8 Total
2 High severity
6 Medium severity
0 Low severity
Summary

This document establishes Fitbit's data collection, use, and sharing practices for health and activity data generated by Fitbit devices and applications. Fitbit collects heart rate, sleep pattern, menstrual cycle, GPS location, and exercise data, and the policy authorizes sharing such data with third-party application developers designated by the user, corporate affiliates, and entities acquiring Fitbit in a merger or acquisition. Accounts linked to Google services operate under the Google Privacy Policy rather than this policy.

Technical / Legal Breakdown

This document is Fitbit's standalone privacy policy governing the collection, use, and sharing of personal data through Fitbit devices, apps, and services for users who have not linked their Fitbit account to a Google Account; users who have linked to a Google Account are directed to the Google Privacy Policy instead. The policy states that Fitbit collects a broad range of data categories including health and fitness metrics (sleep, heart rate, activity, exercise, menstrual health, weight), precise GPS location, device and usage data, payment information, and user-generated content, and the terms authorize sharing this data with service providers, corporate affiliates, third-party app developers with user consent, and potential acquirers in a corporate transaction. The policy's carve-out routing Google Account-linked users to a separate Google Privacy Policy creates a bifurcated data governance structure that may make it materially difficult for users to identify which policy governs their data, and the breadth of health and fitness data collected, including menstrual cycle and sleep data, raises sensitivity considerations that may engage protections beyond standard consumer privacy frameworks. The policy engages GDPR for EEA and UK users, CCPA and related California privacy law for California residents, and due to the nature of health and fitness data collected, may require evaluation under the FTC Act's health breach notification guidance and applicable state health privacy laws; jurisdiction-specific rights including data access, deletion, correction, and portability are acknowledged for EU, UK, Swiss, and California residents. The policy was last updated February 27, 2026, and compliance teams should note that the Google Account integration pathway effectively transfers data governance to Google's framework, which has its own regulatory posture and may alter user rights in practice.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 2 provisions
Medium — 6 provisions

Monitoring

Fitbit has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Biometric and Health Data Collection and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

BIPA
Illinois, USA
View official text ↗
CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
HIPAA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 19, 2026 06:26 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000276
Version ID CA-V-000792
SHA-256 57bb5070b60fb4a283fbce5f5f44be0e8de849a37aeb58fdedadaf1ee6109c35
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans