Your WHOOP data remains yours.
This notice explains the small, read-only personal pilot operated by Mation for the MaxRaw Fitness experience. It is intentionally narrower than a production health-data service.
Current pilot posture
- Read-only WHOOP access
- Local process-memory storage only
- No sale, advertising, or automated decisions
Effective 3 September 2026
01 / Scope and operator
Who this notice covers
This notice applies only when you connect a WHOOP account to the current Mation Fitness / MaxRaw personal pilot. Mation operates the integration from Auckland, New Zealand. WHOOP remains responsible for its own service, account, wearable, and data practices.
The pilot is a development and evaluation environment. It is not a medical device and does not provide diagnosis, treatment, emergency monitoring, or automated coaching decisions.
02 / Data we access
Only the authorised WHOOP scopes
If you choose to connect, WHOOP asks you to approve access before any data is retrieved. The pilot requests profile, recovery, cycle, sleep, workout, and offline access. Offline access allows WHOOP to issue a refresh token so the local session can refresh an expired access token while the pilot is running.
Profile
Your WHOOP member identifier and basic profile details, including name and email address.
Recovery
Recovery scores and the physiological measures WHOOP includes with those records, such as heart-rate variability and resting heart rate.
Cycles and strain
Physiological-cycle timing, day strain, heart-rate summaries, and related WHOOP status fields.
Sleep
Sleep records, duration and stage summaries, sleep performance, and related WHOOP status fields.
Workouts
Workout type and timing, activity strain, heart-rate summaries, and related WHOOP workout fields.
The pilot does not request WHOOP's body-measurement scope. It may also process basic connection and diagnostic information needed to complete OAuth safely, such as connection status, expiry time, and error details.
03 / How we use it
A personal, read-only preview
We use the authorised data to:
- show your recent WHOOP information inside the local MaxRaw experience;
- test the connection, consent, disconnection, security, and user experience;
- diagnose a connection problem when you ask us to help; and
- evaluate whether this capability should move beyond a personal pilot.
We do not use the pilot data for advertising, sale, data brokerage, eligibility decisions, or automated medical or coaching decisions. The pilot does not write back to WHOOP.
04 / Storage and retention
Temporary by design
During this pilot, the WHOOP access token, rotating refresh token, and fetched snapshot are held only in the local app server's volatile process memory. They are not intentionally written to a Mation production database, browser storage, or application file. Stopping or restarting that process clears its local memory.
Choose Disconnect WHOOP before stopping the app. The pilot first requests revocation at WHOOP and then removes the local session. If the process stops before revocation, remove the app's access through WHOOP or contact us for help. WHOOP and internet/tunnel providers may retain their own account, security, and request records under their respective policies.
05 / Sharing and transfers
No sale of health data
We do not sell your WHOOP data or share it with advertisers, data brokers, other trainers, or other clients. Your data moves between WHOOP, the secure OAuth/network services needed for the connection, and the local pilot on your test computer. Those providers may process information outside New Zealand under their own terms and privacy notices.
We may disclose information if required by law, or when reasonably needed to protect a person, the service, or our legal rights. We would limit any such disclosure to what is necessary.
06 / Security
Safeguards for the pilot
You authorise access
WHOOP shows the requested permissions before you connect. The pilot cannot access your account unless you approve them.
Memory-only pilot
OAuth tokens and the fetched WHOOP snapshot are held only in the local app server's process memory. This pilot does not write them to a Mation production database or application file.
Server-side connection
The client secret and token exchange stay on the server. The OAuth callback uses HTTPS, short-lived state, and local-origin controls.
Disconnect means revoke
Disconnect first asks WHOOP to revoke access, then removes the local in-memory session. You can also remove access through WHOOP.
No system can promise absolute security. If we identify a material privacy or security issue affecting you, we will assess it and take appropriate action.
07 / Your choices and rights
You stay in control
You can decline the WHOOP connection, disconnect it, or revoke access through WHOOP. You may also ask whether we hold personal information about you and request access or correction. Because the pilot uses volatile local memory, we may no longer hold a retrievable copy after it is disconnected or stopped.
For an access, correction, deletion, or privacy request, email cam@mation.nz. We may need enough information to confirm your identity and locate the relevant connection. You may also contact New Zealand's Office of the Privacy Commissioner if you are not satisfied with our response.
08 / Other services
Independent services and notices
WHOOP is a separate service. References to WHOOP describe compatibility and do not imply that WHOOP sponsors or endorses Mation or MaxRaw Fitness.
09 / Changes and contact
Questions are welcome
We will update this notice before materially changing the data, purposes, storage, or sharing posture described here. The effective date at the top shows when this version took effect.