{"id":16909,"date":"2019-11-17T10:45:03","date_gmt":"2019-11-17T18:45:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/11\/17\/news-10646\/"},"modified":"2019-11-17T10:45:03","modified_gmt":"2019-11-17T18:45:03","slug":"news-10646","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/11\/17\/news-10646\/","title":{"rendered":"How to Lock Down Your Health and Fitness Data"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5dcef56ea0ab490008bbf667\/master\/pass\/Security_data_6228-000821.jpg\"\/><\/p>\n<p><strong>Credit to Author: David Nield| Date: Sun, 17 Nov 2019 12:00:00 +0000<\/strong><\/p>\n<p class=\"content-header__row content-header__dek\">Apps like FitBit and Apple Health collect some of the most sensitive data you have. Here&#39;s how to control what they can see, and what they can do with it.<\/p>\n<p>Whether you&#x27;re a Fitbit user worried about <a href=\"https:\/\/www.wired.com\/story\/google-buys-fitbit-wearables-data-antitrust\/\">Google&#x27;s recent $2.1 billion purchase<\/a> of the company or just generally privacy conscious, you should pay attention to where your health and fitness data goes, and who has access. It&#x27;s among the most sensitive data you have.<\/p>\n<p>While you unfortunately can&#x27;t control where all of your health information goes\u2014as a <a href=\"https:\/\/www.wired.com\/story\/google-is-slurping-up-health-dataand-it-looks-totally-legal\/\">Google partnership with Ascension<\/a>, the nation&#x27;s second-largest health system, has unfortunately proved\u2014you can still dedicate a few minutes to health data audit, making sure your calorie burns and step counts are completely private. Or if not, that they&#x27;re only shared by choice.<\/p>\n<p>It shouldn&#x27;t take long, and it follows the same principles as any other data privacy audit: Check which data is being collected, which parts of it are public, and how many of your apps can access to it.<\/p>\n<p>We can&#x27;t cover every single fitness app out there, but these are the main players. If you&#x27;re using something else, you should be able to use a similar process to check what information is being logged and how it&#x27;s being used.<\/p>\n<p>Apple is <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.apple.com\/privacy\/features\/&quot;}\" href=\"https:\/\/www.apple.com\/privacy\/features\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">very keen<\/a> to emphasize how highly it prioritizes your privacy. Data in the Health app is encrypted both on your devices and on Apple&#x27;s servers, and if you <a href=\"https:\/\/www.wired.com\/story\/two-factor-authentication-apps-authy-google-authenticator\/\">have two-factor authentication turned on<\/a> for your account (which you should), not even Apple can look at the health logs you&#x27;ve built up.<\/p>\n<p>You can read Apple&#x27;s privacy policy <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.apple.com\/legal\/privacy\/en-ww\/&quot;}\" href=\"https:\/\/www.apple.com\/legal\/privacy\/en-ww\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">here<\/a> but you should also read the privacy policies of the various services you link up with Apple Health. To see which apps are currently connected to Apple Health, open the app on your device, tap your avatar in the top right corner, then choose <strong>Apps<\/strong> under <strong>Privacy<\/strong>.<\/p>\n<p>Note that the permissions on the next screen will be split up into write permissions\u2014the app can add data to Apple Health\u2014and read permissions, which means the the app can take and use data from Apple Health. You have the option to disable any permissions, to disconnect the app completely, and to fully delete all the data the app has collected\u2014at least in terms of what has been shared with Apple Health.<\/p>\n<p>Speaking of deleting data, pick <strong>Devices<\/strong> from the previous menu, then choose a device from the list, and you can erase everything Apple Health holds on you with a couple of taps. You can also delete individual records, rather than everything at once, by selecting the individual categories listed.<\/p>\n<p>The data you share with other people is something else to consider. If you&#x27;ve set up activity sharing with a friend through your Apple Watch and you&#x27;re no longer than friendly, you need to open the Watch app on your phone, then choose <strong>My Watch<\/strong> and <strong>Friends<\/strong>. Tap on the friends you no longer want to share your stats with to remove them.<\/p>\n<p>There&#x27;s no master setting to stop Apple Health collecting data from your devices once you&#x27;ve turned it on, but you can effectively stop it by blocking its access to the sensors in your phone. From iOS Settings, tap <strong>Privacy<\/strong>, then <strong>Motion &amp; Fitness<\/strong>, then turn off the <strong>Fitness Tracking<\/strong> option.<\/p>\n<p>Google&#x27;s rather lengthy privacy policy is available <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/policies.google.com\/privacy?hl=en-US&quot;}\" href=\"https:\/\/policies.google.com\/privacy?hl=en-US\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">here<\/a>, split into sections, and covering data collected with Google Fit. Again, also check the privacy policies of any apps you connect to Google Fit. There&#x27;s more on Google Fit specifically\u2014the data it collects and why\u2014available <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/support.google.com\/accounts\/answer\/6098255&quot;}\" href=\"https:\/\/support.google.com\/accounts\/answer\/6098255\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">here<\/a>.<\/p>\n<p>If you want to see the data Google Fit has on you, open up the Google Fit app on your Android phone. (If it&#x27;s not installed, nothing will have been collected.) Tap <strong>Profile<\/strong>, then the cog icon on the top right. On the next screen you can disable activity tracking and the location logging that goes along with it on two separate toggle switches.<\/p>\n<p>Tap <strong>Manage your data<\/strong> then <strong>Manage data<\/strong> to take a look at all the health and fitness data Google Fit has collected about you to date. Unfortunately you can&#x27;t view the data here\u2014you need to go back to the front of the app for that\u2014but you can erase data in any category such as heart rate or steps. To get rid of everything, tap Clear all data then confirm your choice.<\/p>\n<p>It&#x27;s also important to check which apps can write data to and read data from Google Fit. From the front of the settings menu, right after you tap the cog icon, select <strong>Manage connected apps<\/strong> to see all the apps that currently have permission to interact with Google Fit. Select an entry, then choose <strong>Disconnect<\/strong> to revoke these permissions.<\/p>\n<p>Google Fit doesn&#x27;t have much of a social aspect, or any kind of public profile, so you don&#x27;t have anything to worry about on that score. No one besides Google and your connected apps are going to be able to take a peek at your fitness stats unless they somehow get ahold of your phone.<\/p>\n<p>Unlike Apple Health, you can uninstall Google Fit from your phone if you want to make sure it&#x27;s not collecting any data on you. If you&#x27;re logging data from a connected Wear OS smartwatch and want to stop this from happening, meanwhile, open the Fit app, scroll down to <strong>Settings<\/strong>, then tap <strong>Sign out<\/strong>.<\/p>\n<p>It&#x27;s not yet clear exactly what Google&#x27;s acquisition of Fitbit means for your Fitbit or Google Fit data. But now you can open up the Fitbit app on your phone or Fitbit on the <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.fitbit.com\/&quot;}\" href=\"https:\/\/www.fitbit.com\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">web<\/a> to manage what it collects. You can read Fitbit&#x27;s current privacy policy <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.fitbit.com\/legal\/privacy&quot;}\" href=\"https:\/\/www.fitbit.com\/legal\/privacy\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">here<\/a>.<\/p>\n<p>If you use Fitbit, you have a profile page, which your friends can see if you connect up with them. In fact, anyone with a Fitbit account can see it, if they&#x27;re looking specifically for you. To manage what&#x27;s visible on this profile through the app, tap your avatar on the top left, then <strong>Privacy<\/strong>, then choose what&#x27;s public and what&#x27;s private.<\/p>\n<p>Back on the previous screen you can select <strong>Manage data<\/strong> to do just that: pick <strong>Manage third-party apps<\/strong>, and you can disconnect anything that&#x27;s been hooked up to Fitbit and that can access the health and fitness data that you&#x27;re logging.<\/p>\n<p>The other option here is <strong>Delete account<\/strong>, which, as you might expect, wipes everything you&#x27;ve ever done with Fitbit off the record, including from Fitbit&#x27;s servers. If you&#x27;re really worried about what Google might be planning in terms of data collection and targeted advertising, then this is one of the options you might be weighing up.<\/p>\n<p>You don&#x27;t get any options for restricting what Fitbit can track, or deleting just certain categories of data: it&#x27;s all or nothing. Once you&#x27;ve set up a Fitbit tracker or smartwatch, it&#x27;ll track everything unless you remove it from the Fitbit app entirely.<\/p>\n<p>Fitbit includes quite a few social features for challenging your friends and sharing your goals and achievements with other people. To manage the people you&#x27;re connected to\u2014and the people who can see the data you&#x27;re sharing)\u2014in the Fitbit app tap your avatar, then your name. From there you can remove or block friends.<\/p>\n<p>Like Fitbit, Strava encourages social sharing and community interaction, so you need to think about what other people can see in terms of your running routes and your daily step counts, as well as the information that Strava is gathering. You can view the full Strava privacy policy <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.strava.com\/legal\/privacy&quot;}\" href=\"https:\/\/www.strava.com\/legal\/privacy\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">here<\/a>.<\/p>\n<p>As soon as you open up the Strava app, you&#x27;ll see the <strong>Following<\/strong> tab, where you can manage the friends, colleagues, and random acquaintances who are keeping tabs on your activities in Strava. From the same screen you can stop these people from following you and block them from trying to follow you in the future.<\/p>\n<p>To change what your friends and other Strava users can see about you, open the Strava menu (three lines, top left), then tap <strong>Settings<\/strong>, then choose <strong>Privacy Controls<\/strong>. Here you can set viewing permissions for everything from your group activities to your profile page. There&#x27;s also the <strong>Privacy Zones<\/strong> option, which lets you set certain areas\u2014close to your home or place of work, for example\u2014where your activities aren&#x27;t logged.<\/p>\n<p>The controls we&#x27;ve mentioned let you set the default options for who can see your runs and cycles, but you can also tweak activities manually. Select a logged activity, then <strong>Edit<\/strong>, then <strong>Privacy Controls<\/strong> and you can hide it from other people, even those who are currently following you.<\/p>\n<p>There are a couple of other settings to check in Strava, which is relatively comprehensive when it comes to giving you privacy controls. From the <strong>Settings<\/strong> pane, tap <strong>Link Other Services<\/strong> to see third-party apps and devices with access to your account stats. You can remove them here, if needed. You can also select <strong>Data Permissions<\/strong> from <strong>Settings<\/strong> to limit the data Strava collects from your phone and your connected wearables.<\/p>\n<p>While individual activities can be deleted in Strava by opening them up and choosing the <strong>Delete<\/strong> button on the menu, you can&#x27;t really delete a whole lot of data very quickly using this method. Your only option when it comes to deleting all your Strava data is to close down your account. You need to log on to Strava on the web, then click <strong>Get Started<\/strong> under <strong>Download or Delete Your Account<\/strong>.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/health-fitness-data-privacy\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5dcef56ea0ab490008bbf667\/master\/pass\/Security_data_6228-000821.jpg\"\/><\/p>\n<p><strong>Credit to Author: David Nield| Date: Sun, 17 Nov 2019 12:00:00 +0000<\/strong><\/p>\n<p>Apps like FitBit and Apple Health collect some of the most sensitive data you have. Here&#8217;s how to control what they can see, and what they can do with it.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21382],"class_list":["post-16909","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-privacy"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16909","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16909"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16909\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16909"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16909"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16909"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}