Showing posts with label #CyberAwareness #DigitalSafety #NaijaTech #HealthDataPrivacy #ZaraikeDigital #SecuringAfricasDigitalFuture. Show all posts

Your Fitness Tracker Is a Spy You Paid For

Your Fitness Tracker Is a Spy You Paid For | Zaraike Digital Services
Day 4 · Week 1 · Healthcare Cybersecurity · Zaraike Digital Services

Your Fitness Tracker Is a Spy You Paid For

By Uchenna Okafor  |  IT Manager & Founder, Zaraike Digital Services  |  Securing Africa's Digital Future

You bought it.

You strapped it to your wrist. You wear it to bed, to the gym, to church, to work.

And every single day, it quietly learns your heart rate, your sleep pattern, your location, your stress levels — and for many women, your menstrual cycle.

Now ask yourself a question you have probably never asked: where does all of that data actually go?

You paid for the watch.
Someone else is getting paid for you.
📡 What Your Wearable Already Knows
❤️
Heart Rate & RhythmContinuous, 24 hours a day — including irregular patterns that hint at health conditions
😴
Sleep CyclesWhen you sleep, how well, how often you wake — patterns that reveal stress, illness, or lifestyle habits
📍
Location HistoryWhere you go, how often, at what time — built into a movement profile over months and years
🩸
Menstrual & Fertility DataCycle tracking, fertility windows, pregnancy attempts — among the most sensitive data a person can generate

The Diary That Tells on You

🔒 A simple story

Imagine you had a magic diary. Every day, it writes down everything about you without you even asking — when you wake up, when you're tired, when you're scared, when you're sick, even how fast your heart beats when you're nervous.

You think it's just your diary. Your secret. Your private little book.

But this diary has a tiny hidden mailbox at the back. Every night, while you sleep, it slips a copy of everything it wrote — straight to companies you've never met. They read about your whole day. Then they sell what they learned to other companies.

You never opened that mailbox. You didn't even know it was there. But it's been there since the day you got the diary — sitting quietly on page one, in writing too small for you to notice.

That diary is your smartwatch. The mailbox is a setting called "data sharing with partners." And it has probably been switched on since the day you took it out of the box.

👔 Explain It Like a Professional

The Wearable Data Economy

Wearable devices occupy a unique position in the data economy: they are simultaneously consumer electronics and continuous biometric sensors. Unlike a one-time form submission, a wearable generates a persistent, longitudinal stream of physiological and behavioural data — often more granular and harder to anonymise than data collected through any other consumer channel.

Most wearable manufacturers operate on a freemium or hardware-plus-services model, where the device sale is only one revenue stream. The accompanying mobile application frequently includes embedded software development kits (SDKs) from advertising networks, analytics providers, and — critically — health and life insurance data aggregators. Biometric data, once transmitted to these third parties, can be cross-referenced with other data sources to build remarkably detailed behavioural and health-risk profiles.

Crucially, much of this data falls outside traditional health privacy regulation. In most jurisdictions, including Nigeria under the NDPR, wearable-generated wellness data is not classified with the same protections as clinical medical records, despite being arguably more revealing — because it is continuous, contextual, and collected without a clinician's oversight or consent framework.

The implications extend beyond advertising. Life and health insurers in several markets have begun incorporating wearable data — sometimes voluntarily submitted for "discount" programs, sometimes acquired through data broker relationships — into underwriting and premium calculation models.

The device on your wrist was never just a fitness tool. It is a biometric data pipeline, and you are both the source and the product.

From Your Wrist to Their Servers — In Four Steps

01

Collection

Your wearable's sensors capture heart rate, movement, sleep, and location in real time, syncing to its companion app every few minutes.

02

Transmission

The app uploads this data to the manufacturer's cloud servers — and, depending on the SDKs embedded in the app, simultaneously to third-party analytics and advertising platforms.

03

Aggregation

Data brokers combine your biometric data with other available information — your shopping habits, your location history, your demographic profile — to build a composite picture of who you are.

