The Data These Apps Actually Collect (It's More Than You Think)
Period tracking apps collect far more than cycle start and end dates. Flo, Clue, Glow, and similar menstrual health apps prompt users to log sexual activity, contraceptive use, pregnancy attempts, physical symptoms, mood shifts, energy levels, and prescription medications. Many integrate with phone GPS to record location data. The result is not a simple health calendar — it is a detailed behavioral and reproductive profile built entry by entry, often across years of daily use.
That profile has commercial value. Most consumer period and fertility tracking apps monetize user data by sharing it with third-party data brokers, advertisers, and analytics companies. Users typically agree to this through terms-of-service agreements written in dense legal language that few people read in full. The transaction happens quietly: your logged records of unprotected sex or a missed period can be packaged, sold, and resold without any additional notification to you.
The legal protection covering that data is startlingly thin. HIPAA — the federal law that governs medical privacy — applies to healthcare providers, insurers, and their direct business associates. It does not apply to consumer wellness apps. A gynecologist's records of your reproductive history are legally protected. The same information you typed into Flo at 11 p.m. on your phone is not. That gap places period tracker data in a largely unregulated gray zone where companies set their own rules and users have almost no statutory recourse if those rules change or are violated.
Several states have begun passing consumer health data privacy laws — Washington's My Health My Data Act is the most aggressive example — but enforcement is limited and geographic reach is uneven. For the roughly 50 million people in the United States who use period tracking or fertility monitoring apps, the default legal position is that their most intimate health information enjoys fewer protections than their online shopping history.
The Missing Context: How Urban Surveillance and App Data Converge
Exposed San Francisco Police Department drone footage, left unsecured on the open web, put a concrete face on what urban surveillance infrastructure actually captures: granular, continuous records of where people go, when they go there, and how long they stay. That footage isn't an anomaly. It reflects a surveillance layer that now blankets most major American cities, operating quietly alongside the apps millions of people carry in their pockets.
Period tracking apps collect location data. City surveillance systems collect movement records. Investigators can subpoena both. The critical gap in most reproductive privacy coverage is the failure to connect these two streams into what they actually form together: a compounding evidence chain capable of placing a specific person at a specific reproductive health clinic on a specific date.
Here's how that chain builds. A menstrual cycle app logs that a user disabled location sharing on a Tuesday morning — itself a data point. Cell tower records show the phone traveled to a particular zip code. SFPD-style drone footage, or fixed camera networks in cities like Chicago, New York, and Atlanta, can then confirm physical presence near a Planned Parenthood or an independent abortion provider. None of these data sources, reviewed in isolation, tells prosecutors much. Cross-referenced, they reconstruct a detailed timeline a prosecutor in a state with abortion restrictions can use as evidence.
Existing privacy law was built around siloed data categories. HIPAA covers medical providers, not app developers. The Electronic Communications Privacy Act predates smartphones by decades. No federal framework currently governs the convergence of app-layer reproductive data with physical surveillance records, which means no single law blocks investigators from assembling these pieces.
The San Francisco footage exposure also signals something specific about data security: surveillance records collected by public agencies carry weak retention and access controls. Period app data sold to third-party brokers carries weaker ones. Women using fertility tracking apps, ovulation predictor tools, or menstrual health platforms in states where abortion is now criminalized are navigating a surveillance environment that existing digital privacy rights were never designed to protect them from.
The Legal Threat That Most App Store Reviews Won't Warn You About
Most period tracking apps display a privacy policy. Few users read them. Fewer still understand what those policies actually permit — and in a post-Roe legal environment, that ignorance carries real consequences.
In states where abortion is criminalized or severely restricted, prosecutors can subpoena menstrual cycle data, last-period logs, and pregnancy prediction records as evidence of a suspected crime. A missed period entered into an app on Tuesday becomes a data point a district attorney can request by Friday. The user never receives notice. The app company, facing a valid legal order, complies.
The threat doesn't stop at subpoenas. Data brokers operate an entirely separate and legal pipeline. These companies purchase raw location data from apps, aggregate it, and sell it to buyers with virtually no restrictions on who those buyers are. That means location signals showing a phone traveling to a reproductive health clinic can be purchased by anti-abortion advocacy groups, private investigators, or individuals with no law enforcement credentials at all. No warrant required. No notification sent to the person whose movements are being sold.
The San Francisco City Attorney's Office demonstrated that local governments can move aggressively when federal law stays silent — its cease-and-desist letters to Apple and Google targeted 13 AI nudifying apps almost exclusively used to harm women and girls. That action showed real institutional muscle. Reproductive health data has not received the same attention. No comparable enforcement wave has targeted period trackers, fertility apps, or the data brokers profiting from the intimate health information those apps collect.
The result is a regulatory vacuum that millions of people fill with misplaced trust. Apps marketed as menstrual health tools and cycle tracking assistants sit inside a legal framework that treats the data they generate as a commercial commodity first and a health record almost never. HIPAA protections apply to medical providers, not to wellness apps. That distinction matters enormously when law enforcement comes looking.
