Research ReviewHealth Data & Privacy

Wearable Data Privacy in 2026: Who Has Your Cycle and Sleep Data

V
Vora Team
14 min readUpdated September 20, 2026

Research Review

The Short Answer

If your priority is cycle tracking data, Apple has the strongest terms of the major platforms, and the reason is structural rather than promotional. Apple's consumer health policy states plainly that "Apple does not sell your consumer health personal data", says Health app data is end to end encrypted, and confirms that Cycle Tracking predictions are calculated on your device instead of on a server. Apple also binds every other app on the platform: App Review Guideline 5.1.3 forbids apps from using HealthKit data "for advertising, marketing, or other use-based data mining purposes", and tells developers they "may not store personal health information in iCloud".

For sleep data the ranking is the same, for the same reasons, with Oura a close second on paper: Oura says it does not sell personal data and does not share it for cross-context behavioral advertising, and it commits to opposing or narrowing overbroad law-enforcement requests. Google's Fitbit line sits in the middle, protected by a specific and checkable promise that health data is not used for Google ads. Samsung is the outlier you should read carefully before trusting it with cycle or sleep data, for reasons set out below.

The catch, and it applies to every name above: none of this is HIPAA. These are company policies, not legal obligations, and a policy can be rewritten. The one thing that does not change is data you never uploaded, which is why on-device processing matters more than any promise.

Platform Where the data lives Used for ads? Cycle data handling Deletion
Apple Watch and iPhone Health On device, plus iCloud sync that is end to end encrypted when two-factor authentication is on No. Apple says it does not sell consumer health personal data, and App Review bars other apps from ad use of HealthKit data Cycle Tracking predictions calculated on device User controlled in the Health app and iCloud settings
Fitbit Air and Google Health Google cloud account No. "Health and wellness data is not used for Google ads", and Google says it never sells personal information Named as "female health data" in the policy's California biometric disclosures Most data within 30 days, up to 90 days for backups
Oura Cloud servers, with Apple Health and Health Connect sharing only by permission No sale, and no sharing for cross-context behavioral advertising Reproductive health treated as sensitive, processed only with consent Measurement data kept while the account is active, minus legal retention
Samsung Health Device plus Samsung cloud Statement does not claim an advertising ban for health data Menstrual cycle information named directly as collected data Reported to be tied to the AI training consent, see below
WHOOP Not verified for this update Not verified for this update Not verified for this update Not verified for this update
Vora (our app) Cloud servers with encryption in transit and at rest, some data cached on your device No. Health data is not used for advertising and is not sold Whatever you choose to connect, under the same terms Account deletion removes your data within 30 days, except where law requires retention

We checked every row against the company's own published policy on September 20, 2026, except WHOOP, whose policy pages returned an error to our automated request that day. Rather than describe terms we could not read, we left the row blank. Read WHOOP's policy yourself before you decide.

What Your Wearable Actually Collects

Modern wearables collect far more than step counts. A typical smartwatch or health ring now records heart rate (continuous or periodic), heart rate variability, sleep duration and staging, blood oxygen saturation (SpO2), skin temperature, respiratory rate, GPS location, elevation, menstrual cycle data, electrodermal activity, and in some cases voice data through built-in microphones. Combined over weeks and months, this creates a remarkably detailed physiological profile of your life, one that can reveal health conditions, emotional states, physical location patterns, and daily routines.

The depth of this data collection is not inherently problematic. It is what enables the health insights that make wearables valuable. The problem is what happens to this data after it leaves your wrist or finger.

Where Your Data Goes: Platform by Platform

Not all wearable companies handle your data the same way. The differences are significant.

Apple (Apple Watch, iPhone Health). Apple has built its health data architecture around on-device processing and end-to-end encryption. There is one condition most summaries leave out: Apple's own documentation ties that protection to two-factor authentication, stating that with iOS 12 or later and two-factor turned on, "Apple will not be able to read your health and activity data synced to iCloud". Without two-factor, the data is still encrypted in storage and in transit, but not end to end. Apple's consumer health policy adds that "Apple does not sell your consumer health personal data". When your device is locked with a passcode, Face ID or Touch ID, everything in the Health app other than your Medical ID is encrypted and inaccessible by default. Of the major platforms, Apple offers the strongest default protections, and the two-factor setting is worth checking today if you have never looked.

Google and Fitbit. Fitbit hardware, including the screenless Fitbit Air, now runs through the Google Health app, and the data is governed by the Fitbit privacy policy and Google's health commitments. Google's current published commitment is specific and easy to hold it to: "Health and wellness data is not used for Google ads", alongside "We never sell your personal information". The Fitbit policy is broader about who else can touch the data, listing sharing with service providers for work including "data analysis, research, and surveys", with corporate affiliates and partners for external processing, and with third parties where legally required. Deletion is the clearest number on the page: after you delete your account, most of your information is deleted within 30 days, and it can take up to 90 days to clear backups.

