You strap on your fitness tracker and head out for a run. It logs your heart rate, GPS route, sleep quality, and stress levels. What you probably don’t think about is where that data goes after it leaves your wrist.
The short answer: it depends entirely on which brand you’re wearing. Fitness tracker privacy varies wildly across devices — and the differences have real consequences. A Duke University study found that 79% of popular health and fitness apps share user data with third parties, while only 28% of users were aware this was happening.
This guide cuts through the marketing language and compares what Fitbit (now Google Health), Garmin, Apple Watch, Whoop, and Oura actually do with your data — and which one comes out on top.

The HIPAA Gap Nobody Talks About
Before comparing brands, there’s one thing every wearable user needs to understand: your fitness tracker data is almost certainly not covered by HIPAA.
HIPAA — the US health privacy law most people assume protects all medical information — only applies to covered entities: hospitals, health insurance plans, healthcare clearinghouses, and their direct business associates. Consumer wearable companies like Fitbit, Garmin, Oura, and Whoop are none of these.
That means the heart rate data your smartwatch records has fewer legal protections than a note your doctor jotted down on a paper chart. As the University of Cincinnati Law Review noted in a 2026 analysis, consumer wearable data exists in a largely unregulated privacy gap at the federal level.
Some state laws do provide partial protection — California’s CCPA and Illinois’ BIPA apply in specific circumstances — but there’s no federal floor. What you’re left with is each company’s own privacy policy, and those policies vary enormously.
Fitbit (Google Health): The Most Complex Story
Privacy rating: ⚠️ Caution
Fitbit’s privacy situation changed fundamentally when Google completed its acquisition. As of May 2026, all Fitbit accounts have migrated to Google accounts, meaning your health data is now governed by Google’s privacy policy — one of the most expansive data policies in the tech industry.
Google has committed that Fitbit health and wellness data will not be used for Google Ads, and this pledge applies globally. But Google’s privacy policy broadly permits using data to “improve services,” a category that covers a lot of ground. A 2025 systematic analysis published in the Journal of Medical Internet Research flagged Google/Fitbit as having among the most permissive data-sharing terms of any major wearable manufacturer.
Fitbit’s own terms acknowledge sharing data with employers and insurance companies that offer Fitbit services to their employees — a common corporate wellness program arrangement. The privacy policy also permits sharing aggregated and de-identified data with third parties for research and commercial purposes. And a 2024 Imperial College London study demonstrated that supposedly de-identified fitness datasets could be re-identified with 87% accuracy using just three data points: age range, zip code, and activity pattern.
What Fitbit collects: 23 data types according to Apple’s App Store privacy labels — more than any other major tracker in this comparison. In 2026, Whoop faces a class-action lawsuit in California alleging its data-sharing practices violate the California Invasion of Privacy Act; Fitbit has faced similar litigation in the past.
Bottom line: Fitbit’s hardware is solid, but Google’s ownership introduces meaningful data-sharing exposure that privacy-conscious users should weigh carefully.
Garmin: Mid-Pack, But Cleaner Than Most
Privacy rating: ✅ Reasonable
Garmin occupies a credible middle position. According to Apple’s App Store privacy labels, Garmin Connect collects 12 data types — compared to Fitbit’s 23 — and has no third-party advertising tracking. Garmin keeps data within its own ecosystem rather than sharing it with ad networks.
The weaknesses: Garmin’s privacy policy isn’t the easiest to find, and the data deletion process requires emailing specific addresses rather than a simple self-service portal. Garmin’s policy does permit sharing aggregated data with third parties for research purposes, which is fairly standard.
Garmin’s approach to security has also drawn scrutiny. A 2020 ransomware attack on Garmin’s systems exposed the real risk of storing sensitive health data in cloud infrastructure. The company recovered, but the incident highlighted that even companies with relatively restrained sharing practices can expose user data through third-party attacks.
What Garmin collects: 12 data types. Six support core functions (workouts, heart rate, sleep, GPS, device IDs, usage patterns). The other six serve broader purposes.
Bottom line: Garmin is a reasonable choice for users who want GPS-focused fitness tracking without aggressive data monetization. Not perfect, but noticeably cleaner than Fitbit/Google.
Apple Watch: The Strongest Default Privacy
Privacy rating: ✅✅ Strong
Apple has built its health data architecture around a specific and verifiable claim: Apple processes health data on-device wherever possible, and what does sync to iCloud is end-to-end encrypted — meaning even Apple cannot read it.
Apple’s Consumer Health Personal Data Privacy Policy states that Health app data with two-factor authentication enabled is encrypted such that it is “not readable by anyone — even Apple.” HealthKit data is not used for advertising. Apple does not sell health data to third parties. Apps that request access to your health data through HealthKit require explicit, granular permission for each data type — you can allow step tracking while blocking heart rate access, for example.
Apple collects 9 data types compared to Fitbit’s 23, and the company enforces strict App Store review guidelines for apps accessing health information. The one caveat: Apple’s protections apply to the Apple ecosystem. If you connect third-party apps to your health data, those apps operate under their own privacy policies, not Apple’s.
What Apple collects: 9 data types. The company does not share identifiable health data with advertisers and cannot decrypt your iCloud health data.
Bottom line: For users for whom privacy is the primary concern, Apple Watch offers the strongest default protections of any mainstream fitness tracker.

Whoop and Oura: The Subscription Trackers
Whoop privacy rating: ⚠️ Caution
Oura privacy rating: ✅ Reasonable
Whoop’s privacy policy permits sharing data with third-party service providers and business partners, and aggregated population-level data is offered for research and commercial purposes. The company integrates third-party analytics SDKs — including tools from Meta and Google — that transmit usage data. In 2026, Whoop is facing a class-action lawsuit in California alleging its data-sharing practices with advertising partners violate state privacy law.
