Which health apps train AI on your data?
None of the 5 health apps on file has a policy that says whether it trains AI on your data, so none is graded. Each entry shows what was read and what was searched for.
Do they train on your genotype, your cycle and your sleep?
Nearly every story about health-app privacy is about who the data is sold to. The apps here hold a genotype, a cycle history or what a person tells a meditation app about their mood. They’re graded on a narrower question: does that data train a model, and how hard is it to stop. Read together, none of the documents named below reaches an answer. They differ in how close they come. Some name a model, a machine-learning platform or a machine-learning purpose and stop short of saying whether your data trains it. Others never reach the subject at all.
The ones that name a model, a platform or a purpose and stop there
Clue says its AI features run on its own “Foundation Model”, described as “trained by Clue”, and it’s unusually plain about where data doesn’t go: “No data is transferred to Anthropic”. What the model was trained on is the sentence that’s missing. The policy does route de-identified health data, behind a toggle in its privacy settings, towards improving predictions and developing algorithms. That isn’t the same statement, and a document this careful could make it if it meant to.
Flo is specific about where cycle data goes: to a named sub-processor its policy describes as a “Machine Learning Development Platform”, receiving “Personal data relating to cycle dates, goals, symptoms” for cycle predictions, retention forecasting and content. The word “train” isn’t in the policy. Its Privacy Portal FAQ asks whether your data trains Flo’s AI and answers for third parties: “Your personal data is not used to train third party AI models.” One Flo document does answer for Flo. A newsroom post from 2021 quotes its CTO on training models “on Flo’s large user population”. Five years old, never repeated or withdrawn, and Flo is being asked whether it still holds.
Headspace’s AI section is more careful than most: it defines AI and separates behind-the-scenes uses from features you interact with. None of that is about inputs. The clause puts “To power machine learning algorithms that support our Platform” among the purposes personal information serves, and no form of “train” appears in the policy. A separate page on its approach to AI, also captured, says its licensed clinicians “review a subset of random Ebb conversations daily for quality assurance and continuous improvement”. Human review, not a statement that those conversations train a model.
The ones that never reach the subject
A genotype doesn’t change, and it implicates relatives who never consented to anything. The privacy statement is careful in other ways, research participation is an opt-in programme with its own consent, and never uses any form of “train”, “machine learning” or “artificial intelligence”. The nearest it comes is a line saying it may “infer new information from other data we collect”, with predicting “certain health predispositions” as its example. That’s about deriving results for you. Whether customers’ genetic information trained whatever does the deriving, it never says.
Calm knows when you can’t sleep and what you reach for when you can’t. Its policy contains no form of “train”, no “machine learning”, no “artificial intelligence”. Its single “model” is your phone’s hardware model. What it says is adjacent: it disclaims inference from health data, “we do not infer any health-related characteristics from this information”, of sleep data arriving from Apple HealthKit or Google Health Connect. Inferring things about you at the point of use isn’t training a model on you, so the silence is on training specifically.
Side by side
2 pairs of health apps people choose between, with both verdicts on one page.