How secure is your period-tracking app?:Some share more data than you think; Here’s what you should do shouldn’t

Period-tracking apps deal with some of the most personal information people can put on their phones. They can tell you when your next period may arrive, estimate ovulation, track symptoms and help you understand changes in your body. But think about what you tell these apps. A Mozilla Foundation investigation, reported by the BBC, examined six popular period-tracking apps – Flo, Clue, Stardust, Spot On, Period Calendar and Euki and found major differences in how they handle user data. Some offer strong privacy protections, while others share certain information with companies such as Google, Meta and TikTok. Stardust was found sending detailed reproductive-health data to another company, though this doesn’t necessarily mean anything illegal is happening. The findings weren’t all negative. Some apps have improved their privacy practices, while Euki stood out for its strong privacy protection. So, how can you tell if your period tracker protects your privacy? Here are some key things to check. Does your health information leave the app? This is perhaps the most important question: Who actually gets to see the health information you enter? Mozilla found several privacy concerns across the apps it examined. However, Stardust was the only app found sending detailed reproductive-health information to another company. Stardust is a period tracker that combines menstrual-cycle tracking with astrology and horoscopes. It also makes a strong privacy promise on its website: “Your data is private. Period.” Companies commonly use outside services to process information and understand how people use their products. There is no suggestion that RudderStack or the other companies mentioned here are doing anything unlawful or malicious. The privacy concern is simpler: the more places sensitive information travels, the more opportunities there are for a data breach or a legal request for that information. Mozilla privacy researcher Shoshana Wodinsky, who conducted the tests, argues that users should at least be clearly told what happens to their information. Can companies tell that you use a period tracker? An app doesn’t have to share your period dates or pregnancy status to create a privacy concern. Sometimes, simply revealing that you use a reproductive-health app can be sensitive information. Mozilla found that several apps sent basic information about users to advertising and analytics services operated by companies including Google, Meta, Microsoft and TikTok. This information can include an identification number and details about the user’s device. Some people may not mind. But Sara Geoghegan, director of the Consumer Privacy Program at the Electronic Privacy Information Center (EPIC), says even knowing that someone uses a reproductive-health app can have consequences. For example, it could potentially tell law enforcement that a particular person uses an app containing reproductive-health information. Geoghegan describes digital surveillance as a “tapestry” made from many separate pieces of information. When those pieces are combined, they can reveal much more about someone than any individual piece would. Which apps send this kind of information? Mozilla found that Period Calendar, also known as Period Tracker Period Calendar, sent identification numbers and device information to Google and advertising company InMobi. Stardust reportedly sends similar information to Facebook and AppsFlyer, an advertising-analytics company. However, Stardust users can opt out through their phone’s privacy settings. And when users access Planned Parenthood’s website through Spot On, Mozilla says similar information is sent to companies including Google, Microsoft, TikTok and Pinterest. Mozilla says users can’t prevent this. Stardust told the BBC that it doesn’t share health information with advertising platforms. The company said it uses AppsFlyer and Meta to measure and improve its advertising campaigns. Is your health data on your phone or in the cloud? Another key privacy question is where your health data is stored. What has the company done with user data before? Mozilla says an app’s privacy history matters just as much as its current practices. Flo is a key example. In 2021, it settled a case with the US Federal Trade Commission (FTC) over allegations that it shared sensitive user information with Meta, Google and others despite promising to keep it private. Mozilla says Flo has since greatly improved its privacy practices, although it later added new advertising partnerships with Google, Meta and others. Users can turn these connections off in privacy settings. Flo told the BBC that the practices involved in the FTC case ended five years ago and that it did not admit wrongdoing. In 2022, another investigation found lists of devices using Clue, Period Calendar and other period trackers being sold online. Clue said the data came from the wider mobile-advertising system, not its app, and stressed that it has never sold user data. Stardust has also faced privacy questions. It previously appeared to promise end-to-end encryption, but references to it disappeared from its website after journalists raised questions. Stardust did not address the BBC’s questions about the issue. The bigger question: How much privacy do you expect from a period tracker? Meanwhile, several services can share identifiers or device information with advertising and analytics companies, even when they don’t share actual menstrual or reproductive-health records. None of this automatically means these apps are breaking the law. But reproductive-health information is among the most personal information a person can have. The answers can tell you far more about an app’s privacy than a simple promise that your data is “private.”

Leave a Reply

Your email address will not be published. Required fields are marked *

Enquire now

Give us a call or fill in the form below and we will contact you. We endeavor to answer all inquiries within 24 hours on business days.