Fitness trackers and smart rings promise motivation and better sleep, but the sensors doing the measuring rarely stop working once a workout ends. Independent audits from groups like the Electronic Frontier Foundation and Mozilla have found wide gaps in how these devices handle the heart-rate, location and health data they collect. Here are ten trackers that quietly gather more than most wearers realize.
1. Fitbit: Heart Data, Ad Targets

Fitbit wristbands track heart rate, sleep stages and daily step counts around the clock, compiling a continuous health profile of the person wearing it. Wikipedia’s Fitbit article notes that European regulators have fielded complaints and a United States class action alleges the company shares that heart-rate and sleep data, and because Google now owns Fitbit, the same records can flow into Google’s advertising systems.
The dispute centers on whether metrics gathered to track fitness later shape the ads a person sees across unrelated Google products. Fitbit’s app lets users limit some data sharing, but the litigation contends much of it happened without clear, specific consent from account holders.
2. Oura Ring: Location Logged, Unencrypted

The Oura Ring records body temperature, sleep cycles and movement, and newer models add continuous, precise GPS tracking of a wearer’s location during workouts. Mozilla’s Privacy Not Included review found that this health and location data is stored on Oura’s own servers without end-to-end encryption, meaning the company itself can access the underlying records rather than only the wearer.
Mozilla’s assessment treats that gap as a meaningful risk given how sensitive fertility, sleep and location data can be. Oura’s privacy policy allows account holders to export or delete their data, but the review found no technical guarantee that Oura is locked out of reading it first.
3. Google Pixel Watch: Fitbit Ties, Google Reach

The Google Pixel Watch runs Wear OS and leans on the Fitbit app, now owned by Google, to log heart rate, sleep stages and workout activity from its wrist sensors. Wikipedia’s Pixel Watch overview describes this Fitbit-based health tracking as a core feature, tying the watch’s daily biometric readings directly into the same account system Google uses across its other services.
Because the watch’s health data lives inside a Fitbit account under Google’s ownership, it sits alongside the company’s other user records rather than a separate, walled-off health silo. Wearers can review and export their Fitbit data through account settings, though the integration itself is built in, not optional.
4. Apple Watch: The Encryption Exception

The Apple Watch tracks heart rate, movement and, on newer models, blood oxygen and temperature trends, but handles the resulting health records differently than most rivals. An EFF wearable privacy audit found Apple Watch to be one of the only devices in its category offering end-to-end encryption for that data, an exception the report said most competing smart watches, rings and bands lack.
That encryption means health data synced through the Health app is designed so that only the account holder, not Apple, can read the contents. The EFF report singled this out as a rare practice, framing most of the rest of the market as falling short of it.
5. Samsung Galaxy Watch: Outside HIPAA’s Reach

The Samsung Galaxy Watch measures heart rate, sleep and blood oxygen through its Samsung Health platform, compiling ongoing wellness data on the wearer. Wikipedia’s entry on the watch line notes that independent privacy assessments have rated it a mid-tier performer, and because the watch is not classified as a HIPAA-covered device, its health data can legally be shared with or sold to outside parties.
That gap exists because consumer wellness data generally falls outside the federal health-privacy law that governs doctors and insurers. Samsung’s privacy policy sets terms for how Health data may be used, but the mid-tier rating reflects assessors’ view that protections still lag the strongest devices available.
6. Garmin Forerunner: Routes Logged Nonstop

The Garmin Forerunner line continuously logs GPS running routes alongside heart rate, pace and other biometric readings during every tracked workout. Wikipedia’s Forerunner entry notes this ongoing route and biometric logging as a defining feature, and Garmin, like most fitness brands, is not a HIPAA-covered entity, so the health data it collects is not bound by federal medical-privacy rules.
In practice that means detailed running routes, which can reveal a wearer’s home address and daily habits, are governed by Garmin’s own privacy policy rather than health-specific law. Garmin allows users to adjust activity-sharing settings, but the underlying GPS logging itself is built into how the watch functions.
7. Xiaomi Smart Band: No Transparency Report

The Xiaomi Smart Band tracks steps, heart rate and sleep through its companion app, feeding continuous activity data back to Xiaomi’s platform. Wikipedia’s Mi Band article notes the line has been grouped by the Electronic Frontier Foundation among wearables with substantive privacy deficiencies, citing an absence of transparency reporting about how that data is handled.
Without a published transparency report, users have little independent confirmation of how long Xiaomi retains activity data or who inside the company can access it. The EFF’s grouping placed the band alongside other budget trackers found to offer minimal disclosure compared with higher-tier competitors.
8. Withings ScanWatch: Medical Data, No Shield

The Withings ScanWatch records heart rhythm, blood oxygen and sleep apnea signals, storing detailed medical-grade metrics through the Withings companion app. Wikipedia’s profile of Withings describes it as a mid-tier privacy performer whose makers can access the detailed health metrics it stores, since the device sits outside the scope of federal health-privacy law.
That means the sleep apnea and heart-rhythm readings a ScanWatch collects, though medical in nature, are handled under Withings’ own data policy rather than hospital-grade privacy protections. Users can view and export their data through the app, but the company itself retains access to the same records.
9. Amazfit: Own Brand, Own Rules

Zepp Health, the Chinese company formerly known as Huami, sells its Amazfit fitness bands and watches worldwide, with sensors that track heart rate, sleep stages and step counts synced through the company’s Zepp companion app. Wikipedia notes that Zepp Health previously manufactured earlier Xiaomi Mi Band models before launching Amazfit as its own, separately branded product line.
That history means the biometric readings an Amazfit device records are processed under Zepp Health’s own privacy policy rather than a partner company’s terms, since Amazfit operates independently of Xiaomi today. The Zepp app lets wearers view their recorded activity data, though the article does not detail how long Zepp Health retains the underlying records.
10. Huawei Watch GT: Weakest Privacy Marks

The Huawei Watch GT tracks heart rate, sleep and blood oxygen through Huawei’s companion health app, compiling continuous biometric data on its wearer. Wikipedia’s Huawei Watch entry notes that an Electronic Frontier Foundation assessment flagged Huawei’s bands and watches among those with the weakest privacy protections in the wearable category.
The EFF’s assessment pointed to gaps in transparency reporting and user control over how that biometric data is handled compared with rivals it rated more favorably. Huawei’s health app allows some data-export options, but the weak-protection finding reflected the broader pattern reviewers found across the company’s wearable lineup.
More from Morning Overview
- The NSA warns one messaging setting can clone your texts to a stranger
- Security experts still urge phone owners to switch off one location-tracking setting
- Automakers are quietly dropping the stop-start feature many drivers love to hate
- A granite sarcophagus surfaced in Egypt with its original lid still sealed