Noom · Noom Terms of Service

Health and Wellness Data Collection

High severity
Share 𝕏 Share in Share 🔒 PDF

What it is

When you use Noom, you share sensitive health details like your weight, food diary, and exercise habits. Noom collects and uses this data for its services and improvements, and explicitly tells you this data is NOT protected by HIPAA.

Consumer impact (what this means for users)

Your sensitive health data — including weight, food intake, and physical activity — is collected by Noom but does not receive HIPAA protections, meaning Noom has greater latitude to share or use this data with partners and advertisers than a doctor or hospital would have with your medical records.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a data deletion request to Noom's privacy team at privacy@noom.com, referencing your account email address and requesting deletion of all health and personal data under applicable privacy law (CCPA for California residents, GDPR for EU users).

Cross-platform context

See how other platforms handle Health and Wellness Data Collection and similar clauses.

Compare across platforms →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

Noom explicitly disclaims HIPAA protection for your health data, meaning your weight, nutrition, and fitness information can be used and shared under less restrictive rules than medical records — this is a significant privacy gap many users do not expect.

View original clause language
By using the Services, you may provide us with certain personal information, including health and wellness information such as your weight, height, food intake, physical activity, and other health-related data. You consent to Noom collecting, storing, and using this information to provide and improve the Services, and as described in our Privacy Policy. Noom is not a covered entity under HIPAA, and the health information you provide is not protected health information under HIPAA.

Institutional analysis (Compliance & legal intelligence)

REGULATORY FRAMEWORK: This provision engages the FTC Health Breach Notification Rule (16 CFR Part 318), which applies to non-HIPAA health apps and requires notification to users and the FTC in the event of unauthorized access to individually identifiable health information — the FTC has actively enforced this rule against health apps since 2023. CCPA/CPRA (Cal. Civ. Code §1798.100) classifies health and medical information as sensitive personal information requiring explicit opt-in consent for use beyond primary purpose. GDPR Art. 9 treats health data as a special category requiring explicit consent (Art. 9(2)(a)) for EU users. The document's explicit disclaimer of HIPAA coverage, while legally accurate for a wellness app, may not eliminate FTC jurisdiction over deceptive data practices.

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • FTC
    The FTC has enforcement authority over health data practices for non-HIPAA covered wellness apps under the FTC Health Breach Notification Rule (16 CFR Part 318) and FTC Act Section 5.
    File a complaint →
  • Hhs Ocr
    While Noom disclaims HIPAA coverage, users who believe their health data has been misused may consult HHS OCR, and any future change in Noom's service model (e.g., integration with covered entities) could trigger HIPAA obligations.
    File a complaint →

Provision details

Document information
Document
Noom Terms of Service
Entity
Noom
Document last updated
April 29, 2026
Tracking information
First tracked
April 28, 2026
Last verified
April 28, 2026
Record ID
CA-P-003839
Document ID
CA-D-00396
Evidence Provenance
Source URL
Wayback Machine
SHA-256
de01a3efcc4be9e8cb194056bfe5fceebf1b9c6feb473a060565313528073c29
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Noom | Document: Noom Terms of Service | Record: CA-P-003839
Captured: 2026-04-28 06:48:11 UTC | SHA-256: de01a3efcc4be9e8…
URL: https://conductatlas.com/platform/noom/noom-terms-of-service/health-and-wellness-data-collection/
Accessed: May 2, 2026
Classification
Severity
High
Categories

Other provisions in this document