Research Review
The Short Answer
If your priority is cycle tracking data, Apple has the strongest terms of the major platforms, and the reason is structural rather than promotional. Apple's consumer health policy states plainly that "Apple does not sell your consumer health personal data", says Health app data is end to end encrypted, and confirms that Cycle Tracking predictions are calculated on your device instead of on a server. Apple also binds every other app on the platform: App Review Guideline 5.1.3 forbids apps from using HealthKit data "for advertising, marketing, or other use-based data mining purposes", and tells developers they "may not store personal health information in iCloud".
For sleep data the ranking is the same, for the same reasons, with Oura a close second on paper: Oura says it does not sell personal data and does not share it for cross-context behavioral advertising, and it commits to opposing or narrowing overbroad law-enforcement requests. Google's Fitbit line sits in the middle, protected by a specific and checkable promise that health data is not used for Google ads. Samsung is the outlier you should read carefully before trusting it with cycle or sleep data, for reasons set out below.
The catch, and it applies to every name above: none of this is HIPAA. These are company policies, not legal obligations, and a policy can be rewritten. The one thing that does not change is data you never uploaded, which is why on-device processing matters more than any promise.
| Platform | Where the data lives | Used for ads? | Cycle data handling | Deletion |
|---|---|---|---|---|
| Apple Watch and iPhone Health | On device, plus iCloud sync that is end to end encrypted when two-factor authentication is on | No. Apple says it does not sell consumer health personal data, and App Review bars other apps from ad use of HealthKit data | Cycle Tracking predictions calculated on device | User controlled in the Health app and iCloud settings |
| Fitbit Air and Google Health | Google cloud account | No. "Health and wellness data is not used for Google ads", and Google says it never sells personal information | Named as "female health data" in the policy's California biometric disclosures | Most data within 30 days, up to 90 days for backups |
| Oura | Cloud servers, with Apple Health and Health Connect sharing only by permission | No sale, and no sharing for cross-context behavioral advertising | Reproductive health treated as sensitive, processed only with consent | Measurement data kept while the account is active, minus legal retention |
| Samsung Health | Device plus Samsung cloud | Statement does not claim an advertising ban for health data | Menstrual cycle information named directly as collected data | Reported to be tied to the AI training consent, see below |
| WHOOP | Not verified for this update | Not verified for this update | Not verified for this update | Not verified for this update |
| Vora (our app) | Cloud servers with encryption in transit and at rest, some data cached on your device | No. Health data is not used for advertising and is not sold | Whatever you choose to connect, under the same terms | Account deletion removes your data within 30 days, except where law requires retention |
We checked every row against the company's own published policy on September 20, 2026, except WHOOP, whose policy pages returned an error to our automated request that day. Rather than describe terms we could not read, we left the row blank. Read WHOOP's policy yourself before you decide.
What Your Wearable Actually Collects
Modern wearables collect far more than step counts. A typical smartwatch or health ring now records heart rate (continuous or periodic), heart rate variability, sleep duration and staging, blood oxygen saturation (SpO2), skin temperature, respiratory rate, GPS location, elevation, menstrual cycle data, electrodermal activity, and in some cases voice data through built-in microphones. Combined over weeks and months, this creates a remarkably detailed physiological profile of your life, one that can reveal health conditions, emotional states, physical location patterns, and daily routines.
The depth of this data collection is not inherently problematic. It is what enables the health insights that make wearables valuable. The problem is what happens to this data after it leaves your wrist or finger.
Where Your Data Goes: Platform by Platform
Not all wearable companies handle your data the same way. The differences are significant.
Apple (Apple Watch, iPhone Health). Apple has built its health data architecture around on-device processing and end-to-end encryption. There is one condition most summaries leave out: Apple's own documentation ties that protection to two-factor authentication, stating that with iOS 12 or later and two-factor turned on, "Apple will not be able to read your health and activity data synced to iCloud". Without two-factor, the data is still encrypted in storage and in transit, but not end to end. Apple's consumer health policy adds that "Apple does not sell your consumer health personal data". When your device is locked with a passcode, Face ID or Touch ID, everything in the Health app other than your Medical ID is encrypted and inaccessible by default. Of the major platforms, Apple offers the strongest default protections, and the two-factor setting is worth checking today if you have never looked.
