Můj Whoop
WHOOP and Oura Turn Your Body Into Data. What Are the Privacy Risks?

WHOOP and Oura Turn Your Body Into Data. What Are the Privacy Risks?

Inc.com warns about health data dangers from wearables. What does it mean for WHOOP and Oura Ring users? A practical breakdown.

Lukáš Beran5 min read
  • privacy
  • health data
  • oura
  • biohacking
  • whoop

Inc.com published an article yesterday about how wearables like WHOOP and Oura Ring transform the human body into a stream of data — and why that can be risky. As someone who's been wearing WHOOP for over two years and had an Oura Ring before that, it made me stop and think. Not about whether the trackers work (they do), but about what actually happens to my heart rate, sleep cycles, and heart rate variability (HRV) once they leave my wrist.

What Inc.com's Article Is About

The article draws on a theatrical performance called One Night Only, which dramatizes a scenario where intimate health data from wearables falls into the wrong hands. It's not science fiction. The author points to something concrete: health data from commercial trackers in the US is not protected by HIPAA, the law that shields data from doctors and hospitals. WHOOP and Oura aren't medical devices. They're consumer electronics. And the data they generate — resting heart rate (RHR), HRV, skin temperature, blood oxygen, sleep stages — falls under the companies' terms of service, not healthcare legislation.

That means your data protection depends primarily on what the company writes in its privacy policy. And whether you actually read it.

Where US Users Stand

Here's the thing: if you're in the US, you don't have the same legal shield that Europeans do. The US has no equivalent to GDPR. Health data from consumer wearables isn't automatically classified as "sensitive personal information" the way it is in Europe. Your protection depends on what WHOOP and Oura choose to offer — and what they're legally required to do under state laws, which vary.

If you're in Europe, you've got GDPR — a regulation that classifies health data as a "special category of personal data" with stricter protections. WHOOP and Oura have to respect GDPR for European users. That means:

  • They need a legal basis for processing your health data (typically your consent).
  • You have the right to access your data, export it, and request deletion.
  • They must inform you if they share data with third parties.

But GDPR protects you on paper. In practice, it's messier.

What WHOOP and Oura Actually Do With Your Data

I went through the current privacy policies of both companies. A few observations:

WHOOP says it collects physiological data, location data, device information, and app usage. Data can be shared with service providers (cloud, analytics) and used in anonymized form for research. WHOOP also lets you share data with coaches through WHOOP Teams — and that depends on who you grant access to.

Oura has a similar model. It collects biometric data, stores it in the cloud, and can use it in aggregated or anonymized form to improve the product.

Both companies claim they don't sell data to third parties for advertising. But "we don't sell" and "we don't share" are two different things. Anonymized data can be shared with partners — and the debate over how easily anonymized health data can be re-identified has been going on in the research community for years.

Three Concrete Risks Worth Thinking About

1. Your employer and insurance company. Mostly a US scenario, but not entirely far-fetched. If you share WHOOP data through Teams with a corporate wellness program, your employer sees your recovery score. Today that seems harmless. But what if someone wants to correlate your productivity with sleep quality?

2. Data breaches. No company is immune. WHOOP has had security incidents in the past (though not massive breaches). A database containing daily HRV, RHR, sleep patterns, and menstrual cycles from thousands of people is an attractive target for attackers.

3. Changing terms. Privacy policies change. Companies get acquired. The startup you trust today could be owned by a corporation with a completely different data policy in two years. Your 2024 data will still be in the cloud.

What You Can Actually Do About It

I'm not saying you should shove WHOOP in a drawer. I still wear mine — the value it gives me for training and sleep is real. But I do a few things deliberately:

  • I regularly check who I'm sharing data with. WHOOP Teams, connected apps, integrations. Anything I don't need, I disconnect.
  • I export my data locally. WHOOP lets you do this. I do it once a quarter. If the company disappeared tomorrow, I'd have my numbers.
  • I read privacy policy updates. Yeah, it's boring. But just scan the "What we share" and "Third parties" sections. Takes five minutes.
  • I don't use health data as public flex. Recovery score screenshots on Instagram are fine, but every post like that is a piece of your health profile out there on the internet.
Info

If you're in the EU, you have the right under GDPR to request a complete data export from WHOOP and Oura, and to request deletion. Just email their data protection contact — you'll find it in their privacy policy.

Conclusion Without the Panic

Inc.com's article isn't alarmist nonsense. It names a real problem: commercial wearables generate sensitive health data, and regulation lags behind the technology — especially in the US. In Europe, GDPR helps, but it's not an impenetrable shield.

Wearing WHOOP and thinking about where your data flows isn't paranoia. It's part of the same mindset that got you tracking your sleep and HRV in the first place. You want control over your body — so have control over the data flowing out of it too.

Want a WHOOP too?

Through my link you get the WHOOP hardware free + the first month of membership free. WHOOP rewards me with one month back. Win-win, costs you nothing extra.

Get WHOOP free →