WHOOP Security & Privacy Scorecard

by WHOOP · iOS

76
Overall trust score
Acceptable
76
Security
77
Privacy

Activity, sleep, and recovery data is processed by multiple analytics and marketing platforms, including Amplitude and Iterable. Purchases and subscriptions run through Stripe, Shopify, and Afterpay. Health metrics are stored with strong security practices, but usage patterns are shared with several third-party services.

Best for

Tracking fitness goals with a WHOOP wearable

Avoid if

Users who want health data off marketing platforms

Findings

  • 0 critical
  • 1 high
  • 6 medium
  • 5 low
  • 12 info

1 issue identified across security and privacy analysis.

Top security issues

  • App Transport Security completely disabled across entire app process, enabling HTTP downgrade attacks on continuous biometric data transmission
  • Approov API attestation SDK configured with staging environment key in production, potentially weakening the primary remaining API security control after ATS is disabled
  • Amplitude Engagement SDK executes server-provided URLs without validation, enabling malicious deep link or phishing URL injection via compromised Amplitude account

Top privacy issues

  • Main app privacy manifest declares zero data collection despite active HealthKit, precise background location, and contacts access — App Store Privacy Nutrition Label materially inaccurate
  • Iterable marketing SDK transmits email, phone number, and device ID linked to user identity for advertising purposes in context of a continuous health monitoring device
  • Amplitude analytics underdeclares UserID collection and uses behavioral targeting data for real-time ad campaign delivery without disclosure beyond standard analytics

Full analysis

Security Score: 76/100 | Privacy Score: 77/100

What This Means for You

Activity, sleep, and recovery data is processed by multiple analytics and marketing platforms, including Amplitude and Iterable. Purchases and subscriptions run through Stripe, Shopify, and Afterpay. Health metrics are stored with strong security practices, but usage patterns are shared with several third-party services.

Recommendation: Use With Caution

Best For: Tracking fitness goals with a WHOOP wearable
Avoid If: Users who want health data off marketing platforms

Key Findings

Data Security - 3 findings (2 low, 1 info)

Network Security - 5 findings (1 high, 2 medium, 1 low, 1 info)

Code Safety - 0 findings

Privacy - 3 findings (2 medium, 1 info)

Privacy Concerns

What Data is Collected

Health and fitness metrics, including activity levels, sleep duration, recovery scores, and heart rate data, are collected and processed by the app. Purchase history, subscription details, and payment information are collected when shopping in-app or managing a membership. In-app behavior and usage patterns are also collected.

Third-Party Data Sharing

Data is shared with the following services:

  • Amplitude Analytics and Amplitude Engagement - Behavioral analytics and user engagement tracking
  • Iterable - Marketing messaging and push notifications
  • Stripe - Payment processing
  • Shopify - Commerce and purchasing
  • Afterpay - Buy-now-pay-later payments
  • Sentry - Error and crash diagnostics
  • Intercom - Customer support chat
  • GetStream Chat - In-app community messaging
  • Memfault - Device performance monitoring
  • AWS Cognito - Account identity management
  • hCaptcha - Account protection during sign-in
  • Typeform - User surveys and feedback collection

Understanding the Scores

Category Score
Security 76/100
Privacy 77/100
Data Security 95/100
Network Security 65/100
Code Safety 88/100
Data Collection 73/100
Data Sharing 80/100
User Control 80/100

Positive Security Features

  • Locally stored health data is protected by strong storage security practices (Data Security: 95/100).
  • Code safety practices are well-implemented across the application, scoring 88/100.
  • Account access is managed through AWS Cognito, a well-established cloud identity management service.

Areas for Improvement

  • Network communications between the app and its servers travel with less protection than expected, meaning user data sent on public Wi-Fi may not be fully protected.
  • Behavioral data and usage patterns are shared with Amplitude and Iterable, both marketing and analytics platforms, beyond what the core service requires.
  • Third-party services receive health-related data without clear disclosure of how long they retain it.

About This Analysis

App Details

  • App: com.whoop.iphone
  • Version: 5.45.0 (Build 553019)
  • Scan Date: 2026-04-01
  • Platform: iOS

Versions & scan history

ScanDateOverall score
#1 (current) 76/100