Noom · Noom Privacy Policy · View original document ↗

Sensitive Health Data Collection

Medium severity High confidence Explicitdocumentlanguage Rare · 2 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Noom Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Noom collects detailed health information including your weight, food logs, BMI, exercise habits, and sleep patterns when you use the app.

This analysis describes what Noom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Health data is among the most sensitive categories of personal information; its collection and potential sharing creates meaningful privacy exposure for users.

Consumer impact (what this means for users)

Weight, food logs, BMI, and exercise data you enter into Noom are collected and may be used for purposes beyond delivering the service, including personalization and sharing with third parties. Users who are concerned about the sensitivity of this data should review Noom's data sharing practices and consider exercising deletion rights.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@noom.com requesting deletion of your health data, specifying the categories of data you want removed and your account details.

How other platforms handle this

Strava Medium

If we collect health information from these integrations (such as heart rate), we will not sell or use it for advertising or other similar purposes; we do not disclose it to third parties without your prior consent; and we will only use it for the specific purposes described in this Policy.

Calm Medium

With your permission, we may also receive data from your mobile device's health app (like Apple HealthKit or Google Health Connect), including hours of sleep and sleep goals. However, we do not infer any health-related characteristics from this information and only process it consistent with the pur...

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

See all platforms with this clause type →

Monitoring

Noom has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We collect information you provide when you use our Services, including: Health and fitness information, such as height, weight, body mass index (BMI), food logs, exercise habits, sleep patterns, and other health-related information you choose to share with us.

— Excerpt from Noom's Noom Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: Health and fitness data falls within the definition of sensitive personal information under CPRA for California residents, triggering additional rights and potential opt-in consent requirements; under GDPR, health data constitutes a special category of personal data under Article 9, requiring explicit consent or another enumerated lawful basis for processing; Washington State's My Health MY Data Act may also apply to the extent Noom collects consumer health data from Washington residents; the FTC has issued guidance on health data privacy and has taken enforcement action against health app operators under Section 5 of the FTC Act. GOVERNANCE EXPOSURE: High. The collection of weight, food logs, BMI, and behavioral health patterns from a large consumer base creates significant regulatory exposure across multiple US state privacy frameworks and GDPR; the breadth of health data categories collected, combined with downstream sharing with third parties, represents a materially elevated compliance obligation relative to non-health applications. JURISDICTION FLAGS: California (CPRA sensitive data provisions), Washington State (My Health MY Data Act), EU/EEA (GDPR Article 9 special categories), UK (UK GDPR equivalent provisions); users in these jurisdictions have heightened rights and the applicable legal standards for processing this data are more stringent than general personal data. CONTRACT AND VENDOR IMPLICATIONS: Any vendor or employer procuring Noom as a wellness solution should assess whether health data collected by Noom flows into their own data ecosystems; data processing agreements with Noom should specify restrictions on secondary use of employee health data; procurement teams should verify that Noom's vendor contracts with downstream analytics and advertising partners include appropriate health data protections. COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a data mapping exercise to confirm all health data categories collected are accurately reflected in Records of Processing Activities; consent mechanisms for health data collection should be reviewed to confirm they satisfy the explicit consent standard under GDPR and opt-in requirements under applicable US state laws; a data protection impact assessment (DPIA) may be warranted given the sensitivity of the data processed at scale.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over unfair and deceptive practices related to health data collection and sharing by consumer app operators.
    File a complaint →
  • State AG
    State attorneys general enforce CPRA (California), My Health MY Data Act (Washington), and other state health and consumer privacy laws applicable to this data.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
HIPAA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Noom Privacy Policy
Entity
Noom
Document last updated
May 5, 2026
Tracking information
First tracked
April 28, 2026
Last verified
May 10, 2026
Record ID
CA-P-003844
Document ID
CA-D-00397
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
05252f553ca6864667d2e582f332534d7ecc993e8e01284deda5add6a0607bb0
Analysis generated
April 28, 2026 06:52 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Noom
Document: Noom Privacy Policy
Record ID: CA-P-003844
Captured: 2026-04-28 06:52:27 UTC
SHA-256: 05252f553ca68646…
URL: https://conductatlas.com/platform/noom/noom-privacy-policy/sensitive-health-data-collection/
Accessed: June 17, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Noom's Sensitive Health Data Collection clause do?

Health data is among the most sensitive categories of personal information; its collection and potential sharing creates meaningful privacy exposure for users.

How does this clause affect you?

Weight, food logs, BMI, and exercise data you enter into Noom are collected and may be used for purposes beyond delivering the service, including personalization and sharing with third parties. Users who are concerned about the sensitivity of this data should review Noom's data sharing practices and consider exercising deletion rights.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 2 platforms. See the full comparison.

Is ConductAtlas affiliated with Noom?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Noom.