Oura. Oura stores health data on cloud servers and states that it has not sold personal information and does not sell or share personal data for cross-context behavioral advertising. Sharing with Apple Health or Health Connect happens only with your permission. Two details set Oura apart in the current policy. It treats reproductive health as sensitive data processed "only with your consent", and it commits to reviewing law enforcement and government requests case by case and to "oppose, seek to narrow, or reject" requests it considers overly broad or legally deficient. That last commitment is a company promise rather than a legal shield, but few competitors put it in writing. Measurement data is kept while your account is active, with some records held longer for accounting and tax obligations.

Samsung. Samsung's US consumer health data privacy statement, last updated July 1, 2025, names exactly the data category people worry about: "Reproductive or sexual health information (such as menstrual cycle information you provide through our Services)". It describes sharing with third-party devices and apps you connect, with Samsung's affiliates and subsidiaries, and with vendors acting on Samsung's behalf. In July 2026, Notebookcheck and Android Headlines both reported a new in-app prompt titled "Consent to the Use of Health Data for AI Training and Modeling", covering sleep and cycle tracking, heart rate, medications and medical records, and both reported that declining stops cloud synchronization and removes existing data from Samsung's servers. Samsung's published consumer health statement does not mention AI training or human review, so the prompt is the document that matters. Read it rather than tapping through it.

WHOOP. WHOOP's privacy policy pages refused our automated request on September 20, 2026, so we have nothing verified to report about its current terms and will not guess. If you are weighing WHOOP on privacy grounds, open its Privacy Center in a browser and read the sections on third-party sharing and on de-identified data before you subscribe.

Cycle Tracking Data: Which Platform Actually Protects It

Menstrual cycle data is the most sensitive thing a mainstream wearable records, and it is the one category where the platforms differ in kind rather than in degree. The question is not only whether a company promises not to sell it. It is whether the data ever leaves your device, and what every other app on the platform is allowed to do once it has access.

On iPhone, Apple states that Cycle Tracking predictions are calculated on device, which means the inference about your cycle is made locally rather than on a server. Apple's App Review Guidelines then constrain third-party apps: section 5.1.3 says apps "may not use or disclose to third parties data gathered in the health, fitness, and medical research context", including through the HealthKit API, "for advertising, marketing, or other use-based data mining purposes", and the same section tells developers they "may not store personal health information in iCloud". A period tracking app on the App Store that reads your Health data is bound by that rule as a condition of being on the store.

Android caught up in a way worth knowing about. Cycle data in Health Connect is a separate permission, READ_MENSTRUAL_CYCLE_PHASE, and Google Play's health permissions policy places it in the high-sensitivity reproductive health group, where developers must give "a clear and detailed justification" for requesting it. The same policy forbids "Transferring, selling, or using user health and fitness data for serving ads, including personalized or interest-based advertising", and separately forbids using it "to determine credit-worthiness, insurance eligibility, employment suitability, or for lending purposes". Health Connect itself keeps health records on your device and lets you turn read permission off per data type, though Android's own help page adds a caution people miss: when third-party apps access your records, "they may make a copy of your data".

Samsung is where the picture changes. Menstrual cycle information is named directly in Samsung's consumer health data statement, and the AI training consent prompt reported in July 2026 covers cycle tracking among the data types. That combination, sensitive data plus a consent flow where declining is reported to cost you your cloud history, is a different proposition from on-device predictions.

Oura sits between the two. Reproductive health is processed only with consent, there is no sale and no cross-context advertising, but the data does live on Oura's servers. Fitbit names "female health data" in the biometric categories of its California disclosures, which tells you the data is collected and classified rather than how narrowly it is used.

The practical answer: if cycle privacy is the deciding factor, an Apple Watch paired with an iPhone that has two-factor authentication enabled gives you the most protection by default, because the prediction never needs a server and every other app is bound by store rules. On Android, Health Connect gives you a real per-data-type switch, so grant cycle access to nothing you do not actively use.

Sleep Data: Who Has the Strongest Terms

Sleep is the quiet privacy problem. Cycle data is obviously sensitive, so people guard it. Sleep data looks harmless and is not: a continuous record of when you are unconscious, for how long, and how often you wake is also a record of when your home is occupied, when your routine breaks, and when your health changes. Health Connect stores it as a sleep session with stages, and every platform above collects it by default.

