Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that Noom collects and analyzes health data including weight, mental state, sleep, exercise habits, and food intake, as well as sensitive demographic data including racial or ethnic origin, religion, and philosophical beliefs, including data inferred rather than directly provided by users.
This analysis describes what Noom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes collection of data categories that qualify as 'special categories' under GDPR Article 9 and as 'sensitive personal information' under CCPA/CPRA, triggering heightened processing requirements and opt-out rights in multiple jurisdictions. The disclosure that sensitive demographic data may be inferred by Noom rather than directly provided by users adds an additional processing layer that may require distinct legal basis evaluation under applicable frameworks.
The agreement authorizes Noom to collect and analyze health and sensitive demographic information, including data inferred from user activity, and to use this data across all stated purposes including product improvement, AI and machine learning development, personalization, marketing, and advertising. Under applicable state and federal frameworks, users in covered jurisdictions may have rights to limit use or disclosure of sensitive personal information beyond what is necessary to provide the Noom service.
Cross-platform context
See how other platforms handle Collection and Use of Sensitive Health Data and similar clauses.
Compare across platforms →Monitoring
Noom has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Health data: We collect and analyze information concerning your health, such as weight, mental state, sleep and exercise habits, and food intake. Sensitive demographic data: We collect information about racial or ethnic origin, religion, or philosophical beliefs that you may provide or we infer throughout the program to better support you.Excerpt from Noom's Privacy Policy
(1) REGULATORY LANDSCAPE: Collection of health data and sensitive demographic data (racial or ethnic origin, religion) engages GDPR Article 9 (special categories of personal data), which generally requires explicit consent or another enumerated lawful basis for processing. Under CPRA, sensitive personal information including health data and racial or ethnic origin is subject to the right to limit use and disclosure. Washington's My Health My Data Act imposes additional consent and deletion requirements for consumer health data. The FTC Act may apply to health data practices of non-HIPAA-covered entities. (2) GOVERNANCE EXPOSURE: High. The collection of inferred sensitive demographic data, in addition to directly provided health data, creates layered exposure. The policy does not specify which GDPR Article 9 lawful basis applies to health or demographic data processing, stating only general bases such as consent and legitimate interests, which may be insufficient for special category data without explicit basis identification. (3) JURISDICTION FLAGS: EEA and UK users face the highest exposure given GDPR Article 9 requirements; Washington state residents are covered by the My Health My Data Act; California residents have CPRA sensitive data rights. Illinois, Texas, and other states with health data provisions may also create exposure depending on user base geography. (4) CONTRACT AND VENDOR IMPLICATIONS: Downstream disclosure of sensitive health and demographic data to advertising and analytics vendors requires data processing agreements that specifically address sensitive data categories. Vendor assessments should confirm that advertising partners have adequate technical and contractual controls for sensitive data received through Noom's data flows. (5) COMPLIANCE CONSIDERATIONS: Legal teams should audit whether explicit consent mechanisms exist for health and sensitive demographic data processing under GDPR Article 9; evaluate whether data minimization principles are satisfied given the breadth of health and demographic data collected; and confirm that data processing agreements with advertising partners address sensitive data handling obligations specific to GDPR, CPRA, and Washington My Health My Data Act.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision authorizes collection of data categories that qualify as 'special categories' under GDPR Article 9 and as 'sensitive personal information' under CCPA/CPRA, triggering heightened processing requirements and opt-out rights in multiple jurisdictions. The disclosure that sensitive demographic data may be inferred by Noom rather than directly provided by users adds an additional processing layer that may require distinct legal …
The agreement authorizes Noom to collect and analyze health and sensitive demographic information, including data inferred from user activity, and to use this data across all stated purposes including product improvement, AI and machine learning development, personalization, marketing, and advertising. Under applicable state and federal frameworks, users in covered jurisdictions may have rights to limit use or disclosure of sensitive …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Noom.