If you are asking whether Hims & Hers is private, US regulators now say the answer was not what the company promised. On July 29, 2026, the Federal Trade Commission, joined by the State of Utah and Los Angeles County on behalf of California, sued the telehealth firm, alleging it shared customers' sensitive health information with advertising platforms including Meta and Snap while marketing itself as private and discreet. The company calls the claims baseless and plans to fight them, so treat everything in the complaint as an allegation, not a proven fact.
The case matters even if you have never used a telehealth app, because it shows how an app can promise privacy in plain English and still leak what condition you are being treated for. This is a guide for a normal person: what the FTC actually alleged, what a tracking pixel is, how to check the apps you already use, and what you can do to limit the leak.
What the FTC actually alleged
The FTC's complaint says Hims & Hers moved sensitive health data to advertising companies in two main ways. First, it allegedly shared customer lists that were segmented by health condition or treatment type. Second, it allegedly placed third-party tracking pixels and software development kits, known as SDKs, on its website that automatically sent user actions to advertising partners. The complaint names Meta and Snap as recipients.
Reporting on the complaint says the trackers involved were not limited to those two platforms. TechCrunch reported the FTC alleged Hims & Hers placed pixel-sized trackers from Meta, Snap, Microsoft, Pinterest, Reddit, and X on its website, and that these trackers captured and shared users' health information in a way that ran contrary to the company's own privacy policy.
The complaint also targets billing. The FTC alleges the company charged customers almost immediately after they submitted an intake form, before the promised consultation with a medical provider took place. It alleges refill charges landed roughly ten days earlier than customers would reasonably expect, with cancellation deadlines set just two days before that early refill, creating a window that was easy to miss. The case is brought under Section 5 of the FTC Act and the Restore Online Shoppers' Confidence Act.
The market reacted fast. Hims & Hers shares fell nearly 15 percent on the day the lawsuit was announced, a reminder that data-privacy allegations carry real financial weight even before a court weighs in. The company said its privacy policy makes clear that users may choose how their data is used, and it dismissed the allegations as baseless.
These are allegations in a civil complaint filed in the Northern District of California. A complaint is one side's account. Nothing here has been decided by a court, and Hims & Hers disputes the claims.
What a tracking pixel is, in plain language
A tracking pixel is a tiny piece of code an app or website loads from a third party, usually an advertising company. It is often invisible, historically a single transparent image one pixel wide. When it loads, it can quietly report back to that third party: what page you viewed, what button you tapped, and an identifier tied to you. An SDK is the same idea inside a phone app rather than a web page.
Here is why that turns into a privacy problem. If a page is titled after a specific condition or a specific medication, the fact that you loaded it can be enough to reveal why you are there. You do not need to type your diagnosis into an ad company's box. Visiting a page about hair loss, weight loss, erectile dysfunction, or a mental health treatment, while a pixel from an ad platform is watching, can hand that context to the platform. The company can then build audiences of people who looked at that treatment and target ads to them.
This is not a new pattern. The FTC has taken similar action against other health and telehealth companies in recent years, including GoodRx, BetterHelp, Cerebral, and Monument, over data shared with third-party tech platforms.
Why a "private" app can still leak your conditions
The core lesson is that a privacy promise in marketing copy is a policy, not a wall. A company can print "we take your privacy seriously" on its homepage and still wire an ad tracker into the checkout flow. The words describe intent. The code decides what actually happens to your data. When the two disagree, only the code moves the information.
There is a business reason this keeps happening. Free and low-cost consumer apps often depend on advertising, and advertising rewards precise targeting. An app that can tell an ad platform exactly which visitors looked at a specific treatment can run cheaper, better-converting ads. That incentive pulls against keeping health signals inside the app. The safer position is structural: build the product so the sensitive data has nowhere to leak, rather than promising restraint you are financially motivated to break.
When you read "we take privacy seriously" or "your data is safe with us," treat it as a claim to verify, not a fact. The real question is what the app is technically built to do with your data, and who else it sends data to.
How to check whether an app shares data with advertisers
You cannot audit an app's servers, but you can gather strong signals in a few minutes. None of these prove wrongdoing on their own. Together they tell you how exposed you are.
- Read the privacy policy's sharing section, not the headline. Search the page for the words advertising, partners, third parties, pixels, and analytics. If it says data may be shared with advertising or marketing partners, that is the part that matters.
- Check the app store privacy label. On the App Store, look at App Privacy and Data Linked to You. On Google Play, open the Data safety section. Look specifically for Health & fitness data listed as shared or collected for advertising.
- Look at who the app loads. On a computer, open the site, then your browser's developer tools, and watch the network requests for domains like facebook, meta, snap, doubleclick, or other ad networks loading while you browse condition pages.
