Menstrual Cycle

Are Period Tracker Apps Safe? What the Record Shows

Last updated: 2026-08-01 · Menstrual Cycle

TL;DR

Period tracking itself is safe and useful — the risk lives in an app's architecture. Every major documented incident (Flo, Premom, Glow) involved data leaving the phone: shared through third-party SDKs or exposed from servers. HIPAA does not cover consumer period apps, so the protection you get is the protection the app's design gives you. Apps that keep data on-device, require no account, and embed no ad or analytics trackers remove the risk class entirely.

Are period tracker apps safe to use?

The honest answer: it depends entirely on how the app is built, because the law mostly won't protect you. Consumer period trackers are not covered by HIPAA — the US health-privacy law applies to healthcare providers and insurers, not wellness apps. That means an app's own architecture and privacy policy are effectively the whole ballgame.

The documented failures all share one shape. In 2021 the FTC alleged that Flo, the most popular tracker, shared users' health data — including pregnancy status — with analytics divisions of Facebook and Google between 2016 and 2019 through embedded software development kits (SDKs), contrary to its own privacy promises. In 2023 the FTC charged the ovulation app Premom with sharing health data with Google, AppsFlyer, and two China-based analytics firms without consent. In 2016 Consumer Reports found the Glow app's password-change flow let anyone take over any account and read their fertility data.

None of these incidents happened because someone tracked their period. They happened because the data left the phone — to advertising SDKs or to servers with weak controls. That's the variable to evaluate: not whether to track, but where your data physically lives and who else is in the room.

FTC File No. 192-3133 (Flo Health, 2021)FTC v. Easy Healthcare (Premom, 2023)Consumer Reports (2016)

Which period tracker privacy problems are actually documented?

It's worth separating documented cases from internet rumor. The record contains four anchor incidents.

Flo Health: the FTC's 2021 complaint alleged Flo shared users' menstrual and pregnancy data with third-party analytics firms from 2016 to 2019 despite promising privacy; Flo settled without admitting wrongdoing. The related class action ended in 2025 with Google paying $48M, Flo $8M, and the analytics firm Flurry $3.5M — a combined $59.5M fund — while a federal jury separately found Meta liable under California's wiretapping law for collecting Flo users' data. All settling companies deny wrongdoing.

Premom: in 2023 the FTC charged its maker with sharing identifiable health information and precise location data with third-party analytics firms, including two based in China, without user consent. The company paid a $100,000 penalty and is permanently banned from sharing health data for advertising.

Glow: California's Attorney General settled with Glow for $250,000 in 2020 over 2013–2016 security failures, including a flaw that let anyone change any user's password.

Industry-wide: Mozilla's 2022 review of 25 reproductive-health apps and devices gave 18 of them its *Privacy Not Included* warning label, and 8 failed minimum security standards. That's a 2022 snapshot — practices change — but it shows how widespread weak defaults were.

FTC.gov press releases (2021, 2023)California AG, People v. Glow (2020)Mozilla Foundation, Privacy Not Included (2022)

Can my period tracker data be used against me legally?

This fear became widespread after Dobbs in 2022, so it deserves a precise answer. Digital-rights groups that track actual prosecutions, including the Electronic Frontier Foundation, report that period-app data has not been the key evidence in abortion-related cases — text messages, search history, and social-media messages have been. So the documented risk is lower than the headlines suggested.

But "hasn't been" is not "can't be." Any data that exists on a company's server can, in principle, be subpoenaed, and apps differ enormously in how they'd respond. MIT Technology Review reported in June 2022 that Stardust's then-privacy-policy said it would share data with authorities "whether or not legally required" (language the company later revised), while Berlin-based Clue stated it would not respond to US subpoenas for health data under GDPR.

The structural point stands regardless of policy wording: a subpoena can only reach data that exists somewhere to be subpoenaed. If your cycle history is stored only on your phone — not on any server, not tied to any account — there is no third-party copy for a legal request to target. That is the architecture-level answer to a legal-level worry.

EFF (June 2022)MIT Technology Review (June 2022)

Does HIPAA protect my period app data?

No — and this is probably the most consequential misunderstanding in this space. HIPAA covers "covered entities": healthcare providers, health plans, and their business associates. A consumer app you downloaded from the App Store is none of those. Your gynecologist's records are HIPAA-protected; the same information typed into a period app generally is not.

What applies instead is a patchwork: the FTC Act's prohibition on deceptive practices (which is what caught Flo — promising privacy and not delivering), the FTC's Health Breach Notification Rule (used against Premom in its second-ever enforcement), state laws like California's CMIA, and the EU's GDPR for European users. These punish broken promises after the fact; none of them prevents an app from sharing your data if its privacy policy discloses it in the fine print.

Practical consequence: reading the privacy policy matters more for a period app than for almost any other app you use. Look specifically for what's shared with "partners" or "service providers," whether data is used for advertising, and what the policy says about legal requests.

HHS.gov HIPAA guidanceMozilla Foundation (2022)FTC Health Breach Notification Rule actions (2023)

What should I check before trusting a period tracker?

Five checks cover most of the risk, and all of them come straight from how the documented failures happened.

1. Where does data live? On-device storage means no server copy exists — the strongest guarantee available. If data goes to the cloud, everything else on this list matters more.

2. Are there third-party SDKs? Both FTC cases (Flo, Premom) describe embedded analytics and advertising SDKs as the leak vector. If the app shows ads or its policy mentions analytics partners, assume data flows outward.

3. Is an account required? An email-linked account ties your identity to your cycle history. No account means no identity linkage.

4. What happens when you delete? Deleting an app does not delete server-side data. Look for an explicit deletion right and whether the company says it instructs third parties to delete too.

5. What's the law-enforcement policy? Clear language about how the company handles subpoenas is a good sign; silence or broad "we comply with authorities" language is a red flag researchers specifically called out.

Apps built to pass these checks exist. Mozilla's 2022 review named Euki — which stores everything locally — as its only "Best Of" pick, and PinkyBloom was designed around the same principle: data stays on your phone, no account, no third-party SDKs, so checks 1–4 pass by construction.

EFF (2022)Mozilla Foundation, Privacy Not Included (2022)FTC complaints (2021, 2023)

What is the safest way to track my period?

Ranked by how much of the documented risk each option removes:

On-device apps are the strongest option that's still convenient. When cycle data is stored and processed only on your phone, the whole class of server-side incidents — SDK sharing, breaches, subpoenas of company servers — becomes structurally impossible rather than contractually promised. This is PinkyBloom's architecture, and it's why privacy reviewers favored Euki's local-only design; the guarantee comes from where the data is, not from a policy that can change.

Cloud apps with strong governance are a workable middle ground if you need multi-device sync: prefer GDPR-jurisdiction companies with explicit no-advertising, no-data-sale policies and a stated position on legal requests. You are trusting promises, but well-regulated ones.

Pen and paper or a plain calendar is genuinely private but loses the things that make tracking clinically useful — pattern detection, prediction, symptom history you can show a doctor.

What you shouldn't do is stop tracking out of fear. Cycle data is one of the most useful health signals you have — the American College of Obstetricians and Gynecologists treats the menstrual cycle as a vital sign. The evidence-backed move is to keep the data and change where it lives.

ACOGMozilla Foundation (2022)EFF (2022)

Related questions

Get personalized answers from Pinky

PinkyBloom's AI assistant uses your cycle data to give you answers tailored to your body — private, on-device, and free forever.

Download on the App StoreGet it on Google Play
Download on the App StoreGet it on Google Play