SOMABack

Privacy Policy

Last updated: August 8, 2026

SOMA is built to help you feel better in your body. We believe that wellness data is personal, and we treat it that way. This policy explains what we collect, how we use it to build your rituals, where it lives, and how you can delete it.

1. What we collect

When you use SOMA without connecting a wearable, we only collect the choices you make in the app — such as session length, focus area, and experience type — and a local record of completed sessions so you can view your history.

If you choose to connect WHOOP, we request read-only access to recovery, sleep, workout, cycle, and basic profile data. Specifically, we may read:

  • Recovery score, HRV, and resting heart rate
  • Sleep duration, sleep performance, and awake time
  • Daily strain and recent workout type, duration, and strain
  • Your first name from your WHOOP profile, so we can personalize the greeting

We do not collect heart-rate traces, GPS routes, GPS locations, or any other sensitive health data beyond what is listed above.

2. How we use your data

SOMA uses your data to compose a short, adaptive mobility or wind-down ritual. The engine weights recent activity and recovery to decide what to emphasize, how long to hold positions, and how intense the session should feel.

For example: after a high-strain day we may bias toward restorative work and longer holds; after good sleep and low strain we may include more activation. All decisions are made locally in real time and are not used to build a marketing profile.

We do not sell your data. We do not use it for advertising. We do not share it with employers, insurers, or any other third party for their own purposes.

3. WHOOP data in detail

WHOOP access is optional and initiated by you. When you tap "Connect WHOOP", you are sent to WHOOP's own authorization screen where you can approve or deny the requested scopes.

The WHOOP token is stored in an encrypted, http-only server-side session cookie. It is never written to plain browser storage or exposed to the client. We only read from WHOOP when you load the app or explicitly refresh the connection.

If you disconnect WHOOP inside SOMA, we immediately clear the session and token. We do not retain a copy of WHOOP data after disconnection.

4. Where data is stored

Session history and your in-app preferences are stored in your browser's local storage. This stays on your device and is not transmitted to our servers.

WHOOP tokens and profile data are stored in encrypted server-side session cookies hosted on the infrastructure that runs SOMA. The encryption password is kept as a server secret and is not accessible from the browser.

We do not currently store WHOOP data in a database. If that changes in the future, we will update this policy and ask for your consent where required.

5. Third-party services

SOMA uses WHOOP as a data source. WHOOP's own privacy practices apply when you use their service. We also rely on standard infrastructure and analytics providers to keep the app running and to diagnose errors, but these providers do not receive your WHOOP data or session history for their own purposes.

6. Cookies and similar technologies

We use a single encrypted server-side cookie to maintain your WHOOP session. This is necessary for the integration to work. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

7. Your rights

Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your personal data. Because most SOMA data lives on your device, you can usually exercise these rights directly inside the app:

  • View your completed sessions on the Progress page.
  • Disconnect WHOOP at any time from the home screen, which deletes the server token.
  • Clear your browser's local storage to remove all local session history.

If you need help with a data request, contact us at the address below and we will respond as soon as we can.

8. Data deletion

Disconnecting WHOOP removes the access token from our server and stops any future reads. Clearing your browser's local storage removes your local history.

If you want us to delete any server-side logs or error reports that may contain your data, email us at privacy@soma-app.example and we will handle it promptly.

9. Children's privacy

SOMA is not intended for users under 16. We do not knowingly collect data from children. If you believe a child has provided us with data, please contact us so we can delete it.

10. Changes to this policy

We may update this policy as the app evolves. If we make material changes, we will update the "Last updated" date at the top of the page and, where appropriate, notify you inside the app.

11. Contact us

Questions about privacy or data deletion? Reach out at privacy@soma-app.example.

SOMA supports everyday movement and wellbeing. It is not medical advice. If anything feels painful, ease off or stop.