Cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Fitbit app on Android sending info to Facebook

Replies are disabled for this topic. Start a new one or visit our Help Center.

Facebook recently launched a new privacy tool called "Your off-Facebook activity", which allows you to see which sites and services you use send information to Facebook.

The tool is accessible here: https://www.facebook.com/off_facebook_activity/

I was interested to see that the service that communicated the most with Facebook was Fitbit. This was very curious as (to the best of my knowledge) I have never explicitly connected my Facebook account with my Fitbit account.

 

fb-fb.jpg

 

This is the kind of information that shows up in the Facebook tool showing what information Fitbit are sending - assuming that is just an event that indicates the Fitbit application has been opened. I have also seen event type "CUSTOM"; not clear what other data (if any) is sent along with that. 

 

fitbit-2-edited.jpg

I contacted Fitbit support who suggested that it might be because I have used the Facebook website on my mobile device and I had granted the "Android Internal WebView" permission (on the Fitbit site, https://www.fitbit.com/settings/applications ), which might allow the Fitbit app to access my Facebook cookies.

 

The Fitbit WebView permissionThe Fitbit WebView permission

I removed that permission, cleared all Facebook cookies from the (Chrome) browser on my device, and have not been back to Facebook since on that device. (Note: I do still have Whatsapp and Instagram applications installed).

However, a few days later, I was [not really very] surprised to see still seeing Fitbit activity being reported to Facebook.

I went back to the Applications permission screen and was surprised to see that the Android Internal WebView permission was back again! Note the "approved on" date difference:

fitbit-revoke-4-crop.jpg

 

I revoked the permission and then played around in the Fitbit app and on the device itself again for a few seconds. I am not sure exactly what the trigger is, but basically some common simple task - like opening the app and syncing - simply silently re-adds this application authorisation back into your account.

 

Now, I'm not really confident that this permission is directly related to the Facebook information leakage anyway - I have logged out of Facebook in my browser. Maybe there is some leftover cookie or something stuck in the WebView session that has linked my Facebook session to Fitbit.

 

I have sent an update to Fitbit support via Twitter - they have been helpful and responsive so far, but I suspect this is a fairly low-level technical issue that might be hard to resolve through support channels.

 

Facebook /does/ include an option to turn off activity tracking from Facebook:

facebook-turn-off-fitbit.jpg

So it's possible to "force disconnect" it, but I'm uncomfortable doing that without really knowing the precise method of how this information is being sent (it seems like hitting this "turn off" won't stop the information from being sent, but instead just stop Facebook from recording it, or acting on it, or whatever). I'd rather stop the information from being sent at all.

 

Curious to know if anyone else has checked their own Off-Facebook Activity and noticed this and, if so, were they able to "disconnect" the link between Fitbit reporting to Facebook?

 

Edit: Fitbit Ionic, Pixel 3 phone, everything latest version.

Best Answer
4 REPLIES 4
I have been discussing this with Fitbit support who have provided a few options - e.g., clearing Fitbit app data, uninstalling/reinstalling, etc. But Fitbit is still sending data to Facebook for my account. The only thing I can think of is that it's doing it by some device ID on my Android that was previously established and linked to my account, but there's no obvious way to remove that link from the Fitbit side (it is possible to do on the Facebook side, but I'm more interested in understanding how Fitbit is doing it).
Best Answer

If you uninstall WhatsApp and Instagram, do you still see activity being sent?

Best Answer
0 Votes

I would say more likely is they use the Facebook SDK for app data analytics. Most apps on your phone try to send data to Facebook because of this. Some are terrible and just package the full SDK and it sends tons of data on what you do in the app to FB.  Some are a little better and trim down what they send. 

 

I myself don't use FB as I hate their privacy destroying ways. So, my phone has never logged into FB and the app has never been installed. I have an app ( Netguard if you're curious ) that shows me all traffic on my phone. Fitbit tries to talk a lot to FB throughout the day. 

 

I block all traffic to FB from my phone as I don't want to help build a "shadow" profile as they call it. But, basically I wanted to say that the app still attempts to talk to FB from my phone constantly even though I don't use FB.  I certainly haven't logged into it or installed the app.

 

So I don't think there's anything you did to cause the data sending to happen or anything you can do, save get an app that will allow you to define what you want to block then block traffic from the Fitbit app to FB. Well, then you may see all the other apps that do that too and may decide to block them as well. On Android at least. I'm unsure if Apple would allow you, who bought the phone yet they say they actually own it, to have that control

Best Answer
0 Votes

Fitbit has 4 separate Facebook trackers within their Android app that is sending your data to Facebook.  That's regardless if you have Facebook installed.  An app called Exodus on the Play Store will show you that and the other trackers.  Fitbit has 11 total trackers which is awful for privacy.

Best Answer
0 Votes