Lock In Dashboard

WHOOP privacy notice

Lock In - OC · Last updated 25 September 2026

Purpose and operator

Lock In Dashboard is a personal tracking application operated by Lock In - OC for its owner's use. Its WHOOP connection retrieves authorised information for personal review and validation. It is not a medical service.

Information used

With permission, the connection reads available sleep, recovery, physiological cycle, workout and body-measurement records. These may include:

Not every measurement in the WHOOP app is available through its API. The current connection does not request account profile information. Previews request a recent 14-day window, plus current body measurements. The owner-initiated historical import requests available sleep, recovery, cycle and workout records from 23 December 2025 through its fixed start-of-import time. It preserves the API source records, their identifiers and available scores in encrypted storage. Current body measurements are a snapshot, not a fabricated historical weight series.

Authorisation and security

Sign-in takes place with WHOOP in Chrome or Safari. Lock In does not ask for or store the WHOOP password. The owner enters their developer Client Secret in the authenticated private dashboard's setup field. The Cloudflare Worker backend uses it only with the official WHOOP service. The Client Secret and renewable access tokens are encrypted in Cloudflare D1 using AES-GCM, with a separate key in Cloudflare Worker secrets. They are never returned to the dashboard, bundled in the app, or included in ordinary dashboard exports, this public page or application logs. The owner-only service decrypts them when needed; this is not end-to-end encryption against the cloud operator. Browser-bound, expiring, one-use authorisation state and serialized token renewal protect the shared sign-in flow.

Storage and sharing

The latest successful recent-data preview is encrypted and stored in a separate private Cloudflare D1 connection record, so the same preview is available on the owner's PC and phone. It remains until replaced by the next successful manual refresh or cleared on disconnection/forgetting. Failed or partial refreshes do not replace it. The preview is separate from daily logs, schedule records and normal exported dashboard backups. Displayed readings also exist in browser/app memory while open. No private records are deliberately cached by the app's service worker or stored in browser local storage.

The historical archive and import checkpoint are separately encrypted in Cloudflare D1 using AES-GCM and the shared vault key, with owner and record-specific authentication. Only collection types and opaque source keys are indexed outside encryption. Batches are resumable and provider IDs are consolidated, not duplicated. Closing the import page pauses future batches; a request already in progress may finish. A completed import is a fixed snapshot and does not keep downloading in the background. An encrypted coverage report records date coverage, counts and missing/unscored records. The archive remains until explicitly cleared, disconnected or forgotten; a new authorisation cannot silently mix a paused import with another grant.

Cloudflare hosts and processes the shared connection, encrypted credentials, preview, historical archive and existing private dashboard records. Access is restricted by the owner's Cloudflare Access policy and application-level owner checks. The D1 database has an EU jurisdiction setting; that setting does not promise that every Worker or provider log is processed only within the EU. Existing dashboard records and exports may also be copied by the owner's configured backup and cloud-sync services, including OneDrive where enabled. Ordinary dashboard exports exclude the WHOOP connection credentials, separate preview and historical archive. The owner controls exported files.

This public page contains no health records or connection credentials. It uses no analytics scripts, advertising, embedded trackers or cookies of its own. The hosting provider, Cloudflare, may process ordinary website-access information such as IP addresses under its privacy policy.

Lock In does not sell WHOOP data or use it for advertising. The private cloud backend sends authorisation and read requests to WHOOP. This separate public privacy page receives no health records or credentials. No automatic transfer to an AI service is part of the integration.

Retention and control

Disconnect & revoke requests WHOOP revocation and then clears the active shared credentials, preview and imported history once confirmed. If revocation fails, the app reports that it has not been confirmed. Forget shared connection clears active shared credentials, preview and history without revoking authorisation at WHOOP; access should also be revoked in the WHOOP app. Clear WHOOP history removes only the imported source archive and coverage checkpoint, keeping the connection and recent preview. These actions do not change existing dashboard records. Previously opened devices may display stale in-memory readings until refreshed or closed. Cloudflare's database recovery systems may temporarily retain encrypted earlier copies under its retention policies; clearing active records does not immediately erase those recovery copies.

The older optional PC-only preview remains separate: it uses Windows-encrypted local credentials and an in-memory preview. It is not automatically uploaded or deleted by this shared setup. The owner should stop using that old connection after authorising the shared connection to avoid competing token renewals. Forget local connection in the old window clears that PC's stored connection without deleting shared dashboard records. Revoking WHOOP permission may invalidate both connections.

Corrections to WHOOP measurements should be made through WHOOP and then refreshed in the preview. The historical snapshot is not automatically updated; clear and re-import it if a complete refreshed snapshot is required. Deleting separately recorded dashboard information must also account for copies in exports, retained database versions and cloud backups. Those copies require separate removal according to the owner's backup setup. Contact the operator below for questions about access, correction or deletion.

Contact

Lock In - OC
olliecampbell04@gmail.com