Privacy Policy
Last updated: 31 August 2026
Oura MCP is a personal, single-user service operated by an individual for their own use. It is not offered to the public and has no other users.
What is accessed
With the account owner’s explicit OAuth authorization, the service reads their own Oura Ring data: daily activity, readiness and sleep summaries, heart rate, stress, workouts, SpO2, sessions, tags, and basic profile information including email.
What is stored
Only OAuth tokens are stored, on the operator’s own server, in a file readable exclusively by the service account. Health data itself is never written to disk: it is fetched from the Oura API on demand and passed straight to the requesting client.
Who it is shared with
Nobody, with one deliberate exception the owner has chosen: the data is delivered to the AI assistant the owner connects (for example Anthropic’s Claude), and is therefore processed under that provider’s privacy policy. The data is not sold, not used for advertising, not used to train any model by this service, and not shared with any other third party.
Retention and deletion
Tokens are deleted when they expire or when the owner revokes access in their Oura account settings. Revoking access there immediately and permanently ends this service’s ability to read any data.
Contact
Written by and for the operator of this deployment; contact details are on file with the Oura developer application.