The ranking follows the same logic as cycle data, because the policies do not carve out sleep as a special category. Apple's protections cover Health app data as a whole, so sleep inherits the end to end encryption and the App Review ban on advertising use. Oura's no-sale and no-cross-context-advertising commitments cover sleep alongside everything else, and its law enforcement stance is the strongest written position of the group. Google's ads commitment covers health and wellness data, which includes the nightly sleep reports the Fitbit Air produces. Samsung's reported AI training prompt names sleep explicitly.

Where a sleep-specific judgment does bite is the export path. If you send sleep data onward to another app, the receiving app's policy governs the copy, not the wearable maker's. Android's help page says this directly. Granting a sleep permission is not a view, it is a copy.

Fitbit Air Privacy: What the Screenless Tracker Sends to Google

The Fitbit Air, announced May 7, 2026 at $99.99, has no screen and no buttons, which makes it easy to forget you are wearing it. Google's announcement lists what it records: "24/7 heart rate, heart rhythm monitoring with Afib alerts, SpO2, resting heart rate, heart rate variability, sleep stages and duration, and more". All of it pairs with the Google Health app, and the Google Health Coach sits behind Google Health Premium at $9.99 a month after the trial.

There is no separate Fitbit Air privacy policy. The device inherits the Fitbit policy and Google's health commitments described above, which means the ads promise applies, the sale prohibition applies, and the 30 day and 90 day deletion windows apply. Google Health also lets you "check, remove access to, or delete data you've shared with Google Health Coach at any time", and export or delete your health data from the app settings.

The honest caveat for the Air specifically is that a screenless tracker gives you less feedback about what it is doing. There is no display telling you a workout auto-detected or a measurement was taken. If you buy one, go into the Google Health privacy settings once, look at the list of connected services, and decide what you want syncing outward before the record gets long.

The Regulatory Gap: HIPAA Does Not Protect You Here

This is the most important thing most wearable users do not understand: HIPAA almost certainly does not cover your wearable data. HIPAA applies to "covered entities," defined as healthcare providers, health insurers, and healthcare clearinghouses, along with their business associates. Consumer wearable companies are none of these. The heart rate data your Oura Ring records, the sleep data your Apple Watch tracks, the GPS data your Garmin logs: none of it falls under HIPAA protection unless it is shared directly with a covered healthcare provider through a regulated channel.

This means that the health data wearable companies collect about you has fewer federal privacy protections than the data your doctor's office collects. There is no federal requirement for wearable companies to limit how long they retain your data, no requirement to obtain specific consent before sharing it, and no requirement to notify you if it is sold or transferred to another company in an acquisition.

One federal rule does reach into the gap, and it is worth knowing because almost nobody mentions it. The FTC's Health Breach Notification Rule requires "vendors of personal health records and related entities to notify consumers following a breach involving unsecured information", and the FTC has explicitly applied it to health apps and connected devices that fall outside HIPAA. It is a breach notification rule, not a privacy rule: it does not limit what a company may do with your data while it holds it. What it means in practice is that if a wearable company loses your data, you are entitled to hear about it, even though HIPAA never applied.

State-Level Laws Are Filling the Gap (Slowly)

In the absence of federal legislation, several states have enacted laws that provide stronger protections for biometric and health data.

Illinois Biometric Information Privacy Act (BIPA). BIPA is the most aggressive biometric privacy law in the United States. It requires informed consent before the collection of biometric identifiers (fingerprints, voiceprints, facial geometry, retina scans), provides a private right of action (meaning individuals can sue), and has resulted in significant settlements against companies that violated its terms. While BIPA's coverage of wearable health metrics like heart rate and HRV is still being tested in courts, it sets the precedent that biometric data requires explicit consent.

California Consumer Privacy Act (CCPA) and CPRA. California law classifies wearable-derived metrics including heart rate, sleep data, and skin temperature as "sensitive personal information." Consumers have the right to know what data is collected, request its deletion, and opt out of its sale. The California Privacy Rights Act (CPRA) added further protections, including requirements for data protection impact assessments.

Washington My Health My Data Act. Enacted in 2023, this law imposes strict consent requirements on any entity collecting health data, regardless of whether it qualifies as a HIPAA-covered entity. It specifically targets the regulatory gap that consumer health apps and wearables fall into.

Anonymized vs. De-identified Data: Why It Matters

Many wearable companies state that they share "anonymized" or "de-identified" data. These terms are not interchangeable, and the distinction matters. De-identified data has had direct identifiers (name, email, device ID) removed, but often retains enough contextual information (location patterns, demographic data, biometric signatures) to be re-identified through cross-referencing with other datasets. Multiple studies have demonstrated that supposedly de-identified health datasets can be re-linked to individuals with surprising accuracy.

True anonymization is technically much harder and involves transforming data so that re-identification is practically impossible. When a wearable company says it shares "de-identified" data for research purposes, that data may still carry meaningful privacy risk, particularly when combined with other data sources.

What to Look for in a Privacy Policy

Most people do not read privacy policies, and wearable companies rely on that fact. If you are going to invest 5 minutes in understanding how your health data is handled, look for these specific things:

  • Data storage location. Is your health data stored on your device, in the cloud, or both? On-device storage with encrypted backup is the most private architecture.
  • Third-party sharing. Does the policy permit sharing data with "partners," "service providers," or "affiliates"? These broad categories can encompass advertisers and data brokers.
  • Data retention. How long does the company keep your data after you delete your account? Some companies retain data for years after account closure.
  • Data portability and deletion. Can you export your data? Can you request permanent deletion? Is the deletion process straightforward or deliberately complex?
  • Policy change notifications. Does the company commit to notifying users before changing its privacy practices, or can it update the policy at any time without notice?

Where Vora Fits

Vora is our own app, so treat this section as disclosure rather than a recommendation, and hold it to the same standard as every policy above. Vora does not sell user data, does not use health data for advertising, and does not use your health data to train generalized AI or machine learning models, and it does not permit its service providers to do so. For Garmin data the policy goes a step further, stating that Vora does not use it, and does not permit anyone else to use it, to determine your eligibility for credit, insurance or employment. Data is stored on cloud servers with encryption in transit and at rest, with some cached on your device for performance. When you delete your account, Vora removes your data from its systems within 30 days, except where retention is required by law.

Where your numbers come from matters for privacy too, because every hop is another copy. Vora connects directly to Oura, Garmin, Fitbit and WHOOP (beta) on both iPhone and Android, and to Samsung Health on Android. Anything else reaches Vora through Apple Health on iPhone or Health Connect on Android, which is the same per-data-type permission model described above: you decide which categories are shared, and you can switch them off. The direct Fitbit and WHOOP connections have limited spots, and Samsung Health does not share HRV, resting heart rate or respiratory rate with Vora.

Ultimately, the best protection for your wearable data is awareness. Know what your device collects, where that data goes, and what rights you have over it. The regulatory landscape is evolving, but right now, the responsibility to protect your health data falls largely on you.

Frequently Asked Questions

Is my wearable health data covered by HIPAA?

Almost certainly not. HIPAA only applies to covered entities like healthcare providers, health insurers, and clearinghouses. Consumer wearable companies like Fitbit, Oura, and Whoop are not covered entities. Your wearable health data has fewer federal privacy protections than the data your doctor collects.

Which wearable company has the best privacy practices?

Apple currently offers the strongest default privacy architecture for consumer health data. Much of it is processed on device, it is end to end encrypted when synced to iCloud provided you have two-factor authentication turned on, and Apple states it does not sell consumer health personal data. Oura is the strongest of the cloud-based options on paper, with no sale, no cross-context advertising, and a written commitment to push back on overbroad law enforcement requests.

Which smartwatch has the most comprehensive privacy policy for cycle tracking data?

Apple, and the reason is architectural rather than promotional. Apple says Cycle Tracking predictions are calculated on your device, so the inference never needs a server, and App Review Guideline 5.1.3 bars every other app on the platform from using HealthKit data for advertising, marketing or data mining. On Android, cycle data sits behind a separate Health Connect permission that Google Play classes as high-sensitivity reproductive health, so you can grant or deny it per app.

Which sleep tracking smartwatch has the most robust data privacy policy?

The same ranking applies, because no major platform writes separate terms for sleep. Apple's encryption and advertising restrictions cover Health app data as a whole, including sleep. Oura's no-sale and no-cross-context-advertising commitments cover sleep too. Google commits that health and wellness data is not used for Google ads, which covers Fitbit sleep reports. The bigger risk with sleep data is the export path: once you share it with another app, that app's policy governs the copy.

Is Fitbit Air data private, and what does it send to Google?

There is no separate Fitbit Air privacy policy. The Air records 24/7 heart rate, heart rhythm with Afib alerts, SpO2, resting heart rate, heart rate variability, and sleep stages and duration, and it syncs to the Google Health app under the Fitbit privacy policy. Google states that health and wellness data is not used for Google ads and that it never sells personal information. If you delete your account, most data goes within 30 days and backups can take up to 90 days.

Does Samsung Health use my health data to train AI?

Notebookcheck and Android Headlines both reported in July 2026 that Samsung Health began showing a prompt titled Consent to the Use of Health Data for AI Training and Modeling, covering sleep and cycle tracking, heart rate, medications and medical records, and that declining stops cloud synchronization and removes existing data from Samsung's servers. Samsung's own published consumer health data statement does not mention AI training, so read the in-app prompt itself rather than relying on the policy page.

What is the difference between anonymized and de-identified data?

De-identified data has had direct identifiers removed but may retain enough contextual information to be re-identified through cross-referencing with other datasets. True anonymization transforms data so re-identification is practically impossible. When a wearable company shares de-identified data, it may still carry meaningful privacy risk.

What state laws protect my wearable data?

Illinois BIPA requires informed consent before collecting biometric identifiers and provides a private right of action. California CCPA/CPRA classifies wearable-derived metrics as sensitive personal information with rights to deletion and opt-out of data sales. Washington's My Health My Data Act imposes strict consent requirements on any entity collecting health data, including wearable companies.

Sources & References

  1. Kulkarni P, et al.. Privacy in Consumer Wearable Technologies: A Living Systematic Analysis of Data Policies Across Leading ManufacturersJournal of Medical Internet Research (2025)
  2. University of Cincinnati Law Review. Steps, Sleep, Safety: Rethinking Privacy for Wearable Health Devices (2026)
  3. Jang J, et al.. Usage Trends and Data Sharing Practices of Healthcare Wearable Devices Among US Adults: Cross-Sectional StudyJournal of Medical Internet Research (2025)
  4. ICLG. Digital Health Laws and Regulations Report 2026: USA (2026)
  5. Vora. Vora Privacy Policy: data storage, security and AI providers (checked September 14, 2026)
  6. Apple. Consumer Health Personal Data Privacy Policy (checked September 20, 2026)
  7. Apple. Health App & Privacy (checked September 20, 2026)
  8. Apple. App Review Guidelines, section 5.1.3 Health and Health Research (checked September 20, 2026)
  9. Google Health. Our Continued Commitment To Data Privacy and Security (checked September 20, 2026)
  10. Google. Fitbit Privacy Policy (checked September 20, 2026)
  11. Google Play Console Help. Android Health Permissions: Guidance and FAQs (checked September 20, 2026)
  12. Android Help. Manage connected apps in Health Connect (checked September 20, 2026)
  13. Android Developers. Health Connect data types (checked September 20, 2026)
  14. Oura. Oura Privacy Policy (checked September 20, 2026)
  15. Samsung. Samsung Consumer Health Data Privacy Statement (last updated July 1, 2025, checked September 20, 2026)
  16. Notebookcheck. Medications, menstrual cycle, and more: Samsung shares sensitive data with AI and employees (2026-07-13)
  17. Android Headlines. Samsung Health Ultimatum: Share Your Private Medical Data with AI or Lose It Forever (2026-07-15)
  18. Google. Introducing the new Google Fitbit Air (2026-05-07)
  19. Google Health Help. What is new with the redesigned Google Health app (checked September 20, 2026)
  20. US Federal Trade Commission. Health Breach Notification Rule (checked September 20, 2026)

All research discussed in this article is summarized in our own words. We link to original sources for full access. This content is for informational purposes and does not constitute medical advice.

data privacywearable databiometric securitycycle trackingsleep trackingHIPAAhealth dataprivacy policyApple WatchOura RingFitbitSamsung HealthBIPA

Experience it yourself

AI-powered workouts, photo nutrition logging, HRV recovery tracking, voice coaching, and more - all free to start.

Download Vora Free

Related Articles

Health Data & Privacy

Stop Renting Access to Your Own Health Data: The 2026 Shift to No-Subscription Wearables

A quiet backlash is reshaping wearables in 2026: people are tired of paying a monthly fee just to see their own recovery data. Here is the no-subscription landscape, why it is happening, and what to look for.

Read more
Wearable Reviews

Amazfit Helio Ring vs Oura Ring (2026): No-Subscription vs the Sleep King

The Amazfit Helio Ring is a no-subscription smart ring taking on Oura. Here is how they compare on sleep, recovery, accuracy, and true cost, and which is right for you.

Read more
Health Technology

Ultrahuman Ring AIR vs Oura Ring (2026): No-Subscription Ring vs the Sleep King

The Ultrahuman Ring AIR is the leading no-subscription challenger to Oura. Here is how they compare on sleep, recovery, accuracy, and total cost, and which one is right for you.

Read more

Explore All Features

All FeaturesBiology & Health ScoreVoice CoachingNutrition TrackingRecovery & HRVMeditationCycle TrackingApple WatchIntegrationsDaily Plan