10 Total
0 High severity
7 Medium severity
3 Low severity
Summary

This document establishes Calm's data collection, use, and sharing practices for users of its meditation and sleep application. Calm collects personal data including sleep patterns, mood check-ins, meditation history, and health app data, and the policy authorizes use of this data for behavioral advertising on other platforms through advertising partners. The policy establishes opt-out mechanisms available through calm.com/optout, cookie preference settings, and device-level ad tracking controls.

Technical / Legal Breakdown

This document is Calm.com, Inc.'s Privacy Policy (last updated December 12, 2024), governing the collection, use, and disclosure of personal data across Calm's websites, mobile applications, and related services, with stated legal bases including contractual performance, legitimate interests, and consent depending on the processing activity. The policy states that Calm collects a broad range of data including identifiers, health-adjacent data (sleep habits, moods, check-in reflections), device and usage data, inferred characteristics such as gender and age estimates, and third-party health app data (Apple HealthKit, Google Health Connect); the terms authorize disclosure of this data to service providers, advertising partners, analytics providers, and affiliated entities, and permit use for behavioral advertising and cross-platform ad targeting. Notably, the policy discloses that Calm may convert email addresses or phone numbers into advertising identifiers for cross-platform ad targeting, and that it makes educated guesses about user gender or age from derived data; while these practices are disclosed, their interaction with GDPR's requirements around inferred sensitive data and the CCPA's definition of sensitive personal information may require further evaluation depending on jurisdiction. The policy explicitly engages GDPR (citing Standard Contractual Clauses and adequacy decisions for international transfers), the California Consumer Privacy Act as amended (CPRA), and the UK GDPR, with Calm.com, Inc. designated as data controller and named EU and UK DPO representatives identified; California consumers and EU/EEA/UK users receive materially distinct disclosures and rights, and compliance teams should note the policy's reliance on legitimate interests as a legal basis for marketing and analytics processing, which faces heightened scrutiny under GDPR.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
Medium — 7 provisions
Low — 3 provisions

Monitoring

Calm has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Behavioral Advertising as Data Sale or Sharing and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
HIPAA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 19, 2026 06:18 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000218
Version ID CA-V-000749
SHA-256 8ed73dc0c7bd8d40dc9579c58c758f8df55f0ae2f39eaa5850c285c267924182
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans