That Step Count Is Worth More Than You Think — And Not Just to You
You strapped on your fitness tracker to count steps and maybe guilt yourself into drinking more water. That part's working fine. What you probably didn't sign up for was sharing your resting heart rate, sleep cycles, menstrual data, or stress scores with a network of apps, data brokers, and — in some cases — your health insurance company.
Yet here we are.
The fitness and health app ecosystem in the US is a surprisingly tangled web. Your Fitbit talks to Google Health. Your Apple Watch feeds into Apple Health, which shares with third-party apps you approved once and forgot about. Your gym's app syncs with your insurer's wellness portal. Each connection made sense at the time. Together, they form a data pipeline that most people have never actually looked at.
Let's look at it.
How the Data Actually Moves
It starts simple. Your wearable — whether it's a Garmin, Fitbit, Apple Watch, Whoop, or a cheap tracker from Amazon — collects raw data and sends it to that brand's app. From there, things branch out fast.
Most fitness apps include a permissions section where you've (probably) approved connections to other services. Apple Health and Google Fit act as central hubs, pulling data from multiple sources and making it available to any app you've granted access. That could include:
- Nutrition apps like MyFitnessPal or Cronometer
- Meditation apps like Calm or Headspace
- Telehealth platforms like Teladoc or One Medical
- Insurance wellness programs like those offered by UnitedHealthcare, Aetna, or Cigna
- Employer wellness platforms like Virgin Pulse or Vitality
The last two are where things get genuinely interesting. A growing number of US health insurers offer premium discounts or gift card incentives in exchange for sharing fitness data through their wellness portals. Sounds like a fair trade — until you read what you're actually agreeing to share.
What Your Insurance Company Might Actually Be Seeing
Insurer wellness programs vary a lot in what they collect. Some only pull step counts. Others request access to sleep data, heart rate trends, weight, and workout frequency. A few employer-sponsored programs go further, collecting data that gets aggregated and analyzed at the population level.
Here's the thing: health data shared through a wellness app often isn't covered by HIPAA the same way your doctor's records are. HIPAA applies to covered entities — hospitals, insurers in their official capacity, healthcare providers. A wellness app you downloaded voluntarily may operate under a different set of rules, governed mainly by its own privacy policy and whatever you agreed to in the terms of service.
That data can be sold to third parties, used for targeted advertising, or shared with data brokers — depending on the app. Companies like Strava have faced scrutiny for exposing user location data. Period tracking apps have come under fire for selling reproductive health data. The fitness space is not immune.
How to Actually Audit What You're Sharing
Good news: this is fixable. It just takes about 20 minutes and a little patience.
Step 1: Check Your Apple Health or Google Fit Permissions
On iPhone: Go to Settings > Privacy & Security > Health. You'll see every app that has requested access to your health data, along with exactly what categories they can read or write. Tap any app to review or revoke its permissions.
Alternatively, open the Health app > your profile icon (top right) > Apps and Services. This gives you a cleaner view of connected apps.
On Android (Google Fit / Health Connect): Open Settings > Apps > Health Connect (it may be under Google services depending on your device). Tap App permissions to see which apps have access to which data types.
Step 2: Audit Your Fitness App's Own Settings
Don't stop at the phone level. Open your Fitbit, Garmin, Whoop, or other wearable app and look for a Connected Apps or Integrations section in settings. This shows what you've linked at the platform level — separate from what your phone's health hub shows.
Revoke anything you don't recognize or no longer use.
Step 3: Check Your Insurance or Employer Wellness Portal
If you've ever signed up for a wellness rewards program through your health plan or employer, log into that portal and look for a Connected Devices or Data Sharing section. Many of these platforms (Virgin Pulse, Rally Health, Vitality) show you exactly what's being synced and let you disconnect your tracker.
If you're not sure whether your employer's wellness program is collecting data, check your benefits documentation or ask HR directly what data the platform receives and how long it's retained.
Step 4: Review Privacy Policies for Your Top Three Health Apps
Yeah, nobody loves this part. But for the apps you use most — your fitness tracker app, your nutrition logger, your sleep tracker — it's worth spending five minutes searching their privacy policy for the words "sell," "share," "third party," and "de-identified."
De-identified data is a common phrase that sounds reassuring but can be misleading. Research has shown that health and location data can often be re-identified even after names are stripped out.
What You Can Actually Do to Limit the Exposure
You don't have to quit your fitness tracker cold turkey. But you can tighten things up significantly:
- Only connect apps you actively use. That recipe app you linked to Apple Health three years ago? Gone.
- Opt out of data sharing for research or advertising where apps offer the choice — many do, buried in settings.
- Skip the wellness program incentives if the trade-off doesn't feel worth it. A $50 gift card for a year of heart rate data is a pretty thin deal.
- Use a separate email address for health and fitness apps to limit cross-platform data linking.
- Check your app permissions after every major update. Apps sometimes reset or expand permissions when they push a new version.
The Bottom Line
Your fitness data is genuinely valuable — to advertisers, to researchers, to insurers trying to model risk, and to data brokers who make a business of packaging and reselling it. The good news is that you do have real control here, it's just not handed to you upfront.
Spend a few minutes running through the audit steps above, cut the connections you didn't intentionally make, and you'll have a much clearer picture of who's actually watching your workout. Your health data belongs to you — keep it that way.