04

Monetisation

That composite profile is sold or licensed to advertisers, insurers, and research firms — often without ever directly identifying you by name, but with enough specificity to target you precisely.

This Has Already Happened to Millions

Example 01 — Strava's Global Heatmap (2018)

A Fitness App Accidentally Exposed Secret Military Bases

Strava, a popular fitness tracking app, published a global heatmap showing aggregated user activity from millions of devices. Analysts quickly discovered the heatmap revealed the exact layouts of secret military bases in conflict zones — because soldiers wearing fitness trackers had unknowingly mapped the bases through their daily runs. If aggregated fitness data could expose military secrets, it can certainly expose far more about an ordinary person's daily life.

Example 02 — Fitbit Data and Insurance Programs

Wearable Data Entering Insurance Underwriting

Several insurers across global markets, including programs referenced by Fitbit and other wearable partnerships, have offered premium discounts to users who share their activity data. While framed as a wellness incentive, this establishes a precedent: health-adjacent behavioural data is being formally integrated into financial risk assessment — a shift few users fully register when they accept the optional integration.

Example 03 — Period Tracking Wearables Post-Roe (USA, 2022)

Reproductive Data Became a Legal Liability Overnight

Following the overturning of Roe v. Wade in the United States, privacy researchers raised urgent alarms about period and fertility tracking data stored by wearable companies — warning it could be subpoenaed in legal proceedings related to abortion in states where it had become criminalised. Data collected for personal wellness purposes suddenly became potential evidence in a completely different context the user never anticipated.

🔐 What to Do Today

You don't need to throw away your smartwatch. You need to take back control of what it's allowed to share.

01

Check Your App's Data Sharing Settings

Open your wearable's companion app and go to privacy or data settings. Look specifically for toggles related to "research partners," "third-party sharing," or "personalised ads." Switch off anything not essential to the app functioning.

02

Turn Off Location Access When Not Needed

Unless you are actively tracking a run or route, your wearable does not need constant location access. Set location permissions to "while using the app" rather than "always," or disable it entirely for features you don't use.

03

Read What "We Share With Partners" Actually Means

Search the privacy policy for the words "partners," "third parties," or "affiliates." This section — usually short and easy to skip — tells you exactly who else has access to your body's data and what they're permitted to do with it.

A smartwatch was never sold to you as a surveillance device. It was sold as a wellness companion — something to help you sleep better, move more, and understand your body.

But somewhere between the marketing and the fine print, your body's data became someone else's business model.

You paid for the device.
Don't let someone else profit from you twice.

Uchenna Okafor
IT Manager  |  Strategic IT Leadership, Governance & Infrastructure Resilience
Founder, Zaraike Digital Services
🔗 LinkedIn 📝 Blog
#WearableTech #DataPrivacy #CyberAwareness #DigitalSafety #NaijaTech #HealthcareCybersecurity #ZaraikeDigital #SecuringAfricasDigitalFuture

🔐 Your Health App Knows More About You Than Your Doctor Does

Your Health App Knows More About You Than Your Doctor | Zaraike Digital Services
Day 1 · Week 1 · Healthcare Cybersecurity · Zaraike Digital Services

Your Health App Knows More About You Than Your Doctor Does

By Uchenna Okafor  |  IT Manager & Founder, Zaraike Digital Services  |  Securing Africa's Digital Future

When last did your doctor check on you?

Last week? Last month? Maybe three months ago — during that routine visit you almost cancelled?

Now ask yourself: when last did your health app check on you?

This morning. Last night. Every single time you opened your phone.

That little app on your screen — the one tracking your period, your blood pressure, your mental health, your symptoms — it has been watching you every single day, quietly building a profile of you that your doctor, your family, and even you yourself may never fully see.

This is the story of your health data. And it is time you knew what was happening to it.

The Nosy Notebook

🔒 A simple story

Imagine you had a special notebook where you wrote down everything — when your tummy hurts, when you feel sad, when you have a headache, what medicines you take. You carry this notebook everywhere.

Now imagine that notebook secretly makes photocopies of your notes and sends them to strangers — people you've never met, who live far away, who sell those notes to other strangers for money.

