← Wearables
D

Watch Series 9

Serious concerns
Apple · 🇺🇸 United States · Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
FCC ID: BCG-A2978
Chipset: Apple S9 SiP
App: com.apple.Bridge
Manufacturer: Apple

⚠️ The bottom line

Apple says your health data is encrypted so even they can't read it. But their own law enforcement guidelines show they can hand over iCloud backup data — which can include health records — to police with a court order. Most users don't enable the extra 'Advanced Data Protection' setting that actually makes this end-to-end encrypted. Apple approved 93% of government data requests. Apple says its Watch has top-tier security with advanced encryption and on-device processing. But government-grade spyware called Pegasus has already been used to break into Apple Watches without the owner even touching their device — just receiving a specially crafted iMessage was enough. More spy-grade vulnerabilities were found being exploited in 2025. If surveillance companies can break in, so might others.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Spying
3/4 HIGH
Is someone spying on me?
Data Sharing
4/4 EXTREME
Who gets my data?
Security
4/4 EXTREME
Is it actually secure?
Honesty
2/4 MODERATE
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
10Contradictions
2Critical
5High
3Medium
6Sources
Findings by concern
Spying 3/4 HIGH 3 findings
⚠️ criticalfirmware analysis vs regulatory findings
Apple says its Watch has top-tier security with advanced encryption and on-device processing. But government-grade spyware called Pegasus has already been used to break into Apple Watches without the owner even touching their device — just receiving a specially crafted iMessage was enough. More spy-grade vulnerabilities were found being exploited in 2025. If surveillance companies can break in, so might others.

What they claim: Apple Watch Series 9 contains advanced security features including the S9 SiP with Neural Engine for on-device processing and encrypted data handling.

What we found: Despite Apple's security architecture, the Apple Watch has been successfully targeted by NSO Group's Pegasus spyware via the BLASTPASS zero-click exploit chain (CVE-2023-41061 + CVE-2023-41064, both critical severity). Citizen Lab discovered this exploit could compromise fully-patched Apple Watch devices (watchOS before 9.6.2) without any user interaction via iMessage. Additional actively-exploited WebKit vulnerabilities in 2025 (CVE-2025-43529, CVE-2025-14174) demonstrate ongoing susceptibility to sophisticated surveillance attacks.

⚡ highapp permissions vs policy claims
The Apple Watch app has permission to access your heartbeat, blood oxygen, body temperature, menstrual cycle, ECG readings, crash detection, fall detection, and your exact location at all times. That's the most intimate data any consumer device collects. Apple says they don't sell it, but this data is on Apple's servers and can be handed to police. Any watchOS app you install can also ask for bits of this data.

What they claim: Apple Watch companion app (built into iOS) requests access to extremely sensitive data categories: HEALTH_RECORDS, HEALTH_SHARE, HEART_RATE, BLOOD_OXYGEN, ECG, WRIST_TEMPERATURE, MENSTRUAL_CYCLE, SLEEP_ANALYSIS, FALL_DETECTION, CRASH_DETECTION, plus LOCATION_ALWAYS.

What we found: Apple's privacy policy states it processes health data on-device and doesn't sell personal data. However, the always-on location tracking (LOCATION_ALWAYS) combined with continuous health monitoring (heart rate every few minutes, wrist temperature, blood oxygen) creates an unprecedented surveillance dataset. While Apple claims not to sell this data, it flows through Apple's servers and is available to law enforcement. Third-party apps on watchOS can also request granular access to health data.

⚫ mediumfirmware analysis vs policy claims
Your Apple Watch tracks your location using five different satellite systems, records your exercise routes, monitors your health 24/7, and processes your payments through Apple Pay. Apple's privacy policy doesn't clearly explain how long they keep your location data or how the combination of your health, location, and payment data creates an extremely detailed picture of your life that could be handed to authorities.

What they claim: Apple Watch Series 9 includes NFC for Apple Pay and always-on location tracking (GPS/GNSS with L1 GPS, GLONASS, Galileo, BeiDou, QZSS) plus optional cellular connectivity.

