Court Denied MyFitnessPal Motion to Dismiss Privacy Suit

A federal judge allowed fraud and wiretapping claims to proceed against the health app in a California privacy case.

Updated on Sept. 30, 2026 in Financial Crime

Bold flat-color editorial illustration showing a stylized geometric courthouse facade, representing legal policy and institutional oversight.
A federal judge ruled that a lawsuit alleging MyFitnessPal engaged in fraudulent data tracking and wiretapping may proceed to trial. AI Illustration. Upload story photo >

Live Poll

Do you trust websites to stop tracking your data once you choose to opt out?

The U.S. District Court for the Northern District of California ruled that a lawsuit against MyFitnessPal over alleged data tracking can move forward. The court denied a motion to dismiss common law fraud and certain privacy claims, though it limited the scope for one plaintiff.

Why it matters

This ruling highlights the legal risks tech companies face when collecting metadata from users who have opted out of tracking cookies. It clarifies that specific allegations of personal data input can be essential for sustaining claims under California privacy statutes.

In the case No. 25-CV-04430-PCP, the court ruled that pleading specific months of usage provided sufficient particularity for fraud claims. While the court dismissed certain wiretapping claims for plaintiff Shah, the litigation continues for plaintiff Wiley.

The players

MyFitnessPal

This is a popular mobile application and website that tracks user nutrition, health goals, and physical activity.

U.S. District Court for the Northern District of California

This is a federal court with jurisdiction over civil and criminal matters in the northern region of California.

The details

Plaintiffs alleged that MyFitnessPal continued to track browsing activity and collected metadata, including UDP port numbers and HTTP request headers, even after users opted out of cookies. The court determined that while browsing activity alone did not constitute a communication, plaintiff Wiley's entry of personal information such as gender and health goals did qualify.

Timeline

  1. February 2024 served as a deadline reference for CIPA claims.

  2. February 2025 served as a deadline reference for invasion of privacy claims.

  3. September 28, 2026 marked the date the court issued the ruling on the motion to dismiss.

Legal Context

This ruling follows the ongoing enforcement trends under the California Invasion of Privacy Act, which regulates how digital entities handle user data. The court's decision signals a broader judicial trend of scrutinizing data collection practices that persist after a user has opted out of tracking.

The ruling underscores the importance for residents to understand how apps collect metadata, as courts are now weighing whether simple browsing counts as a protected communication. Local users should review their privacy settings, as the case sets a precedent for how tech platforms must handle opt-out requests for tracking cookies.

The takeaway

This case reminds consumers that digital platforms may continue collecting metadata even when they opt out of traditional cookies. Protecting your personal data often requires being aware of what information is shared during account registration and goal setting.

Further reading

Learn more about the latest developments in Financial Crime cases across the state.

Source note: This article includes information reported by The National Law Review - A Free To Use Nationwide Database of Legal Publications.

Live Poll

Do you trust websites to stop tracking your data once you choose to opt out?