How it works

On-Device vs. Cloud Health Data: The Questions That Actually Decide Your Privacy

Two wearables can record the identical heartbeat and treat it completely differently. But the on-device-vs-cloud debate hides the questions that decide your privacy — and a cloud product answering those questions honestly can beat an on-device one that doesn’t.

10 min readUpdated 15 September 2026
Two hands holding a phone on a wooden table, backlit by a bright window.

Two wearables can record the exact same heartbeat and treat it completely differently. One interprets it and stores the result on its own servers. The other does the same thing, but keeps that record under a random ID with your name nowhere near it, sells it to no one, and lets you delete it in full whenever you like.

Both are “cloud” products. Both hold your data. And the difference between them matters far more than the on-device-vs-cloud label that usually gets the headline. This is an honest look at what that label does and doesn’t tell you — including where our own watch sits, which is squarely on the cloud side.

What happens between the sensor and the screen

A wearable’s job is a translation. Under the case, an optical sensor shines light into your skin and measures what comes back — a noisy waveform, not a heart rate. Turning that into “62 bpm”, and then into “you slept badly and your recovery is low”, takes several layers of processing.

  1. 1Raw signal. Light reflection, motion from the accelerometer, sometimes skin temperature. Meaningless on its own.
  2. 2Cleaned measurement. Filtering out noise, movement artefacts, and a loose strap, producing an actual beats-per-minute figure.
  3. 3Derived metric. Heart rate variability, sleep stages, recovery scores — computed from patterns across hours or days.
  4. 4Interpretation. “You’re under-recovered.” “Your resting rate has drifted up this month.” The part you actually read.

Where those steps happen — on the device, or on a server — is the on-device-vs-cloud question. It is a real engineering choice with real consequences. It is just not the only thing standing between you and a privacy problem.

The three architectures

On-device (local) processing

The watch and your phone do the work, and the results stay in local storage. Nothing needs to be uploaded for the device to function. This is genuinely strong for privacy — there is simply less data anywhere else — and it has become practical only recently, as phones gained the hardware to score sleep or estimate recovery without a data centre.

Its honest costs are real too: analysis limited to your phone’s hardware, improvements that apply going forward rather than to your history, awkward cross-device sync, and the risk of losing everything with a lost phone unless there is a backup — at which point the data is, by definition, no longer only on your device.

Cloud processing

The device sends measurements to the company’s servers, where they are analysed and returned to the app. Most wearables work this way, for reasons that are genuinely practical: heavier models, instant sync, easy backups, the ability to improve analysis for everyone at once, and simpler support.

The trade is that a record of your body exists on a server you don’t control. That is a real fact, and it is true of us. The questions that follow are the ones that actually matter: what is in that record, whose name is on it, who it is shared or sold to, and whether you can make it disappear.

Hybrid

Most real products sit somewhere between — processing some things locally and syncing others. Hybrid is not a cop-out. The honest question is which data crosses the line, in what form, and what the company does with it once it has it.

The four questions that actually decide it

Whether a wearable processes on the device or in the cloud, these are the questions that determine what your data can be used for. Ask them of any tracker, including ours.

  1. 1Is it sold or shared? Not “do you value privacy” — does the policy permit selling, renting, or sharing your data, including “aggregated” or “de-identified” forms, and with whom? A company with an advertising business has a reason to.
  2. 2Is there tracking attached to it? Advertising and analytics SDKs inside an app quietly build a profile alongside your health data. Their absence is something you can actually verify.
  3. 3Is it stored under your name? Data saved under a random identifier, kept apart from your name and email, reveals far less on its own than the same data filed under your identity.
  4. 4Can you delete it? Not in 30 days, not by emailing support — can you erase your account and your history yourself, whenever you decide to?

What “encrypted” does and doesn’t tell you

Virtually every wearable says your data is encrypted, and almost all of them are telling the truth. It settles less than it appears to, because “encrypted” covers three very different situations.

  • Encrypted in transit. Protected while moving between your phone and the server. Universal, and table stakes — it stops eavesdropping on the wire and nothing else.
  • Encrypted at rest. Stored on disk in encrypted form. Protects against someone stealing the physical drive. The company still holds the keys, so it — and anyone who compels or breaches it — can read the data.
  • End-to-end encrypted. Encrypted with keys only your devices hold, so the company stores your data but cannot read it. This is the strong one, and it is expensive and hard, which is why few consumer wearables actually do it.

Here is where we will not overclaim. The Tribe Watch is not end-to-end encrypted — your data runs on Google Firebase with the standard in-transit and at-rest encryption Google Cloud provides, and we can read it to run the app. That is the plain truth, and it is why we don’t lead with encryption. What we lead with instead is what you can check: it is never sold, there are no trackers attached to it, it is stored under a random ID rather than your name, and you can delete it whenever you want.

How to tell what your wearable actually does

Manufacturers rarely put any of this on the box. These checks are reliable:

  1. 1Open the privacy policy and search. Look for “sell”, “share”, “third part”, “de-identified”, “aggregate”, and “merger”. The clauses matter more than the marketing page.
  2. 2Check who the data can be shared with. Some policies name the recipients — advertising partners, “LLM providers”, employers in corporate deployments. That list is the real disclosure.
  3. 3Look at whether there is an advertising business. A company that sells ads has a standing reason to want your data; a company that sells hardware does not.
  4. 4Look at what happens when you delete. A single button that erases your account and history is a very different thing from a support request that “propagates” over weeks.
  5. 5Turn on airplane mode and record something. If metrics still appear, some processing is local; if not, it is cloud. Useful to know — just not the end of the story.
A privacy policy tells you what a company intends to do. An architecture tells you what it is able to do. The strongest position holds as much of the promise as possible in architecture — and is honest about the rest.

