The policy authorizes the company to de-identify user information and use, create, or sell de-identified data for any lawful business purpose, with AI model training cited as an explicit example.
This analysis describes what Hims & Hers's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that de-identified user data, which may include health-related and other sensitive information, can be used to train AI models and sold to third parties, subject to the adequacy of the de-identification process applied and applicable legal standards.
Interpretive note: The adequacy of de-identification standards applied to health-related and sensitive personal information, and whether the de-identified data sale is compliant with HIPAA, CCPA, and other applicable frameworks, cannot be assessed from the document text alone.
The agreement states that de-identified user information including data derived from health-related interactions may be used for AI model training and may be sold, provided the de-identification process meets applicable legal standards. The policy states the company will not attempt to re-identify de-identified data except for limited testing purposes or as permitted by law.
Cross-platform context
See how other platforms handle AI Model Training Using De-identified Data and similar clauses.
Compare across platforms →"We may de-identify your information and use, create, and sell such de-identified information for any business or other purpose not prohibited by applicable law. For example, we may use de-identified information for the purpose of training our AI models and AI-supported services.Excerpt from Hims & Hers's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that de-identified user data, which may include health-related and other sensitive information, can be used to train AI models and sold to third parties, subject to the adequacy of the de-identification process applied and applicable legal standards.
The agreement states that de-identified user information including data derived from health-related interactions may be used for AI model training and may be sold, provided the de-identification process meets applicable legal standards. The policy states the company will not attempt to re-identify de-identified data except for limited testing purposes or as permitted by law.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Hims & Hers.