Headspace · Headspace Privacy Policy · View original document ↗

Consumer Health Data Privacy Policy (State Law)

High severity Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Headspace Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.

This analysis describes what Headspace's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This dual-framework approach creates separate regulatory pathways depending on the type of health data and the legal status of the entity collecting it. The distinction determines which privacy standards and notice requirements apply to different categories of user health information processed through the platform.

Consumer impact (what this means for users)

Users' health data is governed by different privacy policies depending on whether it falls under state consumer health data laws or HIPAA. If a user's data involves a Headspace Care Provider who is a HIPAA-covered entity, the HIPAA Notice of Privacy Practices establishes the applicable privacy protections; otherwise, the Consumer Health Data Privacy Policy applies.

How other platforms handle this

Strava Medium

If we collect health information from these integrations (such as heart rate), we will not sell or use it for advertising or other similar purposes; we do not disclose it to third parties without your prior consent; and we will only use it for the specific purposes described in this Policy.

Calm Medium

With your permission, we may also receive data from your mobile device's health app (like Apple HealthKit or Google Health Connect), including hours of sleep and sleep goals. However, we do not infer any health-related characteristics from this information and only process it consistent with the pur...

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

See all platforms with this clause type →

Monitoring

Headspace has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Our Consumer Health Data Privacy Policy applies to certain consumer health data that is regulated under applicable state consumer health data laws. Our HIPAA Notice of Privacy Practices applies to protected health information ('PHI') collected in connection with our Services where our Care Providers are covered entities under HIPAA.

— Excerpt from Headspace's Headspace Privacy Policy

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
HIPAA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Headspace Privacy Policy
Entity
Headspace
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 10, 2026
Record ID
CA-P-006419
Document ID
CA-D-00216
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c1c69938a2255531d9160216a80441cc6e236ee7a78005f747b818b71812b907
Analysis generated
May 8, 2026 10:00 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Headspace
Document: Headspace Privacy Policy
Record ID: CA-P-006419
Captured: 2026-05-08 10:00:58 UTC
SHA-256: c1c69938a2255531…
URL: https://conductatlas.com/platform/headspace/headspace-privacy-policy/consumer-health-data-privacy-policy-state-law/
Accessed: June 10, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Headspace's Consumer Health Data Privacy Policy (State Law) clause do?

This dual-framework approach creates separate regulatory pathways depending on the type of health data and the legal status of the entity collecting it. The distinction determines which privacy standards and notice requirements apply to different categories of user health information processed through the platform.

How does this clause affect you?

Users' health data is governed by different privacy policies depending on whether it falls under state consumer health data laws or HIPAA. If a user's data involves a Headspace Care Provider who is a HIPAA-covered entity, the HIPAA Notice of Privacy Practices establishes the applicable privacy protections; otherwise, the Consumer Health Data Privacy Policy applies.

Is ConductAtlas affiliated with Headspace?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Headspace.