The Privacy Cost of Sleep Tracking: What Each Device Sends to the Cloud
Dovy Paukstys
Founder, Komori Care

The Thing Nobody Tells You First
Your sleep tracker is not a medical device, and your sleep data is not protected by HIPAA. Most people assume the same federal law that covers a hospital chart covers the biometrics flowing off their wrist every night. It doesn't. HIPAA only applies to "covered entities" (doctors, hospitals, health plans) and their business associates. A direct-to-consumer sleep tracker is neither, which means the privacy of your sleep data is whatever the company's privacy policy says it is, on the day you read it.
That's the legal reality, and the U.S. Department of Health and Human Services says so plainly. The follow-up matters: if there's no federal law forcing a sleep tracker to keep your data private, the only thing between your bedroom data and an ad network is the company's word and the FTC's Health Breach Notification Rule, which was updated in 2024 to cover non-HIPAA health apps.
This post walks through what every major sleep tracker collects, where it lives, and what each company is allowed to do with it. The privacy policies linked here are primary sources. Read them yourself if anything matters to you.
Key facts
- HIPAA only covers data held by healthcare providers, health plans, and their business associates. Consumer wearables are almost always outside HIPAA's scope.
- The FTC's updated Health Breach Notification Rule (in effect July 2024) now applies to most consumer health apps and connected wellness devices.
- The FTC has fined BetterHelp $7.8M and GoodRx $1.5M for sharing health data with advertisers.
- Garmin's services were knocked offline for days in 2020 by a ransomware attack reportedly settled for around $10M.
- Strava's 2018 global heatmap accidentally outlined U.S. military bases in Iraq, Syria, and Afghanistan from aggregate fitness data.
- A 2025 class action alleges Whoop shared sensitive health information with a third-party tracker without proper consent.
The HIPAA Gap, in Plain English
HIPAA governs Protected Health Information held by covered entities and their business associates. If your sleep tracker company is neither, HIPAA simply does not regulate what they do with your data. Not a loophole. That's the design.
A law-firm summary of HHS's own FAQs is blunt: most fitness, wellness, and consumer health apps are not covered by HIPAA at all. State laws (California's CPRA, Washington's My Health My Data Act, Connecticut's data privacy law), the FTC, and each company's own promises do all the actual work.
So when a sleep tracker says "we take your privacy seriously," the operative phrase is usually buried in the policy: "we may share de-identified data with third parties." De-identified health data is not regulated. It can be sold, combined with other datasets, and re-identified more easily than companies admit.
With that framing, here's what each device actually does.
Oura Ring
What it collects: Heart rate, heart rate variability, body temperature, movement, sleep stages, plus account info, location, and any data you log manually. Source: Oura Privacy Policy.
Where it goes: Cloud servers operated by Oura, a Finland-headquartered company. The policy notes data may be processed on servers outside your home country. Oura says it encrypts data in transit. Encryption at rest is referenced in general terms but not spelled out per data type.
Third parties: Oura's policy explicitly states it does not sell or rent personal information and does not share Service data with third-party advertisers. Website usage data does flow to ad partners. Oura has a separate program with the U.S. Department of Defense that keeps DOD-employee data on a separate platform, which is voluntary for participants.
Notable: Mozilla's Privacy Not Included review rates Oura among the better wearable privacy stories. Oura also publicly committed after Dobbs to oppose law-enforcement requests for reproductive health data.
HIPAA-covered? No. Oura is a consumer wellness device.
Apple Watch and Apple Health
What it collects: Heart rate, HRV, blood oxygen, respiratory rate, wrist-derived sleep stages, plus anything third-party apps push into HealthKit.
Where it goes: By default, Health data lives on your iPhone and Watch, encrypted with your passcode. With iCloud sync and two-factor authentication, Apple's Health privacy page states Health data is end-to-end encrypted, meaning even Apple cannot read it. Apple's overall privacy approach emphasizes on-device processing.
Third parties: Apps connected to HealthKit see only what you explicitly authorize. Apple's business model isn't ad-funded the way Google's is, which materially changes the incentives.
Notable: Apple is the closest thing the industry has to "privacy by default," with one caveat: third-party HealthKit apps are bound by their own policies, and a 2023 Washington Post review found many shared more than users expected.
HIPAA-covered? Apple is not a covered entity. Health data shared with a provider through Health Records is HIPAA-covered only because the provider is the covered entity.
Whoop
What it collects: Continuous heart rate, HRV, skin temperature, respiratory rate, sleep, "strain," and self-reported lifestyle data. Source: Whoop Privacy Policy.
Where it goes: U.S. cloud infrastructure. Whoop uses standard safeguards and acknowledges no security is failsafe.
Third parties: Whoop says it does not sell personal data and carves out advertising-partner sharing via cookies and analytics. De-identified data is shared more broadly. A 2025 class action alleges Whoop shared sensitive health info with a third-party tracker without proper consent. The suit is ongoing.
Notable: A peer-reviewed study clustered Whoop with the highest-risk privacy profile among 17 leading wearables. Whoop wants your data. Whoop's investors want your data more.
