privacydeep-dive

Peloton and NordicTrack Know More Than Your Step Count

Consumer Reports found connected home gym equipment collects health data beyond workouts. Here's what Peloton and NordicTrack actually capture and share.

Peloton data privacy became a broader conversation when a Consumer Reports investigation found that connected fitness equipment manufacturers — including Peloton and NordicTrack’s parent company iFit — were collecting health information that went well beyond the workout metrics displayed on their screens. The investigation found companies gathering data including pregnancy status and dietary habits, categories most users would not expect a treadmill or stationary bike to be capturing.

The problem isn’t unique to fitness equipment, but it’s particularly notable there. Exercise equipment in your home occupies a different position than an app on your phone: it’s a dedicated device you bought for a specific purpose, placed in a private space, and typically expected to do one thing. The gap between what users expect and what these products actually collect is unusually large.


What Peloton Actually Captures

Peloton scored 28 out of 100 in a privacy analysis published in 2026 — a failing grade. The concerns driving that score are specific and documented.

Workout Metrics Shared With Advertisers

Peloton’s privacy policy permits sharing workout data with advertising and analytics partners. This includes workout frequency, session duration, performance metrics, heart rate data during rides and runs, and exercise preferences over time.

These aren’t abstract “usage statistics.” A third-party advertiser receiving your heart rate trajectory across six months of workouts, combined with your device’s advertising identifier, can build a health inference profile without accessing a single medical record. Elevated resting heart rate, changes in workout intensity, gaps in usage that correlate with illness or pregnancy — these patterns are legible to machine learning systems optimized to find them.

Indefinite Retention After Cancellation

Peloton’s terms allow the company to retain your workout history indefinitely, including after you cancel your subscription. Deleting the app doesn’t delete the data. Canceling your membership doesn’t delete the data. The comprehensive fitness history accumulated during your subscription continues to exist on Peloton’s servers under a policy that doesn’t specify a maximum retention period.

API Vulnerabilities and Data Exposure

Security researchers discovered vulnerabilities in Peloton’s API that exposed user profiles, workout statistics, and location data to anyone who knew a valid account ID — without authentication in some cases. Peloton patched the vulnerabilities after disclosure, but the exposure period included a period during which research teams could query account-level data at scale.

The API vulnerability illustrates a structural risk common to connected fitness equipment: the data these platforms collect is stored centrally and accessed through APIs. The security of that data is entirely dependent on the platform’s security engineering — there’s no local-only option for users who want their workout history without platform exposure.


NordicTrack and the iFit Platform

NordicTrack’s fitness equipment runs on the iFit platform, which serves as the software and data layer across the brand’s product line. iFit’s data practices received Mozilla Foundation scrutiny, and the conclusions were similar to Peloton’s.

Data Collection for Advertising

If you sign up for iFit when you register your NordicTrack equipment — which the product actively encourages — your data is collected and used to target you with advertising. The Mozilla Foundation’s Privacy Not Included assessment noted that iFit (NordicTrack) shares personal information with third parties including for marketing purposes, and that phone numbers provided during registration are used for marketing outreach.

The Health Data Category Problem

The Consumer Reports investigation highlighted that connected fitness companies gather information extending into sensitive health categories. Pregnancy status and dietary habits appearing in collected data are particularly notable because they’re categories with explicit legal protection in some jurisdictions (reproductive health data has been the subject of significant state-level legislation following Dobbs) and they’re data points most users would not knowingly provide to a hardware manufacturer.

The mechanism for capturing this data isn’t always explicit forms. Some of it comes through app features that ask about health goals, dietary preferences, and health conditions to personalize workout recommendations. The answers go into a profile, and that profile is subject to the platform’s data sharing practices.


Why “It’s Just Workout Data” Doesn’t Hold

Fitness data is often dismissed as low-sensitivity compared to financial or medical records. The dismissal doesn’t hold up under scrutiny.

Behavioral health inference: A consistent record of workout times, intensities, and gaps in activity is a proxy measure of overall health trajectory. Insurance companies and health platforms have studied these correlations extensively. Workout data, over time, is health data in a functional sense.

