What data we process: We access your Polar Flow data (sleep,
heart rate, activity, recovery) via the Polar AccessLink API to display your personal dashboard.
Legal basis: GDPR Article 6(1)(a) — your consent. You can
withdraw it anytime by deleting your data.
Data storage: Your session token is stored encrypted in
Cloudflare KV for 30 days. We do not store your raw health data permanently.
Data sharing: We do not sell, share, or transfer your data to
any third party. Ever.
Your rights: Access, rectification, erasure, portability, and
restriction. Delete everything with the "Delete Data" button at any time.
Retention: Data is deleted automatically after 30 days of
inactivity, or immediately when you click "Delete Data".
Contact: For privacy questions, contact us through the
dashboard.