The privacy problems hidden in your period tracker
bbc.com
bbc.com
https://f-droid.org/packages/com.drip/
It's not mentioned in the article.
Like Euki it's local-only. I don't know how they compare as far as features but it's cool that there are two good apps out there.
[1] https://www.thebureauinvestigates.com/stories/2025-09-03/met...
This one is about privacy — what data an app chooses to collect and which third parties it intentionally sends that data to. The concern isn't that someone hacked those companies. The distinction is important for us.
Disclaimer: RudderStack founder.
If they can't keep it safe they have no legitimate interest having the data
> Euki is the only app Mozilla recommends without reservations. "Euki is special," Wodinsky* says.
> Unlike the other apps on this list, Mozilla says Euki keeps all your health information stored on your device, without even sending it to the company's servers.
> You don't even need to make an account, so you can stay completely anonymous. Euki also offers a "decoy" feature that shows fake, harmless information if someone gets your phone and tries to snoop.
*Shoshana Wodinsky, a privacy research analyst who tested 6 period tracker on behalf of the Mozilla Foundation
> This is also not Planned Parenthood's first run in with privacy criticisms. I wrote about similar problems four years ago, for example. The organisation didn't respond to a request for comment.
.. And it doesn't look like they care to change anything about it. Who can end this on a positive note? I hate to be this negative but I don't see it.
>Drip, Euki, and Apple Health
https://www.forbes.com/sites/kashmirhill/2012/02/16/how-targ...
This argument gets trotted out whenever people talk about privacy and protection of personal information. I hear it when people discuss LPR systems, cameras, and the like too.
These data-gathering applications of technology should be treated specially because they make it extremely easy to gather high-confidence data about individuals. I bet your data broker couldn't predict when someone was ovulating or whether they were pregnant or count how many miscarriages they had just based on purchase history? This is all data that period tracker apps capture pretty directly. The miscarriages one is particularly bad because that data could be misconstrued as abortion and in US states where that's illegal it could get you into real trouble. There's a small but vocal subset of the population that seems to want to punish women for anything other than a healthy delivery. But when my spouse and I were trying everyone we talked to had at least one if not more miscarriage stories.
The one downside is that they do days since last period as days since the end of your last period, not days since the start, unlike literally every woman and gynecologist ever.
Sadly, a lot of the great boutique lifestyle business paid apps are apple only, and I can't stand the typing experience on iphones.
There is no limit to greed, you can find billionaires who are after trillions. This line of reasoning is at fault.
The value of tracking my diet and health has been well worth it. I will happily pay their asking price and it's heartening to hear that the founders/owners are committed to good practices.
Side note: I recently switched over fully to the Proton Unlimited ecosystem. Another ethical service that I will happily pay for.
I'm beginning to think that we might be able to turn this shitty ad-industry-lead ship around, folks. Or at least we have strong alternatives these days for the people who care.
Now if I can just get my social groups to use Signal.
That's something you can directly do in AI studio for free, or use free API quota.
This is kinda misleading. First of all, MacroFactor uses the Gemini API for photo to calorie/macro estimation, so the data does leave their premises. It does not work completely offline, so it does call home, and after that, you never really know what happens with the data.
MacroFactor charges roughly $70 a year. MacroCodex is free and doesn't require an internet connection to work. It can also offset random weight gain due to PMS or other short term hormonal cyclical issues, as well as other water retention issues. It doesn't even ask for your phone number or email or even date of birth!! (it just asks age) on Android. On the web app, an email is required only for storing your data (due to the volatile web storage offered in PWAs, where the OS/browser can evict storage under memory pressure).
If an app doesn't collect your personal identifiable data it cannot sell it, if it's capable of running offline it can be put behind a firewall rule and/or diagnostic/telemetry data disabled in setting though i'd argue if it's not collecting your personal info and want data for improvement of specific app feature (which benefit from data analysis) then you should perhaps analyze the risk of this decision.
I thought entering the information is like 90% of the tracking, everything else is mostly calculation/averaging and none of it needs to live on a server. The Euki app seems like my idea of what it would always be.
Paying for apps doesn't help as much as expected, as they'll want to keep the revenue stream alive. Solving this conundrum would require to deal with both side of the coin.
The real solution to this would be to give everyone and their dog a standardised online server with legally enforced privacy, and have sandboxed apps manage data in and out in a interexchangeable format, but I feel like I'm asking for peace on earth.
PS: we have banks for money, there should really be something similar for data.
It's very hard to imagine a government who would have this too far up their list of priorities. Switzerland maybe. Then Germany, France. Maybe. It's hard to imagine it catching on between the monied interests who can influence government and the lack of consumer awareness of the problem it is solving.
All you need is for the app to provide the option of saving to local storage – your cloud server software provides a local storage endpoint and does the rest.
There is, but the majority of HN participants hate the existing banks with a white-hot passion, and rail against those banks, and prefer to store their cash under their mattress, and their photos in Chad's garage, and they actively discourage everyone else from trusting banks, especially the biggest ones.
Android comes with auto backup, https://developer.android.com/identity/data/autobackup
App developers choose to collect more data than they need.
That sounds like Tim Berners-Lee’s Solid project.
https://en.wikipedia.org/wiki/Solid_(web_decentralization_pr...
FWIW, this is not an unreasonable ask either.
Whether you’re trying to have a baby, buying her snacks, or planning beach/pool activities together, it’s very useful.
how is that even 10% more convenient than simply speaking? nevermind being worth giving away private data.
No way you can get someone to tell you that unprompted.
