A fact-checked BetterHelp case analysis and audit for aligning privacy promises, advertising data flows, consent, retention and third-party controls.
Short answer: answer: The BetterHelp case shows that a privacy promise is a marketing claim and must match the complete advertising data flow. Before sending any customer identifier or sensitive inference to an advertising platform, trace the promise, field, recipient, purpose, consent and deletion path; stop the transfer if one is missing or contradictory. For health or similarly sensitive data, CDM recommends an explicit prohibition on behavioural advertising unless qualified counsel approves a lawful, specific and verifiable exception.
The common answer—publish a clearer privacy policy or add a consent banner—starts too late. A user can be misled even when a policy exists if the product interface makes a stronger promise, a tracking integration receives more data than the marketing team understands, or a platform may use the data for purposes the company did not constrain.
This case is also often compressed into the phrase “BetterHelp sold therapy notes.” The FTC’s complaint was serious, but precision matters: it alleged disclosure of items including email addresses, IP addresses, service-enrolment information and certain intake-questionnaire responses for advertising.
BetterHelp has said it did not share members’ names or clinical session communications with advertisers and that its settlement was not an admission of wrongdoing. Authority is built by stating both the formal allegation and its limits.
What the FTC record says
The Federal Trade Commission announced its proposed action in March 2023 and finalised the order in July. According to the final complaint, BetterHelp repeatedly promised to keep users’ personal health information private while using and disclosing certain information to Facebook, Snapchat, Criteo and Pinterest for advertising purposes.
The complaint described uses including retargeting visitors, optimising advertisements and finding prospective users who resembled current users. It alleged that BetterHelp did not obtain affirmative express consent for advertising uses and did not adequately limit some third parties’ own uses. These are regulator allegations resolved by a consent order, not findings reached after a contested trial.
The final order required $7.8 million for partial consumer refunds, prohibited disclosure of health data for advertising, prohibited use of personal information for retargeting, required affirmative express consent before specified disclosures, required a comprehensive privacy programme, directed deletion requests to recipients and imposed a retention schedule. Those remedies are especially useful operational evidence: they show the controls a regulator considered material after examining the alleged mismatch.
The Consent Promise Gap Audit
The Consent Promise Gap Audit follows six linked records. A gap anywhere is enough to stop the transfer until the discrepancy is resolved. Do not reduce it to a checkbox exercise; the output should let a reviewer reconstruct what a person was told and what happened to each field.
1. Capture the promise
Collect every statement that can shape a reasonable user’s expectation: landing-page copy, form labels, just-in-time notices, onboarding screens, privacy policy, FAQs, sales scripts and trust seals. Record the exact words, audience, location, date and version.
The governing promise is not automatically the broadest clause in a long policy. A specific reassurance beside a sensitive questionnaire can carry more practical meaning for the user. CDM’s recommendation is to write a one-sentence “reasonable expectation” for each collection point and have privacy counsel challenge it.
2. Inventory the field
Record the raw field and what it can reveal when combined with other data. An email address may look ordinary, but its transmission from a mental-health service can reveal a relationship with that service. Hashing or pseudonymising an identifier does not automatically remove sensitivity when a recipient can match it to an account.
Classify direct data, derived attributes and contextual inferences separately. Marketing teams often inspect only the visible form field and overlook event names, URLs, custom parameters, audience labels or server-side enrichment that travels with it.
3. Map every recipient
Trace browser tags, mobile SDKs, server-side events, customer-data platforms, agencies, data warehouses and advertising platforms. Name the legal entity, not merely the product. For each hop, record whether the recipient acts only on instructions or may use information for measurement, model improvement, matching or another purpose.
Contracts and platform settings are both evidence. A restrictive contract does not repair a tag sending prohibited data, and a clean interface setting does not replace terms that permit broader use.
4. Test the purpose
Compare the collected purpose with every actual purpose. “Provide counselling,” “secure an account,” “measure aggregate service performance,” “retarget this visitor” and “build a lookalike audience” are distinct decisions. Do not bundle them under “improve our services.”
The test is counterfactual: would a reasonable person who supplied this information for the stated service expect this specific recipient and advertising use? That is not a substitute for legal analysis, but it exposes where legal review and explicit choice are required.
5. Verify consent and refusal
Record what action grants permission, what information precedes that action, how refusal affects the service and how withdrawal propagates. A banner click is not useful evidence if the relevant advertising transfer started before the choice or if the consent text did not identify the sensitive purpose.
Test withdrawal with a real record in a controlled environment. Confirm that audiences, downstream exports and future events stop as designed. Retain the test evidence without retaining the sensitive payload unnecessarily.
6. Prove deletion and monitoring
Assign retention periods by purpose and system. Identify who tells recipients to delete information, how completion is verified, and which log will reveal an unauthorised transfer. Review integrations after vendor, schema, campaign or policy changes—not only once at installation.
This last step turns privacy from copy approval into an operating control. A promise can remain unchanged while a tag manager edit silently alters reality.
Reader asset: promise-to-data-flow audit
| Audit field | Required entry | Failure that stops use |
|---|---|---|
| Promise | Exact text, placement, version and reasonable expectation | Promise excludes or contradicts the transfer |
| Data | Field, event, inference, sensitivity and identifier state | Team cannot say what leaves the system |
| Recipient | Legal entity, service, onward use and contract | Recipient or purpose is unknown |
| Purpose | Collection purpose and each downstream purpose | Advertising purpose was not disclosed and approved |
| Choice | Consent event, timestamp, refusal and withdrawal route | Transfer precedes valid choice or withdrawal does not propagate |
| Retention | System period, recipient deletion and proof | No enforceable deletion path |
| Owner | Marketing, privacy and engineering approvers | Nobody can stop and verify the flow |
Run the audit on the rendered customer journey and the network traffic, not the configuration screen alone. Sample at least one acceptance, one refusal and one withdrawal path. Any material discrepancy becomes an incident with an owner and correction deadline.
The position marketers need to accept
CDM’s position is that marketing should not “own” sensitive-data activation by itself. Marketing can define the business purpose, but privacy, security and engineering must independently verify the lawful basis, data minimisation and implemented flow. This slows some campaigns. That friction is appropriate where the downside is invisible disclosure of intimate information.
This article provides operational guidance, not legal advice. Definitions of health data, consent and covered entities vary by jurisdiction, and sector-specific obligations may apply. The audit is a minimum evidence structure for asking the right questions; it is not a compliance certificate.
Related guides
Frequently asked questions
What did the FTC say BetterHelp shared for advertising?
The FTC alleged that BetterHelp used and disclosed information including email addresses, IP addresses, enrolment in its service and certain health-questionnaire responses to advertising platforms including Facebook, Snapchat, Criteo and Pinterest. The alleged purposes included retargeting, advertising optimisation and finding prospective users with characteristics similar to current users.
The complaint did not allege that therapy-session messages were supplied for advertising, and BetterHelp has said it never shared clinical session data with advertisers. The caveat is procedural: the matter ended in a consent order, so describe these points as FTC allegations and order obligations rather than trial findings.
Did BetterHelp admit wrongdoing in the settlement?
No. BetterHelp publicly said the settlement was not an admission of wrongdoing. A consent settlement can impose binding obligations without a contested court deciding every factual allegation. That distinction does not make the order optional or the allegations unimportant; it determines how an accurate article phrases them.
Use “the FTC alleged,” “the complaint states” and “the final order requires.” The exception is a fact independently established by another reliable record, such as the date and amount of the final order, which can be stated directly with its source.
Is hashed customer data safe to send to an ad platform?
Not automatically. Hashing can reduce exposure in some contexts, but a hashed email used for platform matching remains linkable to an account and can carry sensitive context from its source. Evaluate identifiability, the recipient’s matching ability, accompanying event data, purpose, consent and contract together. Treat hashing as one technical measure, not permission.
The caveat is that genuinely anonymised, aggregated information may present a different risk, but anonymisation requires a defensible method and re-identification assessment rather than a label selected by the marketing team.
Does a cookie banner solve the consent problem?
Only if it provides the required information and choice before the relevant transfer, records that choice, honours refusal and propagates withdrawal through every downstream system. Many banners govern browser storage but do not explain sensitive inferences, server-side events or a platform’s own use. Test the actual network and server flow for acceptance, refusal and withdrawal.
The caveat is jurisdiction: consent is not the only possible legal basis for every processing activity, and requirements vary. Qualified counsel should determine the legal basis; the marketing team must still prove the implementation matches it.
Who should approve sensitive-data advertising use?
Require at least a business owner, privacy or legal reviewer, and technical owner who can verify the implemented transfer. Security and clinical or sector specialists may also be necessary. Separate approval prevents commercial urgency from becoming the only risk judgement.
The record should identify the fields, recipient, purpose, consent mechanism, retention, deletion test and expiry date for approval. The exception is an outright organisational prohibition: when policy bans sensitive-data advertising, no campaign-level approver should be able to waive it informally.
How often should marketing data flows be re-audited?
Re-audit after every material vendor, schema, tag-manager, consent, campaign-purpose or privacy-language change, and on a scheduled risk-based cycle. Quarterly is a reasonable CDM starting point for high-risk advertising integrations, but it is not a legal universal. Automated monitoring should alert on new destinations or sensitive parameters between formal reviews. Log the reviewer and the next due date.
The caveat is that a clean quarterly audit cannot excuse an unauthorised transfer discovered today. Pause the affected flow, preserve evidence and follow the incident process immediately.
Next decision: How Do You Propagate a Consent Withdrawal Across a Marketing Stack?
Related reading: How Do You Build a Data-Risk Register for Marketing AI Tools? · How Do You Build a Marketing Evidence and Claims Register in Notion? · The Contemporary Marketing Operating System: Creators, AI, Data and Human Judgment
Sources and research notes
- FTC BetterHelp case docket — complaint, final decision and order, and subsequent refund updates; checked 26 September 2026.
- FTC final BetterHelp complaint — detailed regulator allegations concerning promises, data and advertising uses; checked 26 September 2026.
- FTC final-order announcement — binding remedies and $7.8 million payment; checked 26 September 2026.
- Associated Press report including BetterHelp’s response — company position and procedural context; checked 26 September 2026.
- Limitations: This is a US case and not a complete guide to HIPAA, state health-data laws, GDPR or other regimes. CDM’s audit and recommended prohibition are operational guidance, not a regulator’s test or legal advice.
This article is editorial guidance. Apply the principles in proportion to your market, evidence, and responsibilities.



