Provision record
MyFitnessPal · MyFitnessPal Privacy Policy · View original document ↗

Connected Health Device Data Collection

High severity High confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track MyFitnessPal and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

With user permission, the policy authorizes collection of health data from connected devices including continuous glucose monitors, heart rate monitors, activity trackers, scales, and wearables, as well as from platform health repositories such as Apple HealthKit and Google Health Connect.

This analysis describes what MyFitnessPal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that highly sensitive physiological data, including continuous glucose monitoring readings, heart rate, and body composition metrics, may be ingested from connected devices and platform health repositories into MyFitnessPal's data environment, subject to the broader data use and disclosure practices described in this policy.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

The agreement authorizes ingestion of continuous glucose monitor data, heart rate data, and other wearable-sourced physiological data into MyFitnessPal's systems with user permission; the policy separately states that data received from HealthKit and Google Health Connect will not be used for marketing and advertising or transferred to third parties for marketing and advertising purposes.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a deletion request to privacy@myfitnesspal.com or through the MyFitnessPal Privacy Request Center specifying connected device data categories, and separately revoke device integration permissions within the app settings.

Cross-platform context

See how other platforms handle Connected Health Device Data Collection and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Certain connected devices, such as heart rate monitors, Continuous Glucose Monitoring devices, activity trackers, exercise equipment, scales, and/or wearables, that integrate with the Services, may allow us to collect Food and Activity Diary Data with your permission. With your permission, we may also collect relevant data from your device's health and fitness repository, such as Apple's HealthKit or Android's Google Health Connect.

Excerpt from MyFitnessPal's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: Collection of continuous glucose monitoring and other physiological device data engages Washington's My Health MY Data Act, CCPA sensitive personal information provisions, and potentially GDPR Article 9 for EEA users.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →
  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Provision details

Document information
Document
MyFitnessPal Privacy Policy
Entity
MyFitnessPal
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
July 9, 2026
Record ID
CA-P-015194
Document ID
CA-D-00150
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
e8a00675fe5ad84cfe5a6a7c0d9d88889aaed93bcf547ddec00141f378e8a3ae
Analysis generated
May 8, 2026 05:22 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: MyFitnessPal
Document: MyFitnessPal Privacy Policy
Record ID: CA-P-015194
Captured: 2026-05-08 05:22:54 UTC
SHA-256: e8a00675fe5ad84c…
URL: https://conductatlas.com/platform/myfitnesspal/myfitnesspal-privacy-policy/provision/CA-P-015194/connected-health-device-data-collection/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does MyFitnessPal's Connected Health Device Data Collection clause do?

This provision establishes that highly sensitive physiological data, including continuous glucose monitoring readings, heart rate, and body composition metrics, may be ingested from connected devices and platform health repositories into MyFitnessPal's data environment, subject to the broader data use and disclosure practices described in this policy.

How does this clause affect you?

The agreement authorizes ingestion of continuous glucose monitor data, heart rate data, and other wearable-sourced physiological data into MyFitnessPal's systems with user permission; the policy separately states that data received from HealthKit and Google Health Connect will not be used for marketing and advertising or transferred to third parties for marketing and advertising purposes.

Is ConductAtlas affiliated with MyFitnessPal?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by MyFitnessPal.