Privacy Policy
Updated September 6, 2026
This policy describes the planned data handling for the Age 45 Project, a private integration operated by Josh Surma for his own Oura account. The integration is under development. This public website provides project information; it does not display or collect visitors' Oura health records.
Information collected
After authorization, the integration will retrieve information made available by Oura within the permissions granted by the account owner. This may include profile information; sleep and readiness metrics; activity and heart-rate records; workouts; blood oxygen; stress and recovery measures; cardiovascular measures; and tags or sessions.
Oura record identifiers, source dates and timestamps, and ingestion records will also be retained to trace data to its source, prevent duplicate records, and process corrections. The integration does not request the account's email scope or collect the owner's Oura password.
Purpose and use
Information is used for the owner's Age 45 Project: organizing personal records, reviewing trends, checking data quality, and producing personal analyses and reports. The owner may combine these records with other personal project information, such as nutrition, body measurements, or subjective daily check-ins.
Data is not sold, used for advertising, or published by this integration.
Storage and access
Project records will be stored in the owner's OneDrive account and locally synced project folder. Microsoft processes synced files as the storage provider. Copies may exist on the owner's synced devices and in provider-managed recovery or backup systems.
The pipeline is designed to store authentication secrets in Windows Credential Manager, outside the OneDrive project files. Secrets will not be written into project configuration, raw health-data files, or operational logs. Access depends on the security of the owner's device and associated accounts; no system can guarantee absolute security.
Analysis services
The owner may choose to provide selected project data to an analysis service, including ChatGPT. This is separate from publishing these informational pages. Such use will occur only after checking that the service's terms and data controls support the intended use under Oura's applicable requirements. The project will not use Oura data to train or improve AI models. A service that cannot meet that restriction will not be used with the data.
Retention and deletion
Records will be kept only as long as necessary for the year-long project and its documented follow-up analysis and verification. The owner will review continued retention at the end of the project and remove records that are no longer needed. Records will not be retained indefinitely by default.
Deletion requires removing the relevant source files, processed datasets, and derived copies from the project, and addressing synced copies and any analysis-service copies. Deleted files may remain temporarily in provider-managed recycle bins, version history, or backups under the provider's retention settings. Deleting project copies does not delete the original records held by Oura.
Withdrawing access
The owner can stop collection by disabling the pipeline and can revoke the integration's access through Oura's connected-application controls. Revocation stops future authorized retrieval; it does not automatically delete previously downloaded records. Those records must be removed separately.
Website visits and contact
The project does not add advertising, visitor accounts, or analytics trackers to these pages. This website is hosted on Cloudflare Pages. Cloudflare may process ordinary request information, such as IP addresses and browser details, to deliver and secure the website. See the Cloudflare Privacy Policy: Cloudflare Privacy Policy.
If someone emails the operator, the email address and message will be used to respond and retained only as needed to handle the inquiry.
Changes and questions
This policy will be updated when the project's data practices change. Any expansion beyond the owner's personal account will require a separate review of permissions and privacy practices.
Contact: Josh Surma — jvsfitter@gmail.com