Mation
Mation Fitness · MaxRaw WHOOP personal pilot
Privacy notice

Your WHOOP data remains yours.

This notice explains the small, read-only personal pilot operated by Mation for the MaxRaw Fitness experience. It is intentionally narrower than a production health-data service.

Current pilot posture

  • Read-only WHOOP access
  • Local process-memory storage only
  • No sale, advertising, or automated decisions

Effective 3 September 2026

01  /  Scope and operator

Who this notice covers

This notice applies only when you connect a WHOOP account to the current Mation Fitness / MaxRaw personal pilot. Mation operates the integration from Auckland, New Zealand. WHOOP remains responsible for its own service, account, wearable, and data practices.

The pilot is a development and evaluation environment. It is not a medical device and does not provide diagnosis, treatment, emergency monitoring, or automated coaching decisions.

02  /  Data we access

Only the authorised WHOOP scopes

If you choose to connect, WHOOP asks you to approve access before any data is retrieved. The pilot requests profile, recovery, cycle, sleep, workout, and offline access. Offline access allows WHOOP to issue a refresh token so the local session can refresh an expired access token while the pilot is running.

Profile

Your WHOOP member identifier and basic profile details, including name and email address.

Recovery

Recovery scores and the physiological measures WHOOP includes with those records, such as heart-rate variability and resting heart rate.

Cycles and strain

Physiological-cycle timing, day strain, heart-rate summaries, and related WHOOP status fields.

Sleep

Sleep records, duration and stage summaries, sleep performance, and related WHOOP status fields.

Workouts

Workout type and timing, activity strain, heart-rate summaries, and related WHOOP workout fields.

The pilot does not request WHOOP's body-measurement scope. It may also process basic connection and diagnostic information needed to complete OAuth safely, such as connection status, expiry time, and error details.

03  /  How we use it

A personal, read-only preview

We use the authorised data to:

  • show your recent WHOOP information inside the local MaxRaw experience;
  • test the connection, consent, disconnection, security, and user experience;
  • diagnose a connection problem when you ask us to help; and
  • evaluate whether this capability should move beyond a personal pilot.

We do not use the pilot data for advertising, sale, data brokerage, eligibility decisions, or automated medical or coaching decisions. The pilot does not write back to WHOOP.

04  /  Storage and retention

Temporary by design

During this pilot, the WHOOP access token, rotating refresh token, and fetched snapshot are held only in the local app server's volatile process memory. They are not intentionally written to a Mation production database, browser storage, or application file. Stopping or restarting that process clears its local memory.

Choose Disconnect WHOOP before stopping the app. The pilot first requests revocation at WHOOP and then removes the local session. If the process stops before revocation, remove the app's access through WHOOP or contact us for help. WHOOP and internet/tunnel providers may retain their own account, security, and request records under their respective policies.

05  /  Sharing and transfers

No sale of health data

We do not sell your WHOOP data or share it with advertisers, data brokers, other trainers, or other clients. Your data moves between WHOOP, the secure OAuth/network services needed for the connection, and the local pilot on your test computer. Those providers may process information outside New Zealand under their own terms and privacy notices.

We may disclose information if required by law, or when reasonably needed to protect a person, the service, or our legal rights. We would limit any such disclosure to what is necessary.

06  /  Security

Safeguards for the pilot

You authorise access

WHOOP shows the requested permissions before you connect. The pilot cannot access your account unless you approve them.

Memory-only pilot

OAuth tokens and the fetched WHOOP snapshot are held only in the local app server's process memory. This pilot does not write them to a Mation production database or application file.

Server-side connection

The client secret and token exchange stay on the server. The OAuth callback uses HTTPS, short-lived state, and local-origin controls.

Disconnect means revoke

Disconnect first asks WHOOP to revoke access, then removes the local in-memory session. You can also remove access through WHOOP.

No system can promise absolute security. If we identify a material privacy or security issue affecting you, we will assess it and take appropriate action.

07  /  Your choices and rights

You stay in control

You can decline the WHOOP connection, disconnect it, or revoke access through WHOOP. You may also ask whether we hold personal information about you and request access or correction. Because the pilot uses volatile local memory, we may no longer hold a retrievable copy after it is disconnected or stopped.

For an access, correction, deletion, or privacy request, email cam@mation.nz. We may need enough information to confirm your identity and locate the relevant connection. You may also contact New Zealand's Office of the Privacy Commissioner if you are not satisfied with our response.

08  /  Other services

Independent services and notices

WHOOP is a separate service. References to WHOOP describe compatibility and do not imply that WHOOP sponsors or endorses Mation or MaxRaw Fitness.

09  /  Changes and contact

Questions are welcome

We will update this notice before materially changing the data, purposes, storage, or sharing posture described here. The effective date at the top shows when this version took effect.

Mation

Auckland, New Zealand

cam@mation.nz