Privacy
Your health data. Your rules.
Healthy Shippers only works if sharing health data is always deliberate. So: private by default, nothing published unless you choose it, and nothing sold, ever. Here’s the detail.
- Private by default. Nothing is shared until you say so.
- Connecting WHOOP or Oura doesn’t publish anything.
- You choose what other shippers can see, metric by metric.
- A public profile and research participation are separate consents. Neither is on by default.
- Disconnect anytime. Delete anytime. Delete your account and it all goes.
- No selling or renting your data. Ever, to anyone.
01Who runs this
Healthy Shippers is a health community for people who build things on the internet. The service at healthyshippers.com is run by Robbin Schuchmann OÜ (registrikood 16388851), Sepapaja 6, 15551 Tallinn, Estonia. VAT EE102493683.
Under the GDPR, that company is the controller of your data.
Privacy questions, data requests, corrections, complaints, or “this page is wrong”: hi@robbinschuchmann.com.
02What we store, and why
Five kinds of thing. Only the first is required.
- Your account. An email address, and a password if you set one. Sign in with GitHub, Google or X instead and we get your username, email and avatar there. We never see your password at any of them, and GitHub sign-in gives us no access to your private repositories.
- What you write. Username, display name, bio, goals, experiments, posts, comments, reactions, and any metric you type in by hand.
- What your wearable sends. Only after you connect one, and only what the scopes you granted cover. That’s the next section, because it’s the part that matters most.
- Technical data. Server logs: IP address, timestamp, URL, user agent. That’s how a web server works and how we spot abuse.
- Product analytics. PostHog, on its US cloud, loaded through our own domain so a content blocker doesn’t quietly delete half the numbers. Pageviews and product events: which pages get opened, which features get used. After you sign in those events carry your account id, and signing out resets the identity. No advertising trackers, no ad profiles, and never a health reading.
We store it to run your account, show you your own data, show other shippers exactly what you chose to show them, and keep the site up. The legal basis for each is in the formal bit.
03What your wearable sends
Connecting is optional. You start from Healthy Shippers, finish on the provider’s own site, and grant the scopes you’re comfortable with. We never see your password there. We receive access tokens, which our server encrypts before they reach the database.
| Provider | What arrives, for the scopes you granted |
|---|---|
| WHOOP | Recovery, including heart rate variability and resting heart rate. Sleep: duration, efficiency, consistency, stages. Daily cycles and strain. Workouts: duration, strain, heart rate, calories. Body measurements: height, weight, max heart rate. Through the WHOOP API v2. |
| Oura | Daily sleep, readiness and activity scores, heart rate, and workouts. |
It arrives two ways: a webhook when something changes, and a periodic poll to catch what a webhook missed. We keep the raw payload as an audit trail, so a normalization bug can be fixed without asking you to re-sync a year of data, and we derive normalized metrics from it so a WHOOP sleep and an Oura sleep are comparable. Every metric lands at your default visibility, which is private unless you changed it. Connecting a provider publishes nothing.
Disconnect from your settings at any time, or revoke our access from the provider’s own settings. New data stops arriving and we stop using the token. Data we already have stays until you delete it, so disconnecting doesn’t silently wipe your history.
Fitbit, Hevy and GitHub activity may follow. What WHOOP, Oura or anyone after them does with your data is governed by their own policy, not this one.
04Who can see it
Every row of health data carries its own visibility: private, friends, or public. Private is the default. Your recovery can be public while your weight stays private. Your profile has its own setting, separate from the metrics on it, and changing a default applies to data that arrives afterwards, not to what’s already there.
None of that is enforced in the interface alone. Postgres row-level security decides it on every read, per row, so a bug in a page can’t leak a private row. The query never returns it.
Four consent switches sit on top. They’re independent, and none is on by default:
- Public profile: whether people who aren’t you can see your profile.
- Research: whether your de-identified data can appear in aggregate community research.
- Product email: whether we can email you about the product.
- Leaderboards: whether you appear in public rankings.
Turning one on doesn’t turn on another. A public profile does not opt you into research. Revoke any of them at any time, and revoking takes effect going forward. We keep a dated record of what you granted and revoked, because that record is the proof of what you agreed to. It goes when your account goes.
Keeping everyone else out: provider tokens are encrypted before they reach the database, so the database holds no plaintext token and no key material, and traffic is served over HTTPS. No service is unbreakable, so if your data is ever affected we’ll tell you and we’ll tell the regulator where the law requires it. Found a security problem? Email hi@robbinschuchmann.com.
05Research is separate, and opt in
We’d like to publish a recurring community report, a “State of Shipper Health”: how much shippers actually sleep, which experiments people said helped.
It only ever uses de-identified data from people who separately opted into research. Not from public profiles, not from the product email list. Only from that one consent, and revoking it takes you out of everything published afterwards. We never publish identifiable health data without explicit permission.
It’s observational community data. It shows what people who use Healthy Shippers reported and measured. It is not clinical research, it does not establish causation, and we won’t present it as either.
06What we don’t do
- No selling or renting your data. Ever, to anyone.
- No advertising trackers, and no ad profiles built from anything you store here.
