Health apps collect more personal data than most other software
A health or fitness app knows things about you that your email provider or social media account does not: your weight, heart rate, menstrual cycle, medications, mental health symptoms, or workout location. Because this data is sensitive, health apps face stricter rules than general apps—but those rules have gaps, and the apps themselves vary wildly in what they do with what they collect.
The core trade-off is straightforward: the more data you give an app, the more useful it becomes. A step counter works with almost nothing. A period tracker that predicts your cycle needs months of data. An app that monitors blood sugar for diabetes management needs real-time readings. But each piece of data is also a piece of information that could be sold, hacked, shared with insurers, or subpoenaed by law enforcement. Understanding what each app actually does with your data—not what it says it does, but what its privacy policy and business model actually allow—is how you make a real choice about your own risk.
Key Takeaways
- Health apps in the United States are regulated by the FDA, FTC, and sometimes state medical boards, but these rules do not prevent data sales or require encryption—they mainly prevent false medical claims.
- An app's privacy policy is legally binding, but it often permits the app to sell your data to third parties, share it with employers or insurers, or change the policy with notice.
- Apps that store data on your phone only (not in the cloud) are harder to hack remotely, but you lose access if you switch phones or lose the device.
- If an app requires a login, uses cloud storage, or syncs across devices, your data travels over the internet and can be intercepted unless the app uses end-to-end encryption.
- Choosing between convenience and privacy means deciding whether you want the app to work offline and locally, or whether you need it to sync across your devices and back up automatically.
What the privacy policy actually permits
The privacy policy is the legal document that tells you what an app can do with your data. It is not a promise to keep your data safe—it is a list of what the company is allowed to do. Many health apps explicitly state they can sell anonymized data, share data with business partners, or change the policy at any time with notice (usually 30 days).
Some apps distinguish between what they do now and what they are permitted to do. For example, an app might say "we do not currently sell your data" but also say "we may do so in the future." That second clause means the company can change its business model without your consent—you would just get a notification. If you do not want your data sold under any future version of the app, you need to delete your account and the app before that change happens.
A few apps—notably some period trackers and mental health apps—explicitly promise never to sell data, and they back this up by being funded through subscriptions or nonprofit grants rather than advertising. These are the exception. Most free health apps are free because they sell your data or sell access to your data to advertisers, insurers, or researchers.
How data moves: local storage versus the cloud
An app can store your data in two places: on your phone itself, or on a company server (the cloud). This choice affects both security and convenience.
Local storage means the app keeps everything on your device. Your data never travels over the internet, so it cannot be intercepted by hackers or eavesdroppers. But if you lose your phone, drop it in water, or switch to a new device, your data is gone unless you manually backed it up. Local-only apps also cannot sync across your phone, tablet, and computer—each device has its own separate data.
Cloud storage means the app sends your data to a company server. Your data is backed up automatically, syncs across all your devices, and you can access it from anywhere. But the data has to travel over the internet to get there, and it sits on a company server that could be hacked, subpoenaed, or sold. The company also has a copy of your data, which means they can analyze it, share it, or use it for purposes you did not know about.
Most popular health apps use cloud storage because it is more convenient. But convenience comes with risk. If you choose a cloud-based app, look for one that uses end-to-end encryption—a technical method that scrambles your data so thoroughly that even the company cannot read it. End-to-end encryption is rare in health apps because it makes the company's own analytics harder, but apps like Signal (for messaging) and some encrypted password managers use it as standard.
What happens when you connect to other apps and devices
Many health apps integrate with other apps and devices: your smartwatch, your phone's built-in health app, your insurance company's app, or your doctor's patient portal. Each connection is another place where your data can be shared, copied, or analyzed.
When you connect a fitness tracker to a health app, you are usually giving the health app permission to read data from the tracker. That permission is often permanent—the app can keep reading that data even after you disconnect. Some apps also ask for permission to write data back to the tracker, which means the app can modify what the tracker records.
If you connect your health app to your insurance company's app (some insurers offer discounts for sharing fitness data), you are giving the insurer access to your activity level, weight, or other health metrics. Insurers can use this data to adjust your premiums, deny claims, or flag you for investigation. This is legal in most states, though a few states have passed laws limiting how insurers can use this data.
Before you connect anything, check what permissions the app is asking for. On iPhone, go to Settings > Privacy and look at what each app has permission to access. On Android, go to Settings > Apps > Permissions. If an app is asking for access to your contacts, location, or camera when it does not need it, that is a sign the app may be collecting data for purposes beyond what it claims.
Keeping your account and data find
A strong password is the first line of defense for any app that requires a login. Use a password that is at least 12 characters long, includes uppercase and lowercase letters, numbers, and symbols, and is unique to that app—do not reuse the same password across multiple apps. A password manager like Bitwarden or 1Password can generate and store strong passwords for you.
Two-factor authentication (2FA) adds a second step: after you enter your password, the app sends a code to your phone or email, and you have to enter that code to log in. This means a hacker who steals your password still cannot access your account without also stealing your phone or email. Most health apps offer 2FA as an option, though not all make it mandatory. Turn it on if the app offers it.
If an app stores sensitive data like blood sugar readings or psychiatric notes, consider whether you need the app to sync across devices or whether a local-only version would work for you. A local-only app is harder to hack remotely, but you lose the convenience of accessing your data from multiple devices. This is a real trade-off with no universal right answer—it depends on how sensitive your data is and how much convenience matters to you.
