Provision record
Headspace · Headspace Privacy Policy · View original document ↗

Consumer Health Data Privacy Policy

High severity Unique · 0 of 352 platforms
Stay ahead of the changes
Track Headspace and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

For users in states with consumer health data laws (like Washington's My Health MY Data Act), Headspace has a separate Consumer Health Data Privacy Policy that provides additional protections for your health-related personal information beyond what standard privacy laws require.

This analysis describes what Headspace's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

State consumer health data laws give you stronger rights over sensitive health information collected outside traditional medical settings — including wellness apps — so this provision expands your protections significantly.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@headspace.com to request deletion of your consumer health data or to withdraw consent for its collection and use, referencing the Consumer Health Data Privacy Policy and your state of residence.

Cross-platform context

See how other platforms handle Consumer Health Data Privacy Policy and similar clauses.

Compare across platforms →
ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

Compliance with Washington's My Health MY Data Act (MHMDA) and analogous state laws requires Headspace to obtain consent for collection of consumer health data, provide deletion rights, and restrict sharing without authorization — obligations that …

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Provision details

Document information
Document
Headspace Privacy Policy
Entity
Headspace
Document last updated
May 5, 2026
Tracking information
First tracked
March 20, 2026
Last verified
March 20, 2026
Record ID
CA-P-00216001
Document ID
CA-D-00216
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
b9e0294d40852fc7d7af732cb3ab491f009220676b6a23629173a3df43ff287d
Analysis generated
March 20, 2026 05:35 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Headspace
Document: Headspace Privacy Policy
Record ID: CA-P-00216001
Captured: 2026-03-20 05:35:30 UTC
SHA-256: b9e0294d40852fc7…
URL: https://conductatlas.com/platform/headspace/headspace-privacy-policy/consumer-health-data-privacy-policy/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Headspace's Consumer Health Data Privacy Policy clause do?

State consumer health data laws give you stronger rights over sensitive health information collected outside traditional medical settings — including wellness apps — so this provision expands your protections significantly.

Is ConductAtlas affiliated with Headspace?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Headspace.