Garmin Instinct Series

Garmin Instinct Series

Garmin
Bluetooth

Review date: Nov. 1, 2023

|
|

Mozilla says

|
People voted: A little creepy

These chonky outdoor focused smart watches come in regular, solar powered, a tactical version, a camo version, and even a surfing version. They don't have the fancy touch screens, but they do track all sorts of information about your sleep, stress, heart rate, hike, workout, and help you find your way home if you get lost in the woods. They are rugged and cool. I only say that because this is the smartwatch your favorite *Privacy Not Included reviewer owns and loves. Thanks Garmin for doing a good job keeping my health data all to yourself.

What could happen if something goes wrong?

When your *Privacy Not Included researcher wanted to get a fitness tracking smartwatch to see how stressed out reading privacy policies made her, Garmin is what she went with. Because Garmin seems to do one of the best jobs handling the privacy and security of all the personal data fitness trackers collect, at least according to their really not that stressful privacy policy. (Seriously, companies who have privacy policies, please, look to Garmin as an example of how to do privacy practices and policies right.)

Here’s what this privacy researcher really likes about Garmin. Yes, Garmin's fitness trackers and smartwatches can collect a whole lot of personal information through the device and on the Garmin Connect app. That’s what a fitness trackers and smartwatch are designed to do, that's why we want them. Garmin says they can collect data like email address, device information, location, and all that body-related data like physical activity, stress, sleep patterns, heat rate, pulse ox, and more. Here's the thing. Garmin might collect lots of data, but they then do a pretty good job, as far as we can tell, of respecting it, protecting it, and not trying to make money off sharing or selling it. Gasp! What a wonderful idea.

Your “sharing with others” user settings in the Garmin Connect app are set to “private” by default. Which is great. You can choose to share your data with contacts if you wish, but you have to change your privacy settings to do that. Good work Garmin. Garmin says they don't sell data and they don't share your personal information for advertising purposes with third parties without your consent. They ask you to opt-in rather than opt-out of consent to receive marketing communications from them. And their privacy policy is actually pretty good at laying out what data they collect, clearly explaining why they collect it, and how it is used.

Garmin also seems to do a pretty good job securing the personal information they collect. However, they did suffer that very public ransomware attack in 2020. Ransomware attacks suck and it seems no company is safe from them these days. Good news though, no user data was actually compromised in that attack, so, once more, good work Garmin.

Garmin has been on our Best Of list for a number of years. And we're pleased to say, in 2023, it seems they've gotten even better (which is amazing when so many other companies are getting worse). We were very happy to see that the one gripe we had with Garmin in the past -- the fact that they didn't clearly state they grant all people, regardless of where they live and the privacy laws they live under, the same right to delete their data -- got fixed in 2023.

Garmin actually reached out to us about that and when we pointed out that they didn't clearly state that, they said they would take a look. And now we see this lovely line on their Data Protection Rights page, "Depending on where you reside, you may have rights under applicable laws, subject to conditions and restrictions provided in those laws. Regardless of where you reside, you can access, correct, export, or delete your personal data (including deleting your entire Garmin account) by visiting our Account Management Center." Great work Garmin! This is the kind of care about privacy for everyone, not just the people you're required to grant privacy rights to, that we LOVE to see. (Also, a note to toot our own horn a bit: This is what happen when we point out the issues we see to companies -- sometimes the good ones make change.)

Is your intrepid privacy researcher happy with her decision to get a Garmin fitness tracker? Yes, she is. Although it does make her a little nervous that she now leaves her phone's Bluetooth on all the time. But hey, knowing that body battery score is really cool! And shoot, any smart watch that's good enough for the US Space Force is good enough for us (we joke, we joke!) What’s the worst that could happen with your fun Garmin fitness tracking smartwatch? Well, hopefully nothing, but do beware if you link your data to other third party apps like Strava and MyFitnessPal. Those apps come with their own privacy policies and every time you share your personal information with someone else you increase the vulnerability of that personal information.

Tips to protect yourself

  • Be very careful who you choose to share your Garmin wellness data with.
  • Adjust your privacy settings in the Garmin Connect app to suit your comfort level.
  • Don't connect your Garmin app to any social networks like Facebook, WeChat, etc.
  • When you no longer use the app, go to "Delete account" in the app menu
  • Turn off precise location sharing!
  • Chose a strong password! You may use a password control tool like 1Password, KeePass etc.
  • Use your device privacy controls to limit access to your personal information via app (do not give access to your camera, microphone, images and videos)
  • Keep your app regularly updated
  • Limit ad tracking via your device (eg on iPhone go to Privacy -> Advertising -> Limit ad tracking) and biggest ad networks (for Google, go to Google account and turn off ad personalization)
  • Do not sign up with third-party accounts. Better just log in with email and strong password.
  • Chose a strong password! You may use a password control tool like 1Password, KeePass etc
  • Use your device privacy controls to limit access to your personal information via app (do not give access to your camera, microphone, images, location unless neccessary)
  • Keep your app regularly updated
  • Limit ad tracking via your device (eg on iPhone go to Privacy -> Advertising -> Limit ad tracking) and biggest ad networks (for Google, go to Google account and turn off ad personalization)
  • Request your data be deleted once you stop using the app. Simply deleting an app from your device usually does not erase your personal data.
  • When starting a sign-up, do not agree to tracking of your data if possible.
  • mobile

Can it snoop on me? information

Camera

Device: No

App: Yes

Microphone

Device: No

App: Yes

Tracks location

Device: Yes

App: Yes

What can be used to sign up?

