Privacy Policy — Edge / OpenStrap
Last updated: August 18, 2026
Edge ("the App") is an independent, open-source project. It is not affiliated with, sponsored by, or endorsed by WHOOP, Inc.
We do not collect your health data
This section describes the builds we ourselves distribute. In the official public releases distributed through the App Store and Play Store, we do not collect your health data. Your health information is processed and stored entirely on your device in those releases. We do not upload it, we do not operate a backend that receives it, and we never see it — unless you explicitly choose to install a GitHub release that has health data contribution enabled, or separately enable AI Coach or Health app integration, described below, which send specific data to services you configure.
Edge is open source. The underlying code contains an off-by-default,
compile-time flag (kHealthDataContributionEnabled) that an
independent developer could enable in their own, separately-built
and separately-distributed copy of the app, pointed at a backend of their
own choosing. We do not enable that feature in the official public builds
we publish. If you explicitly download and install a GitHub release, you may
choose to enable this feature for the purpose of improving algorithm and
calibration insights. That choice is entirely under your control, and the
feature is off by default. A self-built copy compiled with that flag on is
that builder's own software and their own responsibility; it is not covered
by this policy.
Anonymous diagnostics
In the official public releases distributed through the App Store and Play Store, the App does not send your health data off your device. The only thing the App sends off your device automatically — aside from the optional, user-initiated integrations described next — is basic crash/error and performance monitoring, via Firebase (Google) — Crashlytics, Performance Monitoring, and Analytics. This is on by default in GitHub releases; you can turn it off at any time in your profile, which stops any further collection immediately. In App Store and Play Store releases, this data collection does not occur. It never includes your health data — only crash reports, basic device info (OS/model/app version), and coarse performance timing. This data is handled under Firebase's own privacy and security practices, not a system we built or operate ourselves — see Google's Firebase privacy & security documentation: firebase.google.com/support/privacy.
Barcode lookup for food logging
The food log can read a barcode with the camera and fill in the nutrition figures for you. Doing that means asking a database, so it is on by default: what leaves is a number the manufacturer printed on the packet, and nothing about you goes with it. Turn it off and the scan stops asking anybody anything.
- What is sent is the barcode. It goes to openfoodfacts.org, the free and open food database. Nothing about you, your meals, your health or your device goes with it. Like any network request it discloses your IP address to them.
- Only when you scan. There is no background lookup, no batch and no pre-fetch.
- A barcode you have scanned before is answered from your own phone. The App keeps a local copy of what it has fetched, so re-scanning the same packet asks nobody anything.
- The camera reads digits and nothing else. No photo is taken, stored or sent. Declining camera access leaves the rest of the food log working.
- Everything still works with it off. Typing the numbers off the pack was always the way in and still is.
You can turn it off at any time in Settings › Privacy › “Look barcodes up online”, and the App then makes no food-related network request at all.
Their data is contributed by the public, is licensed under the Open Database License, and their own terms say it must not be used for medical purposes. So a scanned figure is treated as something you typed rather than something the App measured: anything that fails a basic plausibility check is left blank instead of filled in, and every filled box is yours to edit before you save.
Location and workout routes
If you record a run, ride or walk, the App uses your device's location to draw that workout's route. This is the most sensitive permission the App asks for, so to be specific about it:
- Only during a workout. Location is read only while a run, ride or walk is actively recording. It stops the moment you finish. The App never reads your location in the background at any other time.
- We never ask for "always" access. The App requests while-in-use location only. Recording does continue while your screen is locked or you switch apps — otherwise a workout would stop being recorded the moment you put your phone in your pocket — but that is scoped to the active workout, not a standing permission to follow you.
- It is visible while it happens. On iOS the system's blue location indicator is shown for the whole time the App is reading location in the background. On Android the workout runs as a foreground service with a visible, persistent notification.
- The App never sends your routes anywhere. A route is written to a local database table on your phone and nowhere else. We do not upload it, it is not included in anonymous diagnostics, and it is not sent to your AI Coach provider — the coach is technically prevented from reading route data, not merely asked not to.
- The one exception is you. If you tap Share on a workout, the image you are shown includes a picture of your route, and whatever you send it to receives it. That is your choice, you see the image before it is sent, and it goes wherever you send it — not to us.
- You can delete it. Deleting a workout deletes its route with it, and uninstalling the App removes all of it immediately.
You can decline or revoke location access at any time in your device settings. The App still records the workout — heart rate, duration, strain and the rest — it simply has no map for it.
Optional, user-initiated integrations
If you choose to enable them, the App can also send data to services you configure:
- AI Coach — if you enable this feature and supply your own API key, summaries of your data are sent to the AI provider you configure (by default, OpenAI) to generate coaching responses. Off by default and requires your own API key.
- Health app integration — if you enable it, the App can write derived daily metrics to Apple Health or Google Health Connect, which are controlled by your device's own OS-level health app, not by us. The App can also read from that same health app when you tap an import — your height, weight, date of birth and sex, your resting heart rate, blood pressure, blood glucose and body temperature readings, and your workouts and their routes. Every import is something you start by hand, never a background sync, and what it reads stays on your device: reading from your health app sends nothing anywhere.
What we don't do
We do not sell your data. We do not send your health data to WHOOP, Inc. or any advertising network. We do not require a WHOOP account or credentials to use the App. We do not operate a backend that stores your health data.
Your controls
Turn off anonymous diagnostics at any time in your profile — this stops any further collection immediately. You can also disable AI Coach or Health app integration at any time in Settings if you'd previously turned them on. If you explicitly installed a GitHub release and enabled health data contribution, you can disable that feature at any time from the app's settings. Barcode lookup for the food log is on by default and can be turned off at any time in Settings › Privacy › “Look barcodes up online”.
Uninstalling the App deletes all of your locally stored data immediately. That's the whole picture unless you had separately enabled one of the optional integrations above — in that case, uninstalling stops the App from sending anything further, but does not reach back and delete data already sent:
- Anonymous diagnostics already sent to Firebase are retained and governed by Firebase's own practices (linked above), not by us.
- Data already sent to your configured AI Coach provider (e.g. OpenAI) is retained and governed by that provider's own policies, not by us.
- Metrics already written to Apple Health or Google Health Connect are retained and governed by that platform's own data controls, not by us — manage or delete them from that app directly.
Children
This App is not directed to children under 13 (or the relevant age of digital consent in your jurisdiction) and we do not knowingly collect data from them.
Changes
We may update this policy; material changes will be reflected here with an updated date.
Contact
Questions about this policy: abdulsaheel81@gmail.com.