Coherent Sleep Research

Privacy Policy

A private, single-user integration with the Oura API. This page states exactly what it reads, where that data is stored, and who can see it. The short version: it reads two scopes, stores them on hardware in the operator's home, and shares them with nobody.

Application
Coherent Sleep Research
Operator
Chris Sherman · Saco, Maine, USA
Contact
inquiries@coherentstrategiesllc.com
Users
One — the operator. Not offered to the public.
Scopes
daily · heartrate
Storage
Self-hosted database on the operator's own hardware
Effective
2 September 2026

What this policy covers

1

Who this applies to

This application has exactly one user: its operator, named above. It is a personal sleep-tracking research tool, not a product or service offered to anyone else. No account can be created on it, and no other person's data passes through it.

2

What it reads from Oura

The application requests two OAuth scopes and no others — daily and heartrate. Within those, it retrieves:

  • Nightly sleep periods — bed times, sleep-onset latency, total sleep, sleep-stage durations, efficiency, and the average and lowest heart rate for the night
  • Daily sleep and readiness scores, with their contributing factors and temperature deviation
  • Heart-rate time series

It does not request the personal scope (age, sex, height, weight) or the email scope, and it does not read tags, workouts, sessions, SpO₂, stress, or ring configuration.

3

Where the data is stored

Retrieved data is written to a time-series database running on a single computer on the operator's home network. It is not stored in any cloud service, not replicated to a hosting provider, and not synchronised to any file-sharing service. Records are filed under a pseudonymous participant code rather than a name.

4

Who it is shared with

Nobody. The data is not sold, licensed, published, or disclosed to any third party. There is no analytics service, no advertising network, no crash reporter, and no external processor of any kind. The only network connections the application makes are outbound requests to Oura's own API.

5

How long it is kept

Indefinitely, because the purpose is longitudinal — comparing sleep across months is the point. It is retained until the operator deletes it, and the operator is the only person who can.

6

Withdrawing access

Authorisation can be revoked at any time from Oura account settings, which immediately stops all further retrieval. Data already stored can be deleted from the database directly; because the operator and the data subject are the same person, no request process is needed.

7

Security

API credentials are held in files readable only by their owner, and the application refuses to start if it finds them readable by anyone else. All API traffic uses verified TLS; there is no option to disable certificate verification. The database listens only on the local loopback interface and is not reachable from the network.

8

Changes to this policy

Any change is published on this page with a new effective date. Because the application has a single user, who is also its operator, there is no separate notification process.