Your Fitness App Knows More Than You Think
Ottawa runners, cyclists, and gym-goers who log their workouts on Strava should pay attention to a wild story making the rounds this week, one that turned a simple jog into an international security incident.
A French naval officer stationed aboard the Charles de Gaulle aircraft carrier went for a run around the ship's flight deck and, like millions of fitness enthusiasts worldwide, uploaded the workout to Strava. The problem? The GPS track of his loop neatly outlined the silhouette of one of France's most sensitive military assets, and pinpointed its exact location in the process.
How a Jog Became a Security Breach
Strava, the popular fitness tracking platform used by over 100 million people globally, maps workout routes using GPS data from smartphones and wearables. When that data is set to public, which is the default for many users, anyone can view the route, the location, and even the time it was recorded.
For the French officer, his innocent laps around the deck created a GPS signature that was immediately recognizable as the outline of a Nimitz-class-style carrier. Defense analysts and open-source intelligence researchers quickly identified not just the ship's location, but its movements over time.
The French Navy has not commented publicly on the specific incident, but it is the latest in a long string of cases where fitness app data has inadvertently compromised military operational security.
This Has Happened Before
This isn't the first time Strava has sparked a security scare. Back in 2018, a global heatmap published by the company, showing the aggregate GPS trails of all its users, lit up suspiciously around classified military bases in remote regions of Syria, Afghanistan, and elsewhere, effectively revealing the locations of covert facilities.
That incident prompted militaries around the world, including Canada's, to review their policies on fitness app usage by personnel in sensitive postings.
What Ottawa Users Should Know
For the vast majority of Ottawa residents logging their morning runs along the Rideau Canal or cycling through Gatineau Park, the stakes are obviously much lower than leaking a warship's coordinates. But the incident is a timely reminder about digital privacy that applies to everyone.
Strava's privacy settings are not always intuitive. By default, many accounts share routes publicly, meaning anyone can see where you run, when you run, and, if you run the same route repeatedly, where you likely live or work. The app does offer privacy zones that can hide the start and end points of a route, and accounts can be set to followers-only or completely private.
If you haven't reviewed your Strava privacy settings lately, now is a good time. Ottawa has a huge and active running and cycling community, and most people sharing their workouts do so intentionally, but it's worth making sure your settings reflect what you actually want to share.
The Bigger Picture
The French carrier incident is a vivid illustration of how the always-on, always-connected nature of modern technology can have unintended consequences. Wearables and fitness apps are designed to be frictionless. You just work out, and the data uploads automatically. That convenience is also what makes it easy to forget that your GPS trail is, in essence, a detailed log of your movements.
For military personnel, the lesson is clear. For the rest of us, it's a nudge to think a little more carefully about what our apps are sharing, and with whom.
Source: TechCrunch, March 20, 2026


