The privacy problems hidden in your period tracker
The privacy problems hidden in your period tracker
Some apps are sharing users' health data. New research uncovers which apps lock down your privacy, and which don't.
Stardust is a period tracking app that combines users' menstrual cycles with astrology and horoscopes. It also makes bold privacy promises.
"Your data is private," Stardust says on its website. "Period."
The problem, according to a new report shared exclusively with the BBC, is you and Stardust may have different definitions of "private".
The Mozilla Foundation, creator of the Firefox web browser, investigated the privacy practices of six popular period trackers: Flo, Clue, Stardust, Spot On, Period Calendar and Euki.
Some apps have strong protections. Others handle data in ways you might find disturbing, like sharing information with Google, Meta and TikTok, alongside other companies you've likely never heard of.
This may be perfectly legal. But since the US Supreme court overturned federal abortion protections in 2022, experts worry that data gathered by period trackers could be used in criminal cases. Police have already obtained other kinds of data from tech companies and used it to help put women in jail.
But there's good news too. This isn't the first time period trackers have been criticised for privacy problems, but Mozilla found some apps have cleaned up their acts, and others make privacy their whole mission. Mozilla described Euki, for example, as "squeaky clean".
With Mozilla's help, I want to guide you through the different ways that period trackers handle your data.
Here are four questions that can help you protect your privacy when choosing a menstrual cycle tracker.
Who sees your health data?
Mozilla uncovered numerous privacy problems across various apps, but Stardust was the only one found sharing detailed reproductive health data with another company.
The report found that Stardust sends users' health information to a data management company called RudderStack, which isn't named in its privacy policy. That data includes pregnancy status, birth control, moods, alcohol consumption and specific symptoms like tender breasts and stomach cramps.
Companies often share data with outside services to process information and analyse user behaviour. There's nothing unlawful going on, and there's no reason to think RudderStack (or any company mentioned in this story) is doing something nefarious.
However, experts say it's inherently risky when your data spreads to more places. It creates another opportunity for security breaches or legal requests for information. Besides, you may just be uncomfortable with another company seeing your health data.
A Stardust spokesperson says the company only uses RudderStack as a "technical pipeline" to route data into its own analytics systems, and the app doesn't share anything that could allow RudderStack to identify your name or contact information. "Additionally, RudderStack is contractually prohibited from selling or using it for its own purposes," and RudderStack doesn't store the data long-term, the spokesperson says.
"People deserve better," says Shoshana Wodinsky, a privacy research analyst who conducted Mozilla's tests. At the very least, she says, you should know what's happening.
Spot On, an app made by the sexual health organisation Planned Parenthood, had its own privacy issues related to health information, but the situation was more complicated.
The Spot On app itself doesn't share data with other companies or try to track users, Mozilla says. But tapping certain features – an AI chatbot called Roo and a healthcare provider search tool – opens Planned Parenthood's website in a browser. Mozilla says the website is less secure.
The most striking example:........
