Data Privacy Risks in Women's Health and Period Tracking Apps
Period tracking apps sell intimate health data with minimal legal protection or user consent.

Few information types are as private as what period tracking apps gather: monthly timing, intimate relations, birth control habits, whether a pregnancy begins or ends, and family plans. Hardly any of it gets the same cover as medical files, and companies turned this gap into how they make money rather than fixing it. The gap is what's really driving this, not one company acting badly.
In its privacy documentation, Flo, among the biggest category apps, says it collects these details: full legal identity, contact address, DOB, home location, cycle dates, health signs, body mass, body heat. By itself, each bit of data isn't alarming. Alongside location data plus browsing patterns, though, they create a close reproductive picture, and some AI tools built using biometric signals plus the apps' behavioral inputs are said to forecast pregnancy at rates in the 90s. Tracking daily steps or nightly rest doesn't bring the legal, personal, and coverage risks that reproductive data does, so these apps need actual scrutiny rather than just a shrug.
How apps turn data into money
Most such apps cost nothing to get. Apps without a price tag still need money, so the user's data often becomes what gets traded.
"Sharing with third parties" sounds like one clean transaction between two companies. In reality it's a tangled web of ad networks, analytics firms, and data brokers wired into the app via hidden software most people never see or knowingly accept. Research from BMC Women's Health found in 2025 that period tracker apps pass sensitive, personal health data to third parties 80% of the time. A closer look at 23 well-known period and pregnancy apps showed that 87% passed user data to analytics firms, with two-thirds handing data over for what they said were legal duties, and 61% letting location tracking happen. The Mozilla Foundation found 18 among 25 reproductive health apps checked had failed basic privacy standards.
A basic business reason explains it. Staff at Minderoo Centre say data from people hoping to have a baby carries real worth, since pregnancy triggers fresh consumer habits: buying houses and shifting spending habits. Firms able to spot such changes first are hungry for the data, and they're willing to buy it.
The industry's usual defense, that shared data is "anonymized" or "aggregated," falls apart under scrutiny. Data called anonymized can be re-identified when cross-referenced with external datasets, and this issue grows as more datasets accumulate for comparison. This stems from a legal gap, something that surprises newcomers the first time they learn HIPAA doesn't cover period tracking apps. They're consumer wellness goods, not health entities. There’s no federal law keeping any company from sharing this data with advertisers, or handing it over to law enforcement when asked.
The privacy policy problem: why users can't understand what they're agreeing to
Research says reading the privacy policy of most period apps takes college-level skill. It's a real problem when many users lack the literacy level required to fully understand these policies. Those apps realize most users clicking "agree" aren't grasping the terms they just accepted.
The hiding often happens on purpose. Apps grab permissions before the user realizing what happened, tuck data-sharing disclosures inside a policy, and write so dense that giving consent turns into mere formality rather than any real decision. A study from Texas A&M found that 85% of app privacy notices it checked said nothing clear about how user info gets protected, even though what those apps collect is highly sensitive.
The region fares a little less badly. Under GDPR, menstrual data is a special category needing heightened care, but a 2022 audit found that, of FemTech apps, some 80% failed to obtain proper consent for handling personal data. In the US and EU, plenty of programs call themselves health or fitness aids instead of medical gear, avoiding the strict checks they'd normally face. In October 2024 the EU's Digital Fairness Fitness Check flagged dark patterns in digital tools at large: consent flows aimed at winning a yes rather than telling users anything. Period apps pull many of those same moves.
Most people think they've carefully picked their privacy controls. Studies of what the settings let happen still show a gap in what users believe they picked and what the terms say can happen.
What law enforcement access to this data looks like
Once data is collected by a company, law enforcement can usually compel its release through any legal process that applies, and firms have few ways to say no by the time that process gets underway. For policy expert Amie Stepanovich at Future of Privacy Forum, it's clear: legal power for companies to withhold data largely disappears after a valid subpoena or court order exists.
Since these apps aren't covered by HIPAA, no federal firewall keeps that data from a prosecutor's hands. It's already happening. Facebook chat logs from Nebraska helped prosecute a parent and child over abortion-related charges. Police in the UK accessed one person's Google search history after she used abortion medication outside the legal limit, and her punishment was eventually put on hold. A period tracking app wasn't at issue in either instance, yet both reveal the very sort of digital footprint that such apps create every day.
Police can also get around the company. Analytics vendors plus ad firms hold onto the data well after it departs from the app, so Subpoenas hit those third-party systems just like a user's personal device. There are other ways in too, beyond the courts. A Texas research study found 61% of vulnerabilities inside fertility apps and period tracking tools matched OWASP top-ten entries, which serve as this industry's main catalog for the worst software flaws. Health data this sensitive can escape with no subpoena involved. One error can do it.
Apps made earlier, under different legal rules, still run in a nation whose reproductive data may serve as proof in a prosecution. The change came on quickly. The tech itself never adapted.
The FTC action against Flo Health and the California cases against Flo and Glow
Among federal enforcement efforts here, the FTC's 2021 settlement involving Flo Health stands clearest. Regulators said Flo told people their health data would stay secret, yet it was sharing that info with analytics firms and marketing companies like Facebook plus Google. Flo had to obtain explicit permission before disclosing personal health data from then on, and to be audited by an outside party on its privacy practices. This marked the first time FTC action required a company to notify users of a privacy violation involving reproductive health data.
The settlement left Flo's legal exposure wide open, which should scare those who assume a deal makes the trouble go away. Frasco was a California class action. A California class action, Frasco v. Flo Health, claimed Flo gathered sensitive health records from millions of users and handed them illegally to Meta, Google, and outside companies. Even as Flo promised people their information would remain safe, SDKs from outside software kits embedded within the app allowed Meta to collect sensitive menstrual details and reproductive health data. In September 2025, Meta was found liable for unlawfully gathering and monetizing user data. Flo came to terms mid-trial with plaintiffs, ahead of the jury's decision against Meta.
Fertility app Glow likewise faced action from California's Attorney General during 2020. Xavier Becerra, who was AG at the time, said Glow would pay $250,000 after deciding the app had leaked millions of health records belonging to women, breaking California's Confidentiality of Medical Information Act and other laws.
Read as a whole, these lawsuits show what regulators and judges have found repeatedly in public: the damage here is recorded and real. It has been examined, litigated, and established as truth. What stands out most: outside SDKs still gathered and sent Flo's customer info after the FTC deal. Blocking a single path doesn't seal off the rest. A company might update its privacy policy, but Data still ends up leaking via outside firms and embedded scripts.
How Flo, Clue, Stardust, plus Spot On stack up on privacy
Flo, after settling, is the only period tracker app carrying two ISO certifications for data safety, a setup many in the field treat as top-tier. This certification deserves suspicion, since the value falls short of appearances. Mozilla's 2026 review still called Flo "a data-hungry tracker with an AI symptom chatbot" and scored it 7 out of 10, and the 2025 Meta verdict, tied directly to Flo's own SDKs, shows that a certificate and a real legal judgment against a company can sit side by side without contradiction. The Journal of Medical Internet Research ran its own review, giving Flo's privacy and protections a 3.5 rating from 5.
Clue has its different legal posture mainly because the European company must follow GDPR's Article 9 and give special care to reproductive health data. Clue says it won't hand over health data, even when served a legal subpoena, and by citing European law obligations, the app's policy makes clear that information from data tracked about abortion, pregnancies, or pregnancy endings remains hidden. Yet Clue got the very same 3.5, on a 5-point scale, from that Journal of Medical Internet Research study as Flo. Good policy words don't guarantee better technical protection, and Clue shows this just as clearly as any other app.
Stardust marketed a privacy-first, encrypted option in that period after a big legal decision reshaped reproductive choices. In Mozilla's 2026 review, it got only 2 in 10, below every app compared here. Stardust originally had a policy permitting data sharing to comply with law enforcement requests, later updated that policy, and then tweeted that it would "not be able to produce anything" in response to a government subpoena. The space between this marketing claim and its independent audit result marks the widest gap across the comparison, and somebody interested in a startup that's privacy-branded and hasn't gotten outside checking yet should treat that gap as a red flag rather than a footnote.
Mozilla's 2026 rankings gave Spot On, the Planned Parenthood's cycle plus contraception tracker, a score of 5 from 10. Not the top performer, not the bottom either, and its ranking may be the most frank of the bunch, since it's plain all around.
Where a company operates matters most, more than any marketing claim or set of functions. A European firm works within GDPR's flat prohibition on handling health records of a sensitive kind unless permission is given first, stricter than any US statute requires. Even so, every one of those apps has problems. The difference that separates them is scale: how clear each policy is, whose rules cover it, and how big the gap is between what that company claims and what results an independent audit shows.
