Security & privacy
How we handle your Garmin account
You're giving a service access to years of health data. Here is exactly what we store, what we don't, and how to cut us off.
What we store, and what we don't
| Data | Stored? | Notes |
|---|---|---|
| Your Garmin password | Never | Sent to Garmin's sign-in service during connection; not logged, not written |
| Garmin long-lived token (OAuth1) | Yes, encrypted | AES-256-GCM, key held only in the runtime secret store; deleted on disconnect |
| Garmin short-lived access token (OAuth2) | Yes, cached | Expires within hours; stored in a KV cache keyed to your account |
| Your health and activity data | No | Streams from Garmin through our server to your AI client; not written to disk or logs |
| Connector token | Hash only | SHA-256 of the token; we can verify it but can't read it back. Rotate any time. |
| Email, plan, Stripe customer id | Yes | Needed to run the account |
| Tool-call counts and tool names | Yes, 90 days | For rate limits and debugging. Not the arguments or results. |
| Write audit log | Yes, 90 days | Which write tool ran when, and the Garmin id it affected, so you can see what the AI changed |
How the Garmin connection works
- You enter your Garmin email and password on our connection page. Our server forwards them to Garmin's single sign-on service, the same one the Garmin Connect app uses, and completes MFA if Garmin asks.
- Garmin returns a long-lived token (valid about a year). We encrypt it and store it. The password is discarded.
- When your AI asks a question, we exchange the long-lived token for a short-lived access token (cached), call Garmin, and stream the result to the AI client.
This is the approach used by the open-source garth, python-garminconnect and garmin-connect libraries, which thousands of people have used for years. Garmin's official Health API is restricted to approved partners and paused for new applicants since 2026.
Controls you have
- Disconnect Garmin: deletes the token immediately. Changing your Garmin password also invalidates it.
- Rotate connector token: any AI client with the old token is cut off instantly.
- Writes toggle: on Athlete and Coach, turn all write tools off with one switch. Read plan never has them.
- Deletes toggle: off by default on every plan. Turning it on registers the delete tools and allows DELETE through the raw write tool.
- Per-tool control in your client: ChatGPT and Claude let you disable individual tools.
- Delete account: removes everything within 24 hours, including the Stripe customer record.
How the AI is kept from acting without you
Every tool carries MCP annotations: readOnlyHint: true for reads, destructiveHint: true for deletes. ChatGPT and Claude ask for your confirmation before running any non-read-only tool. The server's instructions to the model also say to confirm with the user before any write.
Infrastructure
- Runs on Cloudflare Workers, D1 and KV, in Cloudflare's network. TLS 1.2+ everywhere; HSTS preloaded.
- Connector tokens have 192+ bits of entropy and are compared in constant time.
- Secrets (encryption key, Stripe keys) live in Cloudflare's secret store, never in code or git.
- Sub-processors: Cloudflare (hosting), Stripe (payments), Resend (email). No analytics cookies; we use cookieless Cloudflare Web Analytics.
- Logs exclude tool arguments and results. Error logs are retained 30 days.
Things we're honest about
- Garmin can change or restrict the interface we use. We'd rather tell you that than pretend otherwise. There's a status page and a 14-day refund on annual plans.
- Self-hosting keeps your token on your own machine, which is strictly more private. We link to the open-source options.
- What your AI provider does with the data it receives is governed by their privacy policy, not ours. Check ChatGPT's and Claude's data-retention settings.
Responsible disclosure
Email security@garmincommunitymcp.com. We acknowledge within 2 business days and fix confirmed issues before public discussion. We don't run a paid bounty yet but will credit you.
See also: Privacy policy · Terms of service