Now, of course I would prefer if that data was end-to-end encrypted.
to be clear, you think getting a notification about an incoming period is more convenient than being directly told about it? even considering you'll probably already be speaking to this person during this period (otherwise the notification is pointless)?
that barely makes sense even in the strict interpretation where it means that it takes less key presses to enter your period information on an app than typing "i'm on my period" every month (though i doubt you can beat typing "pms").
> No way you can get someone to tell you that unprompted.
and you can get people to, connect/sync with you or whatever, on yet another app, made strictly for this purpose, unprompted?
> Now, of course I would prefer if that data was end-to-end encrypted.
but the important question is the intensity of this preferrence. clearly, it's not as strong as your preferrence for... one key press less per month?
how is that saying? if one key press less per month is all it takes for you to give up private information, then i have a bridge to sell to you.
As the article stated, there are apps that don’t share this data with advertisers, and operate on jurisdictions with strong privacy laws.
We don’t live in a state where we would have no recourse against such privacy violations, and we don’t live in a state where women’s reproductive rights are being threatened by the government.
So we’re using the app.
If your bridge is useful, maybe we’ll buy it.
... they could fail to realize that they were hacked last year.
Sadly, the same issues apply to the copies of your private health data in your doctor's computer, your insurance company's computer, your hospital's computer, your pharmacy's computer, etc.
Avoiding the app reduces the attack surface. With the minor moral victory of not having gone out of your way to make it easy for the enemies of your privacy.
Adding to this, my understanding (IANAL) is that any promises to delete or limit sharing of your data could be swept-aside by a bankruptcy judge, putting priority on liquidating the company and its assets for the maximum amount of money for creditors.
If well-intentioned operators erase your data before the company falls into the hands of the trustee or creditors, an unsympathetic legal-system could end up charging them with crimes for it.
If the app is free software, then you don't need to trust; you can verify instead. See: apps on F-Droid.
The technology it is built on is extremely cool. http://pears.com/
Or better yet. Why trust this one (even though the source is on github)? You can just ask your AI agent to build you your custom one on the basis of this technology.
In contrast with the (single) mention of open-source on Mozilla's website that the BBC article cites: https://www.mozillafoundation.org/en/nothing-personal/period...
These articles are always so vague, never explaining the difference between proprietary and free software, and even treating sending data to company servers as some kind of acceptable default, only raising privacy alarms when the data is also sent (directly) to some 3rd party server. As if that makes any difference once the company has your data - they can sell it to whoever themselves.
https://support.apple.com/en-gb/guide/security/sec88be9900f/...
> We are a community of researchers and developers interested in advancing Fully Homomorphic Encryption (FHE) and other secure computation techniques.
(edit: formatting)
Why are so many women saying their periods are suddenly late or irregular? Experts explain https://dailynews.co.za/lifestyle/health/2026-07-14-why-are-...
Your menstrual cycle may affect how well vaccines work https://www.newscientist.com/article/2532245-your-menstrual-...
COVID-19 vaccine 'disrupted the periods of thousands of women' - but changes 'short-lived' https://news.sky.com/story/covid-19-vaccine-disrupted-the-pe...
I always use open source apps, but at the same time I wonder how can my we all benefit from each other data respectfully of privacy, health or otherwise
And anyway the data that the other 50 apps are collecting on most people phones can be used to infer most of this. Your locations, what you bought recently, what you searched online, which sites have you been, what you asked your chat bot, what you liked or viewed in social media...
Although the article doesn't accuse us of doing anything improper, we weren't contacted for comment, so I'd like to clarify our role.
We are customer data infrastructure, not a data broker. We do not buy, sell or monetize the customer data that passes through our systems.
Our role is analogous to infrastructure: customers choose what data to send, and RudderStack routes that data to the destinations they configure (analytics tools, data warehouses, marketing platforms, etc.). The customer owns the data and decides where it goes; RudderStack does not repurpose it for its own business.
Infrastructure providers like us should be held to high standards for security and privacy, but we should not be confused with companies that collect or monetize end-user data.
Ultimately, RudderStack is infrastructure that moves first-party data between systems more like message queues.
I’m struggling to understand why you would feel the need to comment. Or why you even think the BBC would have contacted you. This is one of those moments in PR where a response with no reason makes reasonable people wonder why.
I wanted to clarify that distinction because we've already had people reach out asking whether we were involved in collecting or using this data.
Its bad PR for us
> Mozilla uncovered numerous privacy problems across various apps, but Stardust was the only one found sharing detailed reproductive health data with another company.
> The report found that Stardust sends users' health information to a data management company called RudderStack, which isn't named in its privacy policy. That data includes pregnancy status, birth control, moods, alcohol consumption and specific symptoms like tender breasts and stomach cramps.
> Companies often share data with outside services to process information and analyse user behaviour. There's nothing unlawful going on, and there's no reason to think RudderStack (or any company mentioned in this story) is doing something nefarious.
> However, experts say it's inherently risky when your data spreads to more places. It creates another opportunity for security breaches or legal requests for information. Besides, you may just be uncomfortable with another company seeing your health data.
> A Stardust spokesperson says the company only uses RudderStack as a "technical pipeline" to route data into its own analytics systems, and the app doesn't share anything that could allow RudderStack to identify your name or contact information. "Additionally, RudderStack is contractually prohibited from selling or using it for its own purposes," and RudderStack doesn't store the data long-term, the spokesperson says.
> "People deserve better," says Shoshana Wodinsky, a privacy research analyst who conducted Mozilla's tests. At the very least, she says, you should know what's happening.
Granted, that statement came from our customer and not incorrect, but these small things can be mis-interpreted.
Managed to copy the email though. Thanks for the pointer