Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is Teladoc Health's General Privacy Policy covering data collected from visitors to its public websites, including Teladochealth.com and MyStrength.com, but not from logged-in members whose data is governed by HIPAA. The policy states that Teladoc may collect identifiers, browsing activity, device information, registration form data (including date of birth and health plan), and customer service communications, and may share this data with service providers and, with user consent, advertising partners. California residents and users in certain other states are granted rights to know, delete, correct, opt out of targeted advertising, and limit use of sensitive personal information, exercisable through a webform or by emailing PrivacyRights@teladochealth.com.
This General Privacy Policy governs Teladoc Health's collection, use, and disclosure of Personal Information from visitors to its public websites (Teladochealth.com and MyStrength.com), effective March 9, 2026, and explicitly states it is not a contract. The policy states that Teladoc may collect visitor data (pages visited, device and browser type, IP address, email address, and external/internal identifiers), registration data (name, date of birth, health plan, contact information), and customer service communications, and may share this data with service providers, advertising partners (with consent), law enforcement, and successors in business transactions. The policy draws a material distinction between public website data governed by this policy and Protected Health Information (PHI) collected on secure platforms, which is governed by HIPAA and a separate HIPAA Notice of Privacy Practices; the policy also states that Teladoc does not sell PHI or use it for advertising or data mining, and that opt-in advertising cookies may constitute a 'sale' of personal information under state law definitions including CCPA/CPRA. The policy engages HIPAA via HHS OCR, the CCPA and CPRA via the California Attorney General and the California Privacy Protection Agency, and potentially state consumer health data laws through a supplemental Consumer Health Data Privacy Policy referenced but not reproduced in this document. Compliance teams should note the policy's acknowledgment that GPC signals are honored, that advertising cookie opt-in may trigger state-law 'sale' classification, and that the boundary between public-site personal data and PHI requires careful operational mapping, particularly where registration activity or health-adjacent data collected on public pages may fall under CMIA, HIPAA, or state consumer health data statutes depending on jurisdiction.
The agreement establishes that personal information collected on Teladoc's public websites, including identifiers, browsing activity, registration form data, and customer service communications, may be shared with service providers, advertising partners (where consent is given), law enforcement, and business successors. Under these terms, users in California and certain other states may request access, correction, deletion, and opt-out of targeted advertising through a webform or by email, and the policy states Teladoc honors Global Privacy Control signals to reject non-essential cookies automatically. You can manage cookie preferences at any time by clicking 'Your Privacy Choices' in the website footer, submit a privacy rights request via the webform linked in the policy, or email PrivacyRights@teladochealth.com.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Teladoc has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Activity disclosed to ad partners with consent and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.