Whoop Says It 'Never' Shares Your Data

A federal suit says a marketing pipe called Segment got members' heart rate and stress scores. Whoop's policy names it once, in the section for Korea.

Share

Introduction

There's exactly one place in Whoop's privacy policy where the company names the outside firm that receives your heart-rate data, and it isn't the part written for you. It's a table addressed to South Korean regulators, required under Korea's privacy law, that lists a marketing data platform called Segment as a recipient of "sensor, app, and other data." The U.S. version of that same policy never names Segment. It tells you the opposite: Whoop "never" monetizes member data "by distributing it to other parties, period." A federal class action now alleges that platform received members' heart rate, blood oxygen, real-time stress scores, and video-watching history straight out of the Whoop app. And Whoop's own document proves the company knows exactly how to disclose Segment as a recipient of your body data. It does that for Korea, and not for you.

What the Lawsuit Says Went to Segment

Whoop doesn't sell you a fitness tracker. It sells a membership, $199 to $359 a year, and the strap comes with it. The model works: the company says it passed 2.5 million members and a $1.1 billion bookings run-rate last year, and in March it raised $575 million at a $10.1 billion valuation, with the Qatar Investment Authority and Abbott among the backers. The strap sits on your wrist or bicep and reads you around the clock: resting heart rate, heart-rate variability, blood oxygen, skin temperature, respiratory rate, sleep, strain, recovery.

The complaint that started this, Lomeli v. WHOOP, landed in the Northern District of California in August 2025. Steven Lomeli, a California member represented by the firm Milberg, alleges Whoop "embedded a third-party tracker called Segment into its mobile app" and that Segment collected his data as he used it. The itemized list in the filing is unusually specific: his full name and email, his height, weight and birthday, his resting, maximum and minimum heart rate, the full "Health Monitor" panel of respiratory rate, blood oxygen, HRV and skin temperature, his real-time stress scores, and the title of every educational video he opened in the app. He says he was never told, and never agreed.

Segment isn't a household name, which is part of how it works. It's a customer data platform, owned by Twilio, which bought it for $3.2 billion in 2020. Companies drop Segment's code into their apps so user activity flows into a single pipe that can then be pointed wherever they choose. Lomeli's complaint brings two claims: one under the federal Video Privacy Protection Act, over the video titles tied to his name, and one under California's Confidentiality of Medical Information Act, on the theory that a company tracking your stress, strain and recovery is handling medical information. Whoop hasn't answered the allegations on the merits. It has asked for, and gotten, three separate extensions of its deadline to respond.

The Disclosure Whoop Wrote for Seoul

Start with what Whoop tells you. Its "Privacy Principles" page, still live, states the business model in plain language: members pay fees, and in return, "we never monetize our members' personal data by distributing it to other parties, period." The complaint quotes the same "never sell your information" promise from inside Whoop's own app. It's a clean pledge, and it's the one a U.S. member is meant to walk away with.

Now open the full privacy policy, the long one, last updated April 2026. The section headed "How We Share Personal Data," the part an American reader would actually land on, names no outside company at all. It lists categories instead: "analytics providers," "advertising partners that may collect information on our website through Cookies." No Segment, no Twilio, just shapes where the specifics should be.

Segment appears exactly once in that entire document. To reach it, you scroll to a section that opens, "Notwithstanding '6. HOW WE SHARE PERSONAL DATA'... the following provisions will apply to Korean data subjects." It's a disclosure table Whoop is required to publish under South Korea's Personal Information Protection Act. There, in the row written for Korea, Whoop names Segment outright, gives a @twilio.com contact address, describes the transfer as "Outsourcing / Sensor, app, and other data," and states the purpose: "Facilitate data collection and analysis." It's the same policy and the same data platform; one audience gets the name, the other gets "analytics providers."

Here's what a customer data platform like Segment is built to do, from its own catalog: take the stream of events flowing in from a client's app and fan them out to downstream "destinations" the client switches on with a click. Two of the destinations Segment advertises are Meta's Conversions API and Google Ads. The Conversions API is a server-to-server channel, so data moves from a company's servers to Facebook's without passing through the browser, where an ad blocker or a phone-level tracking opt-out might otherwise catch it. I want to be exact here, because the distinction is the whole story: the Lomeli complaint names only Segment. It does not allege Whoop routed anyone's heart rate to Meta or Google, and no public evidence shows that happened. What's established is narrower. The pipe Whoop stands accused of embedding is the same kind of pipe that's built, and sold, to feed exactly those ad platforms.

There's a real counter-argument, and it deserves airtime. A wearables blogger who read the suit pushed back, calling Segment "just a marketing, analytics and customer data platform that almost every company uses," and arguing the health data "never leaves Whoop's walls." He might be right that nothing reached an advertiser. No one has produced a network capture showing where the data went, and the case is nowhere near resolving that. But "it only reached Segment" is a strange thing to find reassuring, when Whoop's public pledge said member data goes to no outside party, "period," and Segment is precisely the outside party Whoop's own policy discloses to Korea.

Who Benefits

Whoop is the obvious beneficiary, and the benefit is growth. A company climbing toward 2.5 million members and a public-market path needs to know which features keep people subscribed and which behavior predicts a cancellation. A customer data platform turns all of that into structured, exportable data, and that's valuable whether or not a single byte ever reaches an advertiser. The second benefit is cover. The message U.S. members see is the reassuring one, while the concrete admission that Segment receives "sensor, app, and other data" sits in the lone section written for a foreign regulator, where no American user, reporter, or state attorney general has any reason to look.

Segment and its owner Twilio benefit by staying invisible. Segment isn't a defendant in the Lomeli case; it's named as the recipient and otherwise sits outside the fight, which is exactly where a data-infrastructure company wants to be. The more sensitive the data other companies route through your pipe, the more valuable the pipe, and the $3.2 billion Twilio paid in 2020 looks smarter every time another app plugs in. The person wearing the strap never signed up with Segment, has no relationship with it, and in most cases has never heard the name.

Why HIPAA Doesn't Cover Your Wrist

Whatever happens in Lomeli, the structural fact underneath it doesn't move. The reason a company can wire your continuous heart-rate feed into a marketing pipe and leave the whole question to a class action is that no health-privacy law covers it. HIPAA, the law most people assume protects anything with the word "health" on it, only binds "covered entities": health plans, clearinghouses, and health-care providers. A company that sells you a strap reading your blood oxygen while you sleep is none of those. It's how the 1996 statute was written, back when your heart rate lived in a chart at your doctor's office and nowhere else.

The only federal backstop is the FTC's Health Breach Notification Rule, and it does less than the name suggests. It doesn't restrict sharing at all; it requires telling you after an unauthorized disclosure has already happened, and only for certain apps. The FTC didn't even spell out that the rule reaches diet and fitness apps syncing with wearables until an amendment that took effect July 29, 2024, fifteen years after the rule first appeared and long after wearables went mainstream.

The agency knows this pattern, because it has punished it. In 2023 it fined BetterHelp $7.8 million and GoodRx $1.5 million for sharing users' health data with Facebook and other advertising platforms while promising to keep it private. Neither case involved Whoop, and the FTC hasn't opened one against it. But the sequence is on the record: a health app promises privacy, wires sensitive data into an ad-tech pipe, and a regulator responds years later, if at all. Whoop isn't even the only wearable maker facing this theory right now. Oura, the smart-ring company, is fighting a separate set of claims that it shared members' sleep and menstrual-cycle data with advertisers.

The Bottom Line

Take the lawsuit out of it, since it may settle or get tossed, and the durable fact remains: Whoop wrote down that Segment receives "sensor, app, and other data," in plain language, because a foreign regulator made it. American members got the version that says "never... period." The company can clearly disclose the relationship when it decides to. It picked the audience that would see the disclosure, and you weren't it.

Zoom out past one strap and one complaint: 57% of U.S. adults now own a connected health device, by Rock Health's 2025 count. Any of them could pull up the version of the privacy policy Whoop wrote for someone in Seoul and find the same split. The disclosure already exists; it's just addressed to somebody else.