Helix

Does WHOOP sell your data?

The short answer is no, and the useful answer is longer, because what a privacy policy permits and what a company currently does are different questions. What to read, and the clauses that matter.

Updated August 8, 20269 min readWritten by Reviewed by Daniel Okonkwo

The short answer is no. WHOOP sells memberships, and a company charging $239 a year has considerably less incentive to monetise data than a free app does. That is the honest headline and it is also where most articles on this stop, which is a shame, because it is the least interesting part.

Why “do they sell it” is the wrong question

“Sell” is a narrow word and privacy policies are written by people who know that. A company can accurately say it does not sell your data while sharing it with service providers, using de-identified aggregates commercially, disclosing it under legal process, and transferring it wholesale in an acquisition.

None of that is sinister and all of it is standard. But it means the useful question is not what the marketing page says. It is what the privacy policy permits, because the policy is the thing that binds and the practice can change without your involvement.

The HIPAA misconception

A lot of people assume health data is health data and therefore protected. It is not. HIPAA applies to healthcare providers, insurers and their business associates. A company that sold you a fitness membership is generally none of those.

So your continuous heart rate, sleep and HRV history has roughly the legal standing of your shopping history, not your medical record. That is true of WHOOP, Oura, Fitbit and every consumer wearable, and it is worth internalising once rather than assuming otherwise.

What actually protects you, where you live in the right place, is general data protection law rather than health law: the GDPR in the EU and UK, the CCPA in California. Those give you access, deletion and portability rights that apply regardless of what the policy says.

The acquisition clause

This is the one worth caring about. Consumer privacy policies almost universally treat customer data as an asset transferable in a merger, acquisition or bankruptcy.

The practical implication: your judgement about whether to trust WHOOP with years of biometric data is a judgement about WHOOP today, and the data may outlive that company in someone else’s hands. If that bothers you, the mitigation is not choosing a nicer vendor. It is holding less data with anyone, or holding it yourself.

What you can actually do

Export a copy. Your data being useful to you does not depend on the company continuing to exist: how to export your WHOOP data.

Delete rather than just cancel, if the holding is what bothers you. Cancelling stops the billing and keeps the data: how to delete your WHOOP account.

Check the sharing settings for team and group features. Data you shared with a coach or a team is a separate grant from the one you gave the company.

Prefer architectures that hold less. A product that never uploads your biometrics has nothing to sell, nothing to breach and nothing to transfer in an acquisition. That is a structural answer rather than a promise.

For the ring equivalent of this question, the same four clauses apply: see how to delete your Oura account.

Frequently asked questions

Does WHOOP sell your data?

WHOOP's business is memberships, not data brokerage, and it does not present itself as selling personal biometric data to third parties. The more useful question is what its privacy policy permits, because policies grant broader latitude than a company's current practice, and the policy is what binds.

Who can see my WHOOP data?

You, WHOOP itself, its service providers, anyone you have deliberately shared with such as a team or coach through a group feature, and anyone acquiring the company. That last category is the one people forget and it is in almost every consumer health policy.

Is WHOOP data covered by HIPAA?

Generally no. HIPAA covers healthcare providers, insurers and their business associates. A consumer wearable company you bought a membership from is usually none of those, so your biometric data sits outside the protection people assume it has.

What happens to my data if WHOOP is acquired?

Standard privacy policies treat customer data as a transferable business asset in a merger or acquisition. That means the entity holding your history could change without you doing anything, which is the single most underrated clause in this category.

How do I stop WHOOP holding my data?

Cancelling does not delete anything. You need to request account deletion, and in the EU, UK and California you have a statutory right to erasure that is stronger than whatever the app exposes. Export first if you want a copy.

Keep reading

All posts →