent routes, and either one is enough:

  • From FitnessPeak: your dashboard → Disconnect. The stored tokens are deleted immediately.
  • From WHOOP: revoke FitnessPeak's access in your WHOOP account settings. This works even if we've stopped functioning, and our tokens stop working the moment you do it.

Deleting your FitnessPeak account does both, plus removes everything else we hold. See your rights below.


1. What we collect

You give us

  • Email address — for sign-in and service email.
  • Payment details — entered directly with Mollie, our payment processor. We receive a customer reference and payment status; we never see your card number.

WHOOP gives us, with your consent

  • OAuth tokens — encrypted at rest, used to fetch data when a tool is called.
  • Your WHOOP name, email and user id — so the dashboard can show which account is connected.

Generated by use

  • Tool call log — which tool, when, how long, whether it succeeded. Not the data returned.
  • Server logs — standard request logs, with API keys redacted, retained about 30 days.

2. What we do not collect

  • We do not store your WHOOP recovery, sleep, workout or cycle records. They are fetched on demand and passed straight to your MCP client.
  • We do not store your WHOOP password — you authorise through WHOOP's own screen.
  • We do not store card numbers.
  • We run no advertising, analytics or tracking scripts on this site.

3. Why we process it

PurposeLegal basis (GDPR)
Providing the service you subscribed toContract (Art. 6(1)(b))
Taking payment and preventing fraudContract and legitimate interests
Service emails — trial ending, payment receipts, broken connectionContract
Security, abuse prevention and rate limitingLegitimate interests (Art. 6(1)(f))
Accessing your WHOOP dataYour explicit consent, given at the WHOOP consent screen

Health data is a special category under GDPR Art. 9. We process it on the basis of your explicit consent, which you give when you authorise the WHOOP connection and can withdraw at any time by disconnecting.

4. Who we share it with

Three processors, and nobody else:

ProcessorWhat they getWhy
WHOOP, Inc.API requests carrying your tokenThe source of the data
Mollie B.V.Email, name, payment detailsPayment processing
Brevo (Sendinblue)Email address, message contentTransactional email

We do not sell your data. We do not share it with advertisers. We do not use it to train machine-learning models. If we were ever compelled to disclose data by law, we would tell you unless legally prevented from doing so.

Note the obvious one: when your assistant calls a tool, the returned data goes to your AI client. What that provider does with it is governed by their privacy policy, not ours.

5. Retention

DataKept
Account and WHOOP connectionUntil you delete your account
Tool call log12 months, then deleted
Server logsAbout 30 days
Payment recordsAs required by accounting law, typically 5 years

6. Your rights

Under GDPR you can request access, correction, deletion, restriction, portability, and object to processing. Most of these are self-service: your dashboard shows everything we hold and the delete button removes it immediately. For anything else, email hello@fitnesspeak.app — we'll respond within 30 days.

You also have the right to complain to your local data protection authority.

7. Transfers

Our servers are in the EU. WHOOP is a US company, so calling their API transfers data to the US — that transfer is inherent to using WHOOP at all and happens with your consent. Mollie and Brevo are EU-based.

8. Cookies

One cookie: fp_session, holding your signed session token. It is httpOnly, Secure, SameSite=Lax, and expires after 30 days. It is strictly necessary for sign-in, so there is no consent banner. We set no analytics or advertising cookies — the marketing pages set no cookies at all.

9. Children

FitnessPeak is not for anyone under 16. We don't knowingly collect their data; if you believe a child has an account, email us and we'll remove it.

10. Changes

If we change this policy materially we'll email active subscribers before it takes effect. The date at the top always reflects the current version.

Contact

H5 Innovations AS — hello@fitnesspeak.app