1. Introduction
Application: Inwardly
Purpose: Body awareness training through personalized, AI-powered insights correlated with your wearable biometric data.
Contact Email: support@goinwardly.com
Inwardly ("we", "us", "our") is a body awareness training application that helps you understand and optimize your physical performance through personalized insights based on your biometric data.
This Privacy Policy explains how we collect, use, store, and protect data from your WHOOP integration. Please read this policy carefully.
Questions? Contact us at support@goinwardly.com
Application: Inwardly
Purpose: Body awareness training through personalized, AI-powered insights correlated with your wearable biometric data.
Contact Email: support@goinwardly.com
Inwardly is currently operating as a closed beta program with a maximum of 100 active users. During the beta phase, this Privacy Policy may be updated with 7 days notice to users via email or in-app notification.
Your continued use of Inwardly after a policy update constitutes acceptance of the updated terms. We encourage you to review this policy periodically for changes.
When you authorize Inwardly to access your WHOOP account, we collect the following biometric and profile data:
Important: We do not collect any health condition information, medical history, or sensitive health data beyond what WHOOP provides through our authorized scopes.
Inwardly uses the OAuth 2.0 authorization framework with PKCE (Proof Key for Public Clients) to securely access your WHOOP data. This means:
When you authorize Inwardly, WHOOP will ask for permission to access the following scopes:
read:recovery - Recovery score, HRV, and resting heart rateread:sleep - Sleep metrics and sleep stage dataread:workout - Workout strain and activity dataread:cycles - Physiological cycle dataread:profile - Your name and email addressYou authorize these scopes by confirming on the WHOOP consent screen. You can revoke access at any time through your WHOOP account settings.
Your WHOOP data is used exclusively for the following purposes:
We correlate your reported body awareness (tension, energy, focus) with your objective biometric data from WHOOP to deliver personalized insights and recommendations tailored to your physiology and patterns.
Your aggregated data is processed by our AI engine to generate actionable insights about your recovery, sleep quality, training load, and performance trends. These insights are provided exclusively to you and are not shared with third parties.
Your WHOOP metrics are displayed on your personal Inwardly dashboard, allowing you to view your data in one unified location.
If you have connected a coach to your account, your WHOOP data will be visible to that coach on their coaching dashboard so they can provide informed guidance based on your complete biometric picture.
We may use anonymized and aggregated data (data that cannot identify you) for:
We do NOT use your data for:
Your WHOOP data is stored in our secure backend infrastructure:
Storage Infrastructure: Firebase/Firestore
Encryption: All data is encrypted at rest using industry-standard encryption protocols
Location: Data is stored on US-based servers
Access Control: Access to your data is restricted to authorized Inwardly systems and your connected coach (if applicable)
We are committed to protecting your privacy. Your WHOOP data is shared only in the following circumstances:
If you have authorized a coach to access your Inwardly account, your WHOOP data will be visible to that coach on their coaching dashboard. You can disconnect your coach at any time in Settings, which will immediately revoke their access.
Your data is stored on Google Firebase/Firestore infrastructure. Google is our data processor and has agreed to handle your data in accordance with our privacy commitments.
We may share anonymized, aggregated insights with researchers, partners, or public audiences for product research and improvement purposes. This data cannot be used to identify you or any individual user.
Your WHOOP data is retained for the following periods:
You have the following rights regarding your data:
You can view all data we store about you within the Inwardly app (Settings > Account > Data Access). You can also request a complete export of your data.
You can correct your profile information (name, email) within the Inwardly app under Settings > Account.
You can request deletion of your account and all associated data at any time. Submit a deletion request to support@goinwardly.com, and we will delete your data within 30 days.
You can request a complete export of your data in machine-readable format. Go to Settings > Account > Request Data Export, and we will provide your data within 14 days.
You can revoke Inwardly's access to your WHOOP data at any time (see Section 10: How to Disconnect).
You can disconnect your WHOOP account from Inwardly at any time. This will immediately revoke our access token and prevent us from collecting any new data.
Steps to Disconnect:
What Happens When You Disconnect:
You can also revoke access through your WHOOP account settings at https://www.whoop.com/settings/connected-apps.
We implement industry-standard security measures to protect your data:
All data transmitted between your device and our servers is encrypted using HTTPS with TLS 1.2 or higher. This prevents interception of your data in transit.
Your WHOOP access tokens are stored securely in Firebase with encryption at rest. Tokens are treated as sensitive credentials and are never logged or exposed.
Our OAuth client secret is stored in Firebase Secret Manager with restricted access. Only authorized backend services can access it.
Only authorized Inwardly systems can access your stored WHOOP data. Your coach (if connected) can access your data through role-based access controls, and you can revoke their access at any time.
We conduct regular security reviews of our infrastructure and data handling practices to identify and address vulnerabilities.
Inwardly is not intended for users under the age of 18. We do not knowingly collect or retain data from minors. If we become aware that a user is under 18, we will take steps to delete their account and data.
Parents or guardians who believe a minor has used Inwardly should contact us immediately at support@goinwardly.com.
During the beta program, we may update this Privacy Policy. When we do, we will provide 7 days notice to all users via email and in-app notification before the new policy takes effect.
Your continued use of Inwardly after a policy update constitutes acceptance of the updated terms. We encourage you to review this policy regularly to stay informed about how we protect your data.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: support@goinwardly.com
Subject Line: "WHOOP Privacy Policy Question" or "Data Request"
We will respond to your inquiry within 14 days.