← IoT Privacy Database

MyFitnessPal

MyFitnessPal, Inc. · Wearable / Fitness Tracker

✓ Reviewed

2.9Surveillance
Index
Policy — what its policy permitsD
Evidence — what research provesB

MyFitnessPal logs what you eat, your weight and body measurements, exercise and calorie goals, building a detailed picture of diet, health status and behavior patterns. It uses the camera for barcode scanning and links to other fitness services. As an ad-supported app it shares data with advertising and analytics partners, and its account credentials were part of one of the largest breaches on record.

Why this rating

Deductions: collects health, weight and dietary data (-15); as an ad-supported service it shares data with advertising/analytics partners, meeting the sale/targeted-advertising bar (-25); vague retention and processing language (-7). Evidence: the single cited incident is the 2018 breach of ~150M accounts, now more than five years old and weighted at reduced severity; a 2026 tracking-cookie class action (Wiley & Shah v. MyFitnessPal) survived a motion to dismiss but is not yet certified or settled, so it is noted for context rather than counted.

What it is

Manufacturer
MyFitnessPal, Inc.
Category
Wearable / Fitness Tracker
Model years
2005-present
Market status
Current
Companion app
MyFitnessPal

The evidence 1

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Breach report · CNBC · 2018-03

    A February 2018 breach exposed usernames, email addresses and hashed passwords for roughly 150 million MyFitnessPal accounts — one of the largest breaches of that year.

    Why it matters here: Direct breach of this service's user base; older than five years and largely resolved, so weighted at reduced severity.

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database