Google and Fitbit. Fitbit hardware, including the screenless Fitbit Air, now runs through the Google Health app, and the data is governed by the Fitbit privacy policy and Google's health commitments. Google's current published commitment is specific and easy to hold it to: "Health and wellness data is not used for Google ads", alongside "We never sell your personal information". The Fitbit policy is broader about who else can touch the data, listing sharing with service providers for work including "data analysis, research, and surveys", with corporate affiliates and partners for external processing, and with third parties where legally required. Deletion is the clearest number on the page: after you delete your account, most of your information is deleted within 30 days, and it can take up to 90 days to clear backups.
Oura. Oura stores health data on cloud servers and states that it has not sold personal information and does not sell or share personal data for cross-context behavioral advertising. Sharing with Apple Health or Health Connect happens only with your permission. Two details set Oura apart in the current policy. It treats reproductive health as sensitive data processed "only with your consent", and it commits to reviewing law enforcement and government requests case by case and to "oppose, seek to narrow, or reject" requests it considers overly broad or legally deficient. That last commitment is a company promise rather than a legal shield, but few competitors put it in writing. Measurement data is kept while your account is active, with some records held longer for accounting and tax obligations.
Samsung. Samsung's US consumer health data privacy statement, last updated July 1, 2025, names exactly the data category people worry about: "Reproductive or sexual health information (such as menstrual cycle information you provide through our Services)". It describes sharing with third-party devices and apps you connect, with Samsung's affiliates and subsidiaries, and with vendors acting on Samsung's behalf. In July 2026, Notebookcheck and Android Headlines both reported a new in-app prompt titled "Consent to the Use of Health Data for AI Training and Modeling", covering sleep and cycle tracking, heart rate, medications and medical records, and both reported that declining stops cloud synchronization and removes existing data from Samsung's servers. Samsung's published consumer health statement does not mention AI training or human review, so the prompt is the document that matters. Read it rather than tapping through it.
WHOOP. WHOOP's privacy policy pages refused our automated request on September 20, 2026, so we have nothing verified to report about its current terms and will not guess. If you are weighing WHOOP on privacy grounds, open its Privacy Center in a browser and read the sections on third-party sharing and on de-identified data before you subscribe.
Cycle Tracking Data: Which Platform Actually Protects It
Menstrual cycle data is the most sensitive thing a mainstream wearable records, and it is the one category where the platforms differ in kind rather than in degree. The question is not only whether a company promises not to sell it. It is whether the data ever leaves your device, and what every other app on the platform is allowed to do once it has access.
On iPhone, Apple states that Cycle Tracking predictions are calculated on device, which means the inference about your cycle is made locally rather than on a server. Apple's App Review Guidelines then constrain third-party apps: section 5.1.3 says apps "may not use or disclose to third parties data gathered in the health, fitness, and medical research context", including through the HealthKit API, "for advertising, marketing, or other use-based data mining purposes", and the same section tells developers they "may not store personal health information in iCloud". A period tracking app on the App Store that reads your Health data is bound by that rule as a condition of being on the store.
Android caught up in a way worth knowing about. Cycle data in Health Connect is a separate permission, READ_MENSTRUAL_CYCLE_PHASE, and Google Play's health permissions policy places it in the high-sensitivity reproductive health group, where developers must give "a clear and detailed justification" for requesting it. The same policy forbids "Transferring, selling, or using user health and fitness data for serving ads, including personalized or interest-based advertising", and separately forbids using it "to determine credit-worthiness, insurance eligibility, employment suitability, or for lending purposes". Health Connect itself keeps health records on your device and lets you turn read permission off per data type, though Android's own help page adds a caution people miss: when third-party apps access your records, "they may make a copy of your data".
