CWC/

Codex WHOOP Connector

Privacy, in plain language.

This personal integration uses only the WHOOP and Apple Health data you authorize for your private Codex reports.

Personal integrationRead-only source accessNo ads or data sale

Overview

Your authorization stays in your control.

This policy explains how the Codex WHOOP Connector and Syai Health Bridge handle information obtained through the WHOOP Developer API and Apple Health. By authorizing them, you direct the integration to process your data for your own use in Codex.

01

What the integration accesses

With your authorization, the integration can retrieve the WHOOP data covered by the scopes you approve: basic profile information, body measurements, recovery metrics, physiological cycles, sleep records, and workouts. It also receives OAuth access and refresh tokens needed to maintain the connection.

The iPhone bridge separately requests read access to one Apple Health data type: blood-glucose samples. For each sample, it processes the value, date and time, HealthKit identifier, source app or device, and limited device metadata. It does not request write access to Apple Health or access to other HealthKit categories.

The integration does not receive your WHOOP or Syai passwords and does not have access to continuous heart-rate data from the WHOOP API.

02

How the data is used

WHOOP and Apple Health data is used to answer your questions, prepare the daily health report you scheduled, describe sleep, recovery and glucose trends, and personalize informational food or exercise suggestions. It is not used for advertising, unrelated profiling, or automated decisions about employment, insurance, credit, or eligibility.

03

Storage and processing

WHOOP client credentials and OAuth tokens remain on the computer running the connector. The connector does not independently retain WHOOP API responses after a request completes.

Blood-glucose samples are uploaded over HTTPS to a private Cloudflare Pages service and stored in a Cloudflare D1 database so authorized Codex reports can access them while the computer is off. Separate, secret credentials restrict upload and read access. Samples remain stored until you request deletion; disabling the bridge stops future uploads but does not by itself erase previously stored samples.

When you use the integration through Codex, requested WHOOP and glucose data may be transmitted to and processed by OpenAI to generate your response. Its handling and retention are governed by your OpenAI account settings and the OpenAI Privacy Policy.

04

Sharing and sale

The integration does not sell personal information, share it with data brokers, or provide it to advertisers. Depending on the feature used, data can flow between Syai, Apple Health, the iPhone bridge, Cloudflare, the local connector, WHOOP, and OpenAI. Each third-party service also processes information under its own privacy policy.

05

Your controls

You can stop WHOOP access by revoking the app in WHOOP, deleting the local token file, or removing the connector from Codex. You can stop glucose uploads by revoking Blood Glucose access in iOS Health settings or deleting the iPhone bridge. You can also manage or delete conversations using your OpenAI account controls.

You may request deletion of the glucose samples stored in the private D1 database through the contact listed below. Removing authorization prevents future retrieval or upload but does not automatically delete information already retained by WHOOP, Cloudflare, or OpenAI under their respective policies.

06

Security and health information

The integration uses OAuth 2.0 for WHOOP, read-only source permissions, HTTPS for glucose uploads, separate upload and read credentials, and restricted local secret-file permissions. No system is completely secure. WHOOP and glucose insights are informational, not real-time emergency alarms, and are not a substitute for professional medical advice, diagnosis, or treatment. Do not use them to change medication.

07

Third-party policies

For more information about how the source and processing services handle data, review the WHOOP Privacy Policy, Apple Privacy Policy, Syai Privacy Policy, Cloudflare Privacy Policy, and the OpenAI Privacy Policy.

08

Changes and contact

This policy may be updated if the connector's data practices change. The effective date above will be revised when material changes are made. Questions may be sent to the contact email associated with the Codex WHOOP Connector in the WHOOP Developer Dashboard. The same contact may be used to request deletion of cloud-stored glucose samples.