Security & privacy

How we handle your Garmin account

You're giving a service access to years of health data. Here is exactly what we store, what we don't, and how to cut us off.

Updated 2026-10-04 · Report a vulnerability: security@garmincommunitymcp.com

What we store, and what we don't

DataStored?Notes
Your Garmin passwordNeverSent to Garmin's sign-in service during connection; not logged, not written
Garmin long-lived token (OAuth1)Yes, encryptedAES-256-GCM, key held only in the runtime secret store; deleted on disconnect
Garmin short-lived access token (OAuth2)Yes, cachedExpires within hours; stored in a KV cache keyed to your account
Your health and activity dataNoStreams from Garmin through our server to your AI client; not written to disk or logs
Connector tokenHash onlySHA-256 of the token; we can verify it but can't read it back. Rotate any time.
Email, plan, Stripe customer idYesNeeded to run the account
Tool-call counts and tool namesYes, 90 daysFor rate limits and debugging. Not the arguments or results.
Write audit logYes, 90 daysWhich write tool ran when, and the Garmin id it affected, so you can see what the AI changed

How the Garmin connection works

  1. You enter your Garmin email and password on our connection page. Our server forwards them to Garmin's single sign-on service, the same one the Garmin Connect app uses, and completes MFA if Garmin asks.
  2. Garmin returns a long-lived token (valid about a year). We encrypt it and store it. The password is discarded.
  3. When your AI asks a question, we exchange the long-lived token for a short-lived access token (cached), call Garmin, and stream the result to the AI client.

This is the approach used by the open-source garth, python-garminconnect and garmin-connect libraries, which thousands of people have used for years. Garmin's official Health API is restricted to approved partners and paused for new applicants since 2026.

Controls you have

How the AI is kept from acting without you

Every tool carries MCP annotations: readOnlyHint: true for reads, destructiveHint: true for deletes. ChatGPT and Claude ask for your confirmation before running any non-read-only tool. The server's instructions to the model also say to confirm with the user before any write.

Infrastructure

Things we're honest about

Responsible disclosure

Email security@garmincommunitymcp.com. We acknowledge within 2 business days and fix confirmed issues before public discussion. We don't run a paid bounty yet but will credit you.

See also: Privacy policy · Terms of service