Samsung is where the picture changes. Menstrual cycle information is named directly in Samsung's consumer health data statement, and the AI training consent prompt reported in July 2026 covers cycle tracking among the data types. That combination, sensitive data plus a consent flow where declining is reported to cost you your cloud history, is a different proposition from on-device predictions.
Oura sits between the two. Reproductive health is processed only with consent, there is no sale and no cross-context advertising, but the data does live on Oura's servers. Fitbit names "female health data" in the biometric categories of its California disclosures, which tells you the data is collected and classified rather than how narrowly it is used.
The practical answer: if cycle privacy is the deciding factor, an Apple Watch paired with an iPhone that has two-factor authentication enabled gives you the most protection by default, because the prediction never needs a server and every other app is bound by store rules. On Android, Health Connect gives you a real per-data-type switch, so grant cycle access to nothing you do not actively use.
Sleep Data: Who Has the Strongest Terms
Sleep is the quiet privacy problem. Cycle data is obviously sensitive, so people guard it. Sleep data looks harmless and is not: a continuous record of when you are unconscious, for how long, and how often you wake is also a record of when your home is occupied, when your routine breaks, and when your health changes. Health Connect stores it as a sleep session with stages, and every platform above collects it by default.
The ranking follows the same logic as cycle data, because the policies do not carve out sleep as a special category. Apple's protections cover Health app data as a whole, so sleep inherits the end to end encryption and the App Review ban on advertising use. Oura's no-sale and no-cross-context-advertising commitments cover sleep alongside everything else, and its law enforcement stance is the strongest written position of the group. Google's ads commitment covers health and wellness data, which includes the nightly sleep reports the Fitbit Air produces. Samsung's reported AI training prompt names sleep explicitly.
Where a sleep-specific judgment does bite is the export path. If you send sleep data onward to another app, the receiving app's policy governs the copy, not the wearable maker's. Android's help page says this directly. Granting a sleep permission is not a view, it is a copy.
Fitbit Air Privacy: What the Screenless Tracker Sends to Google
The Fitbit Air, announced May 7, 2026 at $99.99, has no screen and no buttons, which makes it easy to forget you are wearing it. Google's announcement lists what it records: "24/7 heart rate, heart rhythm monitoring with Afib alerts, SpO2, resting heart rate, heart rate variability, sleep stages and duration, and more". All of it pairs with the Google Health app, and the Google Health Coach sits behind Google Health Premium at $9.99 a month after the trial.
There is no separate Fitbit Air privacy policy. The device inherits the Fitbit policy and Google's health commitments described above, which means the ads promise applies, the sale prohibition applies, and the 30 day and 90 day deletion windows apply. Google Health also lets you "check, remove access to, or delete data you've shared with Google Health Coach at any time", and export or delete your health data from the app settings.
The honest caveat for the Air specifically is that a screenless tracker gives you less feedback about what it is doing. There is no display telling you a workout auto-detected or a measurement was taken. If you buy one, go into the Google Health privacy settings once, look at the list of connected services, and decide what you want syncing outward before the record gets long.
The Regulatory Gap: HIPAA Does Not Protect You Here
This is the most important thing most wearable users do not understand: HIPAA almost certainly does not cover your wearable data. HIPAA applies to "covered entities," defined as healthcare providers, health insurers, and healthcare clearinghouses, along with their business associates. Consumer wearable companies are none of these. The heart rate data your Oura Ring records, the sleep data your Apple Watch tracks, the GPS data your Garmin logs: none of it falls under HIPAA protection unless it is shared directly with a covered healthcare provider through a regulated channel.
This means that the health data wearable companies collect about you has fewer federal privacy protections than the data your doctor's office collects. There is no federal requirement for wearable companies to limit how long they retain your data, no requirement to obtain specific consent before sharing it, and no requirement to notify you if it is sold or transferred to another company in an acquisition.
One federal rule does reach into the gap, and it is worth knowing because almost nobody mentions it. The FTC's Health Breach Notification Rule requires "vendors of personal health records and related entities to notify consumers following a breach involving unsecured information", and the FTC has explicitly applied it to health apps and connected devices that fall outside HIPAA. It is a breach notification rule, not a privacy rule: it does not limit what a company may do with your data while it holds it. What it means in practice is that if a wearable company loses your data, you are entitled to hear about it, even though HIPAA never applied.
