Fitness Apps & Privacy: What’s the Hidden Cost of Your Workout?
Did you know your most dedicated fitness companion might also be your biggest data dealer? As millions pledge to get healthier each January, intimate workout details become fuel for an invisible economy. Which fitness apps prioritize progress-tracking over privacy intrusion? VPN service Surfshark has scrutinized the Apple App Store listings of 16 leading fitness platforms, uncovering surprising disparities in digital transparency. This data isn’t incidental—your step count, heart rate, or running routes could be monetized via advertisers and third parties. Understanding fitness app privacy is critical when entrusting developers with deeply personal health information.
Peeling Back the Layers: How This Study Analyzed Your App Privacy
Surfshark’s methodology hinges on Apple’s App Privacy Labels—standardized disclosures launched by Apple in 2020 to illuminate app data practices. Researchers analyzed 35 distinct data points spanning 16 categories, examining how apps collect information and whether it’s “linked to you” or used solely for app functionality. This includes essentials like Device ID or Fitness Details, but extends to highly sensitive metadata like Race, Pregnancy, and Political Opinions. Unlike vague privacy policies, Apple’s labels enforce comparative scrutiny—making this a credible benchmark for transparency.
The Heavy Lifters of Data Collection: Which Apps Demand the Most?
Fitbit emerged as the undisputed leader in accumulating user information, harvesting 24 of the 35 identified data types—almost double the study’s average. This includes lengthier logs like Performance Data, Contacts, Search History, and Diagnostics, often intertwined with user identity. While Fitbit relies partly on this data for core features (like syncing workouts or heart-rate analysis), its extensive scope heightens potential misuse. Other notable collectors include:
- Strava: 21 data types
- Mindbody: 19 data types
- Runna: 15 data types
Contrast this with Centr, which collects just three types—User ID, Product Interaction, and Crash Data—though notably, it tracks all three linked to identity.
Functionality vs. Exploitation: When Strava Goes the Extra Mile
Collection volume tells half the story; usage intent reveals critical risks. Strava, widely celebrated for route mapping and athlete communities, is tagged “the worst offender” for exploiting data beyond core functionality. Of its 21 collected metrics, none are purely for app basics. Instead, Precise Location, Photos, and Physical Addresses serve purposes like “app functionality, advertising/marketing, personalization, and analytics.” Imagine your mountainous bike route informing personalized ads for gear—edited: Sharing geolocation with third-parties can expose real-time habits and locations. As the Electronic Frontier Foundation warns, such practices blur lines between service provision and commodification of intimate habits.
The Location Tracking Dilemma: From Precise Coordinates to Coarse Areas
Persistent location surveillance stirs unique privacy alarms by revealing routines and private spaces. Runna and Strava both gather Precise Location—GPS coordinates accurate within meters—tying it directly to user profiles. Nike Training Club and Peloton collect Coarse Location (


