Health and fitness app data: what platforms can infer beyond a step count

A breakdown of how wellness apps collect device data, manage permissions, and share sensitive health information with third parties.

Article prepared with AI assistance, then verified, edited, and approved by Nicolas Coutant.

The short version

Health and fitness apps often collect far more than just a step count. They can infer sensitive details about your medical history, location patterns, and daily routines. This is not a conspiracy theory; it is a consequence of how device data, app permissions, and data sharing agreements function in the current digital ecosystem.

This guide separates what is technically possible from what is legally required. It is not legal advice, nor does it offer a medical diagnosis. It does not provide a checklist for evading rules. Instead, it clarifies the mechanism: when you grant an app access to your phone or wearable, you often enable a chain of data flows that may reach advertisers or other third parties, sometimes without explicit, granular consent.

How it works

The core mechanism relies on three layers: the sensor, the permission, and the transfer.

First, the device layer. Modern smartphones and wearables (like fitness rings or bands) continuously log biometric signals: heart rate, sleep cycles, body temperature, and GPS coordinates. This raw data is intimate. As noted in recent investigations, for a significant portion of Americans owning consumer wearables, this data is often stored without end-to-end encryption, meaning it can be accessed via a subpoena or other legal request.

Second, the permission layer. To function, apps request access to these sensors. When a user clicks "Allow," they often grant broad access. The app then processes this raw input. For example, a fitness app might combine a sudden drop in heart rate with a specific GPS location to infer a medical event or a change in routine.

Third, the sharing layer. This is where the privacy risk often materializes. Apps frequently transmit processed data to third-party companies. These recipients may include advertising networks, data brokers, or analytics firms. The transfer often happens under the guise of "improving services" or "personalizing content," but the end result is that sensitive health metrics become part of a commercial profile.

What is sourced

Recent reporting highlights specific instances where this mechanism has been scrutinized.

Attorneys working with ClassAction.org have raised concerns that several major health-related platforms may be violating state and federal privacy laws. The list of companies under investigation includes MyFitnessPal, Oura, Eden Health, Natural Cycles, Talkspace, and others.

Specific allegations include:

  • MyFitnessPal: Attorneys believe the Android version of the app may have transmitted users' personal health information to third-party companies for advertising and marketing without consent. This is alleged to violate California's Confidentiality of Medical Information Act.
  • Oura: Despite claims of adhering to strict European data privacy laws (GDPR), attorneys suspect the company may send users' personal and health-related information to third-party advertisers without consent.
  • Eden Health: Suspected of sharing sensitive medical data, personal identifiers, and telehealth information with major ad platforms like Meta and TikTok.

These claims are reported by legal groups and are currently part of ongoing investigations or mass arbitration efforts. They illustrate a pattern where health data, often perceived as private, is treated as a commodity for ad targeting.

Caveats

It is crucial to understand the limits of this information.

First, these are allegations and suspicions reported by attorneys and watchdogs. They are not final court verdicts. The companies involved often dispute these claims or argue that their data sharing complies with their terms of service.

Second, the regulatory landscape is fragmented. While the GDPR (General Data Protection Regulation) in Europe mandates strict controls—requiring a legal basis for processing, limiting retention periods, and ensuring data security—US federal law offers less uniform protection for health data collected by apps that are not traditional medical providers.

Third, the concept of "consent" is often buried in lengthy privacy policies. A user may have agreed to a clause allowing data sharing years ago, or may have accepted a "click-through" agreement without reading the details.

Finally, technical controls exist but are not universal. Some platforms, like Apple, have implemented encryption for health data, making it harder for third parties to access raw logs. However, many other vendors do not offer this level of protection, leaving data vulnerable to subpoenas or internal leaks.

What's next

The trajectory for health app privacy involves a tug-of-war between commercial incentives and consumer rights.

On one side, the industry continues to refine its ability to monetize granular health data. The rise of AI-driven health tools means more data points are being collected and analyzed to predict health outcomes, creating a stronger business case for data sharing.

On the other side, regulatory bodies and consumer advocates are pushing for tighter controls. In the US, state-level laws (like those in California) are becoming stricter, and federal agencies are increasingly scrutinizing how health data is handled.

For consumers, the immediate reality is that "opting in" to a fitness app often means "opting in" to a complex data network. The ability to understand what is being inferred—beyond a simple step count—requires a shift from passive acceptance to active scrutiny of permissions and privacy policies.

Going further

Sources

Found an error? Email us — we correct factual mistakes and note significant updates on the article. Contact us

Keep exploring