Privacy Policy

Protocol — stayonprotocol.com

Effective Date: October 1, 2026

Version: 1.2

What this means in plain English

Protocol collects health data from your wearables (like Oura Ring and WHOOP) and other sources you connect, then shows you a unified dashboard with scores, trends, and AI-powered coaching. You can also upload lab results, which we read to pull out your biomarker values. Your data is yours. We use it to run the service for you. We send some of it to OpenAI's API to power the AI features and to read your lab reports, but OpenAI does not use your data to train its models, and neither do we: your health data is never used to train or improve any AI model. We do not keep the lab documents you upload — only the marker values we extract from them. We do not sell your data. We never share your health data with advertisers. If you disconnect Oura or WHOOP, we revoke our access and delete the data we got from it. If you delete your account, we delete your data. This policy explains exactly what we collect, why, and how you can control it.

1. Who We Are

Protocol is operated by Protocol LLC (“Protocol,” “we,” “us,” or “our”), a limited liability company organized under the laws of the State of Michigan, United States. Protocol is a consumer wellness application. Protocol is not a medical device, not a healthcare provider, and not a covered entity under the Health Insurance Portability and Accountability Act (“HIPAA”).

For privacy-related inquiries, contact us at: privacy@stayonprotocol.com

2. Data We Collect

2.1 Data Summary Table

Data TypeSourcePurposeRetentionShared With
Name, email addressGoogle OAuth (Supabase Auth)Account creation, authentication, communicationsDuration of account + 30 days after deletion requestSupabase (infrastructure)
Sleep data (duration, stages, efficiency, bedtime and wake time, HRV, resting heart rate)Oura Ring API, WHOOP API, Apple HealthKitDashboard display, daily scorecards, AI coaching, trend analysisWhile the source is connected; Oura and WHOOP data is deleted when you disconnect (Section 8)OpenAI (AI coaching), Supabase (storage)
Readiness and recovery scoresOura Ring API, WHOOP APIDashboard display, daily scorecards, AI coachingWhile the source is connected; deleted when you disconnect (Section 8)OpenAI (AI coaching), Supabase (storage)
Activity data (steps, calories, active energy)Oura Ring API, WHOOP API, Apple HealthKitDashboard display, goal tracking, AI coachingDuration of account; Oura and WHOOP data is deleted when you disconnect (Section 8)OpenAI (AI coaching), Supabase (storage)
Workout data (sessions, duration, type, heart rate, strain)Oura Ring API, WHOOP API, Apple HealthKit, Protocol FitDashboard display, workout tracking, AI coachingDuration of account; Oura and WHOOP data is deleted when you disconnect (Section 8)OpenAI (AI coaching), Supabase (storage)
Body composition (weight, body fat %, BMI)Apple HealthKit, manual entryDashboard display, trend analysis, AI coachingDuration of accountOpenAI (AI coaching), Supabase (storage)
Nutrition and meal data (meal descriptions, calories, protein, carbs, fat; photos of meals, nutrition labels, or menus that you submit)User manual entry, in-app photo capture or photo library, barcode scans, Apple HealthKit (macros logged by other apps)Estimating the nutrition of a photographed or described meal, meal log display, macro goal tracking, AI coachingDuration of account; a meal log is removed when you delete itOpenAI (estimating meals from photos and text, AI coaching), Supabase (storage)
Additional Apple Health metrics (blood glucose from a CGM or meter, VO2 max, blood oxygen, respiratory rate, wrist temperature)Apple HealthKitEstimated recovery scoring, trend analysis, AI coaching and insightsDuration of accountOpenAI (AI coaching), Supabase (storage)
Menstrual cycle data (the days you log a period and its flow level), only if you turn on Cycle trackingApple HealthKitEstimating your cycle phase so recovery goals, trends, and AI coaching account for itDuration of account; days you delete in Apple Health are removed on the next syncOpenAI (AI coaching), Supabase (storage)
Profile characteristics (age or date of birth, biological sex, height)Apple HealthKit, manual entryCalorie and protein target calculations, per-bodyweight coaching targetsDuration of accountOpenAI (AI coaching), Supabase (storage)
Self-reported data (hydration, supplements, workout notes)User manual entry, Apple Health Medications (iOS 26+, per-medication authorization)Dashboard display, goal tracking, AI coachingDuration of accountOpenAI (AI coaching), Supabase (storage)
Lab results and biomarkers (marker name, value, unit, reference range, status, collection date)Lab report PDFs or screenshots you uploadBiomarker dashboard, trend analysis, lab-based goal suggestions, AI coachingDuration of account; removed immediately when you delete the importOpenAI (reading the report, AI coaching), Supabase (storage)
AI coaching conversation historyUser interactions with AI coachConversational context, coaching continuityDuration of accountOpenAI (AI coaching), Supabase (storage)
App usage data (page views, errors, sessions)Automatic collectionService improvement, error diagnosis; on public website pages only, measuring our marketingDuration of accountVercel (hosting), Cloudflare (CDN), Sentry (error monitoring); Google Analytics and Meta for public website pages only (Section 2.2)
OAuth tokens (access, refresh)Oura, WHOOPMaintain authorized connections to data sourcesDuration of connection; revoked with the provider and deleted upon disconnection or account deletionStored in our encrypted-at-rest database (Supabase); not shared

2.2 Categories of Data

Identity Data. Your name and email address, collected through Google OAuth sign-in via Supabase Auth.

Health and Fitness Data. Sleep metrics, readiness and recovery scores, activity data, workout data, heart rate variability, resting heart rate, and body composition data. On iOS, where you grant access, this also includes blood glucose written to Apple Health by a CGM or meter, VO2 max, blood oxygen, respiratory rate, wrist temperature, and your profile characteristics (age or date of birth, biological sex, and height) so targets can be calculated for you. This data is collected from connected wearable devices and apps through their respective APIs:

  • Oura Ring API (OAuth2; scopes: daily, heartrate, personal, session, spo2, tag, workout)
  • WHOOP API (OAuth2; scopes: read:recovery, read:cycles, read:sleep, read:workout, read:profile, offline). When you first connect, we fetch up to the last 12 months of history.
  • Apple HealthKit (on iOS, via the HealthKit SDK, for the data types you authorize). Protocol also writes back the meals and water you log in the app, so other apps you use see them; it never writes back data it read from Health.
  • Protocol Fit (connected workout app using shared Supabase infrastructure)

Nutrition and Meal Data. The meals you log, with their calories and macros, however you enter them: typed or dictated, scanned by barcode, chosen from your saved foods, or photographed. When you submit a photo of a meal, a nutrition label, or a menu, the image is sent to OpenAI to estimate what you ate; see the AI section below. Protocol also reads macros that other apps have written to Apple Health, and writes the meals you log in Protocol back to Apple Health.

Self-Reported Data. Hydration logs, supplement check-offs, manual weight entries, and workout notes that you enter directly. On iOS 26 and later you can also let Protocol read doses from Apple Health's Medications feature, which you authorize per medication.

Lab and Biomarker Data. If you upload a lab report (PDF) or screenshots of your results, Protocol reads the document and stores the individual biomarker values it contains: marker name, value, unit, reference range, in-range status, and the collection date.

We do not store the uploaded file, and we do not retain the full text of the document. Content in a lab report that is not a biomarker value — your address, phone number, patient or accession identifiers, and your ordering physician's details — is not stored by Protocol. We do keep the file's name so you can recognize the import in your list; if the filename itself contains personal information, rename the file before uploading it.

AI Coaching Data. Your questions to the AI coach and the AI-generated responses, stored to maintain conversational context.

Usage Data. Page views, errors, and session data collected automatically. The iOS app does not collect advertising identifiers. When something goes wrong in the web app, an error report goes to Sentry so we can find and fix it. A report includes the technical details of the error, the page or request involved, your browser and device type, and your account ID. We remove request contents, cookies, web address parameters, and email addresses before a report is sent, and Sentry does not store your IP address. We set error reporting up to leave out your health data.

Website Analytics and Advertising Measurement. Our public website pages (such as the home page, articles, and pricing) use Google Analytics to understand traffic and the Meta Pixel to measure our advertising. These tools set cookies and may connect your visit to activity on other sites. They do not record page views on the signed-in parts of Protocol (your dashboard, coach, profile, settings, and onboarding), and they never receive your health data. Besides public page views, we send Meta a few conversion events that contain no health data — that you completed the quiz, finished signing up, or started a subscription — so we can tell which ads work. If your browser sends a Global Privacy Control signal, we do not load the Meta Pixel. When you arrive from one of our ads, we keep the ad’s campaign tags from the link (such as which ad you clicked) in a first-party cookie for up to 90 days, and if you create an account we save them with it so we can tell which ads bring in members. This stays with us and is not shared, and we skip it when your browser sends Global Privacy Control.

Connection Credentials. OAuth access and refresh tokens for Oura and WHOOP, stored in our database, which is encrypted at rest. They are used only by our servers to sync your data and are deleted when you disconnect.

2.3 Health Data Sensitivity

We recognize that health and fitness data is sensitive. We treat all health-related data collected through Protocol with heightened care. We collect and process this data only with your explicit consent, granted when you connect a data source or enter information into the app, and only as necessary to provide the Protocol service to you.

3. How We Use Your Data

We use your data for the following purposes:

  • Displaying your health metrics on your personal dashboard
  • Generating daily scorecards scored against goals you define
  • Powering the AI coach with your health data context so it can answer your questions, surface insights, and provide personalized recommendations (see Section 4)
  • Reading lab reports you upload to extract your biomarker values, and generating summaries and lab-based goal suggestions from them
  • Computing trends and insights across your connected data sources over time
  • Delivering proactive insights such as morning briefs and goal tracking notifications
  • Diagnosing errors and improving the service using aggregated, de-identified usage data (never health data obtained from Oura or WHOOP; see Section 7)
  • Measuring our marketing on our public website pages (Section 2.2)
  • Communicating with you about your account, service updates, and material changes to these terms

In-App Product Suggestions. Protocol may use your health data to surface contextually relevant suggestions for health products, supplements, devices, or services within the app. For example, if your HRV trends suggest poor recovery, Protocol might suggest a magnesium supplement. These suggestions are generated by Protocol's own systems. Your personal data is not shared with any product manufacturer, advertiser, or other third party in connection with these suggestions. You will always be able to distinguish suggestions from your personal health data.

4. AI Processing Disclosure

Protocol's AI features are powered by the OpenAI API, using OpenAI's GPT models (the specific model changes as OpenAI releases new versions). Your health data, including data obtained from Oura and WHOOP, is sent to OpenAI's API in the following situations:

  • AI coach conversations. When you interact with the coach, your health data and conversation history are sent to generate a response.
  • Automatic insights. Protocol generates daily briefs, weekly reviews, trend readings, workout summaries, and biomarker summaries on your behalf, including for the morning and weekly emails. These are produced by the same API without you starting a conversation.
  • Reading lab reports. When you upload a lab report, the text extracted from the PDF — or the screenshot images themselves — is sent to OpenAI to identify the biomarker values. Because a lab report is transmitted as a whole document, this includes any identifying information the report contains, even though Protocol does not store that information afterward.
  • Estimating meals. When you log a meal by photo or description, the image or text is sent to OpenAI to identify the food and estimate its calories and macros. This applies to photos of meals, nutrition labels, and menus, whether taken in the app or chosen from your photo library.

What this means for your data:

  • OpenAI processes your data as a sub-processor acting on our instructions.
  • We call OpenAI's API with storage disabled (store: false) on every request, so your prompts and responses are not retained in OpenAI's stored-completions logs. OpenAI does not use data submitted through its API to train or improve its models. OpenAI may retain API data for a limited period for abuse monitoring under its API data usage policies.
  • Your data is transmitted to OpenAI over encrypted channels (HTTPS/TLS).
  • No AI training on your data, by anyone. Protocol does not use your health data — including any data obtained from Oura or WHOOP — to create, develop, test, train, fine-tune, or improve any large language model or other artificial intelligence or machine learning model or system, whether ours or a third party's. Your data is sent to OpenAI only to generate output for you.
  • OpenAI's data usage policies for API customers are described at openai.com/policies/api-data-usage-policies.

We disclose this processing to you because your health data leaves Protocol's infrastructure when sent to OpenAI for coaching responses. We ask for your agreement to this processing when you connect Oura or WHOOP, and by using the AI features you consent to it. You can withdraw that consent as described in Section 10.1.