Oura presents a cleaner picture. The Finland-based company is GDPR-compliant by design, states it does not sell or rent personal data to third parties, and explicitly says it does not share app data with third-party advertisers. When Oura faced user concern in late 2025 over a data analytics collaboration involving the US Department of Defense, the company published a detailed response reiterating that member data is not shared with government entities without explicit consent. Oura isn’t perfect — it does use tracking cookies on its website — but its core health data handling compares favorably to most competitors.
Side-by-Side Comparison
| Tracker | Data Types Collected | Third-Party Ad Sharing | Sells Personal Data | HIPAA Covered | Privacy Rating |
|---|---|---|---|---|---|
| Fitbit (Google) | 23 | Yes (analytics SDKs) | No (aggregated only) | ❌ No | ⚠️ Caution |
| Garmin | 12 | No | No | ❌ No | ✅ Reasonable |
| Apple Watch | 9 | No | No | ❌ No* | ✅✅ Strong |
| Whoop | 17 | Yes (analytics SDKs) | No (aggregated only) | ❌ No | ⚠️ Caution |
| Oura Ring | ~10 | No | No | ❌ No | ✅ Reasonable |
*HIPAA applies only when data is shared with a covered healthcare provider through a regulated channel.
What You Can Do Right Now
Regardless of which tracker you use, these steps reduce your exposure:
1. Review connected apps. Every app you’ve linked to your fitness tracker operates under its own privacy policy. Revoke access to any app you no longer actively use. On iPhone: Settings → Privacy & Security → Health. On Android: Google Health → Connected Apps.
2. Disable location sharing when not needed. GPS data is among the most sensitive information your tracker collects — as demonstrated when smart device location data exposed military personnel locations through Strava in multiple incidents. Turn off location tracking for workouts that don’t require it.
3. Opt out of research programs. Most trackers offer opt-outs for using your data in research studies or aggregate datasets. This is usually buried in settings under “Data Sharing” or “Research.”
4. Check your privacy settings after app updates. Companies can update their privacy policies and quietly reset your sharing preferences. A quick check after major app updates takes two minutes.
5. Understand the data broker problem. Even if your tracker doesn’t sell your data directly, the apps connected to it might. Tools like DeleteMe can identify and opt you out of data brokers who may have aggregated your information from multiple sources. As with the broader landscape of consumer privacy risks, wearables are one piece of a larger data collection ecosystem you’re participating in every day.
The Verdict
No mainstream fitness tracker is perfectly private. The industry operates largely outside federal health privacy law, and most companies reserve the right to share at least aggregated versions of your data. But the differences between brands are significant.
If privacy is your top priority: Apple Watch offers the strongest default protections, with on-device processing, end-to-end encrypted cloud sync, and a clear policy of not using health data for advertising.
If you want capable tracking without aggressive data monetization: Garmin and Oura are credible second choices — fewer data types collected, no ad network integration, and more transparent policies.
If you’re currently using Fitbit: the migration to Google accounts in 2026 means your health data is now subject to Google’s broader data policies. It’s worth reviewing what you’ve consented to and adjusting your sharing settings accordingly.
Your fitness data tells a detailed story about your body, habits, and health. It’s worth deciding — deliberately — who else gets to read it. As described in our guide to protecting your personal data from identity theft, the habits that protect your financial data and your health data increasingly overlap.
Is my fitness tracker data covered by HIPAA?
Almost certainly not. HIPAA applies only to covered entities — hospitals, health insurers, and healthcare clearinghouses — along with their direct business associates. Consumer wearable companies like Fitbit, Garmin, Apple, Whoop, and Oura are not covered entities. Your fitness tracker data has fewer legal protections than your medical records unless you share that data directly with a regulated healthcare provider through an official channel.
Does Fitbit sell your health data?
Fitbit (now operated as Google Health) states that it does not sell identifiable personal data and has committed that Fitbit health data will not be used for Google Ads. However, Fitbit’s privacy policy does permit sharing aggregated and de-identified data with third parties for research and commercial purposes, and integrates analytics SDKs from companies including Meta and Google. Since Fitbit accounts migrated to Google in May 2026, your health data is now governed by Google’s broader privacy policy.
Which fitness tracker has the best privacy?
Apple Watch currently offers the strongest default privacy protections among mainstream fitness trackers. Health data is processed on-device where possible, iCloud sync uses end-to-end encryption that Apple itself cannot decrypt, and Apple does not use health data for advertising. Garmin and Oura are solid second choices — both collect fewer data types than Fitbit and do not integrate third-party advertising SDKs into their core health apps.
Can my employer or insurance company access my fitness tracker data?
Potentially, in specific circumstances. Many employers offer corporate wellness programs that use Fitbit or similar devices, and Fitbit’s privacy policy explicitly acknowledges partnerships with employers and insurance companies in this context. There is currently no federal law preventing insurers from using fitness data obtained outside of HIPAA — such as data you voluntarily share through a wellness program — to influence premiums or coverage decisions. The ADA limits how employers can use health data for employment decisions, but the legal landscape remains complex.
How do I stop my fitness tracker from sharing my data?
Start by reviewing which third-party apps have access to your health data and revoking any you no longer use (on iPhone: Settings → Privacy & Security → Health; on Android: Google Health → Connected Apps). Disable location tracking for workouts that don’t require GPS. Opt out of research data-sharing programs in your tracker’s settings — usually found under “Data Sharing” or “Research.” Finally, review your privacy settings after app updates, as companies can quietly adjust default sharing preferences with policy changes.