Do Fitness Trackers Sell Your Data? What Really Happens to Your Health Data
“We don’t sell your data” is one of the most carefully written sentences in tech. Here’s what it leaves out, why HIPAA almost never applies to a wearable, and how to audit your own tracker in ten minutes.

You wear it to sleep. It knows when your heart rate spikes, how badly you rested before a hard week, and — for millions of people — where you ran on Tuesday morning. It is reasonable to want to know where all of that ends up.
The honest answer is more uncomfortable than a straight yes or no. Most major fitness tracker companies do not sell your health data in the way people imagine — there is no marketplace where your resting heart rate is auctioned by name. But the absence of a sale is not the same as privacy, and the gap between those two things is where nearly every real-world scandal has happened.
The short answer
Selling is rare. Sharing is routine. The large wearable companies have strong commercial reasons not to sell identified health records outright: it would be a regulatory disaster and a brand-ending headline. What they do instead is share data with parties they consider part of running the service — analytics providers, advertising platforms, cloud infrastructure, research partners, corporate wellness programs — and describe that sharing in language that sounds narrower than it is.
The result is that your data can reach third parties without a single dollar changing hands for it. That distinction matters legally. It matters much less to you.
Why “we don’t sell your data” is such a carefully written sentence
Read enough privacy policies and you start to notice the same three constructions doing an enormous amount of work.
1. Sharing is not selling
Under most privacy laws, a “sale” means an exchange of personal information for money or other valuable consideration. Handing data to an analytics vendor who processes it on your behalf is classed as sharing with a service provider — a different category with different rules. A company can truthfully say it has never sold your data while a dozen other organisations have handled it.
The clearest illustration came from the fertility app Flo Health. The Federal Trade Commission’s 2021 order found that Flo had promised to keep users’ health information private while passing sensitive data — including that a user was trying to conceive — to third parties including Facebook and Google analytics services. No one bought that data. It arrived anyway.
2. “De-identified” does less than it sounds
Almost every wearable policy reserves the right to share aggregated or de-identified data freely. This sounds like a safe compromise, and sometimes it is. But biometric and location data are unusually easy to re-identify: continuous heart-rate rhythms and daily movement patterns are close to a fingerprint. Researchers have repeatedly shown that a handful of timestamped location points is enough to single out an individual from a large “anonymous” dataset.
The practical problem is that once data leaves under a de-identified label, its onward journey is no longer governed by the promise you originally accepted.
3. Advertising is the tell
If a company sells advertising, or belongs to a parent company that does, your data has commercial value inside that business — even when it is never sold outside it. This is the single most useful question to ask about any wellness product: how does this company make money when I’m not buying anything? A device sold once, at a price, has a much simpler answer than a free app with an ad-funded parent.
If you can’t see how the company makes money, look again — the answer is usually in the privacy policy rather than the pricing page.
What actually counts as health data on your wrist
People tend to picture health data as a diagnosis. On a wearable it is far broader, and much of it is inferential — the device doesn’t measure the sensitive fact directly, it deduces it.
- Cardiac signals — resting heart rate, heart rate variability, and continuous readings that reveal stress responses, illness, and alcohol use.
- Sleep — bedtimes, wake times, restlessness and duration, which map your household routine as precisely as any calendar.
- Movement and location — step counts, workout GPS traces, and the addresses those traces start and end at.
- Reproductive health — cycle tracking, symptoms, and pregnancy status, the most legally sensitive category on the list.
- Inferred conditions — a sustained resting heart rate change or a sleep disruption pattern can suggest illness, depression, or pregnancy before you’ve told anyone.
The gap nobody mentions: HIPAA doesn’t cover your wearable
This is the most common and most costly misunderstanding in consumer health tech. HIPAA — the US health privacy law everyone has heard of — applies to covered entities: health plans, health care clearinghouses, and health care providers who transmit health information electronically, plus the business associates working on their behalf.
A company that sells you a watch is none of those things. The identical heart-rate reading is protected health information when your cardiologist records it and ordinary consumer data when your watch does. Same number, same body, entirely different legal regime.
That doesn’t mean wearables are unregulated. It means the rules are thinner, newer, and vary by where you live:
| Framework | What it covers | What it means for you |
|---|---|---|
| FTC Act & Health Breach Notification Rule | Health apps and connected devices not covered by HIPAA; deceptive privacy claims and unauthorised disclosures. | The main US enforcement route. It punishes broken promises — it does not stop data sharing that was disclosed. |
| Washington My Health My Data Act | Broad “consumer health data” for Washington residents, with a private right of action. | The strongest US state law in this area, and the only one letting individuals sue directly. |
| California CCPA / CPRA | Health data as “sensitive personal information”. | Gives you rights to know, delete, and limit certain uses — if you exercise them. |
| GDPR (UK/EU) | Health data as a special category requiring explicit consent. | The strictest regime, and the reason many policies read differently in Europe. |
This is a plain-language summary for orientation, not legal advice.
Notice the pattern: almost every one of these regimes polices honesty about data practices rather than the practices themselves. Disclose the sharing clearly enough, and it is generally lawful. Which puts the burden squarely back on the person reading the policy.
Four times it went wrong
Abstract risk is easy to shrug off, so here are documented cases — none of which involved a company selling health records to the highest bidder.
- Strava, 2018. A published global heatmap of aggregated, anonymised workout routes inadvertently exposed the layout and patrol patterns of military bases. Nothing was sold; the data was intended to be harmless in aggregate. It wasn’t.
- Flo Health, 2021. The FTC found the fertility app shared sensitive health data with third-party analytics providers after promising users it would keep that information private.
- GoodRx, 2023. The FTC’s first enforcement action under the Health Breach Notification Rule resulted in a $1.5 million penalty over sharing users’ health information with advertising platforms.
- Amazon Halo, 2023. Amazon discontinued its wellness wearable and deleted customer data. Users kept their privacy, and lost the product entirely — a reminder that a device tied to a cloud service lives or dies with that service.
The clause that matters most: what happens if the company is sold
Buried in nearly every privacy policy is a change-of-control provision, usually one sentence long, saying your data may be transferred as an asset in a merger, acquisition, or bankruptcy. It is the least-read and most consequential line in the document, because it means today’s privacy promise is only as durable as today’s ownership.
When Google completed its acquisition of Fitbit in January 2021, the company gave regulators binding commitments not to use Fitbit health data for Google advertising — a genuinely meaningful concession, and also proof that the question was live enough to require one. When 23andMe entered Chapter 11 bankruptcy proceedings in 2025, its database of customer genetic data became an asset in the process, and multiple state attorneys general publicly urged customers to delete their accounts.
Neither case involved a company breaking its word. The word simply changed hands.
A privacy policy is a promise from the company that exists today. Architecture is a promise that survives the company.
That is the real argument for processing health data on the device itself rather than on a server. If the readings never leave your wrist and phone in readable form, there is no central database to transfer, subpoena, breach, or sell — regardless of who owns the brand next year.
How to audit your own tracker in ten minutes
You don’t need to read the whole policy. Open it, and run these searches.
- 1Search “sell”. Look for hedges: “we do not sell your data for monetary consideration” is a much narrower promise than “we do not sell your data”.
- 2Search “share”, “third part” and “partner”. This is where the real disclosure lives. Count the categories — analytics, advertising, research, corporate wellness — and ask whether you expected each one.
- 3Search “de-identified” and “aggregate”. Note what the company is permitted to do with data once it wears that label. Usually: anything.
- 4Search “merger”, “acquisition” and “bankruptcy”. This is the change-of-control clause. Read it once, properly.
- 5Search “delete”. Find out whether deletion is a button in the app or an email request, and whether backups and “de-identified” copies are covered. If deletion takes a support ticket, it isn’t really deletion.
Then check the app itself: which permissions it holds (location and contacts are the ones to question), whether there’s an analytics or personalised-ads toggle, and whether you can export your history in a usable format. A company confident in its practices makes all three easy to find.
What a genuinely private tracker looks like
Once you have read a few of these policies, the differences stop being about wording and start being about structure. Four things separate a company that promises privacy from one that has built for it:
- The data is processed where it is created. Readings interpreted on your device and phone never form a central repository in the first place.
- There is no advertising business anywhere in the corporate family. No ad business, no incentive, no quiet pressure to loosen the policy later.
- Anything that syncs is end-to-end encrypted. Not just encrypted in transit and at rest — encrypted so the company itself cannot read it.
- Deletion is one tap and it is complete. No forms, no waiting period, no quietly retained copies.
This is the standard we hold ourselves to at Tribe, and it is why the Tribe Watch processes your readings on your device, has no advertising business of any kind, and lets you erase everything with a single tap. You can read exactly what we do and don’t collect — it is deliberately short.
Whatever you end up wearing, the useful habit is the same: assume a privacy policy describes a business model, not a promise. Then go and find out what the business model is.
Frequently asked questions
- Do fitness trackers sell your data?
- Most major brands do not sell identified health data outright, and many contractually forbid it. However, nearly all reserve the right to share data with third parties such as analytics providers, advertising platforms, and research partners, and to share de-identified or aggregated data freely. In practice your data can reach other companies without ever being sold.
- Does HIPAA protect my fitness tracker data?
- Almost never. HIPAA applies to health plans, health care clearinghouses, and health care providers who transmit health data electronically, plus their business associates. A consumer wearable company is generally none of these, so the same heart-rate reading is legally protected at your doctor’s office and unprotected on your wrist. Consumer protections come instead from the FTC and from state laws such as Washington’s My Health My Data Act.
- Who owns the data from my smartwatch?
- Legally, “ownership” of data is rarely spelled out. What matters is the licence you grant in the terms of service and the rights you retain in the privacy policy — specifically whether you can export your history, whether you can delete it completely, and what happens to it if the company is acquired or goes bankrupt.
- What happens to my health data if the company is sold?
- Most privacy policies contain a change-of-control clause allowing your data to be transferred as an asset in a merger, acquisition, or bankruptcy. The new owner can typically update the privacy policy going forward. This is why architecture matters more than promises: data processed and kept on your own device has no central database to transfer.
- How can I tell if my fitness tracker is private?
- Open the privacy policy and search for “sell”, “share”, “third part”, “de-identified”, “merger” and “delete”. Then check whether the company has an advertising business, whether data is processed on-device or in the cloud, and whether deleting your history is a single button in the app rather than a support request.

Nothing to sell, because there’s nothing to collect
The Tribe Watch reads your heart rate, sleep and daily activity on your device. No central database, no advertising business, no change-of-control clause that could hand your history to someone else.
- Readings processed on your device, not our servers
- No advertising business — we sell watches, nothing else
- Erase everything with one tap, whenever you want
- No subscription for any tracking feature
Private by design. Yours by default.