State-Level Laws Are Filling the Gap (Slowly)
In the absence of federal legislation, several states have enacted laws that provide stronger protections for biometric and health data.
Illinois Biometric Information Privacy Act (BIPA). BIPA is the most aggressive biometric privacy law in the United States. It requires informed consent before the collection of biometric identifiers (fingerprints, voiceprints, facial geometry, retina scans), provides a private right of action (meaning individuals can sue), and has resulted in significant settlements against companies that violated its terms. While BIPA's coverage of wearable health metrics like heart rate and HRV is still being tested in courts, it sets the precedent that biometric data requires explicit consent.
California Consumer Privacy Act (CCPA) and CPRA. California law classifies wearable-derived metrics including heart rate, sleep data, and skin temperature as "sensitive personal information." Consumers have the right to know what data is collected, request its deletion, and opt out of its sale. The California Privacy Rights Act (CPRA) added further protections, including requirements for data protection impact assessments.
Washington My Health My Data Act. Enacted in 2023, this law imposes strict consent requirements on any entity collecting health data, regardless of whether it qualifies as a HIPAA-covered entity. It specifically targets the regulatory gap that consumer health apps and wearables fall into.
Anonymized vs. De-identified Data: Why It Matters
Many wearable companies state that they share "anonymized" or "de-identified" data. These terms are not interchangeable, and the distinction matters. De-identified data has had direct identifiers (name, email, device ID) removed, but often retains enough contextual information (location patterns, demographic data, biometric signatures) to be re-identified through cross-referencing with other datasets. Multiple studies have demonstrated that supposedly de-identified health datasets can be re-linked to individuals with surprising accuracy.
True anonymization is technically much harder and involves transforming data so that re-identification is practically impossible. When a wearable company says it shares "de-identified" data for research purposes, that data may still carry meaningful privacy risk, particularly when combined with other data sources.
What to Look for in a Privacy Policy
Most people do not read privacy policies, and wearable companies rely on that fact. If you are going to invest 5 minutes in understanding how your health data is handled, look for these specific things:
- Data storage location. Is your health data stored on your device, in the cloud, or both? On-device storage with encrypted backup is the most private architecture.
- Third-party sharing. Does the policy permit sharing data with "partners," "service providers," or "affiliates"? These broad categories can encompass advertisers and data brokers.
- Data retention. How long does the company keep your data after you delete your account? Some companies retain data for years after account closure.
- Data portability and deletion. Can you export your data? Can you request permanent deletion? Is the deletion process straightforward or deliberately complex?
- Policy change notifications. Does the company commit to notifying users before changing its privacy practices, or can it update the policy at any time without notice?
Where Vora Fits
Vora is our own app, so treat this section as disclosure rather than a recommendation, and hold it to the same standard as every policy above. Vora does not sell user data, does not use health data for advertising, and does not use your health data to train generalized AI or machine learning models, and it does not permit its service providers to do so. For Garmin data the policy goes a step further, stating that Vora does not use it, and does not permit anyone else to use it, to determine your eligibility for credit, insurance or employment. Data is stored on cloud servers with encryption in transit and at rest, with some cached on your device for performance. When you delete your account, Vora removes your data from its systems within 30 days, except where retention is required by law.
Where your numbers come from matters for privacy too, because every hop is another copy. Vora connects directly to Oura, Garmin, Fitbit and WHOOP (beta) on both iPhone and Android, and to Samsung Health on Android. Anything else reaches Vora through Apple Health on iPhone or Health Connect on Android, which is the same per-data-type permission model described above: you decide which categories are shared, and you can switch them off. The direct Fitbit and WHOOP connections have limited spots, and Samsung Health does not share HRV, resting heart rate or respiratory rate with Vora.
Ultimately, the best protection for your wearable data is awareness. Know what your device collects, where that data goes, and what rights you have over it. The regulatory landscape is evolving, but right now, the responsibility to protect your health data falls largely on you.