What Are These Apps Asking Me to Agree To?
Terms, privacy notices, health data permissions, and why they are not the same thing.
Last reviewed: August 4, 2026.
You download an app. Before you can use it, a screen asks you to agree.
A week later a different app wants you to accept its privacy policy. Your doctor's office asks you to sign a privacy form. A wellness app asks for your location. A website asks which cookies it may use.
They all feel like the same question.
Will you tap the button so we can move on?
They are not the same question. One button may create a contract. Another may only confirm that you received a document. Another may let a company share your health information. Another turns on your camera.
Most people tap through because the system is built for speed, not understanding. That does not mean you are careless. It often means the screen was designed to be passed, not understood.
Knowing the difference tells you when you have a real choice.
This article is general information, not legal advice. Privacy and health rules differ by state, by country, and by who is holding your information.
Before you tap, five questions:
- Is this a contract, a notice, or a permission?
- Is it required to use the app?
- What exactly does it cover?
- What happens if I decline?
- Can I change my mind, and how?
The rest of this article is why those five questions work.
Six different things one button can mean
1. A contract. Terms of service are the rules between you and the company: what you may do, what they may do, how payments work, who owns your content, how disputes get handled. Tapping I agree can form a contract even if you did not read it, and gives the company a record that the terms were presented and that you signaled agreement. Courts ask whether the notice was reasonably clear and whether you clearly agreed. Companies do not always win that argument. In 2025 a federal appeals court refused to enforce one company's terms because the sign-up screens did not give people fair notice.
2. Proof that you received a notice. A privacy notice describes what an organization says it collects, why, who receives it, and how long it keeps it. Describing is not asking.
At the doctor's office you may be asked to sign that you received the Notice of Privacy Practices required by HIPAA, the federal health privacy law. The U.S. Department of Health and Human Services says plainly that "signing does not mean that you have agreed to any special uses or disclosures" of your records, and that "the law does not require you to sign."
"I received this" is not "I permit this."
3. Permission for one specific use. In health care this is a HIPAA authorization. The rule requires it to name the information, who may release it, who may receive it, the purpose, and an expiration date or event. It must also tell you that you can take it back, and that whoever receives your information may be able to pass it along outside HIPAA's protection.
That is a useful standard to carry into any app. A real permission request tells you what, who, why, how long, and how to change your mind.
4. A switch on your device. Camera, microphone, location, contacts, Bluetooth, health data. These are technical controls your phone or browser gives you, and they should be requested when you pick the feature that needs them. A medicine scanner needs the camera when you scan a label, not at sign-up. Granting the switch is not the same as approving what the company does with what it captures.
5. A tracking choice. Cookie banners ask about storing information, measuring usage, and advertising. What they legally mean varies. What they practically mean is often decided by the layout.
6. Agreeing to be in a study. Research consent is about taking part. It is a separate question from permission to use your health information, even when both are on the same clipboard.
Why do they keep asking?
The rules changed. New prices, features, or dispute terms. The company wants a record that you accepted the new version.
They want to use old data in a new way. A new advertising partner. An AI feature. A research program. Federal Trade Commission staff have warned that it "may be unfair or deceptive" for a company to quietly rewrite its terms so it can start sharing your data or use it for AI training.
Sometimes asking again is the right thing to do. Yesterday's permission should not silently approve tomorrow's unrelated use.
The rules changed in your state or country. Requirements differ by state and country, and several new state privacy laws took effect in 2025 and 2026.
They want a record. A company may need to show which document you saw and what you chose. That record proves you clicked. It does not prove you understood.
The fine print has a business model
Not every agreement is a trap. Some terms are needed to run the service. Some permissions protect you. Some notices are required by law.
But the screen is not neutral just because it looks official.
Information about you has value. A company may sell it, share it, use it to target advertising, train systems, or predict what you will do. It does not need to put your name in a folder marked "for sale" to make money from what it knows about you.
Too many products collect first and invent the reason later.
You have probably heard that if the service is free, you are the product. The Electronic Frontier Foundation adds the qualification that matters: the saying holds when targeted advertising is the business model. But free is not the only warning sign. You can pay for a service and still be tracked, profiled, and monetized.
EFF suggests a better question, and it is the one to carry into any agreement screen: "How does the vendor make money? Do they make money by selling access to, or products based on, your private data?"
A location permission may help you find a nearby pharmacy. It may also feed an advertising or data broker system that has no relationship with you at all, and that can learn where you seek medical care.
When an app cannot explain in plain language why it needs something, do not assume the collection is for your benefit.
Is my health information always protected by HIPAA?
No.
HIPAA follows certain organizations and relationships. It does not automatically follow every piece of health information.
It covers health plans, health care providers who bill electronically, the clearinghouses that process those bills, and the outside companies working for them. Most doctors' offices that bill health plans electronically are covered. A fitness tracker, a symptom checker, or a coaching app you bought for yourself usually is not.
That does not leave those apps unregulated. The FTC's Health Breach Notification Rule, updated in 2024, now expressly reaches health apps and connected devices that HIPAA does not cover. State health data laws apply too. Washington's My Health My Data Act requires your consent before many companies may collect or share consumer health data, and says that consent cannot be buried in a general agreement to terms of use. And a company's own privacy promises can be enforced against it.
So the useful question is not "is this health information?"
It is who is holding it, and why?
Why do people click without reading?
Because reading it all is not realistic.
A 2008 study by Aleecia McDonald and Lorrie Cranor estimated that reading the privacy policies of the sites an average American visits would take roughly 201 hours a year, and put the national cost of that time near $781 billion. Policies have only gotten longer since.
Repetition wears people down. Researchers call it privacy fatigue, and one survey found it predicted what people actually did more strongly than how much they said they cared.
That is not proof that people stopped caring. It is a sign the system asks too much of them.
The buttons can push you toward an answer
Consent screens are designed, and design changes what people pick.
In a field experiment on cookie pop-ups, moving the reject button off the first screen raised acceptance by more than 20 percentage points. Nothing about the offer changed. Only the layout did.
The FTC calls designs like these dark patterns. California's privacy regulator puts the test simply: dark patterns are about effect, not intent. If the privacy protective path takes more steps than the other one, the choice is not equal, whatever the company meant by it.
A choice is worth less when one answer is a tap and the other is an obstacle course.
That obstacle course is not paperwork accidentally getting in your way. It is part of the product. The button, the defaults, and the hidden options did not appear by accident. Someone designed them, and companies can measure which version makes more people give in. Privacy advocates have documented for years how interface design steers people into sharing more than they intended.
An Agree button can also take something away. Terms can be used to waive rights that people did not realistically know they were giving up.
What should a trustworthy app do?
A trustworthy app should not treat your exhaustion as permission.
It should not bury five business decisions under one button and call that informed consent. It should not collect something merely because storage is cheap or because the information may become valuable later. And it should not make you solve its privacy risks by reading thirty pages of legal language.
And it should not begin by taking everything and making you claw your way back to privacy. As the Electronic Frontier Foundation puts it, "the default should be against collecting, using, and sharing personal information."
What it should do is simpler, and harder. It should ask only when there is a real choice. Say whether you are signing a contract, receiving a notice, or granting permission. Keep required uses separate from optional ones. Explain what changed when it asks again. Ask for the camera when you reach for the camera. Make declining as easy as accepting. Collect less. Show you what you have agreed to. Make changing your mind ordinary.
And it should build so that a tired person tapping the wrong button is not the only thing protecting sensitive information.
Where ChartQuest stands
We would rather show you what is built and what is not than hand you another slogan.
Your health story is yours. Your trust is not for sale. Your health is not raw material. That it needs saying is the whole problem.
Available now
- Before you create a care team share link, you see what will be included, who can open it, when it expires, and how to stop sharing. You can stop sharing at any time afterward.
- When you look up local resources, your device rounds your location to about two thirds of a mile before it goes anywhere. You can type a ZIP code instead.
- Directly identifying details are removed before selected record content is sent to an AI model.
- You can export your information and delete your account from inside the app. We show you on screen the narrow things that survive deletion, and why.
- A history of what you agreed to, with the date and version, in your settings.
- Withdrawing an individual agreement inside the app, without writing to us first.
- Accepting our startup agreements one at a time, each its own decision, rather than together.
- A plain-language summary of what changed, shown above the document when a version changes.
- An explanation of why we need the camera or your location, shown before the prompt appears.
The five items at the end of that list were on a "still being built" list when this article was first written. They shipped on August 4, 2026, and we moved them here the same day. We publish the list so you can hold us to it, and so you can watch items move.
Do not take any company's word for this, including ours. Questions are healthy. Ask your doctor. Ask your insurance company. Ask us. Especially us. If we cannot explain it, we have not earned your trust.
Consent should be the moment a person takes control, not the moment an organization hands over responsibility.
Sources
What the agreement screens mean
- 45 CFR 164.508, the six core elements and three required statements of a HIPAA authorization.
- HHS, Notice of Privacy Practices for Protected Health Information, on what signing the acknowledgment does and does not mean. The related obligation is at 45 CFR 164.520(c)(2)(ii).
- HHS FAQ 264, the difference between consent and authorization under HIPAA.
- HHS FAQ 313, why research consent and HIPAA authorization are separate questions.
- Meyer v. Uber Technologies, 868 F.3d 66 (2d Cir. 2017), the two part test for online contract formation. Courts do not always enforce: Chabolla v. ClassPass, 129 F.4th 1147 (9th Cir. 2025) and Godun v. JustAnswer, 135 F.4th 699 (9th Cir. 2025) declined to; Edmundson v. Klarna, 85 F.4th 695 (2d Cir. 2023) and Keebaugh v. Warner Bros., 100 F.4th 1005 (9th Cir. 2024) came out the other way on better designed flows.
Which rules apply to health apps
- HHS, Covered Entities and Business Associates, who HIPAA actually covers.
- FTC Health Breach Notification Rule, 16 CFR Part 318, and the 2024 amendments that reach health apps not covered by HIPAA.
- Washington My Health My Data Act, RCW ch. 19.373, and the Washington Attorney General's overview. Its definition of consent excludes general terms of use, passive action, and deceptive design.
- FTC staff, "AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive", February 13, 2024. A staff blog post, not a rule or an enforcement action.
- FTC, Mobile Health App Developers: FTC Best Practices, on affirmative express consent obtained separately from the privacy policy.
Why the current model fails
- McDonald, A. M., & Cranor, L. F. (2008). The Cost of Reading Privacy Policies. I/S: A Journal of Law and Policy for the Information Society 4(3):543-568.
- Amos, R., Acar, G., Lucherini, E., Kshirsagar, M., Narayanan, A., & Mayer, J. (2021). Privacy Policies over Time: Curation and Analysis of a Million-Document Dataset. WWW 2021.
- Choi, H., Park, J., & Jung, Y. (2018). The role of privacy fatigue in online privacy behavior. Computers in Human Behavior 81:42-51.
- Nouwens, M., Liccardi, I., Veale, M., Karger, D., & Kagal, L. (2020). Dark Patterns after the GDPR. CHI 2020.
- Habib, H., Li, M., Young, E., & Cranor, L. F. (2022). Okay, whatever: An Evaluation of Cookie Consent Interfaces. CHI 2022.
- Matte, C., Bielova, N., & Santos, C. (2020). Do Cookie Banners Respect my Choice? IEEE S&P 2020.
- FTC, Bringing Dark Patterns to Light, Bureau of Consumer Protection staff report, September 2022.
- California Privacy Protection Agency Enforcement Advisory No. 2024-02, September 4, 2024, on symmetry in choice, applied in the CPPA's March 2025 order against American Honda.
Electronic Frontier Foundation
EFF material on eff.org is published under Creative Commons Attribution 4.0 International, per EFF's copyright policy. The license does not cover EFF's trademarks or logo, and nothing here implies EFF endorses ChartQuest.
- Gebhart, G. (2019, updated 2020). EFF's Recommendations for Consumer Data Privacy Laws. Licensed CC BY 4.0.
- Quintin, C., & Okuda, S. (2018). How to Assess a Vendor's Data Security. Licensed CC BY 4.0.
- EFF. Location Data Brokers. Licensed CC BY 4.0. Accessed August 4, 2026.
How we checked these. Research and Sources records what each source does and does not support: where this article simplified a rule to stay readable, a claim we narrowed for lack of a source, a quotation we dropped because we could not find it, and what we left out on purpose.
Have we gotten something wrong, or made something harder than it needed to be? Tell us at privacy@humanviablelabs.com.