You never said they could. But buried on page 47 of the agreement you "agreed" to (the one with all those tiny words you scrolled past without reading) — it said they could.

That's what some health apps are doing. Your phone is the notebook. The strangers are called data brokers. And the photocopying? That's happening right now.

👔 Explain It Like a Professional

The Architecture of Health Data Monetisation

In the digital health ecosystem, consumer-facing applications — symptom trackers, fitness monitors, period apps, mental wellness platforms — collect what the industry classifies as Personal Health Information (PHI) and behavioural data. Unlike hospital records, which are governed by strict regulatory frameworks (HIPAA in the US, NDPR in Nigeria), most consumer health apps operate in a grey zone.

These applications embed third-party SDKs for analytics, advertising, and performance tracking. When a user logs a symptom or searches a condition, that data event can be passed — often in pseudonymised but re-identifiable form — to advertising networks, insurance-adjacent data brokers, and market research aggregates.

The mechanism is typically disclosed (barely) in privacy policies under language like "we may share aggregated or de-identified information with trusted partners" — language that grants the app provider wide latitude while offering the user minimal recourse.

The data product that emerges is extraordinarily valuable: longitudinal health behaviour data, correlated with demographics and location, at scale. A data broker does not need your name. They need your pattern.

This is not a bug. For many apps, this is the business model.

This Is Happening — Including Here

Example 01 — The Period App Scandal

100 Million Users. Most Had No Idea.

In 2019, The Wall Street Journal reported that Flo, one of the world's most popular period and fertility tracking apps, was sharing users' intimate health data — including ovulation predictions and pregnancy intentions — with Facebook. This happened even when users had turned off Facebook data sharing on their phones. Most of its 100 million users had no idea.

Example 02 — Mental Health Apps & Your Employer

Your Mindfulness App May Have Described Your Hard Times to HR.

A 2021 study in JMIR mHealth and uHealth found the majority of top-ranked depression and anxiety apps shared user data with third parties, including platforms that supply data to recruitment and HR analytics companies. That mindfulness app you downloaded during a tough period at work? It may have described that tough period to people making decisions about people like you.

Example 03 — Nigeria & The NDPR Gap

Your Data Leaves Lagos. It May Not Come Back.

In Nigeria, the National Data Protection Regulation (NDPR) exists — but enforcement is still maturing, and the vast majority of health apps downloaded by Nigerians are headquartered abroad, subject primarily to foreign law. When you grant a symptom-checker access to your contacts, location, and microphone, you are transferring data outside any jurisdiction with a clear reason to protect you.

🔐 What You Can Do — Starting Today

You do not need to be a cybersecurity expert. You need three habits.

01

Audit Your App Permissions

Go to your phone settings right now. Find your health or fitness apps. Check what permissions they hold — location, microphone, contacts, camera. Ask: does this app need this access to serve me? If not, revoke it.

02

Read the Third-Party Section of Privacy Policies

You don't need to read the whole policy. Search (Ctrl+F / Command+F) for the words "third party," "partners," "share," or "sell." What you find in those paragraphs tells you most of what you need to know.

03

Delete Apps You No Longer Actively Use

Every dormant app is an open window. A health app you downloaded two years ago is still permitted to collect data in the background on many devices. Delete it. The data it already has, it keeps — but you stop the bleeding.

Your health data is not just personal.
It is commercially valuable in ways that can affect your insurance premiums, your employment prospects, and your financial profile — often without you ever knowing it happened.

Your ATM PIN protects your bank balance.

Your health data, unprotected, can expose something far more intimate.

Guard it like you guard your money.
Because someone, somewhere, is already treating it like theirs.

Uchenna Okafor
IT Manager  |  Strategic IT Leadership, Governance & Infrastructure Resilience
Founder, Zaraike Digital Services
🔗 LinkedIn 📝 Blog
#CyberAwareness #DigitalSafety #NaijaTech #HealthDataPrivacy #ZaraikeDigital #SecuringAfricasDigitalFuture #NDPR #AfricaCybersecurity