- No sponsor access to personal health data. Sponsors can buy a clearly labelled placement and nothing else.
- No sharing with employers, insurers or health services.
- No research participation unless you switched research on yourself.
- No sending your Healthy Shippers activity back to WHOOP, Oura or anyone else. We read from them. Nothing goes the other way.
- No soft delete. Delete is delete.
One exception, and it’s the honest kind: we’d hand over data if a valid legal order required it, or to protect someone’s safety. We’ll tell you when that happens, where we’re allowed to.
07Everyone who touches your data
The whole list. Each one is here because the product needs it, and each is bound to use your data only to provide their service to us.
| Who | What for |
|---|---|
| Supabase | The database, sign-in, and file storage. Profiles, metrics, raw provider events and consents all live here. Hosted on AWS in Singapore (ap-southeast-1). Sign-in and account email go out through Supabase’s own sender, so no separate email company is involved. |
| Hetzner | The server that runs the site itself. It’s in the EU. |
| PostHog | Product analytics, on its US cloud, loaded through our own domain. Pageviews and product events. Never a health reading. |
| GitHub, Google, X | Sign-in only. Each learns that you signed in to Healthy Shippers. None of them gets any health data. |
| WHOOP, Oura | The source of the data, not a recipient of it. We read from them; nothing goes back. |
Nobody else. No payment processor, because there is nothing here to pay for. If we ever take sponsorship, it will be labelled as sponsorship and it will not come with access to anyone’s health data.
08Deleting your data
From your settings: individual metrics, posts and experiments, or the whole account.
Deleting the account cascades. It removes:
- your profile
- every health metric, and every raw provider payload we stored
- your goals and their progress, and your experiments
- your posts, comments and reactions
- your connections to providers, and the encrypted tokens with them
- your consent history, badges, XP and everything else keyed to your account
It’s not a soft delete and there’s no recovery window. Deleting your Healthy Shippers account doesn’t delete anything at WHOOP or Oura; do that on their side.
Until you delete it, we keep it: your account, profile and health data stay for as long as the account does, because they’re what you came here for. Server logs rotate off the server as new ones arrive and are archived nowhere else. Supabase takes a daily backup, so anything you delete survives in a backup until that backup rolls off on Supabase’s schedule. We can’t pull data back out of a backup for you.
09The formal bit
What the GDPR requires us to tell you, in the fewest words that are still true. If this section and the rest of the page ever disagree, that’s a bug. Tell us.
Controller
Robbin Schuchmann OÜ (registrikood 16388851), Sepapaja 6, 15551 Tallinn, Estonia. VAT EE102493683. Contact hi@robbinschuchmann.com.
Why we’re allowed to use it
We run your account and show you your own data because that’s the contract you signed up for. We keep the service up, secure and free of abuse on our legitimate interest in running a service that works, which covers server logs, rate limiting and debugging.
Health data is different. It’s a special category under GDPR Article 9, and your explicit consent is the only basis we rely on for it. The app asks for that consent at onboarding, before any health data is stored, and connecting a provider is a second deliberate act on top. Research and product email are separate explicit consents again. Withdraw any of them and the processing stops going forward.
Your data leaves the EEA
It lives in a hosted Supabase project on AWS in Singapore (ap-southeast-1). We’re an Estonian company, so for members in the EEA that’s a transfer outside the EEA under Chapter V of the GDPR, and Singapore has no European Commission adequacy decision. The safeguard we rely on is the standard contractual clauses in Supabase’s data processing addendum. We’re saying so plainly rather than burying it, because where health data sits is worth weighing before you sign up.
Your rights
The GDPR gives you all of these, and we’ll honour them for everyone. See what we hold about you. Get a copy in a portable format. Correct anything wrong. Delete all of it or part of it. Restrict or object to how we use it. Withdraw any consent, without affecting what was lawful before you withdrew it. Complain to your local data protection authority if you think we’ve got it wrong; ours is the Estonian Data Protection Inspectorate.
Most of it you can do yourself in settings. There’s no self-serve export button yet, so email hi@robbinschuchmann.com for a copy of your data, or for anything else, and we’ll answer within 30 days.
Age
You need to be at least 18. We don’t knowingly collect health data from children. If you think a child has an account, email hi@robbinschuchmann.com and we’ll remove it.
Healthy Shippers is a community and a tracking tool. It is not a medical device, we are not a healthcare provider, and nothing on the site diagnoses, treats or prevents anything. What other shippers share is their experience, not a prescription. Talk to an actual doctor about actual symptoms.
10Later features
Things that don’t exist yet, so this page doesn’t pretend they do.
- Payments. There are none. No payment processor touches this site and nothing here costs money.
- Data export. No self-serve button yet. Email us and a human sends you your data.
- More providers. Fitbit, Hevy and GitHub activity may follow. What your wearable sends applies to whatever comes next, and its table gets a row before the integration goes live.
- An EU region. The database is in Singapore today. As the community grows we’ll weigh moving it to an EU region. Something we’re watching, not a promise.
Any of those arriving changes this page, and the date at the top, before it changes the product. If a change means a genuinely new use of your health data, we’ll ask for consent again rather than quietly editing this page and hoping you don’t notice.