Privacy
Everything below is open source and can be checked against the code. This is unofficial and not affiliated with or endorsed by Garmin. Garmin's own privacy policy applies to the data Garmin holds: garmin.com/privacy.
Garmin in Claude (the connector)
- Stored: the server keeps one row per connection: a random id, a keyed hash of your Garmin profile id, the client's name (for example "Claude"), a state, a counter and timestamps. The row is deleted after 35 days unused.
- Never stored: your password (sent once to Garmin), your email, your Garmin tokens (they are encrypted inside the token your MCP client keeps) and your Garmin data (it is passed through to your client, not kept).
- Logs hold a connection-id prefix, the tool name, a status and a duration only.
The sleep & HRV demo
When you sign in
- Your email and password go from your browser to this server, and from it straight to Garmin's own sign-in service. They are not stored, logged, or sent anywhere else.
- If Garmin asks for a verification code, the half-finished sign-in is kept for up to ten minutes in an encrypted cookie in your browser, then deleted.
- Garmin returns access tokens. They are encrypted and kept only in your browser, as an httpOnly cookie that expires after 30 days. This server keeps no copy and has no database for the demo.
While you're signed in
- Each page view reads your recent sleep data (score, duration, HRV, resting heart rate) and your name from Garmin, draws the charts, and discards the data. It is not stored.
- The demo only reads. It never writes anything to your Garmin account.
Signing out
Sign out deletes the token cookie. To also end the session on Garmin's side, change your Garmin password or review connected sessions in Garmin Connect.
Other data
To limit abuse, demo sign-in attempts are counted per IP address, in memory, for 15 minutes. Nothing else is collected: there is no analytics and no tracking.