← Health Devices
B

Apple Fitness+

Some concerns
Apple · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: Fitness
Manufacturer: Apple

The bottom line

Apple Fitness+ requires an Apple Watch. The Watch requires an iPhone. The ecosystem requires staying in the ecosystem. Your five years of workout data, heart rate trends, and fitness history become golden handcuffs. Apple keeps your health data private — from everyone except Apple, who uses it to ensure you never leave.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Spying
0/4 N/A
Is someone spying on me?
Data Sharing
0/4 N/A
Who gets my data?
Security
0/4 N/A
Is it actually secure?
Honesty
1/4 LOW
Can I trust what they say?
OK Minor or no concerns found.
1Contradictions
0Critical
0High
1Medium
3Sources
Findings by concern
Honesty 1/4 LOW 1 finding
⚫ mediummarketing vs third party research
Apple Fitness+ requires an Apple Watch. The Watch requires an iPhone. The ecosystem requires staying in the ecosystem. Your five years of workout data, heart rate trends, and fitness history become golden handcuffs. Apple keeps your health data private — from everyone except Apple, who uses it to ensure you never leave.

What they claim: Apple Fitness+ promotes private, on-device health tracking that stays with you

What we found: Apple Fitness+ requires an Apple Watch, locking users into a $400+ hardware purchase plus $10/month subscription. While Apple's health data practices are better than competitors, Fitness+ creates deep ecosystem lock-in: workout history, health trends, and fitness data become reasons to stay in Apple's ecosystem. Switching to Android means losing years of health data and workout history.

What happened to real people
Documented incidents involving Apple products and user data.
PRISM participant since 2012. Apple dropped full iCloud E2EE plans (codenamed Plesio/KeyDrop) after FBI objections (Reuters 2020). Advanced Data Protection released 2022 as opt-in with deliberate friction. [source]
Apple handed over iCloud backups in 1,568 cases covering ~6,000 accounts. 90% compliance rate. Surveillance firm: 'If you did something bad, I bet I could find it on that backup.' [source]
Government requests for push notification metadata rose from 158 (H1 2023) to 277 (H1 2024). Push tokens can identify devices and link to accounts. [source]
What your data is worth to governments
Apple complied with 12,043 government data requests in H1 2024. That's +621% over 10 years. Apple has been a confirmed PRISM participant since 2012. Under this programme, the NSA collects stored communications. The company is legally prohibited from telling you. Jurisdiction: US (CLOUD Act, FISA Section 702).
Documented: PRISM participant since 2012. Apple dropped full iCloud E2EE plans (codenamed Plesio/KeyDrop) after FBI objections (Reuters 2020). Advanced Data Protection released 2022 as opt-in with deliberate friction.
Documented: Apple handed over iCloud backups in 1,568 cases covering ~6,000 accounts. 90% compliance rate. Surveillance firm: 'If you did something bad, I bet I could find it on that backup.'
What is PRISM? · What is the CLOUD Act? · Transparency report
Sources