A heatmap that mapped secret military bases
In January 2018, Strava’s global heatmap — a visualization built from aggregated GPS data — became a case study in how fitness data leaks location. A student, Nathan Ruser, noticed that in Iraq and Syria its bright trails traced otherwise unmarked military installations, disclosing “locations and routines of military installations and personnel,” down to features like walking paths and a helicopter pad (The New York Times).
Reuters reported that “the heat-map revelations prompted the U.S. Defense Department, which encourages personnel to limit their internet presence, to review security protocols” (Reuters). U.S. Central Command said it was “in the process of implementing refined guidance on privacy settings for wireless technologies and applications,” and Strava’s “enhanced privacy” option hadn’t stopped some users from feeding the public heatmap (TechCrunch).
The same mechanism that outlined a base at global scale can outline a house at neighborhood scale, and combined with a public feed, a person’s routine.
What the heatmap includes today, and how to lock it down
Strava’s documentation describes the Global Heatmap as “aggregated, de-identified activity data,” updated monthly, excluding activities not set to visibility “Everyone,” any hidden map portion, and activity from athletes who’ve opted out (Strava Support). A Weekly Heatmap, limited to the past seven days and subscriber-only, follows the same rules (Strava Support). Strava’s default visibility for new accounts isn’t documented on these pages — check your own Privacy Controls rather than assume a default. Three settings govern exposure:
Activity privacy controls who sees a workout at all. Under Settings → Privacy Controls, choose “Everyone,” “Followers,” or “Only You” as your default, with per-activity overrides (Strava Support). With “Everyone” selected, the activity “will contribute to Strava Metro and the Global Heatmap by default” and appears on public leaderboards, where others can navigate straight to your profile (Strava Support).
Map visibility (privacy zones) hides only a portion of the map from anyone who can otherwise see the activity: hide the start/end near a chosen address (one-mile radius; past and future), hide the start/end of every activity, or hide an entire map — the last two apply only going forward (Strava Support). Strava is explicit this isn’t a guarantee: “Applying Map Visibility settings to your activity does not mean it would be impossible for someone to deduce a hidden location using additional information,” and these settings “are not shared to other services along with your activities” (Strava Support). Hidden segment times still get matched internally but aren’t shown on leaderboards (Strava Support).
Aggregated data / heatmap opt-out keeps your activity out of the Global and Weekly Heatmaps specifically, separate from who can see the activity itself (Strava Support). A reasonable order: set default privacy to “Followers” or “Only You,” add a privacy zone regardless, and opt out of aggregated data if you don’t want to appear even de-identified.
Apple Watch: what “Sharing” actually shows
Apple’s Fitness app lets you share Activity rings with people you invite. Apple’s guide states sharing shows “highlights of your friends’ activity — like workouts they’ve finished or goals they’ve met,” their “activity rings for the last 7 days,” and a summary of completed activities, with notifications when a friend finishes a workout or meets a goal (Apple Support). It’s invite-based; someone must accept before seeing anything. To stop it: open Fitness, tap Sharing, tap the friend, and choose “Mute Notifications,” “Hide My Activity,” or “Remove Friend” (Apple Support). Apple’s documentation doesn’t say whether the other person is notified by either action — treat that as unknown.
Garmin LiveTrack: real-time location, sent to whoever you invite
Garmin Connect’s LiveTrack feature shares a live map of your activity by email link, “so friends and family can follow along,” including location, pace, elapsed time, distance, and elevation gain (Garmin Support). Some devices support “Auto Start,” launching LiveTrack automatically whenever a compatible outdoor activity begins (Garmin Support).
Two behaviors worth knowing, both documented on the same page: “Extend LiveTrack” keeps a session visible 24 hours after it ends, and pausing (rather than stopping) an activity means LiveTrack “continues updating your location and sharing it with followers until the activity is saved or discarded” (Garmin Support). Garmin doesn’t say whether recipients are notified when a session ends, or whether an account is needed to view a shared link — treat both as unconfirmed. To opt out: Garmin Connect app → LiveTrack → Data & Privacy → Opt Out (Garmin Support).
This is distinct from LiveTrack on Garmin’s inReach satellite communicators, a separate page with its own privacy tiers (Garmin Support) — inReach owners shouldn’t assume Connect settings cover it.
Kids’ smartwatches: when the safety device is the vulnerability
Smartwatches marketed for tracking young children carry a different risk: the flaws aren’t a setting — they’re built in.
In October 2017, the Norwegian Consumer Council (Forbrukerrådet) published #WatchOut, testing four children’s smartwatches — Gator 2, Tinitell, Viksfjord, and Xplora — with a technical assessment by cybersecurity firm Mnemonic (Forbrukerrådet). The report found “critical security flaws in three of the apps and devices,” with two containing flaws that “could allow a potential attacker to take control of the apps, thus gaining access to children’s real-time and historical location and personal details, as well as even enabling them to contact the children directly, all without the parents’ knowledge” (#WatchOut report). Several devices transmitted personal data abroad “in some cases without any encryption in place,” and one watch “functions as a listening device, allowing the parent or a stranger with some technical knowledge to audio monitor the surroundings of the child without any clear indication on the physical watch that this is taking place” (#WatchOut report).
Advertised safety features weren’t reliable: one watch’s SOS button “was found to be unreliable” during testing (#WatchOut report). On consumer rights, “only one of the services actually asks for consent to data collection, none of them promise to notify users of any changes to their terms, and there is no way to delete user accounts from any of the services” (#WatchOut report). BEUC summarized it plainly: “Strangers can easily seize control of the watches and use them to track and eavesdrop on children” (BEUC).
The pattern wasn’t limited to those four watches. In February 2019, the European Commission recalled a different smartwatch, the Enox Safe-KID-One, an unusual step over data and security risk, per The Guardian. Per the Commission’s alert as reported, “The data such as location history, phone numbers, serial number can easily be retrieved and changed,” and “A malicious user can send commands to any watch making it call another number of his choosing, can communicate with the child wearing the device or locate the child through GPS” (The Guardian).
The named models were recalled or discontinued — not a claim about every tracking watch today. But a device built around real-time child location and audio deserves the same scrutiny as any connected device, not less, for being a safety product.
Auditing your own setup
Check your default activity or session visibility — defaults apply going forward, not to what’s already uploaded.
Add a privacy zone around home and work, even on a followers-only feed — a leaderboard entry or changed follower list can expose an endpoint your setting doesn’t cover.
Review who’s receiving your live location — Apple Sharing friends, Garmin LiveTrack recipients — the way you’d review who has access to your shared location elsewhere. These lists accumulate over years; an ex or former workout partner may still be receiving data.
Turn off auto-start for live-tracking if you want sharing to be deliberate, and remember a paused session may keep sharing location.
For kids’ devices, read the privacy policy before buying, look for independent security reporting on the model, and check for a recall before assuming “made for kids” means “reviewed for security.”
If a feed or follower list is already exposing more than intended, social media lockdown covers that ground.