8 Total
2 High severity
6 Medium severity
0 Low severity
Summary

This privacy policy describes MyFitnessPal's collection, use, and disclosure practices for personal health and fitness data, including food logs, caloric intake, exercise activity, weight, body measurements, device information, and location data. The policy authorizes MyFitnessPal to use this data for advertising purposes and to share it with third-party marketing and analytics partners. Users in California and the EU are granted specific rights to access, delete, and opt out of certain data uses through the app's privacy settings or direct contact with MyFitnessPal.

Technical / Legal Breakdown

This document is MyFitnessPal's Privacy Policy, governing the collection, use, sharing, and retention of personal data submitted by users of its calorie-tracking and fitness platform, with stated legal bases including consent, legitimate interests, and contractual necessity depending on jurisdiction. The policy states that MyFitnessPal collects a broad range of data categories including health and fitness data (food logs, exercise records, weight, body measurements), precise geolocation, device identifiers, payment information, and data from connected third-party apps and wearables, and the terms authorize sharing this data with advertising partners, analytics providers, and affiliated entities. Notable among the policy's provisions is the collection and use of sensitive health-related dietary and body data for advertising and personalization purposes, which sits at the intersection of general consumer privacy law and emerging sensitive data protections; while the policy asserts broad data use rights, applicable law in certain jurisdictions (including California and EU member states) may constrain how this sensitive data can be processed without explicit consent. The policy engages GDPR for EU/EEA users, CCPA/CPRA for California residents, and potentially FTC Act oversight given the nature of health data collection at scale; the policy provides region-specific rights sections for EU users (including rights to access, erasure, portability, and objection) and California residents (including the right to know, delete, and opt out of sale or sharing). MyFitnessPal's collection of dietary data, which may constitute sensitive health information under some regulatory frameworks, warrants particular attention from compliance teams evaluating whether the policy's consent mechanisms satisfy applicable legal thresholds.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 2 provisions
Medium — 6 provisions

Monitoring

MyFitnessPal has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Analytics and Tracking Technologies and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
HIPAA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 19, 2026 06:10 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000150
Version ID CA-V-000708
SHA-256 e8a00675fe5ad84cfe5a6a7c0d9d88889aaed93bcf547ddec00141f378e8a3ae
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans