L/ LifeApp

Privacy Policy

AttiaTechnology · Effective September 14, 2026

AttiaTechnology operates LifeApp. This policy explains the information we handle when you use LifeApp, including its optional WHOOP connection. Contact us at support@attiatechnology.com with privacy questions or requests.

Information we handle

  • Account and preferences: your email, optional name, password hash, profile details, fitness goals, display preferences and notification settings.
  • Fitness and nutrition: information you enter, such as exercises, sets, repetitions, weights, body measurements, meals, portions, supplements and workout notes.
  • AI features: prompts, conversations, photos you submit for analysis, relevant profile or activity context, generated results and usage records.
  • Subscriptions: subscription status and payment-provider identifiers. Stripe processes payment details through its payment services.
  • Technical information: session cookies, timezone and device preferences, notification subscriptions when enabled, and request or error information used to operate and protect the service. Hosting services may process IP addresses and request metadata.

How we use information

We use information to provide your account, store and display your logs, calculate progress and nutrition summaries, provide requested coaching and analysis, manage subscriptions, deliver enabled notifications, respond to support requests and prevent abuse. Account administrators can manage access and view support information available in LifeApp’s admin screens.

Optional WHOOP connection

An administrator must first enable WHOOP access for your LifeApp account. This does not connect your WHOOP account or grant permission to retrieve its information. You separately choose Connect WHOOP and authorize access on WHOOP’s own screen. LifeApp does not receive your WHOOP password.

The connection requests recovery, sleep, cycles, workouts and basic profile access, plus permission to renew access. We use the WHOOP account ID to associate the connection with your LifeApp account; the profile email and name are not retained by this integration. The connection also requests body measurements: height, weight and maximum heart rate.

LifeApp stores a selected summary of recovery, heart-rate variability, resting heart rate, sleep, cycle strain, recent activities and body measurements. New connections sync automatically using signed WHOOP webhooks, a daily reconciliation check and refreshes while LifeApp is open. You can pause automatic sync and refresh manually. Existing connections stay manual until you enable automatic sync. Summaries replace previous summaries and include up to seven recent recovery records and up to 50 WHOOP activities from a rolling 28-day window. LifeApp compares activity time windows with your workout logs to provide session reviews, set timelines and training suggestions. WHOOP activity summaries do not provide per-set heart-rate measurements. Webhook deduplication identifiers are retained for up to seven days, then removed by the daily cleanup.

Connection tokens and the selected summary are encrypted before database storage. The admin interface controls feature availability but does not expose your WHOOP metrics or tokens. WHOOP information is not sold, used for advertising or used by LifeApp to train AI models. If you separately enable Use WHOOP in AI coaching, selected recovery, sleep and strain metrics are sent to OpenAI for daily coaching suggestions, and to OpenAI or Google Gemini as context when you use Coach. Daily suggestions are encrypted in storage and replaced as new notes are generated. Turning this option off removes the daily note and stops new automatic sharing; existing Coach conversations remain in your history and may be reused as conversation context. With coaching enabled, matched activity summaries and relevant logged sets may also be included when you ask Coach to review a workout.

Optional body autofill copies WHOOP height and weight only into missing profile fields. You can also review and replace existing values. Copied values become ordinary LifeApp profile data and may be used by existing AI features, independently of the WHOOP coaching switch. These profile copies remain after disconnecting and can be edited in Settings. We do not invent measurement dates or create weigh-ins from this import.

You can choose Settings → WHOOP connection → Disconnect & delete data. This deletes the imported WHOOP summary and connection tokens from LifeApp’s active database and attempts to revoke access with WHOOP. If WHOOP cannot confirm revocation, LifeApp will ask you to also remove its access in WHOOP’s connected-app settings. This does not delete records held by WHOOP, workouts logged separately in LifeApp, copied profile measurements, approved training-target changes or existing Coach conversations.

If an admin disables the feature, refresh stops and the summary is hidden. The encrypted connection remains until you delete it or access is re-enabled. The disconnect/delete control remains available while access is disabled.

The separate Copy for WHOOP feature copies a workout to your device clipboard when you request it. You decide whether to paste it into WHOOP; copying does not automatically transmit it to WHOOP.

Service providers and sharing

LifeApp uses Vercel for hosting, Supabase for database infrastructure and Stripe for payments. When you use AI features, relevant submitted content and context may be processed by OpenAI or Google Gemini. Food-search and barcode features may send lookup queries to food-data services such as USDA FoodData Central and Open Food Facts. These providers handle information under their applicable terms and privacy practices.

WHOOP information stored in LifeApp is processed by our hosting and database infrastructure to provide the connection, and is included in coaching AI requests only with the separate WHOOP coaching choice described above. Copied profile measurements follow the regular profile-data rules. We may also disclose information when necessary to respond to a valid legal requirement, protect the service or address fraud and security incidents.

Device storage and notifications

LifeApp uses cookies and browser storage to keep you signed in, remember preferences and support offline workouts. Saved workout data may remain on your device until it synchronizes or you clear site data. Clearing site data can remove unsynchronized entries. Notification permissions can be changed in your browser or device settings. Some settings apply only to the device where you enable them.

Retention, deletion and your choices

We retain account and activity information to provide the service while your account remains active. You can edit or delete supported entries in the app. To request account deletion, a copy or correction of your information, or assistance with privacy choices, email support@attiatechnology.com. We may need to verify your identity before acting on a request.

Some information may remain in backups, security records or records needed for legal or accounting purposes after removal from the active service. Service providers may have their own retention requirements. Privacy rights and applicable exceptions depend on where you live.

Security and processing locations

We use access controls and other safeguards to protect information, including server-side authorization, hashed passwords, and encryption for stored WHOOP tokens and summaries. No online service or storage system can guarantee absolute security. Our service providers may process information in countries other than your own.

Changes and contact

We may update this policy as LifeApp changes. The effective date above identifies this version. If you have questions about this policy or how AttiaTechnology handles your information, contact support@attiatechnology.com.