Privacy Policy
Last updated: 2026-09-29
W5 ("the app", "we") is a personal project at w5.jmcworld.xyz. This policy explains what data the app accesses, how it is used and stored, and how you can remove it.
1. What we access
The app only accesses your WHOOP data after you explicitly connect your WHOOP account and approve the requested permissions on WHOOP's own authorization page. Depending on the permissions you grant, this may include:
- Profile — your WHOOP user ID, name and email address.
- Body measurements — height, weight and maximum heart rate.
- Sleep — sleep start/end times, sleep stages (light, deep/slow-wave, REM, awake), sleep performance, consistency, efficiency and respiratory rate.
- Recovery — recovery score, resting heart rate, heart rate variability (HRV), blood oxygen (SpO2) and skin temperature.
- Cycles — daily strain, energy expenditure, average and maximum heart rate.
- Workouts / activity — activity type, times, strain, heart rate and related workout metrics.
We do not access your WHOOP password; you sign in on WHOOP's site, and WHOOP gives the app an access token limited to the permissions you approved.
While you are connected, the app fetches new data when you press Sync, and when WHOOP notifies it (via a signed webhook) that a sleep, recovery or workout of yours has changed — in that case the app fetches that one updated record.
2. How we use it
Your data is used only to display and analyse your own data within the app, and to compare WHOOP's official metrics with metrics calculated inside the app. We do not use it for advertising.
3. Sharing and selling
Your data is not sold, rented or shared with third parties for their own purposes. It is not disclosed to anyone except where required by law.
4. Storage and security
- All traffic between your browser and the app, and between the app and WHOOP, uses HTTPS. Plain HTTP requests are redirected to HTTPS.
- The OAuth access and refresh tokens are stored only on our server, each encrypted with AES-256-GCM before it is written to the database. The encryption key is kept outside the database. Tokens are never sent to your browser.
- Your WHOOP data is stored in a private database on our server. The database has no public network port and cannot be reached from the internet — only the app itself can connect to it.
- The app's WHOOP client secret is kept only in the server's configuration and is never sent to your browser.
- Your browser holds only a random session cookie (HTTPS-only, not readable by scripts). WHOOP webhook notifications are accepted only when their WHOOP signature verifies.
- Disconnecting stops all further data collection. The data already stored is kept until you delete it (below).
5. Disconnecting
You can disconnect at any time from the dashboard ("Disconnect WHOOP"). This asks WHOOP to revoke the app's access and deletes the stored tokens, so no further data can be fetched. You can also remove the app's access from your WHOOP account settings.
6. Deleting your data
From the dashboard, "Delete my data" disconnects WHOOP and permanently deletes your account, every WHOOP record stored for it, and the log of WHOOP notifications about it. You can also request deletion by email at the address below; we will complete it within 30 days.
7. Contact
Questions or requests about your data: johnmcklareenjoo@gmail.com
8. Changes
If this policy changes, the "Last updated" date above will change with it.