For users in China, WeChat, QQ, or Apple sign-ins are available.

What data does the company collect?

How does the company use this data?

Garmin Privacy Policy

"If you choose to enable your account to access accounts you have with other app providers, such as your MyFitnessPal, Strava, or TrainingPeaks account, we will obtain information about you from such account, such as the number of calories consumed in a particular day based on information from your MyFitnessPal account or courses and segments from your Strava account."

"If you provide your opt-in consent to receiving marketing information from us, we will also process your email address for the purpose of sending you marketing information about our products, services, and apps, as well as newsletters. The legal ground for processing your email address for this purpose is your consent. You may withdraw your consent at any time by changing your preferences in your account or through the unsubscribe link at the bottom of our marketing emails. The marketing emails you receive from us are based on the preferences you provide in your account, the locale indicated by your Internet Protocol (IP) address, the types of devices you have added to your account, and any subscriptions included in your account. The legal ground for processing this data for this purpose is our legitimate interest in reducing the number of marketing emails sent to each particular customer by selecting which customers receive a particular marketing email rather than sending every marketing email to every customer who has consented to receiving marketing emails. If you reside in mainland China, we may use your mobile phone number to send you marketing communications via SMS."

According to Garmin written statement to us, "Garmin doesn’t share any data collected from a user’s device with third parties unless the user directs us to do so. Some users wish to connect their Garmin accounts with their accounts on other platforms, such as Strava or MyFitnessPal, and we share a user’s data with such other platforms if directed to do so by a user."

Garmin Connect Privacy Policy
"If you choose to authorize us to permit a third party, such as your wellness program provider, or an app, such as MyFitnessPal, Strava, or TrainingPeaks, to access your activity data in your Garmin account, then we will share such data with the third party. We will not do this without your explicit consent. Once you direct us to share data with a third party, the third party's handling of your personal data is the responsibility of that third party, and you should carefully review the third party's privacy policy. You can choose to stop sharing data with the third-party app, platform, or service provider at any time within your Garmin account."

"We may process and disclose personal data about you to others: (a) if we have your valid consent to do so; (b) to comply with legal and regulatory obligations, such as a valid subpoena, court or judicial order, other valid legal process, or record keeping to support applicable reporting and auditing requirements; (c) to investigate potential fraud and enforce any of our terms and conditions or policies; (d) as necessary to pursue available legal remedies or defend legal claims; or (e) as we deem necessary or appropriate for purposes of attempting to get you help in the event you are involved in an emergency situation."

How can you control your data?

Data Protection Rights page
"Regardless of where you reside, you can access, correct, export, or delete your personal data (including deleting your entire Garmin account) by visiting our Account Management Center."

Privacy Policy for Garmin Connect and Compatible Garmin Devices

"We will retain your personal data as long as your Garmin account is considered to be active or in accordance with applicable law and regulatory obligations. In addition, see below under “Manage Your Data” for information on how to delete your data or account."

"We provide a self-service portal, the Account Management Center, to allow you to access, export, correct, or delete your data at any time. The Account Management Center requires you to sign in with your Garmin credentials to ensure that only you can manage your data and exercise your rights."

What is the company’s known track record of protecting users’ data?

Average

They did suffer that very public ransomware attack in 2020. No user data was compromised during this attack.

Child Privacy Information

We request individuals under the age of 13 in the U.S. and under the age of 16 in the rest of the world not provide personal data to Garmin. If we learn that we have collected personal data from a child under the age of 13 in the U.S. or under 16 in the rest of the world, we will take steps to delete the information as soon as possible.

Can this product be used offline?

Yes

User-friendly privacy information?

Yes

Garmin has an easy to find list of all privacy policies. The privacy policies are relatively easy to find and simple to read.

Links to privacy information

Does this product meet our Minimum Security Standards? information

Yes

Encryption

Yes

Garmin devices and apps use a combination of asymmetric and symmetric encryption appropriate to the nature and function of the product, and data stored/transmitted.

Strong password

Yes

In order to use companion apps, an account with a strong password is required.

Security updates

Yes

Manages vulnerabilities

Yes

Privacy policy

Yes

Does the product use AI? information

Yes

Garmin uses Machine Learning (ML) to provide personalized insights to customers who wish to receive them as they pursue their fitness and wellness goals.

Is this AI untrustworthy?

Can’t Determine

What kind of decisions does the AI make about you or for you?

Garmin says in their privacy policy, "Garmin does not make any decisions based on algorithms or other automated processing that significantly affect you."

Is the company transparent about how the AI works?

Yes

Does the user have control over the AI features?

Yes

*privacy not included

Dive Deeper

  • Thousands of Garmin Smartwatches Being Used to Test Space Force Fitness Program
    Military.com News Link opens in a new tab
  • Garmin’s New Aviator Watch Partly Addresses a Risk the War in Ukraine Is Highlighting – Microtargeting
    Forbes Link opens in a new tab
  • Stop Leaving Your Smartphone's Bluetooth On
    Lifehacker Link opens in a new tab
  • A Cyberattack on Garmin Disrupted More Than Workouts
    Wired Link opens in a new tab
  • Ransomware attack on Garmin thought to be the work of 'Evil Corp'
    The Guardian Link opens in a new tab
  • The Garmin Hack Was a Warning
    Wired Link opens in a new tab
  • The Garmin Security Breach: Here’s What You Need to Know
    Terra Nova Link opens in a new tab

Comments

Got a comment? Let us hear it.