You are about to give a stranger’s website your Garmin login. That deserves a straight answer rather than four pages of legal throat-clearing, so here is the whole of it.
Last updated 29 September 2026
When you sign in, your email and password are passed straight to Garmin to be exchanged for an access token. The password is never written to disk, never logged, and is dropped from memory the moment Garmin accepts it. It is not kept in any form: not encrypted, not hashed, not at all. Nobody can recover it later, including me.
If you would rather not type it here at all, that is a reasonable instinct. Run the whole thing on your own machine and your Garmin session never leaves it.
One row per person, on a single server in London, run by Fly.io. That row holds:
b****@gmail.com.
It exists so you can tell which account is connected. The full address
is not stored.
Nothing from Garmin is cached: no activities, no heart rate, no sleep, no location. Each question fetches from Garmin fresh and the answer is gone when the request ends. There is no copy of your training history on this server to leak, subpoena or lose.
Your IP address is held in memory for a few minutes so that repeated failed sign-ins can be slowed down. It is never written to disk, and the web server’s request log is switched off precisely so that private connector addresses do not end up in it.
Reading is unrestricted. Activities, splits, heart-rate zones, daily summaries, sleep, body battery, personal records, the same things you see in the Garmin Connect app.
Writing stays inside the workout library: creating a workout, putting it on a date, taking it off again, and deleting one you no longer want. Deleting is gated rather than merely discouraged. The first attempt only reads the workout’s name back, and removing it takes a second one quoting that name, so nothing goes without having been named out loud first.
Your training history is out of reach. There is no tool that deletes or edits a recorded activity, changes your profile, posts anything, or touches anyone else’s account. A run you actually did cannot be lost through this, whatever is asked of it.
This is the part people miss, so it gets said plainly.
Whatever you ask for arrives in your chat.
Once your Garmin data is in a conversation, it is in that conversation, which means Anthropic or OpenAI handle it under their privacy policy, exactly as they handle everything else you type. If you are not comfortable with your resting heart rate sitting in your chat history, this tool is not for you, and no promise I make about my own server changes that.
Beyond that: nothing is sold, rented, or handed to advertisers, data brokers or anyone else. There is no third party with access to the database. It is one server, one person, no business model.
These pages count views using PostHog on its European servers, configured to leave nothing behind: no cookies, no advertising identifiers, no session recording, and no profile built about you. It records that a page was opened and that a button was pressed, which is how I know whether the instructions actually work. If you use the box on the front page that asks which connector should be next, the name you tapped or typed is recorded the same way, and that is all it carries.
It never receives your email, your Garmin data, or your connector address. That is also why this site has no cookie banner: there is nothing to ask you to consent to.
Open the sign-in page and choose Disconnect. That deletes your row outright (token, masked email, fingerprint, timestamps) and the connection stops working immediately. Nothing is retained afterwards, so there is no backlog to request a copy of or ask to be forgotten from.
Signing in again has the same effect on whatever came before it: the old session is destroyed as the new one is created. If you ever think a connection has ended up somewhere it shouldn’t, signing in once more takes it back.
Removing the connector in Claude or ChatGPT is worth doing too, but it only removes it at their end. The Disconnect button is what deletes the stored session here. Nothing changes on Garmin’s side either way.
This is a personal project run by Bart Etcheverry, in the UK. It is not affiliated with, endorsed by, or connected to Garmin, Anthropic or OpenAI. It reaches Garmin through the same private interface the Garmin Connect website uses, which is why it can break when Garmin changes something.
It is not intended for children under 13, and it is not a medical device. Nothing it tells you is medical advice.
If this policy changes, the date at the top changes with it, and the edit history is public like the rest of it. Questions, or anything here that turns out not to match the code: open an issue, or find me at bartetcheverry.com.