HIPAA-covered? No. Whoop's Consumer Health Data Privacy Notice explicitly states it is not a covered entity or business associate under HIPAA.
Fitbit (now Google)
What it collects: Steps, heart rate, sleep stages, SpO2, weight, location, plus anything third-party apps push in.
Where it goes: Google-operated infrastructure. The Fitbit privacy policy now redirects to Google, and Google's privacy policy applies.
Third parties: Fitbit's policy says "we never sell the personal information of our users." It also says data is shared with Google's corporate affiliates, service providers, and partners. As a European Commission antitrust condition of the 2021 acquisition, Google committed to not using Fitbit health and wellness data for Google ads, to keeping Fitbit data siloed from Google ads data, and to maintaining the commitment for 10 years.
Notable: The Fitbit/Google merger drew serious scrutiny from the U.S. DOJ and EU regulators specifically over health-data concentration. The 10-year commitment expires in 2031.
HIPAA-covered? No.
Eight Sleep
What it collects: Heart rate, respiratory rate, HRV, sleep stages, bed temperature, plus anything from connected wellness programs and Apple Health. Source: Eight Sleep Privacy Policy.
Where it goes: U.S. cloud, including MongoDB Cloud and Vercel per Eight Sleep's security overview. Data in transit and at rest is encrypted with TLS and AES-256.
Third parties: California disclosures acknowledge the company "sells and shares" certain categories of personal information with advertising partners under California's broad statutory definitions. Health metrics are not in that ad-targeting flow, but identifiers (name, email, IP) are. See the separate Consumer Health Data Privacy Policy.
Notable: In late 2023, Eight Sleep's CEO posted publicly about the volume of sleep data collected. The data exists. The company is open about that.
HIPAA-covered? No.
Withings
What it collects: From the Sleep mat: heart rate, respiratory rate, sleep stages, snoring, position. Source: Withings Privacy Policy.
Where it goes: Withings is French. Health data is processed in the European Union under GDPR. The policy states processed Health Data are not transferred outside EU territory, with specific exceptions for U.S. partners on features like ECG (Heartbeat Health).
Third parties: Withings says it does not share health information with advertising partners. Identifiers (name, email) may be shared with ad networks for non-health marketing. Pseudonymized data may be shared with research partners with consent.
Notable: Of the major consumer brands, Withings has the strongest formal data-residency story for U.S. customers who care about EU storage. GDPR compliance is the default.
HIPAA-covered? No (consumer wellness). Some Withings remote-patient-monitoring services follow the healthcare provider's privacy policy, which can be HIPAA-bound.
Garmin
What it collects: Sleep, HRV, stress, "body battery," workouts, GPS routes. Source: Garmin Connect Privacy Policy.
Where it goes: Garmin-operated cloud infrastructure. The policy describes encryption in transit and reasonable security measures.
Third parties: Garmin states it does not share personal information for advertising purposes with third parties without user consent. Sharing only happens when users connect external services (Strava, MyFitnessPal). Garmin's app, per its App Store privacy disclosures, shows no third-party tracking designation.
Notable: In July 2020, Garmin's services were taken offline for days by a WastedLocker ransomware attack attributed to Evil Corp. Garmin said it had no indication customer data was accessed, and many security researchers pointed out that's not the same as confirming none was. Garmin reportedly paid around $10M to recover its systems.
HIPAA-covered? No.
Samsung Health
What it collects: Steps, heart rate, sleep, SpO2, body composition (with compatible scales). Source: Samsung Health Privacy Notice.
Where it goes: Samsung's global cloud. Storage region varies by user location.
Third parties: The parent policy describes sharing with "service providers, business partners, and affiliated companies" and uses analytics and ad partners across product lines. Samsung Health's carve-outs are narrower than the parent policy.
HIPAA-covered? No.
Comparison Table
| Device | Local-only mode? | Cloud encryption | Health data shared with advertisers? | HIPAA-covered? | Sells de-identified data? | Notable incidents |
|---|---|---|---|---|---|---|
| Oura Ring | No | In transit; at rest unspecified per type | No (per policy) | No | De-identified research sharing | DOD program |
| Apple Watch | Yes (no iCloud Health) | End-to-end with iCloud + 2FA | No (non-ad business model) | No | No | Third-party HealthKit apps vary |
| Whoop | No | Standard TLS | Indirect via tracking partners (alleged) | No | Yes, de-identified | 2025 health-tracking class action |
| Fitbit / Google | No | Standard TLS | Not for Google ads (10-yr EU commitment) | No | Yes, de-identified | 2021 merger antitrust review |
| Eight Sleep | No | TLS + AES-256 | Identifiers yes, health no | No | "Sells and shares" per CCPA | None major |
| Withings | No | Standard TLS, EU residency | No | No (consumer) | Pseudonymized research | Strong GDPR posture |
| Garmin | No | Standard TLS | No (per policy) | No | No (per policy) | 2020 WastedLocker ransomware; 2018 Strava-style heatmap concerns adjacent |
| Samsung Health | No | Standard TLS | Varies by partner | No | Yes, common practice | None major specific to Health |
Pre-launch — what Komori is being built toward (Q1 2027)
Komori is in development. The privacy design intent (subject to engineering verification before launch) is:
- Bedside placement only (no wearable, no body contact)
- No optical camera — radar and ambient sensors only
- On-device microphones (InvenSense ICS-43434 MEMS) that only record audio features — sound events (snoring, coughing, alarms) are classified locally, and raw audio is not kept anywhere unless the user explicitly asks for it
- Local-first processing with opt-in cloud sync
- TLS in transit, AES at rest for any data that does sync to cloud
These are privacy-architecture commitments under engineering verification, not consumer-claimable features today. Komori is not FDA-cleared. The wellness-pathway dialogue with FDA is in progress.
What Komori Does, and What We Won't
We're building a contactless bedside monitor. No camera. No wearable. On-device microphones (InvenSense ICS-43434 MEMS) only record audio features — sound events (snoring, coughing, alarms) are classified locally, and raw audio is not kept anywhere unless the user explicitly asks for it. The unit is a radar sensor on your nightstand and a base station that does the heavy processing on-device.
Komori is being designed so that default behavior is local — by design, nothing leaves your home unless you opt in. The base station processes radar signals, extracts position, breathing, and movement, and stores summary data on the device.
Cloud sync will be opt-in. If you want multiple phones, caregiver sharing, or research participation, you turn on encrypted cloud sync. The architecture uses TLS 1.3 in transit and AES-256 at rest. Users will be able to turn cloud sync off and delete cloud data at any time.
We will not sell data — not de-identified, not aggregated. Not to advertisers. Not to data brokers. Not to insurers. The business model is selling hardware and an optional subscription, not selling you.
We are not HIPAA-covered. Komori is a General Wellness device with no FDA clearance. It is not a medical device and is not intended to diagnose, treat, prevent, or cure any condition. If a healthcare provider deploys Komori as part of a clinical program, the data flowing to that provider is HIPAA-covered, because the provider is the covered entity. That's the only path where HIPAA applies, and it's the right one.
What we'd never do: sell data to advertisers, share identified health metrics with third parties without consent, run an ad network on top of your sleep, or train models on your data without consent. These aren't policy hedges. They are commitments we're building into the product.
Read the Komori privacy approach for the full version. If we ever change it, we'll say so on the record, and you'll be able to delete everything first.
What to Look For in Any Sleep Tracker
A short list of questions before you bring any sleep tracker into your bedroom:
- Is there a local-only mode? If not, every byte leaves your home. That's a choice. Make it knowingly.
- Is health data end-to-end encrypted, or just TLS? TLS protects data on the wire. End-to-end encryption means even the company can't read it. Most trackers don't do the second one.
- Does the policy carve out de-identified data? Almost always yes. Read what they're allowed to do with it.
- What's the business model? If ads or data licensing fund the product, your data is part of the product.
- What happened in the last breach? Garmin 2020 and Strava 2018 weren't malicious sales of data. They showed how much gets collected and how concentrated the risk is.
- Does the company commit to resisting law-enforcement requests? Few do. Oura and Apple are exceptions.
A Clear-Eyed Take
Most sleep trackers are not lying when they say they take privacy seriously. Most also collect more than you think, store it on U.S. cloud infrastructure outside HIPAA, and reserve the right to share de-identified versions broadly. None of that is hidden. It's in the policies. It just isn't in the marketing.
If you want minimum data leaving your bedroom, look for products that do real work locally and treat cloud as opt-in. If you're already on Apple's stack, Health with iCloud end-to-end encryption is the strongest mainstream story. Among wrist-worn options, Garmin's no-tracking posture and Withings' EU residency are next-best. If you want a contactless option that doesn't require a wrist or finger, and whose on-device microphones only record audio features (raw audio not kept unless you explicitly ask), that's where we live.
For more, see a bedside monitor without a camera and how it compares with an Apple Watch.
Read the policies. Pick the tradeoff you can live with. Then sleep.
Sources and primary policies referenced
- Oura Privacy Policy
- Whoop Full Privacy Policy and Whoop Privacy Center
- Apple Health App Privacy and Apple Health Data Storage
- Fitbit Privacy Policy via Google
- Eight Sleep Privacy Policy and Consumer Health Data Privacy Policy
- Withings Privacy Policy
- Garmin Connect Privacy Policy
- Samsung Privacy Notice
- HHS HIPAA FAQs on Covered Entities
- FTC Health Breach Notification Rule, 2024 update
- FTC vs. BetterHelp settlement
- FTC vs. GoodRx settlement
- Mozilla Privacy Not Included: Oura Ring
- TechCrunch: Garmin confirms ransomware attack
- CNN: Strava heatmap exposed military bases
- Milberg: Whoop health privacy lawsuit
- Athletech News: Wearables and HIPAA scope
Want updates on Komori?
Join the waitlist — free. No spam, just launch updates and sleep insights.
Want to see your sleep position data?
Get the Insider Pass and be first to experience Komori when it ships.


