Legal

Privacy Policy

This policy explains what data okataoo.io collects, how we use it, who we share it with, and the rights you have over it — with a special focus on the health data you share with us through Garmin.

Effective date: April 19, 2026 Last updated: April 19, 2026

1. Overview

okataoo.io ("okataoo," "we," "us") operates a consumer wellness application and website (together, the "Service") that integrates with Garmin Ltd.'s Health API to help individual Garmin device users better understand their own health and training data through AI-generated insights.

We take privacy seriously. We collect only the data needed to deliver the features you enable, we do not sell your data, and we give you clear controls to disconnect and delete at any time.

In one sentence: We use your Garmin health data only to give you personalized wellness and training recommendations inside okataoo.io — never for advertising, never sold to third parties.

2. Information we collect

2.1 Information you provide directly

2.2 Information collected automatically

2.3 Information from Garmin

If you choose to connect a Garmin account, we receive health and activity data from Garmin's Health API, described in detail in Section 3.

3. Garmin Health API data

okataoo.io integrates with Garmin's Health API under the Garmin Developer Program. We never see or store your Garmin username or password. Authorization is handled exclusively through Garmin's OAuth flow; you remain in control and can revoke access at any time.

3.1 What data types we may access

We request only the data types necessary to power the features you use. Typical data types include:

Data categoryExamplesWhy we use it
Daily SummariesSteps, calories, intensity minutes, floors climbedActivity trends and daily readiness
Heart RateResting HR, continuous HR, max HRCardiovascular trends, recovery scoring
Heart Rate VariabilityHRV status, overnight HRVRecovery and nervous-system load
SleepSleep stages, duration, awake time, respirationSleep quality coaching
Stress & Body BatteryDaily stress, energy scoreStress management guidance
ActivitiesWorkout type, duration, distance, HR zones, pace, powerTraining load and workout review
Training metricsVO₂ max, fitness age, training status, acute/chronic loadLong-term fitness trajectory
User profileHeight, weight, birth year, gender (as provided to Garmin)Personalizing calorie, HR-zone, and pace calculations

You can see the exact scopes okataoo.io has been granted at any time inside the app's Connections settings, and at your Garmin Connect account.

3.2 How this data reaches us

When you authorize the integration, Garmin delivers data to us in two ways, both over encrypted HTTPS:

3.3 What we do NOT do with Garmin data

3.4 Revoking Garmin access

You can revoke okataoo.io's access to your Garmin data at any time:

Once access is revoked, we stop receiving new data immediately. You may additionally request deletion of the historical data we already hold (see Section 10).

4. How we use your information

We use the information described above only for the following purposes:

If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases:

6. How we share information

We do not sell your personal data. We share personal data only in these limited situations:

We do not share Garmin-sourced data with any advertising, analytics, or marketing networks.

7. Use of AI and automated processing

okataoo.io uses AI models to turn your Garmin data into natural-language insights, weekly summaries, and conversational answers about your own data. Here is how this works:

8. Data retention

9. Security

No internet-based service can be 100% secure. If we become aware of a breach affecting your personal data, we will notify you and the appropriate authorities as required by law.

10. Your rights & choices

Depending on where you live, you may have the following rights:

To exercise any of these rights, email info@okatoo.io. We will respond within 30 days. We do not discriminate against users for exercising their rights.

California residents: you have additional rights under the CCPA/CPRA, including the right to know, the right to delete, and the right to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under the CCPA.

11. International transfers

We are based in the United States. If you access the Service from outside the U.S., you understand that your data may be transferred to and processed in the U.S. and in other countries where our service providers operate. Where required, we use appropriate safeguards such as the EU Standard Contractual Clauses.

12. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, please contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by a notice inside the app before the changes take effect. The "Last updated" date at the top of this page will also change.

14. Contact us

Questions, concerns, or requests about this policy or your data?

You can also visit our contact page to reach us through our support form.