5. Third-Party Data Processors

We use the following third-party service providers to operate Protocol:

ProcessorRoleData Location
SupabaseDatabase, authentication, row-level securityUS-East
OpenAIAI coaching and automatic insights; reading uploaded lab reports to extract biomarker valuesUnited States
VercelHosting and edge functionsGlobal CDN
CloudflareCDN, DNS, DDoS protectionGlobal CDN
SentryError and performance monitoring for the web app (error details, the page or request involved, and your account ID; no health data)United States
ResendEmail delivery, including the daily and weekly briefs (which contain your metrics and AI insights)United States
ApplePush notifications (which may include a metric, such as your sleep or a streak) and in-app purchasesUnited States
StripeWeb subscription payments (no health data)United States
SlackInternal alerts, including the text of feedback you send usUnited States
Google Analytics, MetaPublic website analytics and advertising measurement only (Section 2.2); no health dataUnited States

We require each processor to handle your data in accordance with this Privacy Policy and applicable law.

Third-party data source providers. Oura, WHOOP, and Apple may collect usage data related to your use of their APIs and platforms. Oura and WHOOP may each monitor Protocol's use of their APIs and may use such data for any business purpose, including providing enhancements to their platforms or developer support. For details on how these companies handle your data, please review their respective privacy policies.

6. Data Sharing

We do not sell your personal data.

We do not share your personal data with advertisers or data brokers. We share your data only in the following circumstances:

  • With service providers listed in Section 5, solely to operate the Protocol service
  • When required by law, in response to a valid legal process such as a subpoena, court order, or regulatory request
  • With your consent, if we ever seek to share your data in a manner not described in this policy, we will obtain your prior consent
  • In a business transfer, if Protocol is acquired, merges with another company, or sells substantially all of its assets, your data may be transferred as part of that transaction. We will notify you and any applicable API partners (including Oura and WHOOP) before any such transfer and provide you the opportunity to delete your account.

Data from Oura and WHOOP. We use the data you authorize us to receive from Oura and WHOOP only to provide Protocol to you. We never sell, license, or lend it, never use it in advertising, and never show it to other Protocol users or to any third party other than the service providers in Section 5 that run Protocol for you, unless you explicitly opt in. We keep it only while the source is connected (Section 8).

7. Aggregated and De-Identified Data

We may create aggregated, de-identified statistics from app usage data for internal product improvement, such as understanding how often a feature is used. “De-identified” means data from which all direct and indirect personal identifiers have been permanently removed, such that the data cannot reasonably be used to identify any individual. We do not attempt to re-identify de-identified data. De-identified data is used only internally and is not sold, licensed, or shared with third parties.

We do not create de-identified datasets from health data obtained from Oura or WHOOP, and no data — identified, de-identified, or aggregated — is used to train, fine-tune, test, or improve any artificial intelligence or machine learning model (Section 4).

8. Data Retention

We retain your personal data for as long as your account is active. Data from Oura and WHOOP is kept only while that source is connected, and we keep it in step with the source: when WHOOP notifies us that you deleted a record there, we delete our copy.

Disconnecting Oura or WHOOP. When you disconnect either one in the Protocol app or website:

  • We revoke our authorization with the provider and delete the stored OAuth tokens.
  • We immediately delete the records we obtained from that source (sleep, readiness or recovery, activity, and workouts) and recalculate your daily scores from your remaining sources.
  • We clear cached AI insights and mined trends so nothing derived from that source remains; they regenerate from your remaining data.

If you instead remove Protocol's access from inside your Oura or WHOOP account, we stop receiving new data and ask you to reconnect; disconnect the source in Protocol (or email us) and we delete the data as described above.

Apple Health access is controlled in your iPhone's Health settings. Turning it off stops new data; data already synced stays in Protocol until you delete your account or ask us to delete it.

Deleting your account. When you delete your account:

  • We revoke all connected OAuth authorizations with Oura and WHOOP.
  • We delete your account and all associated data, including AI coaching conversation history, from our production database immediately. Residual copies in encrypted backups expire within 30 days.
  • Aggregated, de-identified usage statistics that cannot be used to identify you may be retained.

Lab imports. You can delete any lab import from within the app. Deleting an import immediately removes it and every biomarker value it contributed. Uploaded files and lab report text are never retained, so there is nothing further to purge.

