WHOOP Security & Privacy Scorecard
Android
Detailed health metrics, activity, sleep, and recovery data are collected and shared with marketing and analytics services including Iterable and Firebase, which can use that data to send targeted messages and track user behavior. Options to limit or opt out of this data sharing are minimal, and multiple third-party services receive user information by default.
Best for
Fitness enthusiasts comfortable sharing health data
Avoid if
You want control over your personal health data
Findings
- 0 critical
- 0 high
- 0 medium
- 1 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Unencrypted Health Data Storage
- Unencrypted Authentication Token Storage
- Missing Certificate Pinning Configuration in XML
Top privacy issues
- Health Data Sent to Marketing Platform Without Consent
- Analytics SDKs Initialized Before User Consent
- GPS Location History Stored Unencrypted
Full analysis
WHOOP
Security Score: 45/100 | Privacy Score: 35/100
Scanned: 2026-01-20 | Package: com.whoop.android
What This Means for You
Detailed health metrics, activity, sleep, and recovery data are collected and shared with marketing and analytics services including Iterable and Firebase, which can use that data to send targeted messages and track user behavior. Options to limit or opt out of this data sharing are minimal, and multiple third-party services receive user information by default.
Recommendation: Use With Caution
Best For: Fitness enthusiasts comfortable sharing health data
Avoid If: You want control over your personal health data
Key Findings
Data Security - 4 findings (2 critical, 1 high, 1 low)
Network Security - 3 findings (1 high, 1 medium, 1 low)
Code Safety - 0 findings
Privacy - 6 findings (2 critical, 1 high, 2 medium, 1 low)
Privacy Concerns
What Data is Collected
WHOOP collects detailed biometric and health data including heart rate, heart rate variability, sleep patterns, activity levels, and recovery scores. This data is linked to account identity and device identifiers and is retained by the platform.
Third-Party Data Sharing
Data is shared with the following third-party services:
- Iterable - Marketing automation and targeted messaging
- Firebase - Behavioral analytics and tracking
- Sentry - Error and diagnostic reporting
- Stream Chat - In-app messaging infrastructure
- Stripe - Payment processing
- Mapbox / Google Maps - Location and mapping features
- AWS Cognito - Account authentication
- Nordic DFU - Device firmware updates
- Glide / Coil - Media loading
- TensorFlow Lite - On-device processing
Understanding the Scores
| Category | Score |
|---|---|
| Security | 45/100 |
| Privacy | 35/100 |
| Data Security | 30/100 |
| Network Security | 75/100 |
| Code Safety | 70/100 |
| Data Collection | 40/100 |
| Data Sharing | 35/100 |
| User Control | 30/100 |
Positive Security Features
No notable positive security practices were identified in this analysis.
Areas for Improvement
- Sensitive health and biometric data is routed to multiple advertising and analytics platforms by default, with no clear path to restrict or limit that sharing.
- The app provides very little control over what personal information is collected or which third parties receive it.
- Protections applied to stored health data fall below the standard expected for apps handling this level of personal information.
About This Analysis
This scorecard is based on automated static analysis of the published app. Scores reflect the security and privacy posture of the version analyzed and may change with app updates.
App Details
- App: WHOOP
- Package: com.whoop.android
- Scan Date: 2026-01-20
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #3 (current) | 40/100 | |
| #2 | 42/100 | |
| #1 | 58/100 |