Your Wrist Is Snitching - Wearables, Surveillance, How to Own Your Biometrics
You strap a sensor to your body that reads your heart rate, your blood oxygen, your sleep architecture, sometimes your skin temperature. Then you hand the raw feed to a company whose actual business model is advertising, insurance data licensing, or "we'll figure out monetization later." This is the default configuration of the wearable industry in 2026, and most people never opt out of it because they never realized there was an "in" to opt out of.
This is a field guide for the people who did notice: where the leaks are, where the subpoenas come from, how your watch can rat you out over radio waves without a single byte reaching the cloud, which brands are worth your wrist, and what you can run entirely offline.
The Consent You Never Gave
Consent in wearable land usually means a 40-page ToS you clicked through to unlock step counting. A 2025 audit of 17 major wearable manufacturers found that 76% had transparency issues in their data practices, meaning the majority of the industry cannot clearly account for where your data goes once it leaves the device. That is not a fringe result from one bad actor; that is the median.
Regulators noticed too. In July 2025 the FDA sent WHOOP a warning letter over its Blood Pressure Insights feature, ruling that it constituted an unauthorized medical device. It is a reminder that "wellness feature" is often just "unregulated medical claim" wearing a hoodie. And under updated 2026 FTC guidance, sharing identifiable health metrics with a third-party ad platform without clear informed consent is now formally classified as a breach. That tells you how normalized that sharing had become, that regulators had to spell it out.
The breach side of the ledger is not hypothetical either. A New Zealand patient portal, ManageMyHealth, had hundreds of thousands of sensitive medical documents belonging to more than 120,000 patients exfiltrated in a late-2025 breach, with an extortion attempt attached. Identity-protection company Aura, the company literally selling you protection from this, got hit in March 2026 when an attacker used targeted voice-phishing against an employee to pull roughly 900,000 records. The irony was not lost on anyone.
And legally, the permanence problem is the part people underrate. Health and biometric data is not like a leaked email address: you can rotate a password, but you cannot get new fingerprints or a new cardiac signature. Once that biometric profile is out, insurers, employers, and data brokers can use it in ways that affect your coverage, employment, or creditworthiness. A leaked password is an inconvenience. A leaked HRV baseline correlated against your medical history is a permanent fingerprint.
When Your Watch Testifies Against You
Wearable data does not just leak to hackers or advertisers. It gets subpoenaed, and it gets used, sometimes correctly, sometimes in ways that assume more precision than the sensor actually has.
The canonical case is State v. Dabate (Connecticut, first charged 2017, convicted years later): a man told police his wife was killed by a home intruder over an hour before her Fitbit stopped logging movement. Prosecutors used the Fitbit logs showing the victim was still walking around an hour after her husband claimed she had been killed, and the discrepancy became central to the case. In 2018, a 90-year-old man in San Jose was charged with his stepdaughter's murder after her Fitbit Alta showed a sharp heart-rate spike followed by a rapid slowdown at the exact time surveillance video placed his car at her house. Wearable data has also shown up in disability-fraud litigation, where a plaintiff claiming limited mobility was contradicted by Fitbit data showing sustained activity.
None of these examples are here to make a moral point about the defendants. They are here to make a structural point: your wearable is, by design, a continuously running witness that can be legally compelled to testify, and unlike a human witness it has no fifth amendment and no memory of context. It just has timestamps and numbers, and a prosecutor or insurer's lawyer will supply the narrative around them. If you are not thinking about your wearable data as potential future evidence in any dispute, custody, insurance, employment, criminal, you are behind where the legal system already is.
The Scarier Layer: You Don't Need to Be "Hacked" to Be Tracked
Here is the part most privacy writeups skip: your wearable can leak your identity and location purely through its radio emissions, with zero cloud involvement, zero account, and zero internet connection required. This is RF fingerprinting, and it has been an active academic research area for years.
BLE (Bluetooth Low Energy) devices are supposed to protect you via MAC address randomization, periodically rotating the hardware identifier your watch broadcasts so it cannot be trivially tracked over time. Researchers have repeatedly shown this protection is leaky: one paper demonstrated an address-carryover algorithm that extracts identifying tokens from BLE advertising payloads and tracks a device beyond its address randomization cycles, because payload content and MAC address do not always rotate in sync. Even with correct address randomization, a BLE device can expose hardware details like clock skew, software version, or vendor information through its broadcast profile, which is often distinctive enough to serve as a de-facto fingerprint. Apple's ecosystem got its own teardown: researchers reverse-engineered the BLE Continuity protocol used by Apple Watch, AirPods, and friends, and found they could fingerprint device type and OS version, substantially undermining the anonymization that MAC randomization was supposed to provide.
Cross-referencing radios is where things get genuinely creepy. Contact-tracing research from the COVID era showed that Wi-Fi probe requests, which broadcast the names of recently connected networks, can be correlated with observed Bluetooth MAC addresses to move from an ephemeral Bluetooth identity to a far more persistent identifier built from your Wi-Fi MAC and home and work SSID names. Your watch pings for Bluetooth. Your phone pings for Wi-Fi. Put a passive receiver in a mall, a protest, a border crossing, or a nosy neighbor's driveway, and those two ephemeral signals stitch into one persistent "this specific human was here" record, without a single packet reaching a Garmin or Apple server. That is why airports, malls, and increasingly city "smart infrastructure" run passive BLE and Wi-Fi scanning for crowd analytics today, and why the same infrastructure is trivially repurposable for individual tracking.
The practical takeaway: turning off cloud sync does not turn off your RF footprint. If your threat model includes physical surveillance, protests, stalking, or just not wanting to be a data point in foot-traffic analytics, you need Bluetooth and Wi-Fi radio discipline (airplane mode when not actively syncing, disabling BLE advertising when idle), not just "which cloud did I opt out of."
And this is not a purely academic threat anymore; it is a shipping product. In June 2026, defense contractor Leonardo (a roughly $17B company) started marketing SignalTrace, a sensor add-on for the ALPR (automatic license plate reader) cameras already bolted to street poles, overpasses, and patrol cars across the US. It combines license plate recognition with sensor-captured identifiers from mobile phones, Bluetooth wearables, and vehicle systems, building what Leonardo calls an "electronic fingerprint" by linking devices that repeatedly appear together with a vehicle to a plate number and time-stamped location data. The device categories it correlates include RFID tags, Bluetooth devices, vehicle components, and Wi-Fi sources, meaning your smartwatch, your key fob, your car's TPMS sensors, and even a pet's RFID microchip all become inputs to the same profile.
The part that should actually worry a wearable owner: this fingerprint survives plate swaps. Leonardo's marketing describes identifying one specific car out of a hundred by the fact that it consistently pairs a specific iPhone, an Audi radio, Bose headphones, and a Garmin watch with a given plate, and states the system does not need a plate number first; even if someone obscures their plate, the device fingerprint follows the person, not the vehicle. Correlated data is retained in Leonardo's Enterprise Operations Center, and the company already holds contracts with US Special Operations Command and the General Services Administration. Security researcher Bruce Schneier's read was blunt: possessing and accessing all that correlation data will surely draw scrutiny, and it is almost amazing it is legal now.
This is the deployed version of the research above: a commercial product sold to law enforcement and retailers right now to make de-anonymization profitable at scale. Your Garmin, your AirPods, your fitness band: all inputs. This is the strongest practical argument for radio discipline you will find, not "some researcher showed it is theoretically possible" but "a defense contractor is actively selling this to the agencies whose cameras you drive past every day." For a one-tap practical response, see our guide on going offline against SignalTrace tracking.
Picking Hardware That Respects the Above
Given all this, brand choice matters more than most buyers realize. Here is an honest breakdown by privacy posture, not just marketing copy.
- Garmin: Currently the strongest mainstream option for people who want serious sensor quality and the ability to go fully offline. Data lives on-device in open, well-documented .FIT files; you can pull them via USB with zero account interaction, and Garmin's official FIT SDK means you are not reverse-engineering a proprietary blob. The caveat: initial activation typically still requires a Garmin account, and Bluetooth sync to Garmin Connect Mobile will phone home unless you deliberately disable it. Sensor quality is genuinely competitive with market leaders. Net: best "own your data" option that is not a hobbyist project.
- Polar: Long history in serious HR sensor hardware (chest straps especially), historically more conservative with data-sharing defaults than the big-tech entrants, and has decent local export options via Polar Flow and FlowSync desktop tools. Not open-source, but a reasonable middle ground between a DIY board and full offline independence.
- Open-hardware smartwatches (Bangle.js, PineTime): Open firmware, no mandatory account, no cloud dependency by default, community-auditable code. The trade-off is real: sensor quality (PPG accuracy, HRV precision, sleep staging) lags well behind Garmin, Apple, and Whoop-tier hardware, and polish requires tolerance for a hobbyist product. If your priority is verifiable trust over sensor precision, this is the honest choice.