Check your app's security settings periodically. Look for options to delete old data, limit what the app can access, or restrict who can see your data. Some apps let you set a PIN or biometric lock (fingerprint or face recognition) so that even if someone gets your phone, they cannot open the app without that extra step.
Understanding FDA and FTC rules for health apps
Health apps in the United States are regulated by three bodies: the FDA (Food and Drug Administration), the FTC (Federal Trade Commission), and sometimes state medical boards. But these rules do not work the way many people think.
The FDA regulates apps that make medical claims—for example, an app that says it can diagnose diabetes or treat depression. If an app makes a medical claim, the FDA requires it to prove the claim is true before the app goes on the market. But most health apps do not make medical claims. A fitness tracker that counts steps is not making a medical claim. A period tracker that predicts your cycle is not making a medical claim. These apps are not FDA-regulated, which means no government body has checked whether they work or whether they are safe.
The FTC regulates deceptive advertising and unfair business practices. If a health app says it encrypts your data but does not, or says it does not sell your data but does, the FTC can fine the company. But the FTC does not require apps to encrypt data, to limit data collection, or to avoid selling data—it only requires them to tell the truth about what they do.
State medical boards regulate doctors and nurses, not apps. If a health app is run by a doctor or claims to provide medical information, the state board might have jurisdiction. But most health apps are run by tech companies, not medical professionals, so state boards do not regulate them.
The result is that health apps have fewer rules than you might expect. An app can collect a lot of data, sell it, use it for purposes you did not know about, and change its privacy policy at any time—as long as it tells you it is doing so in the privacy policy.
Choosing between popular apps: what to look for
When you are choosing a health app, compare them on a few concrete dimensions: what data they collect, where they store it, who they share it with, and whether they encrypt it.
For a fitness app, ask: Does it need your location? Does it need to sync across devices, or would a local-only app work? Does it sell data to advertisers or insurers? Does it use end-to-end encryption? A straightforward step counter that stores data locally and does not sync is more private but less convenient. A synced app that backs up to the cloud is more convenient but more exposed.
For a period tracker, the stakes are higher because the data is more sensitive. Some period trackers have been subpoenaed by law enforcement in abortion cases, which means your period data could theoretically be used against you in court. If you use a period tracker, choose one that explicitly promises not to sell data and not to comply with law enforcement requests without a warrant. Apps like Euki and Clue have made these commitments publicly. Apps like Flo have not, which means they could change their policy or comply with requests.
For a mental health or therapy app, look for one that uses end-to-end encryption and does not sell data. Apps like Headspace and Calm are popular but do not use end-to-end encryption, which means the company can read your meditation history or therapy notes. Apps like Sanvello and Talkspace are therapy-specific and use stronger encryption, though they still may share data with insurers if you use insurance to pay.
Read the privacy policy, not just the marketing copy. The privacy policy is the legal document that tells you what the app actually does. Marketing copy tells you what the company wants you to think it does. They are often different.
What to do if an app gets hacked or changes its policy
Health app breaches happen regularly. In 2023, the period tracker Flo was hacked and user data including period dates and pregnancy status was exposed. In 2022, the mental health app BetterHelp was found to be sharing user data with Facebook and other advertisers. In 2021, the fitness app Strava accidentally revealed the locations of military bases because users had recorded their workouts with GPS.
If an app you use gets hacked, the company will usually send you an email notification. The notification will tell you what data was exposed and what you should do. Usually, you should change your password when ready, turn on two-factor authentication if you have not already, and consider whether you want to keep using the app.
If an app changes its privacy policy in a way you do not like, you have a few options. You can delete your account and the app, which removes your data from the company's servers (though they may keep a copy for legal reasons). You can stop using the app but keep your account, which means your data stays on their servers but you are not adding new data. Or you can keep using the app and accept the new policy. There is no way to force a company to delete your data or to keep the old policy—you can only choose whether to keep using the app.
Before you delete your account, read your data if the app offers that option. Many health apps let you export your data as a file (usually a CSV or PDF) that you can keep for your own records. This is useful if you want to switch to a different app or if you want a backup of your health information.
Frequently Asked Questions
Is it safe to use a health app without a password?
No. An app without a password is accessible to anyone who picks up your phone. If the app stores health data, use a strong password and turn on two-factor authentication. Some apps let you set a PIN or biometric lock as an extra layer, which is worth doing for sensitive data.
Can my insurance company see my health app data?
Only if you connect your app to your insurance company's app or explicitly give them permission. If you do not connect them, the insurance company cannot see your app data. But if you do connect them, the insurer can use that data to adjust your premiums or deny claims in most states. Check your state's insurance laws before connecting.
What does "anonymized data" mean, and is it really private?
Anonymized data is data with your name and identifying information removed. But researchers have shown that anonymized health data can often be re-identified by combining it with other data sources. If an app says it sells anonymized data, that data is less private than it sounds, though it is more private than data with your name attached.
Do I need to use the same app on my phone and my smartwatch?
No. You can use different apps on each device. For example, you could use a local-only fitness app on your phone and let your smartwatch sync to the phone's built-in health app. This gives you more control over what data goes where. But it means managing multiple apps and potentially losing the convenience of a single unified view of your health data.
What should I do if I do not trust an app but I want to keep using it?
Limit what you share. If an app asks for permission to access your location, contacts, or camera, deny it if you do not need it. Use a strong password and two-factor authentication. Do not connect it to other apps or devices unless you have to. And check the privacy policy periodically to see if it has changed. You can also use a separate email address for the app so that if it gets hacked, the breach does not expose your primary email.
