Hims & Hers · Hims & Hers Privacy Policy · View original document ↗

Data Retention

Medium severity Medium confidence Explicitdocumentlanguage Common · 137 of 352 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Hims & Hers Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

The policy states that personal information is retained as long as necessary for stated purposes including service delivery, legal compliance, dispute resolution, and agreement enforcement, without specifying fixed retention periods for particular data categories.

This analysis describes what Hims & Hers's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The absence of specific retention periods for particular data categories, including health and medical information, creates ambiguity about how long sensitive data is held and limits the practical predictability of data deletion requests.

Interpretive note: The document does not specify retention periods by data category, creating ambiguity about compliance with CPRA's retention disclosure requirements.

Consumer impact (what this means for users)

This provision establishes that personal information including health data is retained for unspecified durations determined by the company based on stated purposes. Users who submit deletion requests may find that certain data is retained under legal obligation or dispute resolution exceptions.

Cross-platform context

See how other platforms handle Data Retention and similar clauses.

Compare across platforms →

Monitoring

Hims & Hers has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including to provide our Services, comply with legal obligations, resolve disputes, and enforce our agreements. The specific retention period depends on the type of information and the purposes for which it is used.

— Excerpt from Hims & Hers's Hims & Hers Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1) REGULATORY LANDSCAPE: CPRA requires that retention periods be disclosed in the privacy policy for each category of personal information. Vague retention language without category-specific periods may not satisfy this CPRA disclosure requirement. HIPAA also requires covered entities to retain certain health records for minimum periods specified by state law. 2) GOVERNANCE EXPOSURE: Medium. The absence of specific retention periods is a common compliance gap under CPRA. Regulators have indicated that vague retention language may not meet the specificity required by the statute. 3) JURISDICTION FLAGS: California CPRA requires disclosure of retention periods or criteria used to determine retention for each personal information category. This creates heightened exposure for California users. GDPR (applicable to EU users covered by regional policies) similarly requires specification of retention periods or criteria. 4) CONTRACT AND VENDOR IMPLICATIONS: Vendor data processing agreements should mirror the company's retention framework and require deletion of personal information when the company's retention period ends. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should develop and publish category-specific retention schedules to satisfy CPRA disclosure requirements, and confirm that retention periods for health and medical information account for applicable HIPAA and state medical records retention requirements.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 3 platforms — free Get Monitor

Free: track 3 platforms + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • State AG
    California Privacy Protection Agency enforces CPRA's requirement to disclose retention periods for personal information categories.
    File a complaint →

Provision details

Document information
Document
Hims & Hers Privacy Policy
Entity
Hims & Hers
Document last updated
July 5, 2026
Tracking information
First tracked
July 5, 2026
Last verified
July 5, 2026
Record ID
CA-P-013280
Document ID
CA-D-00907
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
b8d8a749b829206ea447774fc34efb6510397ba35713344941241037d807a11c
Analysis generated
July 5, 2026 02:24 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Hims & Hers
Document: Hims & Hers Privacy Policy
Record ID: CA-P-013280
Captured: 2026-07-05 02:24:07 UTC
SHA-256: b8d8a749b829206e…
URL: https://conductatlas.com/platform/hims-hers/hims-hers-privacy-policy/data-retention/
Accessed: July 5, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Hims & Hers's Data Retention clause do?

The absence of specific retention periods for particular data categories, including health and medical information, creates ambiguity about how long sensitive data is held and limits the practical predictability of data deletion requests.

How does this clause affect you?

This provision establishes that personal information including health data is retained for unspecified durations determined by the company based on stated purposes. Users who submit deletion requests may find that certain data is retained under legal obligation or dispute resolution exceptions.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 137 platforms. See the full comparison.

Is ConductAtlas affiliated with Hims & Hers?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Hims & Hers.