Privacy Policy — Jony Health Watch
1. Purpose and scope
Jony Health Watch is a private, personal wellness-reporting integration. It uses the official WHOOP OAuth API to prepare daily health and activity summaries, trend comparisons, and general wellness suggestions for the authorized WHOOP member.
2. Data collected
With explicit OAuth consent, the app may read:
- recovery score, heart-rate variability, resting heart rate, and recovery-related measurements;
- physiological cycles, day strain, average heart rate, and related summaries;
- sleep timing, duration, stages, performance, efficiency, consistency, and related measurements;
- workout type, timing, heart-rate summaries, and accumulated strain; and
- body measurements such as height, weight, and maximum heart rate.
The app does not request WHOOP profile access and does not use WHOOP data for employee attendance, payroll, advertising, or sale.
3. Use and processing
Authorized data is used only to calculate personal daily reports, 7-day and 28-day trends, and general suggestions concerning recovery, activity, sleep, hydration, and meals. The app does not diagnose disease or replace medical advice.
When AI-personalized wording is enabled by the operator, only selected health metrics and derived trends needed for the report may be processed by the configured AI service. WHOOP credentials, access tokens, member identifiers, and account-login information are never included in that prompt.
4. Storage, security, and retention
- OAuth client secrets, access tokens, and refresh tokens are stored only on the operator's Mac in restricted local files.
- Health records and derived summaries are kept in a local database with access limited to the operator.
- Raw API records are retained for up to 90 days. Derived daily summaries and trend values are retained for up to 12 months, unless deleted earlier.
- Credentials and health records are not placed in public logs, source code, or public web pages.
5. Sharing
The app does not sell health data and does not share it for advertising. Data is disclosed only to service providers strictly necessary to retrieve WHOOP data, generate an opted-in report, and deliver that report privately to the operator.
6. User control and deletion
The authorized member may revoke access through WHOOP's connected-app controls at any time. Revocation stops future collection. The operator may also delete local raw records, summaries, and OAuth tokens on request. WHOOP account data remains governed by WHOOP's own privacy policy.
7. Changes
This policy will be updated before the integration materially expands its data categories, purposes, sharing, or retention periods.
Chính sách bảo mật — Bản tiếng Việt
Ngày hiệu lực: 08/08/2026 · Người vận hành: Nguyễn Đình Đạt.
Jony Health Watch là tích hợp sức khỏe cá nhân, chỉ đọc dữ liệu WHOOP mà người dùng đã cấp quyền để tạo báo cáo hằng ngày và so sánh xu hướng. Dữ liệu có thể gồm phục hồi, HRV, nhịp tim nghỉ, chu kỳ/strain, giấc ngủ, buổi tập và số đo cơ thể.
Ứng dụng không xin quyền hồ sơ WHOOP, không dùng dữ liệu cho chấm công, tính lương, quảng cáo hoặc mua bán. Token OAuth được giữ trong file giới hạn quyền trên máy Mac; dữ liệu thô lưu tối đa 90 ngày và bản tóm tắt/xu hướng lưu tối đa 12 tháng.
Nếu bật phần nhận xét cá nhân hóa bằng AI, chỉ các chỉ số cần thiết và xu hướng tổng hợp được dùng để viết báo cáo; không gửi credential, token hay WHOOP member ID. Người dùng có thể thu hồi quyền WHOOP và yêu cầu xóa dữ liệu cục bộ bất kỳ lúc nào.
Các gợi ý chỉ phục vụ chăm sóc sức khỏe và lối sống, không thay thế tư vấn, chẩn đoán hoặc điều trị y tế.