Who Is Profiting — and Who Is Exposed
The period tracking app market runs on a simple formula: offer free fertility and menstrual cycle monitoring, then monetize the intimate health data users willingly input. Flo, Clue, and Glow collectively count hundreds of millions of registered users worldwide. Flo alone reported over 70 million monthly active users before its 2024 IPO — making it one of the most data-rich health platforms on earth, sitting on years of logged ovulation windows, pregnancy attempts, and missed periods.
The privacy policies governing these apps are engineered for flexibility, not protection. Most reserve the right to share de-identified or aggregated data with third-party advertisers, analytics firms, and research partners. "De-identified" is doing enormous legal work in that sentence. Researchers have demonstrated repeatedly that reproductive health data, combined with location signals and device identifiers, can be re-identified with minimal effort.
Women and girls carry the entire risk in this arrangement. The structural parallel to AI nudifying apps is exact: in both cases, a technology built on female bodies generates revenue for venture-backed companies while exposing users to harms those companies face no liability for. San Francisco's City Attorney moved to pull 13 AI face-swap apps targeting women from Apple and Google's stores precisely because accountability was nonexistent. Period tracking sits in the same regulatory vacuum.
Femtech as a sector raised over $1 billion in venture funding in 2021 alone. That capital comes with return expectations that wellness branding cannot satisfy. Data licensing, advertising partnerships, and behavioral profiling fill the gap. The conflict between a company presenting itself as a women's health ally and a company that profits by selling granular menstrual cycle data to the highest bidder is not a tension — it is the business model.
In a post-Roe environment where prosecutors in abortion-restricted states have already sought digital records in criminal investigations, the question of who profits from period tracker data has a direct answer: the app companies and their investors. The question of who is exposed has an equally direct answer: every person who has ever logged a late period, a pregnancy test result, or a fertility treatment into an app they believed was private.
What Responsible Coverage Has Gotten Wrong
Most journalists framed period tracker privacy as a post-Dobbs story — Roe falls, suddenly your cycle data matters. That framing is wrong in two directions. The data collection infrastructure predates June 2022 by years, and it will survive any single legal ruling, any election cycle, any app store policy update. Flo Health was sharing intimate health data with Facebook and Google before most newsrooms assigned a single reporter to reproductive surveillance. The Federal Trade Commission settled with Flo in 2021 — a full year before Dobbs — over exactly that practice. The problem was predatory long before it became politically legible.
Coverage also suffers from a flagship-app fixation. Flo and Clue absorb most of the scrutiny because they have recognizable names and PR teams that respond to press inquiries. The actual ecosystem runs much deeper. Dozens of smaller period and fertility tracking apps operate with privacy policies written to obscure rather than explain data-sharing arrangements, no independent security audits, and no meaningful regulatory attention. Users of those apps carry the same legal exposure as Flo users but receive none of the coverage that might prompt them to act.
The regulatory comparison that reporting keeps missing is face recognition and AI nudification apps. When the San Francisco City Attorney's Office sent cease-and-desist letters to Apple and Google demanding removal of 13 AI nudifying face-swap apps — tools almost exclusively used to target women and girls — the demand generated real public anger. Regulators moved because the outrage was visible and concentrated. Reproductive health data collection produces diffuse harm that accumulates quietly, which makes it easier for platforms, data brokers, and legislators to ignore.
The honest question isn't whether period tracker data can be subpoenaed or sold. Courts and law enforcement in abortion-restricting states have already demonstrated that it can. The question is why the same public pressure that forced action on deepfake apps has not materialized around menstrual surveillance — and whether the answer is that the harm feels abstract until someone gets arrested.
What Users Can Actually Do — and What Requires Systemic Change
Users have real options today. Switching to an offline cycle-tracking app — one that stores data locally on the device and never transmits it to external servers — eliminates the data broker pipeline entirely. Apps like Drip and Euki were built specifically with this architecture. For apps that do require an account, disabling location permissions cuts off one of the most legally dangerous data points: precise geolocation that could place someone near an abortion clinic. Paying for a subscription tier instead of trading data for a free service reduces the financial incentive developers have to monetize user health information in the first place.
The problem is that every one of those steps lands on the individual. A 17-year-old using a default menstrual tracking app on a new Android phone should not need a working knowledge of data broker law to protect herself from prosecution. Placing that responsibility on users is a structural failure, not a personal one.
Closing that gap requires federal legislation. The Health Insurance Portability and Accountability Act does not cover wellness apps — HIPAA was written for covered entities like hospitals and insurers, and a Flo Health or Clue account falls entirely outside its jurisdiction. A federal consumer health data privacy law that explicitly names reproductive health apps, bans the sale of menstrual cycle data, and creates a private right of action would actually move the needle. Washington state passed the My Health MY Data Act in 2023, extending protections beyond HIPAA to consumer health apps, but no equivalent federal law exists.
The San Francisco City Attorney's office demonstrated what aggressive local action looks like when it sent cease-and-desist letters directly to Apple and Google demanding the removal of harmful apps from their stores. That model applies directly here. State attorneys general and city prosecutors can demand that Apple and Google enforce stricter data-handling requirements on any reproductive health app listed in the App Store or Google Play — requiring transparent data retention policies, prohibiting third-party data sharing, and mandating local-only storage options. Platform-level enforcement reaches millions of users immediately, without waiting for Congress.
Individual privacy hygiene matters. It is not sufficient.
Originally published at Newzlet.
Top comments (0)