Fitbit Public P: Intuitive Health Tracking Tool Fitbit
Software
April 10, 2026 5 min read

Fitbit Public Preview Review: Intuitive Health Tracking Tool

3.2 /5 Mixed Result
3.2 / 5.0 average
Recommended
Quick Verdict

Fitbit is a capable consumer health tracker, but from a data privacy and enterprise security perspective, it is one of the riskiest wearable platforms available in 2026. Following Google's full acquisition and mandatory account migration, users of Fitbit now have their biometric health data governed by Google's broader privacy policy — a significant concern for IT security teams and compliance officers. For individuals seeking a fitness tracker reviewed from a cybersecurity lens, read our wearable device security guide on NetworkUstad.com before committing to this platform.

Key Features
Continuous heart rate monitoring with Google Pixel Watch-derived ML algorithms (Charge 6)
ECG and EDA (Electrodermal Activity) stress monitoring (Sense 2 and Charge 6)
SpO2 blood oxygen saturation tracking
Built-in GPS and GLONASS (Charge 6 and Sense 2)
40+ exercise modes with auto-recognition
Google Health app integration with unified account privacy controls
Sleep tracking with Sleep Score and skin temperature sensing
Fitbit Premium subscription for advanced health insights and trend reports
Google Wallet, Google Maps, and YouTube Music (Sense 2 / Charge 6)
7-day battery life (Charge 6) / 6-day battery life (Sense 2)
Technical Specifications
Display (Charge 6) 1.04-inch AMOLED, 450 nits
Display (Sense 2) 1.58-inch AMOLED, 1000 nits, 336u00d7336px
Battery Life 7 days (Charge 6) / 6+ days (Sense 2)
Water Resistance 50m swim-proof
Connectivity Bluetooth LE, NFC (Google Wallet)
Sensors HR, SpO2, ECG, EDA, skin temp, accelerometer, altimeter (Sense 2), GPS/GLONASS
App Compatibility iOS 16.4+ / Android 11.0+ (Google Health app required)
Data Storage (on-device) 7 days detailed motion data, 30 days daily totals
Heart Rate Storage 1-second intervals during exercise, 5-second intervals at rest
Price (MSRP) $159.95 (Charge 6) / $299.95 (Sense 2)
Score Breakdown
3.2/5
Health Data Privacy
2.5
GDPR & Regulatory Compliance
3.0
Enterprise Security Suitability
2.8
Device Features & Sensors
4.2
Transparency & User Control
3.5
Key Statistics
High
Health Data Risk
100M+
Active Users
Partial
GDPR Compliance
Product Details
BrandFitbit
PriceFree (beta access)
Best ForFitness enthusiasts seeking low-barrier entry into data-driven health management

Fitbit and Google: The Acquisition That Changed Everything

Google acquired Fitbit in January 2021 for $2.1 billion, and since then the platform has undergone a complete architectural shift. What was once an independent fitness tracking ecosystem has been absorbed into Google’s broader services infrastructure. By May 19, 2026, all remaining Fitbit accounts were required to migrate to Google Accounts — making it impossible to use Fitbit without handing your health data to one of the world’s largest data brokers. Users who had not migrated by May 19, 2026 lost access to their Fitbit accounts. Google has scheduled data deletion to begin on July 15, 2026 — users can still download their data before that date. The forced migration met significant user resistance, with Google extending its original 2025 deadline multiple times before enforcing the final cutoff. For enterprise IT teams, this consolidation is a critical governance event: health data that was once siloed in a niche fitness app now sits inside Google’s unified data environment.

Health Data Privacy: What Google Actually Collects

Once a user migrates to a Google Account, all Fitbit health metrics — heart rate, sleep patterns, blood oxygen, skin temperature, menstrual cycle data, EDA stress scores, GPS location during workouts, weight logs, and daily activity histories — are governed by the Google Privacy Policy. Google has formally pledged that Fitbit health and wellness data will not be used for ad targeting, and this commitment was contractually enforced by the European Union as a condition of its merger clearance through at least 2024. However, the long-term trajectory is less reassuring. A 2025 systematic analysis published in the Journal of Medical Internet Research identified Google/Fitbit as having among the most permissive data-sharing terms of all major wearable manufacturers. The policy’s language permitting data use to “improve services” is broad and difficult to audit, meaning third-party developers and researchers may gain access to aggregated or anonymised health data pools derived from Fitbit users.

GDPR Compliance: The European Regulatory Lens

For users in the European Economic Area, United Kingdom, or Switzerland, Fitbit International Unlimited (an Irish entity) serves as the designated data controller under the GDPR. Fitbit requests explicit consent before processing any health data — categorised as a “special category” under Article 9 of the GDPR — when pairing a device, enabling exercise data import, or activating features such as female health tracking. Consent can be withdrawn at any time through account settings. Following the migration to Google Accounts, Fitbit and Google entered a joint processing arrangement for limited profile information including user names, photos, and friends lists. This joint controllership arrangement is a nuanced compliance area that data protection officers (DPOs) at European enterprises should examine carefully before deploying Fitbit in workplace wellness programs. The Irish Data Protection Commission oversees Fitbit’s GDPR obligations, and any cross-border data transfers must comply with Standard Contractual Clauses (SCCs) or equivalent adequacy mechanisms.

HIPAA and the Enterprise Wellness Risk

This is where Fitbit’s risks become most acute for US-based corporate environments. HIPAA — the Health Insurance Portability and Accountability Act — only applies to covered entities: healthcare providers, insurers, and their business associates. Consumer wearable companies, including Fitbit, Google, Apple, and Garmin, are not covered entities by default. However, there is an important nuance: Fitbit can operate within a HIPAA-compliant framework when deployed via a Business Associate Agreement (BAA) with a covered entity, or when integrated into an employer’s group health plan that itself qualifies as a covered entity. In those specific enterprise contexts, HIPAA obligations can flow down. Outside of such formal arrangements — which is the case for the vast majority of consumer and corporate wellness deployments — employee biometric data collected through Fitbit has no federal HIPAA protection. The data collected by wearables — heart rate, sleep cycles, SpO2, skin temperature — qualifies as biometric information under several state laws. Illinois in particular has the Biometric Information Privacy Act (BIPA), which imposes strict requirements including written consent, retention policies, and prohibition on selling biometric data. Employers using Fitbit in wellness incentive programs without a properly drafted consent framework and data processing agreement face real legal exposure under BIPA and equivalent state laws in Texas, Washington, and California. Legal analysis from Akerman LLP published in June 2025 confirmed that the biometric data collected by wearables in corporate programs could trigger disability discrimination claims if used in employment decisions — even indirectly.

Corporate Wearable Policies and IT Security Considerations

Enterprise security teams evaluating Fitbit for employee wellness programs should approach the device through the same BYOD framework applied to smartphones and tablets. The Fitbit Charge 6 and Sense 2 communicate via Bluetooth LE — a protocol that, while low energy, still exposes health data in transit to any device within range if Bluetooth security hygiene is not enforced. The devices sync via the Google Health app on employees’ smartphones, meaning corporate health data passes through personal mobile devices, personal Google accounts, and Google’s cloud servers — all outside the corporate perimeter. This data pathway sits entirely outside the reach of corporate DLP (Data Loss Prevention) systems and MDM (Mobile Device Management) solutions. Security-conscious enterprises should require a separate Google Account dedicated to corporate wellness participation, publish a clear wearable device policy governing acceptable use, and work with legal counsel to draft participant consent forms that address state biometric privacy laws. HR and IT teams should also be aware that Fitbit data — even aggregate step counts and activity trends — may contain enough information for insurers or third parties to make inferences about employee health status, creating potential ADA (Americans with Disabilities Act) liability if that data influences employment decisions.

Verdict

Fitbit remains a technically impressive consumer health platform with a mature sensor suite, seamless Google ecosystem integration, and broad fitness tracking capabilities. But viewed through a data privacy and enterprise security lens, it is a high-risk deployment. The mandatory consolidation into Google Accounts, the absence of HIPAA coverage, permissive data-sharing language in Google’s privacy policy, and significant state-level biometric law exposure make Fitbit a liability-heavy choice for corporate wellness programs without rigorous legal and technical controls in place. Individual users who are comfortable within Google’s ecosystem and not in regulated industries will find Fitbit a capable and well-priced wearable. Enterprise and healthcare-adjacent environments should conduct a formal privacy impact assessment before deployment.

Rating: 3.2 / 5 — Capable wearable hardware undermined by serious health data privacy risks in the post-acquisition Google ecosystem.

Reviewed based on Fitbit/Google Privacy Policy, Google Health FAQ, Akerman LLP BIPA Analysis — June 2025, Vora Wearable Privacy Report — March 2026, 9to5Google Fitbit Migration Coverage — July 2026.

Frequently Asked Questions

Is Fitbit HIPAA compliant?

Not by default. Fitbit is a consumer wearable and is not classified as a HIPAA covered entity, meaning standard consumer health data has no federal HIPAA protection. However, Fitbit can be deployed in a HIPAA-compliant manner when a Business Associate Agreement (BAA) is in place with a covered entity such as a healthcare provider or insurer, or when integrated with an employer's group health plan that qualifies as a covered entity. Outside of these specific formal arrangements — which apply to most corporate wellness deployments — employers must not rely on HIPAA for data governance and should instead build compliance frameworks around applicable state laws and their own data processing agreements.

Does Google use Fitbit health data for advertising?

Google has publicly committed that Fitbit health and wellness data will not be used for Google Ads, and this was a contractual condition of the European Commission's merger clearance in 2021. However, Google's broader privacy policy permits use of data to "improve services" — a clause that gives the company significant latitude. The long-term enforceability of the ad-use restriction beyond the initial EU commitment period remains a genuine concern for privacy advocates.

What happened to Fitbit accounts in 2026?

Google made migration to a Google Account mandatory, with the final cutoff set at May 19, 2026. Users who had not migrated lost access to their Fitbit accounts. Data deletion was set to begin July 15, 2026. Users were given the option to download their historical data before deletion. This forced migration was the culmination of a process that began in 2023 following Google's 2021 acquisition.

Is Fitbit GDPR compliant for European employees?

Partially. Fitbit International Unlimited (Ireland) acts as the data controller for EEA, UK, and Swiss users, and Fitbit requests explicit GDPR consent before processing health data under Article 9. However, the joint processing arrangement between Fitbit and Google for profile data following the account migration introduces shared controllership complexities that DPOs should review before enterprise deployment.

Can employers legally require employees to use Fitbit in wellness programs?

Legally, employers face significant constraints. Requiring biometric data collection through wearables may trigger obligations under BIPA (Illinois), CCPA (California), and the ADA. Participation in wellness programs must generally be voluntary, and any incentives offered must meet EEOC guidelines. Explicit written consent is mandatory wherever state biometric privacy laws apply. Employers should consult employment counsel before implementing Fitbit-based wellness programs with incentives or tracking requirements.

What data does Fitbit Charge 6 collect and store locally?

The Fitbit Charge 6 stores 7 days of detailed motion data (minute by minute), 30 days of daily totals, and heart rate data at 1-second intervals during exercise and 5-second intervals otherwise. This data is synced to Google Health's cloud servers via the Google Health app over an internet connection. The device requires iOS 16.4 or Android 11.0 minimum for the Google Health app.

How does Fitbit compare to Apple Watch for privacy?

Apple Watch offers significantly stronger default privacy architecture for consumer health data. Apple processes health data on-device where possible, encrypts it end-to-end when synced to iCloud, and does not use health data for advertising under any current policy. Fitbit/Google's approach centralises health data in Google's cloud with broader data-use permissions. For privacy-conscious users and enterprise environments, Apple Health is the stronger choice from a security standpoint.

What should an enterprise do before deploying Fitbit in a wellness program?

IT and HR teams should conduct a Privacy Impact Assessment (PIA), draft a clear wearable device policy, obtain explicit written biometric consent from participating employees, engage legal counsel to assess state law obligations (especially in Illinois, Texas, Washington, and California), ensure separate personal/corporate Google Accounts are used, and contractually define data retention, access, and deletion terms with any third-party wellness vendors involved in the program.

+Pros

  • Rich biometric sensor suite — ECG, EDA, SpO2, skin temperature all in one device
  • Google's infrastructure provides strong encryption and two-factor authentication
  • Explicit GDPR consent mechanism for health data collection in EEA/UK/Switzerland
  • Broad enterprise wellness program support with historical deployments across Fortune 500 firms
  • Google's commitment (contractually enforced by EU) to not use Fitbit health data for ad targeting

Cons

  • Google Account is now mandatory — health data is fully consolidated into Google's data ecosystem
  • HIPAA does not apply to Fitbit as a consumer wearable — corporate health data has no federal protection
  • Post-acquisition Google Privacy Policy permits use of data to "improve services" — a broad and legally ambiguous clause
  • Users who had not migrated by May 19, 2026 lost access to their Fitbit accounts; Google will begin deleting account data on July 15, 2026
  • State-level biometric laws (e.g. Illinois BIPA) create serious legal exposure for employers using Fitbit in wellness programs