8 Total
5 High severity
3 Medium severity
0 Low severity
Summary

This is Fitbit's privacy policy — the document that explains what personal information Fitbit collects when you use its fitness trackers, smartwatches, and app, and how that information is used and shared. If you've linked your Fitbit to a Google Account, Google's privacy policy also applies to your data. You should know that Fitbit collects sensitive health and fitness data, including heart rate, sleep patterns, and location, and may share it with third parties and Google.

Technical Summary

The Fitbit Privacy Policy (last updated February 27, 2026) governs the collection, use, sharing, and retention of personal data by Fitbit LLC, a Google subsidiary, across its wearable devices, mobile applications, and associated services. The policy distinguishes between users operating with a Google Account — whose data is governed by the Google Privacy Policy — and those using legacy Fitbit accounts, creating a bifurcated data governance framework. Key data categories collected include biometric and health metrics, location data, device identifiers, and behavioral analytics. The policy grants users rights to access, export, and delete their data, and outlines sharing arrangements with third-party service providers, health platforms, and corporate affiliates. Notable provisions address data transfers to the United States, retention schedules tied to account status, and children's data restrictions.

Evidence Provenance
Captured April 19, 2026 06:26 UTC
Document ID CA-D-000276
Version ID CA-V-000792
Wayback Machine View archived versions →
SHA-256 57bb5070b60fb4a283fbce5f5f44be0e8de849a37aeb58fdedadaf1ee6109c35
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Cryptographically signed
Institutional Analysis

🔒 Institutional analysis locked

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Upgrade to Professional — $149/mo
Change Timeline
View full version history (0 captures) →
High Severity — 5 provisions
Medium Severity — 3 provisions

Cross-platform context

See how other platforms handle Biometric and Health Data Collection and similar clauses.

Compare across platforms →

Applicable Regulations

BIPA
Illinois, USA
CCPA/CPRA
California, USA
CFAA
United States Federal
CAN-SPAM
United States Federal
GDPR
European Union
HIPAA
United States Federal
UK GDPR
United Kingdom