WHOOP Security & Privacy Scorecard
by WHOOP · iOS
Activity, sleep, and recovery data is processed by multiple analytics and marketing platforms, including Amplitude and Iterable. Purchases and subscriptions run through Stripe, Shopify, and Afterpay. Health metrics are stored with strong security practices, but usage patterns are shared with several third-party services.
Best for
Tracking fitness goals with a WHOOP wearable
Avoid if
Users who want health data off marketing platforms
Findings
- 0 critical
- 1 high
- 6 medium
- 5 low
- 12 info
1 issue identified across security and privacy analysis.
Top security issues
- App Transport Security completely disabled across entire app process, enabling HTTP downgrade attacks on continuous biometric data transmission
- Approov API attestation SDK configured with staging environment key in production, potentially weakening the primary remaining API security control after ATS is disabled
- Amplitude Engagement SDK executes server-provided URLs without validation, enabling malicious deep link or phishing URL injection via compromised Amplitude account
Top privacy issues
- Main app privacy manifest declares zero data collection despite active HealthKit, precise background location, and contacts access — App Store Privacy Nutrition Label materially inaccurate
- Iterable marketing SDK transmits email, phone number, and device ID linked to user identity for advertising purposes in context of a continuous health monitoring device
- Amplitude analytics underdeclares UserID collection and uses behavioral targeting data for real-time ad campaign delivery without disclosure beyond standard analytics
Full analysis
Security Score: 76/100 | Privacy Score: 77/100
What This Means for You
Activity, sleep, and recovery data is processed by multiple analytics and marketing platforms, including Amplitude and Iterable. Purchases and subscriptions run through Stripe, Shopify, and Afterpay. Health metrics are stored with strong security practices, but usage patterns are shared with several third-party services.
Recommendation: Use With Caution
Best For: Tracking fitness goals with a WHOOP wearable
Avoid If: Users who want health data off marketing platforms
Key Findings
Data Security - 3 findings (2 low, 1 info)
Network Security - 5 findings (1 high, 2 medium, 1 low, 1 info)
Code Safety - 0 findings
Privacy - 3 findings (2 medium, 1 info)
Privacy Concerns
What Data is Collected
Health and fitness metrics, including activity levels, sleep duration, recovery scores, and heart rate data, are collected and processed by the app. Purchase history, subscription details, and payment information are collected when shopping in-app or managing a membership. In-app behavior and usage patterns are also collected.
Third-Party Data Sharing
Data is shared with the following services:
- Amplitude Analytics and Amplitude Engagement - Behavioral analytics and user engagement tracking
- Iterable - Marketing messaging and push notifications
- Stripe - Payment processing
- Shopify - Commerce and purchasing
- Afterpay - Buy-now-pay-later payments
- Sentry - Error and crash diagnostics
- Intercom - Customer support chat
- GetStream Chat - In-app community messaging
- Memfault - Device performance monitoring
- AWS Cognito - Account identity management
- hCaptcha - Account protection during sign-in
- Typeform - User surveys and feedback collection
Understanding the Scores
| Category | Score |
|---|---|
| Security | 76/100 |
| Privacy | 77/100 |
| Data Security | 95/100 |
| Network Security | 65/100 |
| Code Safety | 88/100 |
| Data Collection | 73/100 |
| Data Sharing | 80/100 |
| User Control | 80/100 |
Positive Security Features
- Locally stored health data is protected by strong storage security practices (Data Security: 95/100).
- Code safety practices are well-implemented across the application, scoring 88/100.
- Account access is managed through AWS Cognito, a well-established cloud identity management service.
Areas for Improvement
- Network communications between the app and its servers travel with less protection than expected, meaning user data sent on public Wi-Fi may not be fully protected.
- Behavioral data and usage patterns are shared with Amplitude and Iterable, both marketing and analytics platforms, beyond what the core service requires.
- Third-party services receive health-related data without clear disclosure of how long they retain it.
About This Analysis
App Details
- App: com.whoop.iphone
- Version: 5.45.0 (Build 553019)
- Scan Date: 2026-04-01
- Platform: iOS
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 76/100 |