Menu
JOHN SCHWENGEL

Privacy Policy

Effective July 28, 2026

Overview

This Privacy Policy explains how JohnSchwengel.org and John Lab collect, use, store, and protect information. The public website provides information about John Schwengel’s volleyball and coaching work. John Lab is a private personal-performance dashboard operated by John Schwengel and intended for the operator’s own use.

Information John Lab processes

When an account is connected with permission, John Lab may process:

  • WHOOP data: recovery score, cycle strain, sleep duration, sleep need, related timestamps, and OAuth credentials needed to maintain the connection.
  • Google Calendar data:event titles, descriptions, locations, and start and end times needed to estimate daily schedule load and identify the next event containing “COMPETING” in its title.
  • Nutrition data: daily calories, protein, carbohydrates, fat, source date, timezone, and tracker name sent from the operator’s iPhone through a private Shortcut.
  • Site data: an authentication session, connection status, daily planning text, completed tasks, level, and XP.
  • Team Canada workspace data: a private authentication session and links to separately hosted team resources. The workspace is not indexed or intended for public access.
  • Lesson requests: requester role, names, phone number or email, requested date, time and location, group size, experience level, payment preference, and lesson goals.

John Lab does not request WHOOP profile, body-measurement, workout, or continuous heart-rate scopes.

How information is used

Connected information is used only to display the operator’s performance dashboard, summarize readiness, calculate nutrition progress, understand schedule load, identify upcoming competitions, and generate personalized daily planning suggestions. Lesson request information is used only to review, respond to, and arrange the requested coaching session. Information is not used for advertising, eligibility decisions, insurance, employment, or medical diagnosis.

Storage, security, and retention

OAuth credentials and synchronized nutrition totals are encrypted before being stored in a private Redis database. Information is transmitted over HTTPS. Current WHOOP and Calendar information is requested when the private dashboard refreshes and is not sold or used to build an advertising profile. Daily task progress is stored locally in the operator’s browser. Daily planning text is not saved as a conversation by John Lab. When the adaptive planner is enabled, the current goal and the minimum connected context needed to build that day’s plan are sent to OpenAI with API response storage disabled. Lesson requests may be stored in the private database and delivered to John by email.

Connection credentials and synchronized nutrition totals are kept until the applicable connection is disconnected, its data is cleared, or deletion is requested. No security system can guarantee absolute protection, but reasonable technical and administrative safeguards are used.

Sharing and service providers

Personal information is not sold, rented, or shared for advertising. It may be processed by service providers needed to operate John Lab, including WHOOP, Google, Apple Health, the operator’s selected nutrition tracker (which may be FoodNoms, Cronometer, MacroFactor, or another provider), OpenAI, Vercel, Upstash, and Resend. Those services process information under their own terms and privacy policies. Information may also be disclosed if required by law or necessary to protect the security and integrity of the service.

Control and deletion

Connected accounts can be disconnected from John Lab’s Data Connections page. Disconnecting removes the stored connection credential from John Lab. WHOOP authorization can also be revoked through the WHOOP account or app. Synchronized nutrition data can be cleared from the Data Connections page.

To request access, correction, or deletion of information associated with John Lab, email beach@johnschwengel.org. Requests will be handled within a reasonable period and as required by applicable law.

Children and health information

John Lab is not directed to children under 13. A parent or guardian should complete lesson requests for players under 13. The dashboard provides personal training guidance only and is not a medical service. It is not represented as compliant with HIPAA or suitable for storing regulated medical records.

Policy changes

This policy may be updated as John Lab’s features or connected services change. The effective date at the top of this page will be updated when material changes are made.