What we found: Apple's privacy policy does not specifically disclose the scope of location data retention from Apple Watch. The device tracks precise location via five satellite navigation systems (GPS, GLONASS, Galileo, BeiDou, QZSS), records exercise routes, and combines this with always-on health monitoring. Emergency SOS and crash detection features require location sharing with emergency services, and Apple's policy permits data disclosure 'for purposes of national security, law enforcement, or other issues of public importance.' The combination of health + location + payment (Apple Pay) data creates a comprehensive surveillance profile.

Data Sharing 4/4 EXTREME 1 finding
⚫ mediumpolicy claims vs app permissions
Unlike most smart devices, Apple Watch has zero third-party trackers — that part is genuinely true. But Apple runs its own tracking through servers like 'health-evidence.apple.com.' It collects your app usage, crash data, and diagnostics. Apple's own tracking is on by default and most people never realize they need to opt out.

What they claim: Apple claims zero trackers in the Apple Watch companion system, contrasting with virtually all other smart device apps which contain multiple advertising and analytics trackers.

What we found: The Apple Watch iOS companion app (com.apple.Bridge) contains 0 third-party trackers — a genuine distinction from competitors. However, Apple's own first-party analytics (xp.apple.com, health-evidence.apple.com) serve similar functions to third-party trackers. Apple collects 'app launches, browsing history, search history, crash data, performance diagnostics' according to Mozilla's Privacy Not Included review. Apple's analytics are opt-out rather than opt-in, and most users don't know they exist.

Security 4/4 EXTREME 4 findings
⚠️ criticalpolicy claims vs regulatory findings
Apple says your health data is encrypted so even they can't read it. But their own law enforcement guidelines show they can hand over iCloud backup data — which can include health records — to police with a court order. Most users don't enable the extra 'Advanced Data Protection' setting that actually makes this end-to-end encrypted. Apple approved 93% of government data requests.

What they claim: Apple claims health data is end-to-end encrypted and 'not readable by anyone — even Apple.' Apple's privacy page states: 'Apple does not sell your personal data.'

What we found: Apple's own law enforcement guidelines (updated October 2025) confirm Apple can provide iCloud account data, iCloud backups, device registration details, and 'other data as required by law.' Health data stored in iCloud backups (without Advanced Data Protection enabled) is accessible to Apple and thus to law enforcement with valid legal process. Apple complied with 93% of government data requests in H2 2020. In 2022, Apple admitted providing user data to hackers who forged emergency law enforcement data requests.

⚡ highpolicy claims vs regulatory findings
Apple Watch tracks your menstrual cycle and promises encryption. But after the Supreme Court ended federal abortion rights, this data became legally dangerous. If you haven't turned on Apple's 'Advanced Data Protection' setting (most people haven't), police in states with abortion bans could potentially get a court order to access your period tracking data from Apple's servers.

What they claim: Apple markets the Apple Watch as a privacy-respecting health device with end-to-end encryption protecting sensitive data including menstrual cycle tracking.

What we found: After the Supreme Court's Dobbs v. Jackson decision (2022) ended federal abortion protections, menstrual cycle tracking data became legally sensitive. Apple's encryption protections depend on users enabling specific settings (passcode, two-factor authentication, Advanced Data Protection). Without Advanced Data Protection, iCloud-synced health data including menstrual cycle logs can be accessed by Apple and provided to law enforcement with valid legal process. In states where abortion is restricted, this data could theoretically be subpoenaed.

⚡ highregulatory findings vs app permissions
Apple says your health data is encrypted and safe. But in 2021, a company called GetHealth left over 61 million fitness records — including thousands from Apple Health — in an open database anyone could access. Once you share your Apple Watch data with any third-party app or service, Apple's security promises no longer protect you.

What they claim: Apple Watch health data is protected by Apple's encryption and not accessible to third parties.

What we found: In September 2021, GetHealth — a third-party health data aggregation company — exposed 61,053,956 fitness tracker records in an unsecured, password-free database, including 17,764 Apple HealthKit records in a limited sample. Exposed data included first/last names, dates of birth, weight, height, gender, and geolocation in plain text. This demonstrates that when users share Apple Watch health data with third-party apps and services, Apple's encryption guarantees no longer apply.

⚫ mediumpolicy claims vs regulatory findings
Apple's reputation as the privacy company is partly marketing. Mozilla Foundation — an independent nonprofit — rates Apple Watch as 'somewhat creepy' and says Apple's privacy track record 'needs improvement.' Apple has accidentally given user data to hackers pretending to be police, and millions of Apple Health records have leaked through third-party apps. The 'privacy-first' label doesn't mean your data is actually safe.

What they claim: Apple privacy policy states that health data shared with Apple is protected and Apple 'does not sell your personal data.'

What we found: Mozilla Foundation's Privacy Not Included review rates Apple Watch as 'somewhat creepy' and notes Apple's track record 'needs improvement.' Mozilla flags that Apple shares data with 'service providers, partners, developers, and publishers.' Mozilla also documents that Apple gave user data to hackers who faked being law enforcement in 2022, and notes the 2021 GetHealth breach of 61 million fitness records including Apple HealthKit data. Apple's security reputation is built on marketing rather than a flawless track record.

Honesty 2/4 MODERATE 2 findings
⚡ highpolicy claims vs regulatory findings
Apple says it processes your health data locally on your device for privacy. But through its Research app, Apple funnels your heart rate, menstrual cycle, sleep, and ECG data to universities and outside researchers. The details of who gets your data are buried in study consent forms, not in the main privacy policy most people read. Apple can also re-identify you from this 'de-identified' data.

What they claim: Apple positions itself as the privacy-first alternative for health wearables, stating it 'minimizes data collection by processing as much of your health data on your device as possible.'

What we found: The Apple Research app shares Apple Watch health data — including heart rate, activity, sleep, menstrual cycles, audio levels, and ECG readings — with third-party university and pharmaceutical researchers. Apple states 'certain third-party researchers who are approved may access limited Study Data.' The scope of approved researchers and data access is buried in study-specific informed consent documents, not in Apple's main privacy policy. Apple retains the ability to re-identify research participants.

⚡ highpolicy claims vs firmware analysis
Apple says your health data stays on your device, but the watch's software has built-in connections to a dozen Apple servers including one literally called 'health-evidence.apple.com.' Your heart rate, steps, and other health data flows to Apple's cloud servers by default. You'd have to dig into settings to turn this off, and most people never do.

What they claim: Apple claims health data processing happens on-device via the Neural Engine, minimizing data transmission to the cloud.

What we found: Firmware analysis reveals 12 hardcoded communication endpoints including health-evidence.apple.com, gateway.icloud.com, xp.apple.com, and configuration.apple.com. The Apple Watch continuously syncs health data to iPhone and then to iCloud by default. Heart rate is measured every few minutes at rest and every second during workouts. All this data flows through Apple's cloud infrastructure unless the user specifically disables iCloud Health sync — a setting most users never change.

What happened to real people
Documented incidents involving Apple products and user data.
PRISM participant since 2012. Apple dropped full iCloud E2EE plans (codenamed Plesio/KeyDrop) after FBI objections (Reuters 2020). Advanced Data Protection released 2022 as opt-in with deliberate friction. [source]
Apple handed over iCloud backups in 1,568 cases covering ~6,000 accounts. 90% compliance rate. Surveillance firm: 'If you did something bad, I bet I could find it on that backup.' [source]
Government requests for push notification metadata rose from 158 (H1 2023) to 277 (H1 2024). Push tokens can identify devices and link to accounts. [source]
What your data is worth to governments
Apple complied with 12,043 government data requests in H1 2024. That's +621% over 10 years. Apple has been a confirmed PRISM participant since 2012. Under this programme, the NSA collects stored communications. The company is legally prohibited from telling you. Jurisdiction: US (CLOUD Act, FISA Section 702).
Documented: PRISM participant since 2012. Apple dropped full iCloud E2EE plans (codenamed Plesio/KeyDrop) after FBI objections (Reuters 2020). Advanced Data Protection released 2022 as opt-in with deliberate friction.
Documented: Apple handed over iCloud backups in 1,568 cases covering ~6,000 accounts. 90% compliance rate. Surveillance firm: 'If you did something bad, I bet I could find it on that backup.'
What is PRISM? · What is the CLOUD Act? · Transparency report
Sources