Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy authorizes the company to de-identify user information and use, create, or sell de-identified data for any lawful business purpose, with AI model training cited as an explicit example.
This analysis describes what Hims & Hers's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that de-identified user data, which may include health-related and other sensitive information, can be used to train AI models and sold to third parties, subject to the adequacy of the de-identification process applied and applicable legal standards.
Interpretive note: The adequacy of de-identification standards applied to health-related and sensitive personal information, and whether the de-identified data sale is compliant with HIPAA, CCPA, and other applicable frameworks, cannot be assessed from the document text alone.
The agreement states that de-identified user information including data derived from health-related interactions may be used for AI model training and may be sold, provided the de-identification process meets applicable legal standards. The policy states the company will not attempt to re-identify de-identified data except for limited testing purposes or as permitted by law.
Cross-platform context
See how other platforms handle AI Model Training Using De-identified Data and similar clauses.
Compare across platforms →Monitoring
Hims & Hers has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We may de-identify your information and use, create, and sell such de-identified information for any business or other purpose not prohibited by applicable law. For example, we may use de-identified information for the purpose of training our AI models and AI-supported services.Excerpt from Hims & Hers's Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages HIPAA Safe Harbor and Expert Determination de-identification standards where health information is involved, CCPA and CPRA de-identification provisions, and FTC guidance on de-identification adequacy. The FTC and HHS OCR are relevant enforcement authorities. Emerging state AI governance frameworks and the EU AI Act may engage where AI training data practices are subject to transparency or consent obligations. The adequacy of de-identification applied to health-related browsing data and sensitive personal information requires technical and legal assessment. 2. GOVERNANCE EXPOSURE: Medium. The policy's authorization to sell de-identified data for any lawful business purpose, including to third-party AI developers, depends on the robustness of the de-identification process applied. If de-identification is found inadequate under applicable standards, downstream data uses including AI training could implicate sensitive data obligations. The inclusion of health data and sexual orientation information in the categories of data potentially subject to de-identification and sale adds compliance sensitivity. 3. JURISDICTION FLAGS: California CPRA imposes specific standards for de-identification and prohibits re-identification; the policy's carve-out permitting re-identification for testing purposes should be evaluated against CPRA requirements. HIPAA Expert Determination and Safe Harbor standards apply where PHI is involved. Washington and other states with health data statutes may impose additional requirements on de-identification of health-related consumer data. 4. CONTRACT AND VENDOR IMPLICATIONS: If de-identified data is sold to AI platform vendors or research partners, data sale agreements should address de-identification standards applied, prohibition on re-identification, and downstream data use restrictions. Vendor assessments should confirm that AI training data recipients do not retain contractual or technical capacity to re-identify received data. 5. COMPLIANCE CONSIDERATIONS: Legal and technical teams should assess whether de-identification processes applied to health-related and sensitive personal information meet HIPAA Safe Harbor or Expert Determination standards where applicable; review whether the testing re-identification carve-out in the policy is documented and controlled; and evaluate whether the sale of de-identified AI training data requires disclosure or consent under applicable state AI or privacy frameworks.
This provision establishes that de-identified user data, which may include health-related and other sensitive information, can be used to train AI models and sold to third parties, subject to the adequacy of the de-identification process applied and applicable legal standards.
The agreement states that de-identified user information including data derived from health-related interactions may be used for AI model training and may be sold, provided the de-identification process meets applicable legal standards. The policy states the company will not attempt to re-identify de-identified data except for limited testing purposes or as permitted by law.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Hims & Hers.