Information collected
The integration requests only the Oura daily and workout permissions. If authorized, it may collect daily sleep, activity, and readiness summaries; workout summaries; OAuth access and refresh tokens; authorization state needed to prevent request forgery; and limited technical records needed to operate and secure the integration. It does not request Oura email, personal-profile, heart-rate time series, tags, sessions, or SpO2 permissions.
How information is used
Oura data is used only for the account owner’s private fitness records, personal dashboards, workout review, and related troubleshooting. It is not sold, used for advertising, shared for another person’s benefit, or used to make eligibility, employment, insurance, credit, or medical decisions.
Oura data will not be used to train artificial-intelligence or machine-learning models.
Consent and revocation
Access begins only after the account owner authorizes the requested permissions through Oura. Consent may be withdrawn at any time by revoking the application in Oura or by emailing privacy@aipeterlab.com. Revocation stops future collection. A deletion request may be made through the same address.
Storage and security
The Oura client secret is kept only in protected server-side secret storage. OAuth tokens are never placed in browser code, URLs, analytics, articles, source control, or application logs. Refresh and access tokens are encrypted before being stored in a private server-side database. Access is limited to the private account owner and the service providers needed to run the integration.
Retention and deletion
OAuth state is short-lived and deleted after use or expiration. OAuth tokens are retained only while the integration remains connected and are deleted promptly after disconnection or a verified deletion request. Imported daily and workout records are retained only while useful to the account owner and are deleted within 30 days after a verified deletion request, except where a longer period is required by law or needed briefly for security and recovery. Expired operational records are removed on a routine basis.
Service providers and transfers
Oura supplies the requested data. The blog’s hosting and protected server-side storage providers process data only as needed to operate the integration. Information may be processed where those providers maintain systems, subject to their security and contractual safeguards.
Health information and limitations
Oura information can be sensitive health and wellness data. This private integration is for personal recordkeeping and education, not medical diagnosis, monitoring, or treatment. Do not rely on it for emergencies or professional medical decisions.
Policy changes and contact
Material changes will be posted on this page with a revised effective date. Questions, access requests, consent revocation, and deletion requests may be sent to privacy@aipeterlab.com.