← all articles

Who can see your fitness data

privacy fitness-trackers health-data location-data wearables

A route map that begins and ends at your front door is an address. Not a clue pointing at one. An address, published, timestamped, with a note attached saying how long you were away from it.

That is the thing worth fixing this week. Almost nobody asks me about it. What they ask about is the insurer.

The insurer question, answered properly

The fear runs like this. The watch measures your resting heart rate, the company sells it on, and one day a premium arrives priced on a number you did not know had left your wrist.

In most markets that is not what happens. Underwriting is regulated, and the inputs behind a price have to survive being examined later, which rules out quietly buying a behavioural feed and acting on it. Nobody here is being virtuous. A regulator wants a defensible reason behind a number, and a purchased behavioural feed makes a poor one.

What does exist is the version you join yourself. Connect the tracker, hit some targets, collect points or a discount. Disclosed in full, entirely opt in.

I would not join one, and privacy is not my reason. A discount for good numbers is a surcharge on everyone who cannot produce good numbers, and the group that cannot skews towards people already unwell or already working two jobs. It gets marketed as a reward and it works as a sort.

That is an argument about insurance pricing though. Nothing leaked. Nobody took anything.

So the popular fear names a mechanism that mostly is not running, and while it holds everyone’s attention, four settings sit untouched.

The address, and why it goes first

Activity apps are social products with a sensor bolted on. Feed, followers, applause button, posting switched on out of the box.

The map is the payload. Where you set off, where you stopped, on what date, for how long. The running is the least informative thing on it.

Forty of those maps all clipped at the same circle will give up the centre of the circle, which is the flaw in the privacy zone feature people rely on. Set the zone anyway, make it far wider than feels necessary, and if you want it to genuinely work, walk a few streets before pressing start.

Regularity turns the map into a rota. A loop at the same hour on most weekdays tells a stranger when the house is empty and roughly how long they have. A cycle commute is worse again, because it draws a line between where you sleep and where you work. A dog walk at eleven every night is a fixed appointment in a fixed place.

And then a fortnight with no activity at all, bracketed by two runs in a different climate, is a holiday announcement with the dates filled in.

Look at your follower list while you are in there. On plenty of these platforms following needs no approval, and where it does, most people tap accept because a request reads as a compliment. I went through a list with somebody once and roughly a third of it was accounts they could not place.

Health facts nobody entered

I have written elsewhere about what a couple of years of supermarket receipts give away, and I am not running that argument twice. Purchase history implies things nobody typed into a form, because a sequence carries facts that none of its individual rows contain. Take that as read.

What changes here is the subject matter and the sampling rate.

A doctor sees most people twice a year. A tracker takes a reading every few minutes, for years, through every night, including the long stretches when nothing whatsoever is wrong. That is the part worth noticing. A change is only legible against a baseline, and very little else in an ordinary life produces one.

A resting heart rate drifting upward across a season. A sleep record that fragments and then stays fragmented. Six years of daily activity that halts on a Tuesday and never resumes. A step count that collapses for eleven days and comes back at half.

I am not a doctor and none of those are diagnoses. That is the argument rather than a disclaimer attached to it. They do not need to be diagnoses to be acted on. Something can sort you by health without ever being right about your health, and the wrong inference is the harder one to live with, because no screen anywhere displays it to you and there is nothing to appeal.

Protection attaches to the room, not to the fact

Here is the gap between what people assume and what is true.

The same number in two places gets two different levels of protection, and what decides it is who is holding it, not what it is about.

A resting heart rate recorded at a clinic sits inside health specific rules in most countries. Confidentiality duties, limits on disclosure, a professional with a licence to lose.

The identical figure, produced by a wrist sensor and stored by a consumer app company, is generally just data a company has. No medical duty attaches, because no medical relationship exists.

Under a general privacy law you do get something. Health data is usually a special category with extra conditions on processing. That is a genuine right and it belongs to data protection, which is a different animal from medical confidentiality and a good deal easier to satisfy with a consent screen at signup.

People assume sensitivity travels with a fact. It does not. It attaches to the room the fact was created in.

An aggregate over six people

The employer buys the devices or funds the subscriptions, a step challenge appears with a prize, and the promise is that the company only ever receives aggregates.

Usually true. Usually not sufficient.

An average across a team of six is not anonymous. When the average shifts and five of them know their own figure, the sixth person’s figure is arithmetic anyone in the room can do.

Participation is data by itself. Who joined, who never did, who was in until March and then went quiet. That requires no step count to change hands at all.

There is also a company in the middle that goes unmentioned at the launch meeting. The challenge runs on a platform bought in from somewhere, the promise about aggregates binds the employer, and the vendor holds the raw stream under its own contract. Nobody read that one out.

When a bonus or a premium contribution depends on taking part, voluntary stops meaning much. I have no objection to an employer paying for a gym. I object to an employer paying for a stream of physiological data and filing it under benefits.

If you are joining anyway: a separate account, nothing on it you would not pin to the noticeboard by the lift, and sleep tracking off.

The clause about acquisitions

Fitness companies get bought. Hardware companies get bought. Platforms fold and their assets get sold off in pieces, and a database is an asset in a liquidation like anything else.

The policy you accepted almost certainly says your data may be transferred in the event of a merger, an acquisition or a sale of assets. Everybody agreed to that line. Nobody read it.

Which means a signup is best read as an agreement with whoever ends up owning the database, arriving with whatever business model they arrive with. The privacy policy on the screen in front of you is only the version that happens to be current.

Panic is the wrong response and the timing is the point. Care belongs at the start, because later you are weighing nine years of continuous history against a vague unease, and the sunk cost wins that every time.

What I had backwards

For years I treated this as a hardware question. Which brand, whose security page was less embarrassing, whether the company had a past worth worrying about. I chose a device on that basis and felt like I had done the work.

The device barely matters. The sensor is the least interesting component in the arrangement. Everything with consequences happens in the account, in the sharing defaults, and in whatever else the account got wired to.

The wiring is what I missed. I had connected my fitness account to other apps years earlier for convenience and could not have named them on request. Log in with, sync to, share with. Every one of those is a copy walking out under a policy I never read.

I was comparing wrist straps with a door open behind me.

The order I would do it in

Set default activity visibility to yourself. Then check the back catalogue separately, because on several platforms changing the default does nothing to what is already published, and the old posts are where the address actually sits.

Privacy zones at home and anywhere else you sleep regularly, drawn wide.

Open the connected apps screen and revoke anything you are not using this month. Most people find between two and six.

Find the third party sharing switches. They sit apart from visibility and get labelled research, partners or personalisation.

Skip the social login. That join is permanent in practice.

Then make one decision about sleep. Of everything a tracker collects, the sleep record implies the most and gets used by the fewest people. Mine is off. That is a preference and I will argue it, but it is a preference and not a rule.

None of this stops the company you signed up with from holding what it holds. It narrows the audience to that one company, which is a much smaller number than most people are publishing to right now.

If you only do one item, do the map. The inference problem is a slow argument about the next decade. A route starting at your front door is a fact about tonight. The rest of what I test is here.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →