Fitness levels leaked: what it means and what to do

Risk level: low. Can you change it: no. Found in 1 breaches in this directory.

What this data is

Your self-reported or tracked fitness level, workout history, step counts, heart rate trends and sometimes exercise routes, stored by gyms, fitness apps, wearables and dating apps.

The risk on its own

A fitness level on its own is low risk. It cannot log in to anything or prove who you are. Detailed tracking data is more personal, and heart rate or weight trends start to edge into health information.

The risk combined with other data

The real concern is location. Workout routes that start and end at the same point usually reveal a home address, and regular session times reveal when you are out. Paired with your name, that helps a stalker or burglar. Health trends can also feed insurance and marketing profiles.

How criminals use it

  • Someone uses the start point of your regular running route to find where you live.
  • Your gym check-in times show when your home is empty each week.
  • Weight and heart rate data are used to target you with fake supplements and health products.

What to do now

  1. Hide the start and end of your activities in apps that support it, such as the Map Visibility settings in Strava.
  2. Make activity feeds and routes visible to approved followers only, or to you only.
  3. Change the password on the fitness or gym account and remove third party app connections you no longer use.
  4. Delete old workouts with routes that begin at your home if you do not need them.

Frequently asked questions

Is my fitness level sensitive?

Not really on its own. The routes, locations and health measurements from trackers are the parts worth protecting.

Can workout routes reveal my address?

Yes. Routes that start and finish at the same spot often mark a home. Hiding the start and end of each activity removes that clue.

Is wearable data health information?

Some of it can be, such as heart rate or sleep data, although in many countries fitness apps are not covered by health privacy law the way doctors are.

Breaches that exposed this data

  • Mate1.com: 2016-02-29, 27M accounts, Astrological signs, Dates of birth, Drinking habits, Drug habits, Education levels, Email addresses

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.