Location inference: Peloton bikes and treadmills are used at home. But connected fitness equipment often syncs with GPS-enabled wearables and tracks outdoor workouts through apps. Location data from outdoor runs, bike routes, and hikes is part of the complete fitness profile many users build through these platforms.

Household inference: A Peloton account linked to multiple family members, or workout patterns that shift dramatically, can reveal information about household composition, schedules, and health changes that extend beyond the primary account holder.

Legal exposure: Health data is increasingly sought in legal proceedings. Workout records were subpoenaed in cases involving personal injury claims, insurance disputes, and family law matters. What you consider private fitness data, a subpoena can transform into legal evidence — stored on a company’s servers under a retention policy you didn’t negotiate.


What the Connected Fitness Category Is Becoming

The original Peloton model was a hardware product with a subscription content layer. The business model has evolved. Peloton now generates revenue from advertising in addition to subscriptions, and its ability to offer advertisers health-behavioral targeting depends on the data its products collect.

This shift matters because the data collection that made sense for “delivering personalized workout recommendations” now serves a secondary purpose — advertising revenue — that users didn’t sign up for when they bought the hardware.

NordicTrack’s parent company iFit has followed a similar trajectory: hardware sold, software platform capturing data, data used for advertising and third-party partnerships.

The competitive pressure in connected fitness pushes companies toward data monetization. Hardware margins are thin; subscription revenue is volatile; advertising revenue from health-behavioral data is attractive. The user who bought a $2,000 treadmill to get healthy did not necessarily intend to become an advertising inventory product.


Practical Steps for Connected Fitness Users

Review Your Platform’s Privacy Settings

Both Peloton and iFit/NordicTrack have privacy settings that allow some control over data sharing. The controls are limited — you can’t opt out of all data collection while retaining platform functionality — but reducing advertising-specific sharing is possible.

For Peloton: Account Settings → Privacy → adjust sharing preferences for third-party advertising and analytics.

For iFit: Account Settings → Privacy controls → manage marketing permissions.

These settings reduce some downstream data sharing. They don’t affect Peloton’s or iFit’s own retention of your workout history.

Request Your Data

Under CCPA (California), GDPR (EU), and an increasing number of state privacy laws, you have the right to request a copy of the data a company holds about you. Submitting a data access request to Peloton or iFit gives you visibility into the full scope of what’s collected — including categories you may not have known about.

For California residents: you can also request that Peloton delete your data. Data deletion requests are processed under California’s deletion rights framework, though some categories of data (required for legal compliance, security, or active subscription service) may be retained.

Consider the Wearable Integration Scope

If you’ve connected a Fitbit, Apple Watch, or Garmin to your Peloton or NordicTrack account, the data sharing runs in both directions. Your connected equipment shares workout summaries with the wearable platform; the wearable may share additional health metrics back to the fitness platform.

Check the connected apps section of each platform and remove integrations you don’t actively need. Each integration point is an additional data flow between platforms, each with its own retention and sharing practices.

Be Deliberate About Health Questionnaires

When a fitness app asks about your health goals, dietary preferences, weight loss targets, or health conditions during setup or in regular prompts — that information goes into your profile. The workout recommendation benefit is real; so is the data collection.

If you’re not comfortable with a piece of health information appearing in your advertising profile, don’t provide it to the platform’s health questionnaire, regardless of how the question is framed.


The Offline Alternative

The cleanest data answer for home gym equipment is hardware that doesn’t require a platform account to function: a treadmill with a manual incline dial, a stationary bike without a touchscreen, a set of adjustable weights, or resistance equipment that simply doesn’t connect to anything.

This trades features — no on-demand classes, no performance tracking, no workout library — for a device that doesn’t know you exist beyond the purchase record. For users whose primary concern is health data privacy, this trade-off may be worth making.

For users who use the connected features, the framework is the same one that applies to any connected service: understand what you’re providing, use the available controls, and don’t assume that “workout app” is a low-sensitivity data category just because it involves a bike rather than a doctor’s office.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts