Privacy Policy
Effective date: May 28, 2026 · Last updated: August 20, 2026
OMNI Platforms ("OMNI," "we," "us," or "our") operates the OMNI web platform and the Omni Companion iOS application (collectively, the "Services"). We are deeply committed to protecting your privacy and the security of your personal and health data. This Privacy Policy explains what information we collect, how we use and share it, and the rights available to you under applicable law—including the FTC Health Breach Notification Rule, the California Consumer Privacy Act (CCPA), and the Washington My Health My Data Act (WMHMDA).
By registering for or using the Services, you acknowledge that you have read this Privacy Policy and agree to its terms. If you do not agree, please do not use the Services.
1. Information We Collect
1.1 Account & Identity Data
When you create an account we collect your username, email address, password hash, preferred language, unit system, and role (user, monitor, doctor, or personal trainer).
1.2 Consumer Health Data
The OMNI platform is a health-tracking service. We collect and process a broad range of consumer health data, including:
- Biomarkers (blood work, lab results, biometric measurements such as height, weight, body composition)
- Physical fitness data (workouts, activities, personal records, exercise logs)
- Nutritional data (food logs, macronutrients, fasting periods)
- Supplement and medication logs
- Medical history (conditions, allergies, surgeries, hospitalizations)
- Family medical history
- Hormonal health data
- Sleep and mental health self-assessments
- Genomic profile data (if submitted)
- Journal entries and experiment tracking data
- Data imported from connected health devices and apps (e.g., WHOOP, Apple Health, Fitbit, and Withings)
1.3 Information Imported from WHOOP
Connecting a WHOOP account is optional. If you choose to connect WHOOP, we use WHOOP's OAuth authorization process and, with your permission, collect:
- Basic profile information: your WHOOP user ID, first and last name, and email address
- Body measurements: height, weight, and maximum heart rate
- Cycle and activity information: strain, energy expenditure, average and maximum heart rate, workout distance, and workout timestamps
- Recovery information: recovery score, resting heart rate, heart rate variability (HRV), blood oxygen saturation (SpO₂), and skin temperature
- Sleep information: sleep duration and stages, sleep performance, consistency, efficiency, respiratory rate, and sleep timestamps
- Connection information: the permissions you granted, encrypted access and refresh tokens, token expiration, connection timestamps, and last synchronization time
OMNI requests WHOOP permissions for profile, body measurement, cycle, recovery, sleep, and workout data, plus offline access so the connection can be refreshed without requiring you to sign in to WHOOP each time. OMNI receives WHOOP data only after you authorize the connection and use the synchronization feature.
1.4 Device & Usage Data
We automatically collect IP address, browser/device type, operating system, referring URLs, pages visited, and session duration. On mobile devices this includes device identifiers and OS version.
1.5 Communications
We retain emails and in-app messages you send or receive through the platform.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and personalize the Services
- Generate health insights, protocol recommendations, and the Human System Profile Index (HSPI)
- Connect to your WHOOP account, synchronize the health and fitness information you select, and display it in your OMNI health history
- Facilitate care coordination between users and linked health professionals
- Send transactional emails (registration confirmation, password reset, login verification codes)
- Send operational notifications and weekly health summaries
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
We do not sell your personal information or consumer health data to third parties. We do not use your health data for advertising purposes.
3. How We Share Your Information
- Linked professionals. If you provide a link code during registration, your health data will be visible to the linked doctor, personal trainer, or monitor you designate.
- Connected services such as WHOOP. When you ask us to connect WHOOP, OMNI communicates with WHOOP to authorize and maintain the connection, retrieve the data categories you approved, and revoke access when you disconnect. WHOOP processes information in accordance with its own Privacy Policy. OMNI does not send your imported OMNI health history back to WHOOP.
- Service providers. We share data with vendors who help us operate the Services (cloud hosting, transactional email) under confidentiality agreements that prohibit them from using your data for any other purpose.
- Legal compliance. We may disclose information when required by law, subpoena, court order, or government regulation, or to protect the rights and safety of OMNI, our users, or the public.
- Business transfers. In the event of a merger, acquisition, or sale of assets, user data may be transferred. We will notify you via email or a prominent notice on the Services before your data is transferred and becomes subject to a different privacy policy.
4. WHOOP Choices and Controls
You control whether OMNI can access your WHOOP data. You may decline to connect WHOOP and continue using other parts of the Services. You may also disconnect WHOOP at any time from the WHOOP integration screen.
When you disconnect, OMNI attempts to revoke its access through WHOOP and deletes the stored WHOOP OAuth connection, including its access and refresh tokens and WHOOP profile metadata. Disconnecting stops future WHOOP synchronization, but health metrics already imported into OMNI remain in your OMNI health history. You may delete those imported metrics using available account controls or request their deletion as described in Sections 6, 7, and 10. You may also manage OMNI's authorization through your WHOOP account.
5. FTC Health Breach Notification Rule (16 CFR Part 318)
As a vendor of personal health records, OMNI complies with the FTC Health Breach Notification Rule. In the event of a breach of security of individually identifiable health information maintained in unsecured form, we will:
- Notify each affected individual without unreasonable delay and no later than 60 calendar days after discovery of the breach.
- Notify the Federal Trade Commission (FTC) as required.
- In cases involving more than 500 residents of a state, notify prominent media outlets serving that state.
Breach notifications will include: (a) a description of the breach; (b) the types of information involved; (c) steps you can take to protect yourself; (d) what OMNI is doing to investigate and mitigate the breach; and (e) contact information for questions.
6. California Consumer Privacy Act (CCPA / CPRA)
If you are a California resident, you have the following rights under the CCPA and the California Privacy Rights Act (CPRA):
Right to Know
You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources from which we collected it, the business or commercial purpose for collection, and the categories of third parties with whom we share it.
Right to Delete
You may request that we delete personal information we have collected from you, subject to certain exceptions permitted by law.
Right to Correct
You may request that we correct inaccurate personal information we maintain about you.
Right to Opt-Out of Sale or Sharing
We do not sell or share (for cross-context behavioral advertising) your personal information. You do not need to take any action to exercise this right.
Right to Limit Use of Sensitive Personal Information
We use sensitive personal information (including health data) only to provide the Services you requested. We do not use it for additional purposes without your consent.
Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights.
How to Exercise Your California Rights
Submit requests by email to contact@core-dynamics.io or through your account profile. We will respond within 45 days. We may verify your identity before processing requests.
7. Washington My Health My Data Act (WMHMDA)
The Washington My Health My Data Act (SB 1155, effective March 31, 2024 for regulated entities) applies to consumer health data of Washington State residents. OMNI collects consumer health data as defined by the WMHMDA, including health conditions, diagnoses, biometric data, physical activity, sleep, nutritional data, and other health-related information.
Consent
We obtain your consent before collecting consumer health data that is not strictly necessary to provide the Services you have requested, including by asking you to authorize optional connections such as WHOOP. You may withdraw consent at any time by disconnecting the integration or contacting us (see Section 10 below). Withdrawal of consent will not affect the lawfulness of processing before withdrawal.
No Sale of Consumer Health Data
We do not sell consumer health data as defined by the WMHMDA. We do not share consumer health data with third parties for advertising purposes.
Washington Consumer Health Data Rights
If you are a Washington resident, you have the right to:
- Confirm and access whether we collect, share, or sell your consumer health data and obtain a list of third parties with whom we have shared it.
- Withdraw consent for our collection and sharing of your consumer health data.
- Delete consumer health data collected about you from our records and direct our processors to delete it.
How to Exercise Your Washington Rights
Submit requests to contact@core-dynamics.io. We will respond within 45 days (extendable by an additional 45 days with notice). We will not require you to create an account solely to exercise your rights.
Appeals
If we decline to take action on your request, we will inform you of the reason and explain how to appeal the decision. You may submit an appeal to contact@core-dynamics.io with "WMHMDA Appeal" in the subject line.
8. Data Retention
We retain your account and health data, including health metrics imported from WHOOP, for as long as your account is active or as needed to provide the Services. WHOOP connection credentials and profile metadata are retained only while the integration remains connected and are deleted from OMNI when you disconnect. When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law or necessary to resolve disputes.
9. Data Security
We implement administrative, technical, and physical safeguards designed to protect your information, including password hashing, encrypted communications (TLS), encryption of stored WHOOP access and refresh tokens, end-to-end encrypted messaging, access controls, and new-country login alerts. No security system is impenetrable; we cannot guarantee that information may not be accessed, disclosed, altered, or destroyed in a breach.
10. Contact Us
For privacy-related questions, requests, or complaints, contact us at:
OMNI Platforms
Privacy & Data Protection
Email: contact@core-dynamics.io
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on the Services at least 30 days before the changes take effect. Continued use of the Services after the effective date constitutes acceptance of the revised policy.