Before you tell an app something personal, it is reasonable to ask where that information goes. A mood entry, a conversation, and a device identifier can each reveal something about you. A thoughtful choice starts with understanding the service, not with sharing more to see what happens.
What can a wellbeing app collect?
Start with information you deliberately provide: profile details, messages, audio, questionnaire answers, and connected health data. Then look for information collected through use, such as device identifiers, usage events, and approximate location. The exact mix depends on the app and your permissions. Do not assume every service collects the same things.
Separate the reason a feature needs information from the company’s other uses for it. Processing a message to answer you, retaining it for account history, sharing usage data with an analytics provider, and using it to train an AI model are different activities. A clear policy should let you distinguish them.
Why the privacy details matter
In 2023, the FTC finalized an order prohibiting BetterHelp from sharing sensitive health data for advertising and requiring $7.8 million in relief, resolving allegations about disclosures despite privacy assurances. This is a documented case about a particular company, not evidence that all mental health apps have identical practices.[1]
Four different questions
- Collection: what information enters the service?
- Access: which people and providers can see or process it?
- Purpose: is it used to provide care, operate the service, advertise, or train models?
- Retention: what remains after a conversation, export, or account deletion?
Does HIPAA cover a mental health app?
Not automatically. HHS explains that information entered into a personal-use app generally falls outside HIPAA unless the app is provided by a covered entity or its business associate. The relationship and activity matter, not simply whether the information is about health. Other privacy obligations may still apply.[2]
When a company says “HIPAA compliant,” ask which service and relationship the statement describes. It should not be read as a government seal guaranteeing every feature, integration, or use of your data. A consumer choosing a wellbeing app needs understandable answers even when HIPAA is not the relevant framework.
A five-question check before signing up
Read with a specific purpose
Who gets my information?
Look for named provider categories, advertising partners, analytics services, and human access. Ask whether the model provider receives message content and under which settings.
Can my words train AI?
Find a direct explanation of training and service improvement. Check whether the choice is optional and whether it applies to past data, future data, or both.
What can I choose separately?
See whether using a core feature requires optional permissions. Microphone access, wearable connections, marketing messages, and data sharing need their own explanation.
What does delete mean here?
Find the process, expected timing, backup treatment, and any retention exceptions. Removing an app from a phone is different from requesting account deletion.
Who can answer a privacy question?
Look for a working privacy contact and a clear way to exercise available rights. Save the response if it affects your decision.
A message you can send to a provider
If the answer only repeats “we take privacy seriously,” you still do not have an answer to those questions. You can pause, share less, or choose another approach. A notebook or a conversation with a qualified professional has different practical considerations; neither choice requires you to give an app a trial with your most sensitive details.
After you have already shared information
Review permissions and connected services. Export information you want to keep if that option exists, using a private device and storage location. Follow the account-deletion process if you decide to leave, and keep the request confirmation. Ask about information retained for legal or security reasons rather than assuming deletion is instant or absolute.
Common privacy questions
Is encryption enough to make an app private?
Encryption protects data in particular conditions. It does not, by itself, tell you who may access decrypted information, how long it is kept, or whether it is used for advertising or training.
Does deleting the app delete my account?
Usually these are separate actions. Use the service’s documented account-deletion process and ask what it covers.
Should I share everything so an AI can understand me?
You can start with less. Share only what you are comfortable providing after understanding the service and its limits. Personalization is not a reason to abandon your boundaries.




