Headspace · Headspace Privacy Policy · View original document ↗

Collection of Sensitive Health and Mental Health Information

High severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Headspace recorded 2 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Headspace Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Headspace collects detailed health information including mental health history, medications, emotional state, and stress levels that you provide directly when using its services.

This analysis describes what Headspace's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This is among the most sensitive categories of personal data, and its collection by a consumer app with both clinical and non-clinical features means different parts of the same dataset may be subject to materially different legal protections depending on how they were generated.

Consumer impact (what this means for users)

When you provide information about your mental health history, medications, or emotional state through Headspace, this data is collected and may be used for service delivery, personalization, and potentially analytics purposes; clinical health data collected through therapy or psychiatry features is protected by HIPAA, while similar data collected through coaching or wellness features may be subject to broader sharing permissions under the general privacy policy.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Email help@headspace.com to request access to or a copy of the personal and health information Headspace holds about you, specifying the data categories you wish to access.

Cross-platform context

See how other platforms handle Collection of Sensitive Health and Mental Health Information and similar clauses.

Compare across platforms →

Monitoring

Headspace has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We collect personal information that you provide to us such as... health and medical information, including mental health information, information about your physical health, medical history, health conditions, medications, and similar information... information about your emotional state, stress levels, and other mental wellness information.

— Excerpt from Headspace's Headspace Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: Collection of mental health and medical data implicates HIPAA for clinical contexts, GDPR Article 9 (explicit consent required for special category health data) for EU users, CPRA's sensitive personal information framework for California users (which includes mental health data and requires a specific notice and opt-out right for use beyond necessary purposes), and state consumer health data laws. The FTC's health breach notification rule may apply if health information collected by a personal health record application is disclosed without authorization. GOVERNANCE EXPOSURE: High. The collection of mental health data including medications, emotional state, and mental health history in a consumer app context creates significant regulatory exposure because the same categories of data may be governed by different regimes depending on the feature through which they were collected. Data minimization requirements under GDPR and the sensitivity-based restrictions under CPRA require careful scoping of collection purposes and retention limits. JURISDICTION FLAGS: EU and UK users have the strongest protections via GDPR Article 9, which requires explicit consent for health data processing. California users are protected by CPRA's sensitive personal information rules. Washington State users may have rights under the My Health MY Data Act for health data collected outside HIPAA contexts. Healthcare-adjacent mental health data may also engage state mental health confidentiality statutes in various US jurisdictions. CONTRACT AND VENDOR IMPLICATIONS: Any vendor receiving this category of data must be assessed for appropriate data processing agreements under GDPR and HIPAA BAA requirements where applicable. Vendors providing analytics or advertising services should not receive mental health or medication data, and data minimization controls should be verified in vendor contracts. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm that consent mechanisms for collection of mental health and health data are differentiated by service context (clinical vs. non-clinical), that data retention periods for this category are defined and implemented, and that cross-border transfers of health data to non-adequate countries have appropriate safeguards under GDPR Chapter V. A data protection impact assessment may be warranted for large-scale processing of special category health data under GDPR Article 35.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • Hhs Ocr
    HHS OCR enforces HIPAA protections for mental health and medical data collected in clinical service contexts where Headspace operates as a business associate
    File a complaint →
  • FTC
    The FTC has authority over unfair or deceptive practices involving health data collected by consumer apps and enforces the Health Breach Notification Rule for personal health record applications
    File a complaint →

Provision details

Document information
Document
Headspace Privacy Policy
Entity
Headspace
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 10, 2026
Record ID
CA-P-009698
Document ID
CA-D-00216
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c1c69938a2255531d9160216a80441cc6e236ee7a78005f747b818b71812b907
Analysis generated
May 8, 2026 10:00 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Headspace
Document: Headspace Privacy Policy
Record ID: CA-P-009698
Captured: 2026-05-08 10:00:58 UTC
SHA-256: c1c69938a2255531…
URL: https://conductatlas.com/platform/headspace/headspace-privacy-policy/collection-of-sensitive-health-and-mental-health-information/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Headspace's Collection of Sensitive Health and Mental Health Information clause do?

This is among the most sensitive categories of personal data, and its collection by a consumer app with both clinical and non-clinical features means different parts of the same dataset may be subject to materially different legal protections depending on how they were generated.

How does this clause affect you?

When you provide information about your mental health history, medications, or emotional state through Headspace, this data is collected and may be used for service delivery, personalization, and potentially analytics purposes; clinical health data collected through therapy or psychiatry features is protected by HIPAA, while similar data collected through coaching or wellness features may be subject to broader sharing permissions …

Is ConductAtlas affiliated with Headspace?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Headspace.