Privacy Policy
Last updated: 27 June 2026
Compound is a personal health-tracking service operated by RH Media (Robin Hunuki), based in Australia. It lets you log your own protocol, recovery and bloodwork. Each account’s data is private to that account. Compound is a tracking tool for your own records and does not provide medical advice or diagnosis.
What this app stores
- Daily protocol logs (compounds taken, doses, free-text notes, morning weight).
- Bloodwork schedule and results links you add yourself.
- Recovery and sleep metrics: recovery %, heart rate variability (HRV), resting heart rate (RHR), sleep duration, and deep/REM sleep minutes. These are either entered manually or pulled from WHOOP (see below).
WHOOP data
If you connect WHOOP, the app uses the WHOOP API (OAuth 2.0) with your explicit authorization to read your recovery, sleep, cycle and profile data (scopes: read:recovery, read:sleep, read:cycles, read:profile). This data is used solely to display your own metrics back to you inside this app and is stored in your private database. It is never sold, shared, or used for any other purpose. WHOOP access tokens are stored server-side only and are never exposed to the browser.
You can revoke WHOOP access at any time from your WHOOP account settings, after which the app stops receiving new WHOOP data.
Storage and security
Data is stored in a Supabase (PostgreSQL) database hosted in the Sydney, Australia region. Each account can only ever access its own data: isolation is enforced at the database level with per-user row-level security. API secrets and access tokens are held server-side and are never sent to the browser.
Sharing
None. Your data is not shared with, sold to, or disclosed to any third party. The app contains no advertising and no third-party analytics or tracking.
Your control and rights
You can edit or delete any record at any time, and disconnect WHOOP whenever you like. From your Account page you can export all of your data as a file, or permanently delete your account, which erases all of your data. Data is retained until you delete it or close your account.
Contact
Questions about this policy can be directed to robin@rhmedia.io.