9. Data Security

We implement administrative, technical, and physical safeguards designed to protect your data, including:

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Row-level security in our database (Supabase)
  • OAuth tokens kept only in our encrypted-at-rest database, used only by our servers, and deleted on disconnect
  • Access controls limiting employee access to personal data

No system is perfectly secure. We cannot guarantee absolute security, but we are committed to maintaining commercially reasonable protections appropriate to the sensitivity of health data.

Breach Notification. In the event of a data breach affecting your personal data, we will notify affected users in accordance with applicable law (including within 72 hours where required). We will also notify affected API partners as required by our agreements with them: Oura within 24 hours, and WHOOP as soon as possible and in any event within 48 hours of discovering the incident. We will work with them to investigate, mitigate, and resolve it.

10. Your Rights and Choices

10.1 All Users

Regardless of where you live, you can:

  • Access your data by viewing it in the Protocol app or by contacting us at privacy@stayonprotocol.com
  • Correct your data by updating it in the app or by contacting us
  • Delete your data by deleting your account in the app or by contacting us. Deletion will be completed within 30 days.
  • Disconnect data sources at any time through the app settings
  • Limit AI processing by not using the AI coach, not uploading lab reports, and turning off the daily and weekly brief emails in your settings. Protocol also generates insights automatically for surfaces you open (such as the daily brief and biomarker summaries); disconnecting Oura or WHOOP stops their data being sent to OpenAI. If you want your health data excluded from AI processing entirely, contact us at privacy@stayonprotocol.com.

10.2 California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:

  • Right to Know. You may request the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collected it, the business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete. You may request deletion of your personal information, subject to certain exceptions.
  • Right to Correct. You may request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing. We do not sell your personal information. The Meta Pixel on our public website pages (Section 2.2) may count as “sharing” for cross-context behavioral advertising under California law; it never receives health data. You can opt out by enabling Global Privacy Control in your browser, which we honor, or by emailing us.
  • Right to Non-Discrimination. We will not discriminate against you for exercising any of these rights.

To exercise these rights, contact us at privacy@stayonprotocol.com. We will verify your identity before fulfilling your request.

Categories of personal information collected (for CCPA purposes): Identifiers (name, email); health information (sleep, activity, recovery, body composition, and lab biomarker results you upload); internet or electronic network activity information (usage data); inferences drawn from the above (AI coaching insights, scores).

We do not sell personal information. We never share health information for advertising.

10.3 European Economic Area, United Kingdom, and Switzerland (GDPR)

If you are located in the EEA, UK, or Switzerland:

  • Lawful Basis. We process your personal data on the basis of: (a) your explicit consent, provided when you create an account and connect data sources; and (b) the necessity of processing to perform the service you have requested (Article 6(1)(a) and (b) GDPR). For health data (a special category), we rely on your explicit consent (Article 9(2)(a) GDPR).
  • Data Controller. The data controller is Protocol LLC, Michigan, United States.
  • Your Rights. You have the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data. You also have the right to withdraw consent at any time. To exercise these rights, contact privacy@stayonprotocol.com.
  • Data Transfers. Protocol is a US-based service. Your data is stored and processed in the United States. By using Protocol, you consent to the transfer of your data to the United States.
  • Supervisory Authority. You have the right to lodge a complaint with your local data protection supervisory authority.
  • Data Protection Agreements. If full GDPR compliance requires a separate Data Processing Agreement for your use case, please contact us.

Note on independent controller status: With respect to data received from Oura, Protocol and Oura each act as independent data controllers. Neither party processes personal data received under the Oura API Agreement as joint controllers. Each party is independently responsible for complying with its obligations as a controller under applicable data protection law.

11. Children's Privacy

Protocol is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have collected personal information from a person under 18, we will delete that information promptly. If you believe a minor has provided us with personal information, please contact us at privacy@stayonprotocol.com.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' advance notice by email (to the address associated with your account) and through an in-app notification. Non-material changes (such as formatting or clarification) may be made without advance notice. The “Effective Date” at the top of this policy will always reflect the most recent version. Your continued use of Protocol after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

13. Contact Us

For questions, requests, or complaints regarding this Privacy Policy or your personal data:

Email: privacy@stayonprotocol.com

Website: stayonprotocol.com