Privacy
Last updated 14 August 2026. H5 Innovations AS operates FitnessPeak and is the data controller.
Summary. We store your email, an encrypted WHOOP token, and a log of which tools were called. We do not store your health records, we do not sell or share your data, and we do not use it to train models. Delete your account and everything goes.
What FitnessPeak does with your WHOOP data
If you arrived here from WHOOP's authorisation screen, this is the section you want. Everything below it is the full policy.
What we ask WHOOP for
FitnessPeak requests these scopes, all of them read-only. WHOOP lists them on the consent screen before you approve, and you can decline any of them.
| Scope | What it lets us read | Why we need it |
|---|---|---|
read:recovery | Recovery score, resting heart rate, HRV, blood oxygen, skin temperature | The whoop_recovery tool |
read:sleep | Sleep stages, duration, performance, efficiency, respiratory rate | The whoop_sleep tool |
read:workout | Per-workout sport, strain, heart rate, calories, distance | The whoop_workouts tool |
read:cycles | Whole-day strain and heart rate | The whoop_cycles tool |
read:profile | Your name, email and WHOOP user id | Showing which WHOOP account is connected |
read:body_measurement | Height, weight, max heart rate | Calculations that need to normalise by body mass or heart-rate reserve |
offline | Nothing on its own | Lets us refresh the access token so the connection survives past an hour |
What we can never do
- We cannot write to your WHOOP account. We request no write scopes, so we cannot log workouts, edit journal entries, or change any setting — regardless of what our code does.
- We never see your WHOOP password. You authorise on WHOOP's own screen; we receive a scoped token, nothing else.
- We do not read anything outside these scopes. WHOOP enforces that, not us.
Where your WHOOP data goes
When your AI assistant calls a tool, FitnessPeak fetches the relevant records from WHOOP, formats them as a table, and returns them to your assistant. We do not keep a copy. There is no database of your recovery scores here — only the encrypted token used to fetch them on demand, and a log of which tool was called and how long it took.
One thing worth being clear about: the data your assistant receives goes to your AI provider — Anthropic, OpenAI, or whoever you use — under their privacy policy, not ours. That is inherent to connecting any data source to an AI assistant. Choose your client accordingly.
Your explicit opt-in
Before you can connect any source, FitnessPeak asks you to tick a box confirming you understand that the data your assistant requests is transmitted to your AI provider. That is a requirement of WHOOP's developer terms, which prohibit exposing WHOOP data to a third party without the explicit opt-in of the person it belongs to — and your AI provider is a third party.
We record the exact wording you agreed to and when, not merely that you agreed. Withdrawing it from your dashboard disconnects every source immediately, because consent that does not stop the transmission is not consent.
How to disconnect
Two independent routes, and either one is enough:
- From FitnessPeak: your dashboard → Disconnect. The stored tokens are deleted immediately.
- From WHOOP: revoke FitnessPeak's access in your WHOOP account settings. This works even if we've stopped functioning, and our tokens stop working the moment you do it.
Deleting your FitnessPeak account does both, plus removes everything else we hold. See your rights below.
1. What we collect
You give us
- Email address — for sign-in and service email.
- Payment details — entered directly with Mollie, our payment processor. We receive a customer reference and payment status; we never see your card number.
WHOOP gives us, with your consent
- OAuth tokens — encrypted at rest, used to fetch data when a tool is called.
- Your WHOOP name, email and user id — so the dashboard can show which account is connected.
Generated by use
- Tool call log — which tool, when, how long, whether it succeeded. Not the data returned.
- Server logs — standard request logs, with API keys redacted, retained about 30 days.
2. What we do not collect
- We do not store your WHOOP recovery, sleep, workout or cycle records. They are fetched on demand and passed straight to your MCP client.
- We do not store your WHOOP password — you authorise through WHOOP's own screen.
- We do not store card numbers.
- We run no advertising, analytics or tracking scripts on this site.
3. Why we process it
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the service you subscribed to | Contract (Art. 6(1)(b)) |
| Taking payment and preventing fraud | Contract and legitimate interests |
| Service emails — trial ending, payment receipts, broken connection | Contract |
| Security, abuse prevention and rate limiting | Legitimate interests (Art. 6(1)(f)) |
| Accessing your WHOOP data | Your explicit consent, given at the WHOOP consent screen |
Health data is a special category under GDPR Art. 9. We process it on the basis of your explicit consent, which you give when you authorise the WHOOP connection and can withdraw at any time by disconnecting.
4. Who we share it with
Three processors, and nobody else:
| Processor | What they get | Why |
|---|---|---|
| WHOOP, Inc. | API requests carrying your token | The source of the data |
| Mollie B.V. | Email, name, payment details | Payment processing |
| Brevo (Sendinblue) | Email address, message content | Transactional email |
We do not sell your data. We do not share it with advertisers. We do not use it to train machine-learning models. If we were ever compelled to disclose data by law, we would tell you unless legally prevented from doing so.
Note the obvious one: when your assistant calls a tool, the returned data goes to your AI client. What that provider does with it is governed by their privacy policy, not ours.
5. Retention
| Data | Kept |
|---|---|
| Account and WHOOP connection | Until you delete your account |
| Tool call log | 12 months, then deleted |
| Server logs | About 30 days |
| Payment records | As required by accounting law, typically 5 years |
6. Your rights
Under GDPR you can request access, correction, deletion, restriction, portability, and object to processing. Most of these are self-service: your dashboard shows everything we hold and the delete button removes it immediately. For anything else, email hello@fitnesspeak.app — we'll respond within 30 days.
You also have the right to complain to your local data protection authority.
7. Transfers
Our servers are in the EU. WHOOP is a US company, so calling their API transfers data to the US — that transfer is inherent to using WHOOP at all and happens with your consent. Mollie and Brevo are EU-based.
8. Cookies
One cookie: fp_session, holding your signed session token. It is httpOnly, Secure, SameSite=Lax, and expires after 30 days. It is strictly necessary for sign-in, so there is no consent banner. We set no analytics or advertising cookies — the marketing pages set no cookies at all.
9. Children
FitnessPeak is not for anyone under 16. We don't knowingly collect their data; if you believe a child has an account, email us and we'll remove it.
10. Changes
If we change this policy materially we'll email active subscribers before it takes effect. The date at the top always reflects the current version.
Contact
H5 Innovations AS — hello@fitnesspeak.app