Health and fitness app data: what platforms can infer beyond a step count
A breakdown of how wellness apps collect device data, manage permissions, and share sensitive health information with third parties.
Article prepared with AI assistance, then verified, edited, and approved by Nicolas Coutant.
The short version
Health and fitness apps often collect far more than just a step count. They can infer sensitive details about your medical history, location patterns, and daily routines. This is not a conspiracy theory; it is a consequence of how device data, app permissions, and data sharing agreements function in the current digital ecosystem.
This guide separates what is technically possible from what is legally required. It is not legal advice, nor does it offer a medical diagnosis. It does not provide a checklist for evading rules. Instead, it clarifies the mechanism: when you grant an app access to your phone or wearable, you often enable a chain of data flows that may reach advertisers or other third parties, sometimes without explicit, granular consent.
How it works
The core mechanism relies on three layers: the sensor, the permission, and the transfer.
First, the device layer. Modern smartphones and wearables (like fitness rings or bands) continuously log biometric signals: heart rate, sleep cycles, body temperature, and GPS coordinates. This raw data is intimate. As noted in recent investigations, for a significant portion of Americans owning consumer wearables, this data is often stored without end-to-end encryption, meaning it can be accessed via a subpoena or other legal request.
Second, the permission layer. To function, apps request access to these sensors. When a user clicks "Allow," they often grant broad access. The app then processes this raw input. For example, a fitness app might combine a sudden drop in heart rate with a specific GPS location to infer a medical event or a change in routine.
Third, the sharing layer. This is where the privacy risk often materializes. Apps frequently transmit processed data to third-party companies. These recipients may include advertising networks, data brokers, or analytics firms. The transfer often happens under the guise of "improving services" or "personalizing content," but the end result is that sensitive health metrics become part of a commercial profile.
What is sourced
Recent reporting highlights specific instances where this mechanism has been scrutinized.
Attorneys working with ClassAction.org have raised concerns that several major health-related platforms may be violating state and federal privacy laws. The list of companies under investigation includes MyFitnessPal, Oura, Eden Health, Natural Cycles, Talkspace, and others.
Specific allegations include:
- MyFitnessPal: Attorneys believe the Android version of the app may have transmitted users' personal health information to third-party companies for advertising and marketing without consent. This is alleged to violate California's Confidentiality of Medical Information Act.
- Oura: Despite claims of adhering to strict European data privacy laws (GDPR), attorneys suspect the company may send users' personal and health-related information to third-party advertisers without consent.
- Eden Health: Suspected of sharing sensitive medical data, personal identifiers, and telehealth information with major ad platforms like Meta and TikTok.
These claims are reported by legal groups and are currently part of ongoing investigations or mass arbitration efforts. They illustrate a pattern where health data, often perceived as private, is treated as a commodity for ad targeting.
Caveats
It is crucial to understand the limits of this information.
First, these are allegations and suspicions reported by attorneys and watchdogs. They are not final court verdicts. The companies involved often dispute these claims or argue that their data sharing complies with their terms of service.
Second, the regulatory landscape is fragmented. While the GDPR (General Data Protection Regulation) in Europe mandates strict controls—requiring a legal basis for processing, limiting retention periods, and ensuring data security—US federal law offers less uniform protection for health data collected by apps that are not traditional medical providers.
Third, the concept of "consent" is often buried in lengthy privacy policies. A user may have agreed to a clause allowing data sharing years ago, or may have accepted a "click-through" agreement without reading the details.
Finally, technical controls exist but are not universal. Some platforms, like Apple, have implemented encryption for health data, making it harder for third parties to access raw logs. However, many other vendors do not offer this level of protection, leaving data vulnerable to subpoenas or internal leaks.
What's next
The trajectory for health app privacy involves a tug-of-war between commercial incentives and consumer rights.
On one side, the industry continues to refine its ability to monetize granular health data. The rise of AI-driven health tools means more data points are being collected and analyzed to predict health outcomes, creating a stronger business case for data sharing.
On the other side, regulatory bodies and consumer advocates are pushing for tighter controls. In the US, state-level laws (like those in California) are becoming stricter, and federal agencies are increasingly scrutinizing how health data is handled.
For consumers, the immediate reality is that "opting in" to a fitness app often means "opting in" to a complex data network. The ability to understand what is being inferred—beyond a simple step count—requires a shift from passive acceptance to active scrutiny of permissions and privacy policies.
Going further
- ClassAction.org Health Data Privacy Investigations — A list of apps and websites currently under investigation for potential privacy violations and data sharing.
- CNIL: General Data Protection Regulation (GDPR) — The official European framework for data protection, outlining principles like purpose limitation and data minimization.
- EFF: Fitness Trackers Are a Subpoena Away — An analysis of encryption standards across major wearable brands and their vulnerability to law enforcement requests.
Sources
- Health app personal data GDPR CNIL
- AI health data privacy CNIL guidance
- Is Consumers’ Health Information Being Shared? - ClassAction.org
- DeleteMe Acquires Permission Slip from Consumer Reports to Expand Consumer Privacy and Data Rights Protection - The Manila Times
- Fitness Trackers Are a Subpoena Away: EFF Finds Only Apple Encrypts Health Data - Tech Times
- Trustworthy Health Apps: What to Look For and What to Avoid - Healthline
Found an error? Email us — we correct factual mistakes and note significant updates on the article. Contact us
Keep exploring
Credit freeze vs fraud alert: what each does after a data breach
A breakdown of the procedural differences between a credit freeze and a fraud alert in the US system, based on FTC guidance and recent breach reports.
Read the article →Password managers: free vs paid, what actually matters
A Monday-morning scenario, security model, sync, recovery, free options (browser, Bitwarden, Apple, Google) and paid ones (1Password, Dashlane, Proton Pass, KeePass): an honest comparison to choose — and migrate in about an hour.
Read the article →Public Wi‑Fi: what’s true and what’s myth
Café, airport, hotel: what public Wi‑Fi can actually expose in 2026, what’s overhyped, and the simple habits that matter.
Read the article →