- Amazfit / Xiaomi-ecosystem bands: Interesting only because of third-party tooling (see Gadgetbridge below), which can fully decouple the hardware from the vendor's cloud app. The hardware and its default app have unremarkable privacy defaults out of the box; you are relying entirely on community reverse-engineering to make these private, not on vendor intent.
What to avoid: Any wearable where the core functionality is contractually inseparable from a cloud account, most notably WHOOP-style subscription devices, where you do not own the hardware's core value proposition independent of an active paid cloud subscription, and offline or local-only operation is not supported at all. Also be wary of budget no-name Bluetooth bands sold via marketplace storefronts with opaque companies behind them. The 2025 audit finding that 76% of manufacturers had transparency issues skews worse the further you get from established brands, and there is essentially zero public scrutiny of what these devices' firmware does with your data or your radio footprint.
Going Fully Local: Tools That Don't Need Big Tech
If you want the sensor data without the corporate middleman, the FOSS quantified-self ecosystem has matured a lot:
- Gadgetbridge: The flagship project here. It is a free and open source Android app that lets you use your smartwatch or fitness tracker without the vendor's closed-source application, without creating an account, and without transmitting data to the vendor's servers. It supports a wide range of hardware including many Amazfit, Mi Band, and other budget wearables, and data lands in a local SQLite database on your phone. From there you own the pipeline entirely. It is on F-Droid, actively maintained, and markets itself as a free and cloudless replacement for gadget vendors' closed-source applications.
- GoldenCheetah: FOSS desktop software originally built for cyclists and athletes that imports and analyzes fitness data entirely locally on Linux, macOS, and Windows. Good fit if your priority is training-load analysis rather than daily biometric journaling.
- Health Connect (AOSP): Google's on-device health data broker, notably not cloud-bound: it is part of the open-source Android base and ships without Google apps on privacy-focused ROMs. Community Gadgetbridge integrations are wiring this in as a neutral local hand-off layer between apps, so your own biohacking engine could read from it without either app needing a direct vendor integration.
- InfluxDB + Grafana (self-hosted): The classic combo for piping FIT-derived metrics into a local time-series database and building your own dashboards. No product does this for you out of the box, but it is the standard stack quantified-self hobbyists reach for once Gadgetbridge or a FIT export gives them raw data.
- fitparse / Garmin FIT SDK: For anyone extracting from Garmin-format files directly, these let you parse .FIT binaries to CSV and JSON locally, no cloud round-trip required.
- Open Humans: Not a tool exactly, but worth knowing about: a nonprofit data-sharing framework built around participant control, useful if you ever want to voluntarily contribute anonymized data to research on your own terms rather than a corporation's.
The common thread: none of this requires trusting anyone's server. Everything runs, parses, and stores locally, and every piece is auditable because the code is public.
Bottom Line
None of this is as inaccessible as it used to be. A few years ago, "build your own local biometrics pipeline" meant a serious software engineering background or a lot of patience with unfamiliar codebases. That barrier has mostly dissolved. AI coding assistants now make it genuinely realistic for a motivated non-professional to build, or heavily customize, their own local-first health engine: writing a FIT parser, standing up a self-hosted dashboard, wiring Gadgetbridge output into a personal database, or auditing your own pipeline for the kind of silent data-integrity issues that quietly corrupt long-term trend analysis.
You do not have to choose between "own my data" and "have decent tooling" anymore. The gap between what big-tech wearable apps offer and what you can build yourself has never been smaller, and it is shrinking every month.
Sources and Verification
- Sahha: State of Wearable Health Data 2026
- Wikipedia: Aura data breach (2026)
- Wikipedia: ManageMyHealth data breach
- The Lyon Firm: Wearable Device Data Privacy and Legal Rights
- Dr. Layne McDonald: Strengthening Privacy Protections for Wearable Tech (2026)
- LCG Discovery: Digital Forensics of Wearables, incl. State v. Dabate
- BBC: Fitbit data used to charge US man with murder
- PoPETs 2019: Tracking Anonymized Bluetooth Devices
- ScienceDirect: Device discovery and tracing in the BLE domain
- arXiv: Handoff All Your Privacy, Apple BLE Continuity Protocol
- arXiv: Privacy and Integrity Risks of Contact-Tracing Apps
- The Deep Dive: Leonardo SignalTrace ALPR device tracking
- Yahoo Tech: License Plate Cameras Now Track Your Phone, Wearables, and Your Pets
- AI Weekly: Leonardo ties phone Bluetooth IDs to plate readers
- Schneier on Security: Enhanced License Plate Tracking
- ELSAG (Leonardo): SignalTrace product page
- F-Droid: Gadgetbridge
- GitHub: awesome-quantified-self