Chatbots and AI showing up within period apps: one more way exposure happens
Period tracking tools already include AI chatbots. A feminine hygiene firm from India enables menstrual cycle tracking via an AI chatbot inside WhatsApp. They're moving to everyday messaging apps where handling the data gets even less clear. As one thing that makes its app data-hungry, Flo's AI symptom chatbot was flagged by Mozilla's 2026 review.
Scholarship hasn't kept pace, and there's no end in sight. Researchers have identified AI chatbot privacy in period trackers as an emerging area needing further study. Experts have noted that millions use AI chatbots, which collect personal data for training, yet privacy practices for these tools remain understudied.
Studies of AI companies have found that chat data is often used for model training. Practices vary, with some companies processing personal data differently than others. At a company offering many services, such as Google, Meta, Microsoft plus Amazon, health details typed in AI can be stored with a user's searches, buying data, and activity in the same account.
The law hasn't kept pace. In the US, the protections covering information given to AI companies are split across a mix of state rules, with no full framework on the national level. When someone shifts from simple period tracking into an AI conversation tool, they give information under a separate, much harder-to-see set of rules than what they accepted when they joined. They get no warning that things are different mid-conversation now.
Where current protections work and where they fall short
HIPAA won't protect everyday health programs in the US. Afterwards, the FTC can act to punish deceptive practices, as happened with Glow and Flo, yet it can't impose proactive privacy standards ahead of any injury. There's still no broad federal privacy law for this group, and nothing in sight points to one arriving anytime.
Local law fills the gap unevenly, in places. Some places put in reproductive health data protections following a big legal change involving abortion; some went another way. A user's real legal cover comes down to where they're based, an absurd result once data can travel anywhere the second it's sent from the device.
The EU's rules seem better in theory. Under GDPR, Article 9 classifies period information separately, and using it is banned outside strict, set grounds such as clear permission. By classifying themselves as mere wellness tools rather than actual medical devices, most apps dodge the EU's Medical Devices Regulation, which could impose stricter rules. Even with GDPR active, oversight lagged: in that 2022 audit, just under 80% showed FemTech apps failed at getting proper consent. The EU's Digital Fairness Fitness Check, flagged in October 2024, might one day tackle dark patterns baked deep into consent flows, with real consequences for period apps collecting user sign-off.
Enforcement is the one piece of this setup that gets real outcomes. FTC consent deals, with California AG settlements and later jury verdicts, have made businesses share more and, sometimes, pay real money. Still, the SDK issue that persisted at Flo following its FTC settlement hits a limit: any company might update its policy while letting data slip out through a partner's tools built into their app. The policy gap stays widest with AI-integrated health tools. Chatbots inside period apps, plus general-purpose AI fielding reproductive health concerns, remain largely beyond privacy law today in the US and Europe alike.
Ways people can limit exposure
Where a given app sets up shop determines the law governing it, and that by itself should guide what app a user chooses. Businesses in Europe follow GDPR's harder limits on passing along health details, so people there get better backing than American rules currently offer. Mozilla's 2026 ratings give a clear comparison: Flo with 7 from 10, Spot On with 5, Stardust with 2. Stardust shows the clearest gap between Marketing terms such as "private" or "encrypted" and an actual verified certification or independent audit.
Individuals can also cut back on what they record at the start, and this carries more weight than most would guess. Apps usually push users to log much more than basic cycle tracking really requires, and each additional entry turns into another piece of data stored where its user can never see it. Details regarding pregnancy intentions, alongside sexual activity and abortion, pose the greatest legal danger inside the app. Pause before typing them into software where legal protections lack plain spelling.
Permissions also need periodic check from time to time. That survey of 23 apps found 61% could use Location tracking, though basic cycle logging doesn't require it, and turning the permission off in settings keeps the app's main purpose working. These steps don't eliminate every danger, so nobody should act like they do. But with this information already surfaced during enforcement, class action lawsuits, plus one case using digital chat logs, viewing a period tracker with equal caution to any data collector on a device hasn't been optional for some time.
Sources
- Privacy and Security of Women’s Reproductive Health Apps in a Changing Legal Landscape
- Exploration of Reproductive Health Apps’ Data Privacy Policies and the Risks Posed to Users: Qualitative Content Analysis - PMC
- ftc.gov
- ftc.gov
- ftc.gov
- All Eyes on my Period? Period tracking apps and the future of privacy in a post-Roe world
- Period Tracking Apps: Does HIPAA Protect My Data?
- ftc.gov


