← Back to blog

What Your Walking App Knows About You

Joel RenkBy Joel Renk··6 min read

In October 2024, the French newspaper Le Monde published an investigation that did not involve hacking anything. Reporters found the Strava profiles of 26 US Secret Service agents, 12 members of the French presidential security detail and six officers of Russia's Federal Protection Service. Then they read the runs.

An agent's morning jog began at a San Francisco hotel a few hours before Joe Biden arrived there for talks with Xi Jinping in 2023. Emmanuel Macron's detail traced a private weekend in Honfleur in 2021 that appeared on no official schedule. Several of Vladimir Putin's bodyguards logged runs near a Black Sea palace he has denied owning.

Nobody leaked anything. Nobody was breached. The bodyguards uploaded their workouts to a fitness app, and the app did exactly what it was built to do.

That is the part worth understanding, and it is the part almost every article about fitness app privacy gets wrong.

The risk is not that your app sells your data

Ask people what worries them about a location app and most say the company will sell their data to advertisers. It is a reasonable worry and it does happen. But it is not what has actually gone wrong, repeatedly, in public.

Go back to the first big one. In November 2017 Strava published a global heatmap built from around a billion activities: roughly three trillion individual GPS points, some 17 billion miles of movement, all aggregated and anonymised. It was a beautiful piece of data visualisation and it was published deliberately.

In January 2018 an Australian researcher named Nathan Ruser noticed something odd about it. In the middle of the Syrian desert, where there should have been nothing, there were glowing loops of jogging track. They were the perimeters of military bases. Journalists then confirmed the same pattern across Iraq and Afghanistan: base outlines, supply routes, patrol paths, and the daily rhythm of who moved where and when. Some of the sites were installations the US government had never publicly acknowledged. Strava restricted street level heatmap access that March, and the Department of Defense opened a review.

No individual in that dataset was identified. That was the point. The data was anonymised and aggregated, and it still drew a map of classified infrastructure, because a hundred soldiers running the same loop is a shape, and shapes mean something.

So the honest summary is this. In both of the famous cases, the data was working as designed. Nothing was stolen and nothing was sold. Public defaults, plus aggregation, plus somebody clever looking at the result.

That reframes what you should actually be checking.

What a walking app can see

Not all of these apply to every app, and the differences matter more than the list itself.

Where you are, precisely. Consumer GPS is accurate to a few metres in the open. That is precise enough to identify a building, not just a street.

Where you are when you are not using the app. Background location is the single biggest distinction between apps. An app with background permission knows your movements when it is closed and in your pocket. An app without it knows only what happens while you are looking at it.

When you do things, which is often more revealing than where. A route is one fact. The same route at 07:10 every weekday is a schedule, and a schedule tells someone when you are reliably not at home.

Your start and end points, which are the sensitive part. This is the piece people consistently underrate. The middle of your walk is usually nothing much. The two ends are your home and your workplace, and a map of your walks marks both of them more reliably than anything else you could hand over. This is measurable, not theoretical: researchers at NC State demonstrated in 2023 that start and stop clusters in Strava's public heatmap could be matched against address data to predict a frequent user's home to within 100 metres roughly 37.5% of the time. We go through that study and Strava's current data terms in Strava alternatives for walkers. Privacy zones that blur a radius around your address exist in most serious apps, and most people never switch them on.

Who you walk with. Friend lists, leaderboards, shared activities and kudos build a social graph on top of the location data. The Le Monde investigation partly worked by following connections between accounts.

What can be inferred. Movement data supports guesses well beyond movement: where you shop, where you worship, which clinic you visited, whether your routine changed suddenly. None of that is collected. All of it is derivable.

The three questions that actually matter

Most privacy advice tells you to read the privacy policy. Almost nobody does, and the policies are written so that reading them rarely changes a decision. These three questions are faster and tell you more.

1. What is public by default?

This is the one that produced every incident above. Not what the company does with your data, but what strangers can see without asking. Check the default visibility of your activities, your profile, your route maps and your following list. If the default is public, assume it has been public since the day you installed the app.

2. Does it collect in the background, and do you need it to?

Background location is genuinely necessary for some features and pure overhead for others. A route recorder that only runs when you press start does not need it. A map that fills in automatically as you walk does. The question is not whether background access is bad, it is whether you are getting something for it.

On iOS, Settings then Privacy & Security then Location Services shows every app and its current level, including a purple arrow next to anything that used your location recently. On Android, Settings then Location then App permissions does the same. Both let you downgrade an app to "While Using" in one tap.

3. Where does the data live, and who else gets a copy?

Jurisdiction decides what rights you actually have rather than what a marketing page promises. Data held in the EU sits under GDPR, which gives you a legal right to a copy of it and a legal right to have it deleted. Also worth knowing which third parties are listed as processors, since that is where data goes without ever being "sold."

A five minute audit

Worth doing once, for every location app on your phone rather than just the walking one.

  1. Open the app's privacy or visibility settings and look at the defaults. Set activity visibility to whatever you would be comfortable with a stranger seeing, because that is the test.
  2. Turn on the privacy zone around your home and your workplace if the app offers one. This is the highest value setting in this list and the most commonly ignored.
  3. Check location permission level in your phone settings, not in the app. Downgrade anything that does not need background access.
  4. Look at your own profile while logged out. Open it in a private browser window. Whatever you can see there, anyone can see.
  5. Request your data export. Any GDPR compliant app has this. It is the only way to find out what is actually stored rather than what you assume is stored.
  6. Delete the accounts you stopped using. An abandoned fitness account is still an accurate map of your life at the time you abandoned it.

Why "we don't sell your data" is an incomplete answer

It is a real commitment and it is worth having. It just does not cover the cases that have actually caused harm.

A company can be entirely honest about never selling your data and still publish an aggregate heatmap that reveals a military base. It can be acquired, along with its database, by a company that made no such promise. It can be breached. It can receive a lawful order. And none of that touches the largest category, which is the data you published yourself because a default was set to public and you never looked.

The useful question is not "do you sell it." It is "what happens by default, what can I turn off, and can I take it all back."

Where we stand

Since this is our blog, the honest disclosure. Fogbreaker is a walking app that reveals a map as you walk, which means it is in exactly the category this article is about, and you should hold it to the same three questions.

What we can state plainly: it is built by Teratis Solutions GmbH, a German company. The data sits on servers in the EU and falls under GDPR. We do not sell it or share it with third parties for advertising. You can delete your account and everything in it yourself, at any time, without emailing anyone to ask.

What we are not going to do is claim the category is risk free because we are in it. A map of the streets you have walked is sensitive by nature. That is true of ours, of Strava, and of every app in this comparison. The appropriate response is to know what it stores, keep your defaults tight, and be able to take it all back when you want to.

The part worth remembering

The bodyguards in the Le Monde story were not careless with a secret. They went for a run and pressed save, on an app whose defaults they had never examined, and the aggregate of thousands of ordinary decisions like that turned into a map of where several heads of state were sleeping.

Almost nobody reading this is protecting a president. But the mechanism is the same at every scale, and so is the fix. Spend five minutes on your defaults. Turn on the zone around your house. Then go for the walk, because the answer to this was never to stop walking or to stop keeping a record of it. It was to know what the record says and who can read it.

Share this post
Keep reading
Fogbreaker
Get the app

Turn your next walk into an adventure

Reveal your city as you walk, earn XP, and climb the leaderboard with friends. Free on iOS and Android.

Download on the App StoreGet it on Google Play