Privacy Policy

Application: Matt Lifestyle  ·  Effective date: 12 July 2026

This Privacy Policy describes how Matt Lifestyle (“the App”, “we”, “us”, “our”) collects, uses, stores, and protects your personal data when you connect your WHOOP account to the App. We are committed to protecting your privacy and to processing your data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Polish law.

1.Data Controller

The controller responsible for your personal data is:

2.What Data We Access

When you authorize the App through WHOOP’s OAuth 2.0 flow, we may access the following data from your WHOOP account, limited to the permissions (scopes) you grant during authorization:

We only access the categories of data covered by the scopes you approve. We do not receive your WHOOP username or password at any time.

3.How We Access Your Data

We access your WHOOP data exclusively through WHOOP’s official Developer API using the OAuth 2.0 authorization-code protocol. Access is granted by a secure access token issued by WHOOP, which you can revoke at any time (see Section 8). We never see or store your WHOOP login credentials.

4.How We Use Your Data & Legal Basis

We use your WHOOP data to:

The legal basis for processing is your consent (GDPR Art. 6(1)(a)), which you provide by connecting your WHOOP account. Because recovery, HRV, sleep, and similar metrics may constitute health-related data, we process them on the basis of your explicit consent under GDPR Art. 9(2)(a). You may withdraw your consent at any time, which will not affect the lawfulness of processing carried out before withdrawal.

5.Data Storage & Security

Your data is processed and stored on a private server hosted by Akamai (Linode) in the European Union region. Data is transmitted over encrypted connections (HTTPS/TLS), and access tokens are stored securely with restricted file permissions. We apply appropriate technical and organizational measures to protect your data against unauthorized access, loss, or disclosure.

6.Data Sharing & Third Parties

We do not sell your personal data. We may share data only in the following cases:

We may also disclose data where required by law or to protect our legal rights.

7.Data Retention

We retain your data only for as long as your WHOOP account remains connected to the App and you continue to use it. When you disconnect the App or revoke access, or upon a deletion request, we delete the associated stored data within 30 days, unless retention is required by law.

8.Revoking Access

You can disconnect the App from your WHOOP account at any time via your WHOOP account settings (under connected apps), which immediately revokes our access token. You may also contact us at mateusz.a.kozlowski@gmail.com to request that we delete your data.

9.Your Rights Under GDPR

You have the right to access, rectify, erase, restrict, and port your data, to object to processing, and to withdraw consent at any time. To exercise these rights, contact us at mateusz.a.kozlowski@gmail.com. You also have the right to lodge a complaint with the Polish data protection authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), uodo.gov.pl.

10.Children

The App is not intended for individuals under the age of 16, and we do not knowingly collect data from children. A WHOOP account is required to use the App.

11.Changes to This Policy

We may update this Privacy Policy from time to time. Any changes take effect when the updated version is published at this address, with a revised effective date shown above.

12.Contact

Mateusz Kozłowski
E-mail: mateusz.a.kozlowski@gmail.com

This document is a practical template, not formal legal advice. If the App will serve users other than yourself, consider a review by a lawyer.