- Notice the ads that follow you. If you research a condition on an app and then see eerily specific ads for that exact treatment elsewhere, that is a real-world signal the app is feeding an ad platform.
- Prefer apps that make money from you, not from advertisers. If the business model is a subscription you pay, the incentive to sell your attention to advertisers is weaker.
How to limit what leaks
You have more control than it feels like. These steps reduce how much any single app can hand to advertisers.
- Turn off ad tracking at the phone level. On iPhone, go to Settings, Privacy & Security, Tracking, and turn off Allow Apps to Request to Track. On Android, go to Settings, Privacy, Ads, and delete or reset your advertising ID.
- Limit ad personalization in your accounts. In your Meta, Google, and other ad accounts, turn off ad personalization and interest-based ads so shared signals are less useful.
- Use your deletion rights. Many states now give you the right to request that a company delete your data. Pharmacies and telehealth services usually have a privacy request or data deletion form. Send the request in writing and keep a copy.
- Separate sensitive browsing. Research health topics in a private or separate browser session so trackers have less history to tie to your identity.
- Trim app permissions and delete accounts you no longer use. Every dormant health account is a copy of your data sitting somewhere. Close the ones you do not need.
Data deletion rights deserve special attention for health services. Several US state privacy laws now let you demand that a company delete the personal information it holds on you, and health data usually gets the strongest protection. When you send that request to a pharmacy or telehealth provider, be specific: ask them to delete your account data and to stop sharing it with third parties, and ask them to confirm in writing when it is done. Keep the confirmation. It is your proof if the company is later found to have kept or shared data it should not have.
None of this makes you invisible, and it should not have to fall entirely on you. The clearest fix is to choose tools that are not built to broker your data in the first place.
Privacy marketing versus privacy by architecture
The difference the FTC case turns on is the difference between a promise and a design. Here is how those two approaches compare against the specific risk in this story.
| What to look at | Privacy as marketing | Private by architecture |
|---|---|---|
| The promise | A policy line saying they take privacy seriously | A design where sensitive data has no path to advertisers |
| Ad trackers | May embed third-party pixels and SDKs in the app | No ad-tracking business model, so no reason to embed them |
| Who profits from your data | Advertisers can pay for precise targeting | You pay for the product, so the incentive to sell you is gone |
| Data isolation | Shared systems and audience lists across partners | Per-user isolation with customer-managed keys and encryption at rest |
| How to verify | Trust the headline copy | Check the model, the trackers, and the stated design |
Where MemX fits
MemX is a personal memory app: you snap or save your documents, photos, voice notes, and messages, then ask a question later and get the answer with its source. A lot of what people store is sensitive, including insurance letters, lab results, prescriptions, and medical bills. That is exactly the category the Hims & Hers complaint is about, so the way MemX is built matters here.
MemX is private by architecture rather than by promise. There is no ad-tracking business model, so there is no commercial reason to embed advertising pixels or SDKs against your data. Your content sits in per-user isolation, protected with customer-managed keys and encryption at rest, and it is not used to train models. In plain terms, your stored health documents are not turned into an audience list for Meta or Snap, because the product is not built to make money that way.
To be honest about the limits: no design removes every risk, and you should still read any app's policy and check its trackers, including ours. The point is that the safest privacy is the kind you can trace to how a product is built and paid for, not the kind you read in a tagline.
01Is Hims & Hers private?
Hims & Hers marketed itself as private, but on July 29, 2026 the FTC and two states sued it, alleging it shared sensitive health data with ad platforms including Meta and Snap. The company calls the claims baseless and is fighting them. These are allegations, not a court finding.
02What is a tracking pixel?
A tracking pixel is a tiny, often invisible piece of code an app loads from a third party, usually an advertiser. When it loads, it can report what page you viewed and what you tapped, tied to an identifier. On phone apps, an SDK does the same job.
03Did Hims & Hers admit to sharing health data?
No. According to reporting, the company called the FTC's allegations baseless and said its privacy policy lets users choose how their data is used. It plans to defend itself in court. The claims come from the FTC's complaint and have not been proven.
04How do I stop apps from sharing my data with advertisers?
Turn off app tracking in your phone settings, reset or delete your advertising ID, disable ad personalization in your Meta and Google accounts, and send data deletion requests to services you no longer use. Also favor apps you pay for over ad-supported ones.
05Can a health app legally share my data with advertisers?
It depends on consent and what the company promised. The FTC's case argues Hims & Hers shared data in a way that contradicted its own privacy policy, which is why it brought claims under the FTC Act and ROSCA. Sharing that breaks a company's own promises can be unlawful.
