Is Your Period App Selling Your Data?
In 2025 a California jury found Meta liable in a period-tracking data case, and regulators have documented real cases of cycle data reaching advertisers. Here is what the public record shows, and a checklist for before you install anything.
Published 27 July 2026

Rarely does the app itself sell a database. The documented risk is what runs inside it: third-party analytics and advertising kits that log sensitive taps as ordinary "app events" and pass them on automatically.
On 1 August 2025 a jury in California saw that exact mechanism play out in court. The app was not the defendant that lost. Meta was, and the jury found it liable for obtaining menstrual and pregnancy information from inside somebody else's software.
What the public record actually shows
The public record shows specific, named enforcement actions against individual apps, such as Flo Health, Premom and the Flo Health class action against Meta, not proof that period apps as a category sell data. In January 2021 the US Federal Trade Commission announced a settlement with Flo Health over allegations that it promised to keep users' health data private, then disclosed it to Facebook's analytics division, Google's analytics division, Google's Fabric service, AppsFlyer and Flurry. The FTC said the disclosures took the form of "app events" and included the fact of a user's pregnancy. The order, finalised in June 2021, requires affirmative consent before health data is shared, plus an independent privacy review. An FTC complaint is issued on a "reason to believe" standard.
In the related class action, Frasco v. Flo Health, Inc. in the Northern District of California, a jury found Meta liable under the California Invasion of Privacy Act for eavesdropping on or recording users' communications with the app through its software development kit. Judge James Donato denied Meta's post-trial motions on 15 September 2025. Google, Flurry and Flo Health settled rather than take a verdict, agreeing to pay a combined 59.5 million dollars without admitting wrongdoing.
In May 2023 the FTC and the Department of Justice filed a complaint and a proposed order against Easy Healthcare, maker of the ovulation app Premom. The federal court entered that order on 26 June 2023. It set a 100,000 dollar civil penalty for breaching the Health Breach Notification Rule and permanently bars the company from sharing health data for advertising. The FTC alleged data went to AppsFlyer, Google, and the analytics firms Umeng and Jiguang.
In 2019 Privacy International ran traffic analysis on six menstruation apps and found Maya and MIA Fem sending information to Facebook through the Facebook SDK, including contraception use and mood entries, whether or not the user had a Facebook account. Four of the six changed their practices or opened internal investigations afterwards.
Then the counterweight. In February 2024 the UK's Information Commissioner's Office reported on its review of period and fertility apps and said plainly that "no serious compliance issues or evidence of harms were identified", while urging developers to improve transparency, consent and accountability. Both are true. Documented failures exist, and they are specific and historic rather than universal.
How cycle data reaches an advertising network
Almost none of this involves a company deciding to sell a database. It involves a software development kit, third-party code the developer drops in for analytics, crash reporting or install attribution. It ships inside the app and runs with the app's permissions.
The FTC's term for what gets sent is "app events". An event can be a launch, a screen view or a tap. When the tap is "log period" or "trying to conceive", the event itself is the health disclosure, even if no medical record ever moves.
The Frasco verdict went further. Liability did not stop with the app, it reached the company operating the kit.
What an App Store privacy label does and does not tell you
An App Privacy label states what an app and its third-party partners declare they collect, but it is self-reported, not independently audited. Apple requires every app to declare its data practices, and the result appears in the App Privacy section of the product page. Its guidance to developers is explicit: "You need to identify all of the data you or your third-party partners collect", meaning analytics tools, advertising networks and SDKs.
Reading one takes about thirty seconds. Open the App Store listing, scroll to App Privacy, tap See Details. Three headings matter, in descending order of seriousness: Data Used to Track You, Data Linked to You, Data Not Linked to You. For a cycle tracker, Health and Fitness under the first is the strongest pre-install signal there is.
Now the limits. The label is self-declared, not audited. Apple tells developers "you're responsible for keeping your responses accurate and up to date", a duty rather than a verification, and carve-outs let some optional collection go undeclared. A clean label is a good sign, not a guarantee.
App Tracking Transparency is the second control, enforced by the operating system. Since iOS 14.5, apps must ask before tracking your activity across other companies' apps and websites, and Ask App Not to Track blocks access to the advertising identifier. What it does not cover is what an app sends to its own servers, or what those servers do next.
Why "anonymised" is a weak word for cycle data
Companies rarely claim they share your name. They claim the data is anonymised, and that is an engineering claim to be checked, not a reassurance. Research in Nature Communications in 2019 by Rocher, Hendrickx and de Montjoye estimated that 99.98 per cent of Americans would be correctly re-identified in any dataset using fifteen demographic attributes. FTC technologists put it bluntly in 2024: data is only anonymous when it can never be associated back to a person, and hashing an identifier does not achieve that. That post cites the Premom complaint, where the company had represented it would share only "non-identifiable data".
Cycle data carries a specific problem too. A menstrual log is a long time series tied to one device, and long time series behave like fingerprints. The valuable part is not your identity anyway, it is your state. Pregnant, trying, not trying. The ICO is clear that inferred health information counts as special category data under UK GDPR, and a fertile-window entry infers exactly that. Stripping the name does not strip the inference. Predictions are estimates, and never a form of contraception, but accuracy is beside the point here. Right or wrong, the inference itself is still a sensitive data point once it has left the device.
A checklist before you install anything
Seven checks, run before installing anything, cover the account, storage, business model, privacy label, deletion, permissions and the tracking toggle.
- Does it require an account? That creates a copy on someone else's server.
- Where is the data stored, and is that stated plainly?
- How does it make money? Free with no ads and no subscription is worth questioning.
- Read the App Privacy label, starting at Data Used to Track You.
- Check what deletion does, and whether it reaches any server copy.
- Grant only the connections you actually need.
- Turn off Allow Apps to Request to Track, at Settings, Privacy and Security, Tracking.
The short version
No regulator has found that period apps as a category sell data, and the ICO found no evidence of harm in its UK review. What has been documented, repeatedly and by name, is sensitive information reaching advertising and analytics companies through embedded third-party code. That risk lives wherever there is a server and someone else's SDK.
Simply Track's position is simple enough to check. There is no account, so there is no server-side copy to breach or subpoena. Data stays on the device, with optional sync to your own private iCloud, optional Face ID lock and optional Apple Health integration. No ads, no data sold. Tracking, the calendar and every first-period guide are free. The Log tab, Insights and the doctor PDF report are Premium, which funds the app.
Sources
- FTC, Developer of Popular Women's Fertility-Tracking App Settles FTC Allegations that It Misled Consumers About the Disclosure of their Health Data: https://www.ftc.gov/news-events/news/press-releases/2021/01/developer-popular-womens-fertility-tracking-app-settles-ftc-allegations-it-misled-consumers-about
- FTC, FTC Finalizes Order with Flo Health, a Fertility-Tracking App that Shared Sensitive Health Data with Facebook, Google, and Others: https://www.ftc.gov/news-events/news/press-releases/2021/06/ftc-finalizes-order-flo-health-fertility-tracking-app-shared-sensitive-health-data-facebook-google
- FTC, Ovulation Tracking App Premom Will be Barred from Sharing Health Data for Advertising Under Proposed FTC Order: https://www.ftc.gov/news-events/news/press-releases/2023/05/ovulation-tracking-app-premom-will-be-barred-sharing-health-data-advertising-under-proposed-ftc
- FTC, Easy Healthcare Corporation (U.S. v.), case timeline and stipulated order: https://www.ftc.gov/legal-library/browse/cases-proceedings/202-3186-easy-healthcare-corporation-us-v
- FTC Office of Technology, No, hashing still doesn't make your data anonymous: https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/07/no-hashing-still-doesnt-make-your-data-anonymous
- CNBC, California jury rules Meta violated privacy law in case involving period-tracking app: https://www.cnbc.com/2025/08/07/jury-rules-meta-violated-law-in-period-tracking-app-data-case.html
- The Record, Judge rejects Meta attempt to overturn Flo privacy verdict: https://therecord.media/judge-rejects-meta-attempt-overturn-flo-privacy-lawsuit
- Period Tracker Data Privacy Litigation, Frasco, et al. v. Flo Health Inc., et al., settlement notice: https://periodtrackerdataprivacylitigation.com/
- Privacy International, No Body's Business But Mine: How Menstruation Apps Are Sharing Your Data: https://privacyinternational.org/long-read/3196/no-bodys-business-mine-how-menstruations-apps-are-sharing-your-data
- ICO, ICO urges all app developers to prioritise privacy: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/02/ico-urges-all-app-developers-to-prioritise-privacy/
- ICO, What is special category data?: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/special-category-data/what-is-special-category-data/
- Apple, App privacy details on the App Store: https://developer.apple.com/app-store/app-privacy-details/
- Apple, User Privacy and Data Use: https://developer.apple.com/app-store/user-privacy-and-data-use/
- Apple, About privacy information on the App Store and the choices you have to control your data: https://support.apple.com/en-us/102399
- Apple, If an app asks to track your activity: https://support.apple.com/en-gb/102420
- Rocher, Hendrickx and de Montjoye, Estimating the success of re-identifications in incomplete datasets using generative models, Nature Communications 2019: https://www.nature.com/articles/s41467-019-10933-3
Common questions
Do period-tracking apps sell your data?
No regulator has found that period apps as a category sell data, and the UK's ICO reported no serious compliance issues in its 2024 review of period and fertility apps. What has been documented, repeatedly and by name, is specific apps such as Flo Health and Premom sharing sensitive data with advertising and analytics companies through third-party code.
If apps do not sell data directly, how does menstrual data reach advertisers?
Through software development kits, third-party code built in for analytics, crash reporting or install attribution. These log "app events", and a tap such as "log period" becomes a health disclosure in itself. In the Flo Health litigation, a jury found Meta liable for obtaining data through its SDK, not through any data sale.
Is "anonymised" cycle data actually private?
Not reliably. Research in Nature Communications found 99.98 per cent of Americans could be correctly re-identified from just fifteen demographic attributes, and FTC technologists say hashing an identifier does not make data anonymous. A menstrual log is also a long time series tied to one device, which behaves like a fingerprint even without a name attached.
Not medical advice
General information, not medical advice. If something about your cycle worries you, speak to a GP.
Keep track of your own cycle
Simply Track logs your period on your iPhone and Apple Watch, and its predictions sharpen the more you record. Your data stays in your own iCloud account.


