Calm · Calm Privacy Policy · View original document ↗

Health App Data Collection (Apple HealthKit and Google Health Connect)

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Calm Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

If you give Calm permission, it can access your sleep data from your phone's health app, and it states it will only use that data for its original purpose without drawing health conclusions from it.

This analysis describes what Calm's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Sleep data from health apps is sensitive personal information; while Calm states it limits use of this data to its original purpose, users should understand what they are consenting to when granting health app access.

Interpretive note: The policy's commitment to process health app data only for its original purpose is an assertion that depends on operational controls not visible in the policy text; its practical enforceability and scope relative to the broader sharing provisions is uncertain.

Consumer impact (what this means for users)

Granting Calm access to Apple HealthKit or Google Health Connect shares your sleep hours and goals with Calm; the policy states this data is not used to infer health characteristics, but it does become part of Calm's data holdings subject to the broader policy.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email support@calm.com to request deletion of any health app data Calm holds about you, and separately revoke Calm's access to your health app in your device's privacy settings.

How other platforms handle this

PlanetScale Medium

When you visit the Careers portion of our websites, we collect the information that you provide to us in connection with your job application. This includes but is not limited to business and personal contact information, professional credentials and skills, educational and work history and other in...

American Airlines Medium

American does not knowingly collect personal information directly from children – persons under the age of 13, or another age if required by applicable law – other than when required to comply with the law or for safety and security reasons. Due to the nature of our Services, we may collect travel i...

GOAT Medium

We may collect information about your location, including precise geolocation information, when you use our Services. We use this information to provide location-based services, such as showing you products available in your area, and for other purposes described in this Privacy Policy.

See all platforms with this clause type →

Monitoring

Calm has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
With your permission, we may also receive data from your mobile device's health app (like Apple HealthKit or Google Health Connect), including hours of sleep and sleep goals. However, we do not infer any health-related characteristics from this information and only process it consistent with the purpose for which it was originally provided.

— Excerpt from Calm's Calm Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: Health app data from Apple HealthKit and Google Health Connect may constitute health data or sensitive personal information under GDPR, CPRA, and various state privacy laws. HIPAA applicability is unlikely given Calm's positioning as a consumer wellness app rather than a covered entity or business associate, but teams should confirm this analysis. The CPRA classifies health and medical information as sensitive personal information subject to heightened protections. The FTC's health breach notification rule may also be relevant depending on the nature of the data and any future breach scenarios. (2) GOVERNANCE EXPOSURE: Medium. Calm's commitment to process this data only for its original purpose is a meaningful limitation, but its operational enforceability depends on technical and organizational controls. The breadth of the broader policy's disclosure and sharing provisions could create tension with this commitment if health app data is not clearly segregated in data systems. (3) JURISDICTION FLAGS: EU/EEA users: health data is a special category under GDPR Article 9, requiring explicit consent and heightened protections. California users: health and medical information is sensitive personal information under CPRA, triggering additional disclosure and opt-out obligations. Illinois and other states with health data statutes may also apply depending on user location. (4) CONTRACT AND VENDOR IMPLICATIONS: Apple's HealthKit developer guidelines and Google's Health Connect policies impose independent restrictions on how developers may use health data, including prohibitions on sharing with advertising platforms. Compliance teams should confirm that Calm's data flows to third-party service providers do not include Apple HealthKit or Google Health Connect data in ways that would violate platform policies or applicable law. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should audit whether Apple HealthKit and Google Health Connect data is technically segregated from advertising and analytics data pipelines. Consent collection for health app data access should be reviewed to ensure it is specific, informed, and revocable. Data mapping should confirm that this data category is not shared with advertising or analytics partners.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive practices relating to health data collection and use by consumer applications, and enforces the Health Breach Notification Rule for certain consumer health apps.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
HIPAA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Calm Privacy Policy
Entity
Calm
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 11, 2026
Record ID
CA-P-009937
Document ID
CA-D-00218
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
6b81368a982bdbc72c1c75ee7ed70374d68d979bedcaaa382c4440f59aef9243
Analysis generated
May 8, 2026 12:04 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Calm
Document: Calm Privacy Policy
Record ID: CA-P-009937
Captured: 2026-05-08 12:04:34 UTC
SHA-256: 6b81368a982bdbc7…
URL: https://conductatlas.com/platform/calm/calm-privacy-policy/health-app-data-collection-apple-healthkit-and-google-health-connect/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Calm's Health App Data Collection (Apple HealthKit and Google Health Connect) clause do?

Sleep data from health apps is sensitive personal information; while Calm states it limits use of this data to its original purpose, users should understand what they are consenting to when granting health app access.

How does this clause affect you?

Granting Calm access to Apple HealthKit or Google Health Connect shares your sleep hours and goals with Calm; the policy states this data is not used to infer health characteristics, but it does become part of Calm's data holdings subject to the broader policy.

Is ConductAtlas affiliated with Calm?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calm.