THE INDUSTRY FILES

Fitness & Wellness

Heart rate, sleep, routes and cycles are filed as fitness, not medical records, so clinical protections mostly do not apply. Join through a workplace scheme or an insurer's plan and there is a direct line to your boss or insurer; the file stays as long as the account does.

TRACKING PRIORITY HIGH

Continuous health and location data, kept with no end date. Keep the record.

IF IT LEAKS HIGH
EXPECT IT KEPT INDEFINITELY

Once called "anonymised", health and activity data is often kept with no end date.

IDENTITY DEMANDED OPTIONAL

Sign-up asks for little; the sensitive data is what you record.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

IF IT LEAKS

This is body data: weight, heart rate, cycles, the routes you run and the hours you turn up. Leaked, it shows a health picture and a daily pattern precise enough to say when your home is empty.

What repeats in the policies

WHAT YOU HAND OVER

Filed as fitness, not as medical records

A band or app logs your heart rate, your sleep, your routes and your menstrual cycle. A gym takes a health declaration when you join, then a record of every entry swipe. Either way it is filed under one heading, 'wellness' or 'activity' data, and the only lock the policies name is your consent, not a medical record's protection. Your cycle log sits in the same list as your step count.

WHERE IT GOES

A direct line to your boss or your insurer

Several policies build in a direct line to an employer or an insurer. Join through a workplace wellness scheme or an insurer's rewards plan, and your activity, or just your gym attendance, becomes something the sponsor receives. It is framed as your choice to take part, and the sharing follows from that one choice.

WHAT STAYS

It stays as long as your account does

How long any of this stays is their claim, and most policies name no number: they keep it as long as your account exists, or as long as they judge necessary, whichever runs longer. Only two put a figure on it, and both are years: one gym holds your data up to six years after you cancel, one app three years after you go quiet. Ending it sooner means requesting a deletion, and that alone can take up to three months to finish.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileLocationHealth Browsing & Activity maybePurchases maybeFinancial maybePhotos & Biometrics maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Health HIGHLY LIKELY

Heart rate, weight, and activity are the record itself.

Where you go LIKELY

Run and ride routes map your home and routine.

What lawfully stays after you leave

Two kinds of hold. LAW SETS IT: a statute makes them keep it. THEY SET IT: a ground the company grants itself.

anonymised, aggregated, or AI-trained data OFTEN KEPT INDEFINITELY THEY SET IT

They treat it as no longer being about you, though such data can sometimes be re-identified.

tax and accounting records ABOUT 6 YEARS LAW SETS IT

Tax and company law makes them keep billing and payment records.

records tied to a live or potential dispute THE LIMITATION PERIOD OF THE CLAIM THEY SET IT

They can keep records to defend a live or possible legal claim.

Who wants this data

Regulators treat wearable body data as an advertising asset. European authorities cleared one wearable takeover only on a ten-year ban on using its users' health data to sell ads. In the US, watchdogs have penalised period-tracking apps that passed reproductive data to advertising and analytics firms after promising to keep it private, and one service's aggregated exercise routes, once published as a public map, exposed the layout of military bases.

SOLD OR SHARED LIKELY

Health and location data is valuable to insurers, advertisers, and brokers.

AI TRAINING MODERATE

Activity and biometric data train health models.

Even anonymised, this can still be you

Anonymised is their word. In January 2018 a fitness app's "anonymous" global activity heatmap was used to locate military bases (TechCrunch, 2018), and public route records of the same kind have identified individual users.

Name, date of birth, postcode TYPICAL

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces TYPICAL

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

Payment patterns SOMETIMES

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

Face and voice SOMETIMES

A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.

Browsing fingerprint SOMETIMES

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

THE STUDIES Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)·Fitness app Strava exposes the location of military bases (TechCrunch, 28 January 2018, 2018)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation, and increasingly AI training can all ride under it. When they want to do something new with your data, this sentence usually already covers it.

THE MOVE An objection draws the line: use your data to run the service, not to improve, target, or train on it.

“we do not sell your personal information”

Often technically true, and still misleading. It usually means no cash changes hands. Data can still flow to ad networks, analytics firms, and partners: on their definition, sharing is not selling.

THE MOVE Flip the do-not-sell switch where one exists. The written objection on top of it goes on your record.

“service providers, partners, and affiliates”

How data leaves the building with no name attached. Recipients are listed by what they do, never who they are. You cannot send a request to a company you cannot name, which is the point.

THE MOVE An access request can ask for the recipients by name, not just the categories. UK and EU law put that choice with you. The reply, or the silence, goes on your record.

“aggregated or de-identified information”

Stripping the name does not strip the pattern, and the pattern often still points at you. Policies grant themselves free, indefinite use of this data because in their telling it is no longer about you.

THE MOVE If a deletion comes back as 'anonymised', keep the reply. It is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

They can keep it for: legal duties, tax rules, fraud prevention, possible lawsuits, their own business reasons. None of them carries a firm end date. Deletion becomes a negotiation, not an event.

THE MOVE Which reasons apply to you, and how long each runs, is a request of its own. Their reply goes on your record.

“you grant us a licence to use your content”

A contract term, not a data setting, so a privacy request cannot undo it. The careful version ends with your account. The broad version can be passed on, never expires, and survives deletion.

THE MOVE Whether the licence ends with the account is written in their terms, not yours. Closing the account goes on your record.

“as long as your account is active”

Retention is tied to whether you still have an account, not to any set length of time, so your full history of heart, sleep and cycle records is kept the whole time you stay signed up. Some add that they hold it as long as they have a business need or the law allows, whichever runs longer.

THE MOVE A deletion is the only thing that ends it, and that is a request you have to make. The reply, or the silence, goes on your record.

“if you choose to participate in an employee wellness program”

Frames the employer and insurer channel as pure opt-in, but once you enrol the sponsor receives your membership or activity data under its own rules. With at least one wearable the line runs both ways: your employer or insurer sends your name or subscriber number in, so the app can check which benefits you qualify for.

THE MOVE What the sponsor receives, and what it may do with it, is theirs to answer. Their reply goes on your record.

“in response to subpoenas, court orders, or legal processes”

The same policy that files your cycle and body data as wellness also lists it among the data it may hand to authorities on a court order or legal demand. No stronger shield sits over reproductive logs than over your step count.

THE MOVE What they would hand over, and to whom, is theirs to answer. Their reply goes on your record.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply. Start your record →