Back to the journal

Privacy and trust

What your period app actually knows about you

A plain-English audit of what cycle apps collect, who can ask for it, what local-only really means, and Flowy's own answers to the same questions.

Key takeaways

  • The useful question is not ‘is it private?’ but ‘who holds it, who can ask for it, and what happens when I stop using it?’
  • The FTC alleged Flo shared health data with marketing and analytics firms; a jury later found Meta liable, and 59.5 million dollars settled the rest. The mechanism was ordinary analytics tooling.
  • HIPAA usually does not cover a consumer app you downloaded yourself. The FTC’s Health Breach Notification Rule does.
  • ‘Local-only’ is not the same as private — backups still leave the device, and an app can store cycles locally while sending revealing analytics events.

Most privacy pages are written to be survived rather than read. That is a problem for cycle apps in particular, because the record they hold is unusually revealing: not just dates, but sex, pregnancy attempts, miscarriage, medication, mood, and the gaps where something went wrong. Before trusting any app with that, the useful question is not "is it private?" but "who holds it, who can ask for it, and what happens when I stop using it?"

A woman lying in bed using a smartphone at night. Photo by Marcus Aurelius on Pexels.

This is an audit you can run on any tracker, including this one. Flowy's own answers are in a table further down, including the parts that are less flattering than a marketing page would put them.

What a cycle app can collect, beyond the obvious

The cycle record is the part everyone thinks about: period start and end dates, flow, symptoms, notes. It is rarely the whole file.

An app account also typically holds an identifier of some kind, usually an email address, phone number, or a sign-in through Apple or Google. Onboarding answers often add date of birth, contraception method, diagnosed conditions, and goals such as trying to conceive. Beyond that sits a second layer most people never see: analytics events describing which screens you opened and which buttons you pressed, crash reports, device identifiers, advertising identifiers where they are permitted, purchase and subscription records, and push notification tokens.

That second layer is where cycle apps have historically gone wrong. Not by selling a spreadsheet of periods, but by wiring a marketing SDK into the app and letting it observe events with names that gave the game away.

The Flo case, and why it matters to every other app

In January 2021 the US Federal Trade Commission alleged that Flo Health had shared sensitive health information from millions of users of its period and ovulation tracker with marketing and analytics firms, including Facebook's and Google's analytics divisions, AppsFlyer, and Flurry, despite promising to keep it private. The order was finalised in June 2021 and required Flo to obtain affirmative consent before sharing health information, notify affected users, and instruct third parties that had received the data to destroy it.

It did not end there. In August 2025 a California federal jury found Meta liable under the California Invasion of Privacy Act over the collection of Flo users' reproductive health data, one of the first wiretapping claims against a large technology company to reach a jury verdict. Separately, Flo Health, Google, and Flurry agreed to pay 59.5 million dollars to settle the claims against them.

Two things are worth taking from this. First, the mechanism was mundane: standard analytics tooling, fed events it should never have been given. Second, it took a regulator and four years of litigation to surface it. You could not have found it by reading the privacy policy, which is precisely the problem.

HIPAA almost certainly does not apply

A common assumption is that health data in an app is protected the way health data in a hospital is. In the United States it usually is not. HIPAA covers healthcare providers, health plans, and their business associates. A consumer app you downloaded yourself generally falls outside it.

What does apply is the FTC's Health Breach Notification Rule, which the FTC updated in 2024 to make explicit that health apps and connected devices not covered by HIPAA, period trackers among them, count as vendors of personal health records and must notify users of a breach of unsecured identifiable health information. The FTC has brought enforcement actions on this ground against GoodRx, BetterHelp, and the fertility app Premom.

In the UK and EU, cycle data is special category data under UK GDPR and the GDPR, which sets a higher bar for lawful processing and consent. In September 2023 the UK's Information Commissioner's Office opened a review of period and fertility apps. Its conclusion was mixed rather than damning: no significant compliance issues or evidence of harm, alongside a clear finding that developers could do better on transparency, valid consent, and accountability. The user survey underneath it is the part worth remembering: more than half of respondents believed they had seen an increase in baby or fertility-related adverts after signing up, 17 percent found those adverts distressing, and 59 percent said transparency about data use mattered more to them than price or ease of use.

What "local-only" actually means

"Local-only" is used loosely enough to be nearly meaningless in marketing copy. Precisely, it means the app writes your records to the device's own storage and never transmits them to a server the developer controls. It is a real and strong property, and it comes with real costs:

  • No sync. A new phone, or a second device, starts empty unless you restore from a backup.
  • Backups still exist. Data local to the phone is generally included in an iCloud or Google backup, which lives on someone else's servers.
  • A device can be inspected. Local-only protects against a breach at the company. It does not make a phone in someone else's hands unreadable.
  • Analytics can still leak. An app can store cycle records locally and still send revealing events to an analytics service. Local storage and local privacy are not the same claim.

Cloud sync is the trade you make for having your history follow you across devices and survive a lost phone. What matters is whether the company says plainly that it holds your data, what protects it, and how you get it back out or delete it.

Flowy's answers to the same questions

Flowy is not local-only, and describing it that way would be false. Here is what it does instead, taken from the privacy policy rather than paraphrased around it.

  • Where do cycle records live? In a Supabase account database with owner-scoped access controls. Sensitive local caches on the phone use iOS file protection. Flowy is an account-based app with cloud sync, not a local-only one.
  • Is health data sold or used for ads? No. Flowy does not sell personal or health data, and does not build an advertising profile from a cycle history.
  • Which third parties are in the app? Supabase for authentication, database and storage; RevenueCat for subscription status, which receives your account identifier and contact profile details; PostHog for product analytics; Sentry for crashes and performance. Apple processes purchases.
  • Do analytics see cycle data? No. Product and error events exclude names, contact details, cycle answers, symptoms, notes, health values, and calendar dates. Session replay is disabled in both PostHog and Sentry.
  • What about this website? It is separate from the app. Microsoft Clarity and the Meta pixel load only if you accept them in the cookie banner; Vercel Analytics counts page views without cookies. None of them can reach app data.
  • What does Apple Health access involve? It is optional and read-only. With permission, Flowy reads selected menstrual flow, basal temperature, cervical mucus, and sleep samples. It never writes back to Apple Health.
  • How long is data kept? Until you delete it or your account. Export files are removed from temporary storage after 15 minutes. Limited billing records are retained for accounting and fraud prevention.
  • How do I get it out, or get rid of it? Export your data, reset health data while keeping your account, or delete the account and everything owned by it, all from inside the app.
  • Who do I ask? rohit@flowyhealth.com. Flowy is built by one person in Vienna, and the about page says who.

Two honest limits. Flowy has not been through an independent third-party privacy audit, and saying otherwise would be the exact kind of claim this article is warning you about. And no company can promise how it would respond to a lawful order it has not received; what it can do is hold less, keep it in fewer places, and let you delete it, which is what the controls above are for.

A ten-minute audit you can run on any app

Do this before you type in a single date.

  1. Read the App Store privacy label first. Look specifically for "Data Linked to You" and whether health or sensitive information appears under "Data Used to Track You".
  2. Search the privacy policy for the words "sell", "share", "advertising", "partners", and "affiliates". Vague sharing language is the tell, not the reassuring sentence at the top.
  3. Find the retention answer. If a policy never says when data is deleted, assume the answer is "indefinitely".
  4. Find the delete flow before you need it. An account you can only close by emailing support is a warning sign.
  5. Check whether export exists. Being able to leave with your history is the practical test of who owns it.
  6. Look for a named human. An address, a company registration, a person who answers. Anonymous health apps are a category worth skipping.
  7. Turn off what you do not need. Ad tracking permissions, optional analytics, cloud backup of the app if you would rather it stayed on the phone.

Frequently asked questions

Can a period app be forced to hand over my data?

Any company that holds data can be served with a valid legal request in the jurisdictions it operates in, and the specifics depend heavily on where the company and the data sit. The practical protections are the boring ones: an app that collects less, retains less, and lets you delete your account has less to hand over. If this is a live concern for you, a lawyer in your jurisdiction is the right person to ask, not an app's marketing page.

Is a paper diary safer?

For the narrow question of company-held data, yes, and it cannot be breached, subpoenaed from a server, or sold. It also cannot be searched, exported for an appointment, or backed up if you lose it. Some people keep dates on paper and use an app only for reminders, which is a perfectly reasonable middle position.

Does deleting the app delete my data?

Usually not. Deleting an app removes it from the phone; an account on a server persists until you delete the account. Use the in-app delete flow first, then remove the app.

Are free apps worse for privacy?

Not automatically, but the question of how the app is funded is worth asking out loud. Subscriptions, advertising, and data licensing are different business models with different incentives, and the second and third involve someone other than you paying for your record.

Flowy keeps your cycle history in one account you control, with export, reset, and delete built in, and is upfront about what it does and does not do. It does not diagnose anything, confirm ovulation, or work as contraception.

This article is for general education only. It is not legal advice, a diagnosis, or a substitute for care from a qualified healthcare professional.

References

#Privacy#Data#Privacy and trust