Provision record
MyFitnessPal · MyFitnessPal Privacy Policy · View original document ↗

Connected Health Device Data Collection

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time MyFitnessPal changes these terms. Follow MyFitnessPal →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for MyFitnessPal Monitor emails you the same day this changes. The archive stays free.
Follow MyFitnessPal →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

With user permission, the policy authorizes collection of health data from connected devices including continuous glucose monitors, heart rate monitors, activity trackers, scales, and wearables, as well as from platform health repositories such as Apple HealthKit and Google Health Connect.

This analysis describes what MyFitnessPal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that highly sensitive physiological data, including continuous glucose monitoring readings, heart rate, and body composition metrics, may be ingested from connected devices and platform health repositories into MyFitnessPal's data environment, subject to the broader data use and disclosure practices described in this policy.

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

The agreement authorizes ingestion of continuous glucose monitor data, heart rate data, and other wearable-sourced physiological data into MyFitnessPal's systems with user permission; the policy separately states that data received from HealthKit and Google Health Connect will not be used for marketing and advertising or transferred to third parties for marketing and advertising purposes.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a deletion request to privacy@myfitnesspal.com or through the MyFitnessPal Privacy Request Center specifying connected device data categories, and separately revoke device integration permissions within the app settings.

Cross-platform context

See how other platforms handle Connected Health Device Data Collection and similar clauses.

Compare across platforms →

Monitoring

MyFitnessPal has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow MyFitnessPal → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Certain connected devices, such as heart rate monitors, Continuous Glucose Monitoring devices, activity trackers, exercise equipment, scales, and/or wearables, that integrate with the Services, may allow us to collect Food and Activity Diary Data with your permission. With your permission, we may also collect relevant data from your device's health and fitness repository, such as Apple's HealthKit or Android's Google Health Connect.

Excerpt from MyFitnessPal's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: Collection of continuous glucose monitoring and other physiological device data engages Washington's My Health MY Data Act, CCPA sensitive personal information provisions, and potentially GDPR Article 9 for EEA users. The policy's carve-out restricting HealthKit and Google Health Connect data from marketing use reflects Apple and Google platform policy requirements. HIPAA does not apply to MyFitnessPal as a consumer app outside a covered entity relationship, but FTC health breach notification rules may apply. 2) GOVERNANCE EXPOSURE: High. Continuous glucose monitoring data and physiological metrics from wearables are among the most sensitive categories of consumer health data. The policy restricts use of HealthKit and Health Connect data for marketing, but the broader Food and Activity Diary Data collection is subject to the full range of uses and disclosures described in the policy, including research partner disclosures. 3) JURISDICTION FLAGS: Washington's My Health MY Data Act applies to consumer health data collected from Washington residents regardless of HIPAA coverage. California CPRA sensitive data provisions apply. EEA users are protected by GDPR Article 9 explicit consent requirements for health data. Illinois users should note that physiological data may intersect with BIPA depending on the specific data modalities collected. 4) CONTRACT AND VENDOR IMPLICATIONS: Apple and Google platform data use restrictions on HealthKit and Health Connect data are incorporated by reference through platform terms, creating an additional contractual layer governing use of device-sourced data. Research partner agreements should be audited to confirm that physiological device data is not transferred under the research partner disclosure category. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate: (a) whether the permission mechanism for connected device data collection constitutes valid consent under GDPR and applicable state law; (b) whether the marketing restriction on HealthKit and Health Connect data is operationally enforced in data pipelines; (c) whether FTC Health Breach Notification Rule obligations apply given the collection of personal health records from connected devices; and (d) whether Washington My Health MY Data Act consent and geofencing requirements are satisfied for Washington residents.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC's Health Breach Notification Rule and general enforcement authority over health data practices under the FTC Act are relevant to the collection of physiological data from connected health devices.
    File a complaint →
  • State AG
    Washington and California state attorneys general have enforcement authority over consumer health data under the My Health MY Data Act and CCPA/CPRA sensitive data provisions respectively.
    File a complaint →

Provision details

Document information
Document
MyFitnessPal Privacy Policy
Entity
MyFitnessPal
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
July 9, 2026
Record ID
CA-P-015194
Document ID
CA-D-00150
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
e8a00675fe5ad84cfe5a6a7c0d9d88889aaed93bcf547ddec00141f378e8a3ae
Analysis generated
May 8, 2026 05:22 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: MyFitnessPal
Document: MyFitnessPal Privacy Policy
Record ID: CA-P-015194
Captured: 2026-05-08 05:22:54 UTC
SHA-256: e8a00675fe5ad84c…
URL: https://conductatlas.com/platform/myfitnesspal/myfitnesspal-privacy-policy/provision/CA-P-015194/connected-health-device-data-collection/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does MyFitnessPal's Connected Health Device Data Collection clause do?

This provision establishes that highly sensitive physiological data, including continuous glucose monitoring readings, heart rate, and body composition metrics, may be ingested from connected devices and platform health repositories into MyFitnessPal's data environment, subject to the broader data use and disclosure practices described in this policy.

How does this clause affect you?

The agreement authorizes ingestion of continuous glucose monitor data, heart rate data, and other wearable-sourced physiological data into MyFitnessPal's systems with user permission; the policy separately states that data received from HealthKit and Google Health Connect will not be used for marketing and advertising or transferred to third parties for marketing and advertising purposes.

Is ConductAtlas affiliated with MyFitnessPal?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by MyFitnessPal.