8 Total
5 High severity
3 Medium severity
0 Low severity
Summary

This is Fitbit's privacy policy — the document that explains what personal information Fitbit collects when you use its fitness trackers, smartwatches, and app, and how that information is used and shared. If you've linked your Fitbit to a Google Account, Google's privacy policy also applies to your data. You should know that Fitbit collects sensitive health and fitness data, including heart rate, sleep patterns, and location, and may share it with third parties and Google.

Technical Summary

The Fitbit Privacy Policy (last updated February 27, 2026) governs the collection, use, sharing, and retention of personal data by Fitbit LLC, a Google subsidiary, across its wearable devices, mobile applications, and associated services. The policy distinguishes between users operating with a Google Account — whose data is governed by the Google Privacy Policy — and those using legacy Fitbit accounts, creating a bifurcated data governance framework. Key data categories collected include biometric and health metrics, location data, device identifiers, and behavioral analytics. The policy grants users rights to access, export, and delete their data, and outlines sharing arrangements with third-party service providers, health platforms, and corporate affiliates. Notable provisions address data transfers to the United States, retention schedules tied to account status, and children's data restrictions.

Institutional Analysis

This policy engages GDPR and UK GDPR obligations for European and UK users, CCPA rights for California residents, and COPPA restrictions for users under 13. The bifurcated data governance model — dif…

This policy engages GDPR and UK GDPR obligations for European and UK users, CCPA rights for California residents, and COPPA restrictions for users under 13. The bifurcated data governance model — differentiating Google Account users from legacy Fitbit account users — creates compliance complexity, …

🔒

Compliance intelligence locked

Regulatory exposure, material risk, and due diligence action items.

Evidence Provenance
Captured March 19, 2026 15:05 UTC
Document ID CA-D-000276
Version ID CA-V-000182
Wayback Machine View archived versions →
SHA-256 a060980eabbf6aefa094b2a637cf6707d7e4bdd2feca286622986315e129154a
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Cryptographically signed
Change Timeline
High Severity — 5 provisions
Medium Severity — 3 provisions