Provision record
Noom · Noom Privacy Policy · View original document ↗

AI and Machine Learning Development Use of All Data Categories

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Noom changes these terms. Follow Noom →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Noom Monitor emails you the same day this changes. The archive stays free.
Follow Noom →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy authorizes Noom to use all collected data categories, including sensitive information such as health data, sensitive demographic data, account credentials, and in-app communications content, for the development of AI and machine learning products and services.

This analysis describes what Noom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision authorizes use of the full scope of collected sensitive data, including health data and demographic data, for AI and machine learning development purposes, which extends beyond the direct service delivery context and may require distinct legal basis evaluation under GDPR Article 9 and emerging AI governance frameworks.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this provision, all data categories Noom collects, including health data, sensitive demographic data, and in-app communications, may be used to develop new AI and machine learning products and services, not only to deliver the existing Noom service. This use is listed as a stated purpose applicable to sensitive information categories.

Cross-platform context

See how other platforms handle AI and Machine Learning Development Use of All Data Categories and similar clauses.

Compare across platforms →

Monitoring

Noom has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Noom → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Product improvement, development, and research. To improve our products and services and develop new products and services (including AI/ML) and conduct user research (surveys, interviews). Contact information, demographic data, payment information, content and files, identifiers and device information, geolocation data, log data, usage data, sensor data, inferences. Sensitive Information: Account access information, sensitive demographic data, contents of communications, health data.

Excerpt from Noom's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: Use of sensitive personal data for AI and machine learning development engages GDPR Articles 5, 6, and 9 (lawfulness, purpose limitation, and special categories); the EU AI Act to the extent AI systems developed using this data are deployed in the EEA; CPRA provisions on use of sensitive personal information; and potentially the FTC Act's prohibition on deceptive practices if AI development use is not clearly communicated to users. The purpose limitation principle under GDPR requires that data be used only for purposes compatible with the original collection purpose, which may require evaluation where health data collected for wellness coaching is repurposed for AI product development. (2) GOVERNANCE EXPOSURE: High. The use of health and sensitive demographic data for AI/ML development is a materially distinct purpose from service delivery. GDPR's purpose limitation and data minimization principles, and CPRA's restrictions on use of sensitive personal information, may constrain the breadth of this authorization as asserted in the policy. (3) JURISDICTION FLAGS: EEA and UK (GDPR purpose limitation and Article 9 for special categories); California (CPRA right to limit use of sensitive personal information); Washington (My Health My Data Act). The EU AI Act may also create obligations depending on the risk classification of AI systems developed using this data. (4) CONTRACT AND VENDOR IMPLICATIONS: If third-party vendors or research partners participate in AI/ML development using Noom user data, data processing agreements must address the sensitive data categories involved and confirm purpose limitation compliance. (5) COMPLIANCE CONSIDERATIONS: Legal teams should evaluate whether the legal basis supporting health data collection for service delivery is sufficient to extend to AI/ML development purposes; whether separate consent is required for this use in GDPR-covered jurisdictions; and whether data minimization and pseudonymization controls are applied when using sensitive data for AI development.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has authority to evaluate whether AI development use of sensitive health data is adequately disclosed and whether data practices meet consumer protection standards under the FTC Act.
    File a complaint →

Provision details

Document information
Document
Noom Privacy Policy
Entity
Noom
Document last updated
May 5, 2026
Tracking information
First tracked
April 28, 2026
Last verified
July 9, 2026
Record ID
CA-P-014861
Document ID
CA-D-00397
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
fda3dc10dae1f5bff4e6c09096e6999baa24395c2dd36eadf4b77fef91c03e0f
Analysis generated
April 28, 2026 06:52 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Noom
Document: Noom Privacy Policy
Record ID: CA-P-014861
Captured: 2026-04-28 06:52:27 UTC
SHA-256: fda3dc10dae1f5bf…
URL: https://conductatlas.com/platform/noom/noom-privacy-policy/provision/CA-P-014861/ai-and-machine-learning-development-use-of-all-data-categories/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Noom's AI and Machine Learning Development Use of All Data Categories clause do?

This provision authorizes use of the full scope of collected sensitive data, including health data and demographic data, for AI and machine learning development purposes, which extends beyond the direct service delivery context and may require distinct legal basis evaluation under GDPR Article 9 and emerging AI governance frameworks.

How does this clause affect you?

Under this provision, all data categories Noom collects, including health data, sensitive demographic data, and in-app communications, may be used to develop new AI and machine learning products and services, not only to deliver the existing Noom service. This use is listed as a stated purpose applicable to sensitive information categories.

Is ConductAtlas affiliated with Noom?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Noom.