Reading, and I guess I'll take the time to explain why it works this way. Unfortunately I have to keep it at fairly high level. Long story short, we don't trust the transport mechanisms by which our customer's data gets from their wrist to our backend. As such, we securely encrypt it on the device and that encrypted payload can only be decrypted once it's on our servers. At that point it becomes available to be fetched over secure APIs.
We've considered other ways of doing this that will preserve our requirements to keep customer data private and unable to be tampered with. We will likely make it more flexible in the future, but this is the scheme that has worked since the company was founded, almost 14 years ago.