CWC/

Codex WHOOP Connector

Privacy, in plain language.

This personal connector reads only the WHOOP data you authorize and only when you ask Codex to use it.

Personal integrationRead-only accessNo ads or data sale

Overview

Your authorization stays in your control.

This policy explains how the Codex WHOOP Connector handles information obtained through the WHOOP Developer API. By authorizing the connector, you direct it to retrieve your data for your own use in Codex.

01

What the connector accesses

With your authorization, the connector can retrieve the WHOOP data covered by the scopes you approve: basic profile information, body measurements, recovery metrics, physiological cycles, sleep records, and workouts. It also receives OAuth access and refresh tokens needed to maintain the connection.

The connector does not receive your WHOOP password and does not have access to continuous heart-rate data.

02

How the data is used

Data is retrieved only when you ask Codex to answer a question, produce a summary, or analyze a trend. It is not used for advertising, profiling unrelated to your request, or automated decisions about employment, insurance, credit, or eligibility.

03

Storage and processing

WHOOP client credentials and OAuth tokens are stored locally on the computer running the connector. The connector does not operate a separate cloud database and does not independently retain WHOOP API responses after a request completes.

When you use the connector through Codex, requested WHOOP data may be transmitted to and processed by OpenAI to generate your response. Its handling and retention are governed by your OpenAI account settings and the OpenAI Privacy Policy.

04

Sharing and sale

The connector does not sell personal information, share it with data brokers, or provide it to advertisers. Data flows only between WHOOP, the local connector, and OpenAI when necessary to fulfill a request you initiate. WHOOP and OpenAI process information under their own privacy policies.

05

Your controls

You can stop access at any time by revoking the app in WHOOP, deleting the local token file, or removing the connector from Codex. You can also manage or delete conversations using the controls available in your OpenAI account.

Removing authorization prevents future retrieval. It does not automatically delete information already retained by WHOOP or OpenAI under their respective policies.

06

Security and health information

The connector uses OAuth 2.0, requests read-only WHOOP scopes, and restricts local token-file permissions. No system is completely secure. WHOOP insights are provided for informational purposes and are not a substitute for professional medical advice, diagnosis, or treatment.

07

Third-party policies

For more information about how the source and processing services handle data, review the WHOOP Privacy Policy and the OpenAI Privacy Policy.

08

Changes and contact

This policy may be updated if the connector's data practices change. The effective date above will be revised when material changes are made. Questions may be sent to the contact email associated with the Codex WHOOP Connector in the WHOOP Developer Dashboard.