Your Workout Data: The Privacy Guide for the Quantified Self
Your watch knows where you run, when you sleep, your heart’s every flutter — and that data lives on servers with policies nobody reads. The quantified-self privacy guide: what’s collected, the thirty-minute settings audit and the sharing choices worth making on purpose.

What’s Actually Collected
The data census: the obvious tier (workouts, routes, heart rate, sleep — the dashboard data you see), the inferred tier (the patterns beneath — your home address from route starts, your schedule from activity times, your health trajectory from the trends; inference is where fitness data gets sensitive), the cycle-data sensitivity (the period-tracking privacy conversation applies to any app holding it — the post-2022 awareness that reshaped the category), and the business-model context (free apps monetize somehow — the data-sharing and advertising relationships living in the policy’s middle paragraphs; paid isn’t automatically private, but free is automatically monetized).
The Thirty-Minute Audit
The settings sweep: the route-privacy zones first (the home-and-work privacy bubbles that hide route starts and ends — the single most important setting on any GPS fitness app; the default is often OFF, and the stranger reading your 6am route’s start address is the threat model), the profile-visibility tier (public-by-default activity feeds audited — the follower approval, the private-account option; the fitness app is a social network wearing a stopwatch), the third-party connections purge (the apps granted access years ago and forgotten — the connected-apps page is a plaque of old permissions; revoke the dead ones), the data-sharing toggles (the anonymized-research and partner-sharing opt-outs — opt-in should be a memory you have), and the download-and-delete literacy (the export-my-data and delete-account paths located BEFORE they’re needed).

The Sharing Decisions
Deliberate over default: the social-feature honesty (the kudos economy motivates genuinely — the community chapters say so; the decision is WHICH activities publish, not whether to exist; the manual-share default beats the auto-publish one), the live-location tier (the safety beacon shared with a trusted person during runs is the feature done right — the night-run chapter’s tool; the always-on location breadcrumb for an audience is the same tech done thoughtlessly), the workplace-wellness fine print (the employer-program wearables and their data flows — the wellness discount’s terms deserve the read), and the household conversation (shared accounts and family visibility set by agreement — the teen’s location-and-activity data especially).
The Proportionate Mindset
Calibrating the concern: the goal is deliberateness, not paranoia (the quantified-self benefits are real — the trends, the motivation, the zone coaching; the guide’s ask is thirty minutes of settings, not abandonment), the periodic re-audit (the annual privacy check-up alongside the checkup chapter’s health admin day — policies and defaults drift; the audit catches it), the minimal-viable-data option (the watch that syncs locally, the app fed only what it needs — the granularity most people never explore), and the principle worth keeping (health data is the most personal category there is — the same care given to bank passwords belongs to the archive of your heartbeats; deliberate beats default, every time). Track everything; share on purpose.
Privacy zones on, feeds audited, dead permissions revoked, share deliberately. The quantified self deserves a quantified audit — thirty minutes buys years of deliberate data.
Keep Reading
This article is for general informational and styling purposes only. Fit, sizing, and product availability may vary.