HealthSource Privacy Policy
HealthSource connects to Oura only with explicit user authorization. It is designed as a read-only recovery and body-context service for approved HealthSource integrations.
Data We Access
Depending on granted Oura scopes, HealthSource may retrieve sleep, readiness, activity, workout, heart-rate-derived sleep metrics, HRV/RMSSD, resting heart rate, lowest heart rate, temperature deviation, SpO2, breathing disturbance, stress, resilience, rest mode, sessions, tags, cardiovascular age, VO2 max, and ring device information.
How We Use Data
Data is used only to provide user-requested, non-medical wellness, recovery, fitness, performance, and training-readiness context. HealthSource does not diagnose, treat, provide emergency support, or make medical claims.
HealthSource does not use Oura-derived data to train, fine-tune, develop, improve, evaluate, or benchmark AI models or AI platforms.
Sharing
HealthSource returns authorized Oura context only to the user-requested, approved HealthSource integration. It does not sell body data, use it for advertising, use third-party analytics SDKs, or expose Oura-derived data as an unapproved provider-record pass-through.
Storage
Production stores encrypted Oura OAuth tokens only while the user keeps Oura connected so HealthSource can refresh access. Local development may cache Oura API responses briefly to avoid unnecessary API calls; provider API records are not kept as a long-term warehouse. Tokens are not returned by MCP tools or API responses.
User Control
Users can revoke Oura access from Oura account settings, disconnect Oura from HealthSource, or ask HealthSource to delete the stored Oura connection and related retained data. HealthSource deletes user data after a deletion request within 72 hours where technically available.
Contact
Contact: support@healthsource.app