Apply it to the wearables people actually buy

A company’s handling of your data tends to follow its revenue. If a business needs your data on its servers to keep charging you, it will keep your data on its servers. Here is what each of the major wearables costs you after the device is in your hands.

WearableCost once you own itHow the money works
Whoop$199–$359 per yearThe band itself is $0. The membership is the product — stop paying and you stop getting your data back.
Oura Ring$69.99/yr on top of a $399 ringOura’s own site states that without a membership “the insights, personal health data, and benefits you receive will be much more limited.”
FitbitFree tier plus a paid Premium tierNow part of Google. Support runs through the Google Health Help Center and Fitbit accounts are being migrated to Google Accounts — so your health data sits inside a company whose primary business is advertising.
Tribe Watch$0. It is $119.99, once.We sell watches. No advertising business, no renewal, and no commercial reason to sell or mine your readings.

Whoop pricing checked 12 August 2026; Oura pricing checked 15 August 2026. Fitbit Premium pricing varies by region and is not quoted here.

Now read the policies attached to those subscriptions. Oura’s — read on 15 August 2026 — lists the parties who may receive your information, and the list includes “LLM providers”. In corporate wellness deployments it includes your employer. It reserves the right to share aggregated or de-identified data without restriction. And it carries the standard change-of-control clause: if the company is sold, your health history is among the assets that move to the buyer.

None of that means Oura is selling your data — its policy explicitly says it does not, and we have no reason to doubt that. That is exactly the point. Every one of those clauses is ordinary, legal and industry-standard. What separates products is not whether the data sits on a server — plenty does, ours included — but whether the company reserves those rights over it in the first place.

To see which side of that line each major brand sits on, we ran all of them through the same five questions.

Why you want as much as possible in architecture

A privacy policy is a statement of present intent from the people currently running the company. It can be amended, it transfers in an acquisition, and it bends under commercial pressure. So the strongest protections are the ones built into how the product works, not just written into what the company promises.

That is the standard we hold ourselves to, honestly. Some of our protections are architecture: there are no advertising or analytics SDKs in the app at all, your scores are stored under a random ID rather than your name, and an anonymous request to our database is refused outright. Some are policy: we don’t sell your data. We can’t pretend the second kind is unbreakable — no company honestly can — so we make it easy to verify and easy to walk away from, with deletion you control. As covered in do fitness trackers sell your data, nearly every real-world failure in this space involved data being used for something the person never agreed to.

There is a hardware side effect worth knowing about. The watch talks only to your phone — we re-flashed it so it never connects to the original manufacturer’s servers — so it needs one Bluetooth radio and no Wi-Fi or cellular. We published the measured figures and how to look up any watch’s own FCC filing — 0.91 milliwatts, against a legal limit of 1,000.

You don’t have to choose our answer. But when you compare wearables, ask the four questions before the on-device-vs-cloud one — because a cloud product that isn’t sold, isn’t tracked, isn’t stored under your name, and can be deleted will often protect you better than an on-device product that quietly does the opposite.

Frequently asked questions

What does on-device processing mean for a smartwatch?
It means the sensor readings are interpreted on the watch and your phone rather than on a company server. Heart rate, sleep and recovery figures are computed locally, so less of your data is stored elsewhere. It is a genuine privacy advantage — but not the only thing that determines who can use your data.
Is on-device processing more private than cloud processing?
Often, but not automatically. On-device keeps less data off your phone, which is a real advantage. But a cloud product that never sells your data, carries no advertising or analytics trackers, stores your records under a random ID rather than your name, and lets you delete everything can be more private in practice than an on-device product that does none of those things. Ask what the data is used for, not only where it is processed.
Does the Tribe Watch process data on-device or in the cloud?
In the cloud. Your data is stored in our database on Google Firebase (Cloud Firestore, in the US), operated by us. We are transparent about that because what protects you is verifiable regardless of architecture: it is never sold, there are no advertising or analytics SDKs in the app, it is saved under a random ID kept separate from your name and email, and you can delete your account and all of it anytime.
What is the difference between encrypted and end-to-end encrypted?
Encryption in transit protects data while it moves; encryption at rest protects it on disk but leaves the keys with the company, so it can still read your data. End-to-end encryption uses keys only your devices hold, meaning the company cannot read what it stores. Few consumer wearables are genuinely end-to-end encrypted — the Tribe Watch is not, and we say so rather than imply otherwise.
How can I tell how private my fitness tracker really is?
Open its privacy policy and search for “sell”, “share”, “de-identified”, “aggregate” and “merger” to see what the company reserves the right to do. Check whether it has an advertising business, whether there are analytics or ad trackers in the app, whether your data is tied to your name, and whether you can delete your account and history yourself in one action rather than by request.
Tribe Watch
The Tribe Watch

Cloud, and honest about it

Your data lives in our database on Google Firebase — locked to your account, saved under a random ID rather than your name, never sold, and with no ad or analytics trackers in the app. $119.99 once, no subscription, delete everything anytime.

  • Never sold, and no ad or analytics trackers in the app
  • Locked to your account, saved under a random ID
  • Erase everything with one tap, whenever you want
  • No subscription for any tracking feature

Private by design. Yours by default.