MilikMilik

Which Health Apps Protect Your Data—and Which Don’t

Which Health Apps Protect Your Data—and Which Don’t
Interest|Mobile Apps

Health App Privacy Starts With Where Your Data Lives

Health app privacy is the set of practices that determine how apps collect, store, encrypt, and share sensitive data such as menstrual cycles, moods, and sexual health information, and whether that data stays on your device or is transmitted to remote servers and external companies that can analyse, monetise, or disclose it to advertisers or law enforcement. Health and fitness apps might look similar in the app store, but their privacy choices are wildly different. Some period trackers and fitness tools promise “private” experiences while quietly sending data to advertising networks and analytics firms. Others minimise risk by keeping information on your phone only, avoiding accounts and cloud sync. If you care about period tracker security and health app privacy, the first question isn’t which app has the cutest interface—it’s who can see your health data, and where that data is stored.

Local Storage vs. Cloud Sync: Why Euki Stands Apart

The clearest privacy divide in period trackers is between apps that store data locally and those that push everything to their own servers. Euki is the rare example that chooses the safer path. Unlike the other audited apps, it keeps all your health information on your device and does not send it to company servers; you don’t even need an account, so you remain anonymous. One quotable conclusion from the audit was: “We strongly recommend Euki for anyone who puts privacy first”. That is a polite way of saying: every extra server involved is another legal and technical risk. Most health and fitness apps, including ones that tout encryption, still store data on infrastructure they control and can access, and may share it with advertisers. If your reproductive health data never leaves your phone, it is much harder for anyone else to get it—whether that’s a marketer or a prosecutor.

When “Private” Apps Share With Tech Giants

Once your health data hits the cloud, you’re in the world of health data sharing—and many popular apps are far more generous with your information than you might expect. The audit found that some apps have strong protections, while others share data in ways you may find disturbing, including with platforms run by Google, Meta, Microsoft and TikTok. Companies often justify this as “processing” or “analytics,” but every additional partner is another potential breach point or subpoena target. One particularly troubling case: Stardust, a period tracker that markets itself as fiercely private, was found sharing detailed reproductive health data—pregnancy status, birth control, moods, alcohol use, and specific symptoms—with an external data management company that the privacy policy did not name. Even if this is legal and “de-identified,” it undermines the app’s privacy narrative and exposes users to risks they never knowingly accepted.

Tracking You, Even When They Don’t Track Your Symptoms

Defenders of mainstream health apps often argue that they don’t share your actual medical details. That misses a crucial point: many still share who you are and the fact that you use a reproductive health app at all. The audit found that many apps send basic user information—device identifiers, app usage data—to advertising and analytics services run by major tech platforms. Period Calendar sends ID numbers and device information to Google and an advertising company, with no way for users to stop it. Stardust shares similar data with Facebook and an ad analytics firm, though you can only limit this via phone-level settings, not inside the app. Even Planned Parenthood’s Spot On app, which doesn’t itself share health data, routes users to a website that passes details about the kind of care you’re seeking, such as HIV testing or gender-affirming services, to an analytics company. Being “tracked” in this way can create a detailed picture of your health life, even without explicit symptom logs.

Flo, Clue, and the Burden of Over-Collection

Not all privacy risks come from shady sharing; sometimes the problem is how much an app chooses to collect and centralise. Flo and Clue were criticised for gathering far more health information than comparable apps and then storing it on their own servers. That volume and sensitivity of data turns their infrastructure into a high-value target for both hackers and law enforcement. Other apps in the same category have already faced privacy scandals, yet many continue to expand what they log—fertility signs, sexual activity, moods, and more—without giving users fine-grained control over what stays on-device. From a health app privacy perspective, over-collection is a structural flaw: the safest data is the data that never existed on a cloud server. When reproductive rights are contested and police have already used tech company data to help put women in jail, storing expansive health histories in central databases is not a neutral design choice; it’s a risk decision.

How to Audit Your Own Apps Before Sharing Health Data

The most important lesson from period tracker security audits is that you cannot outsource judgment to marketing promises. You need to interrogate your apps before trusting them with health information. The audit suggests concrete questions for choosing a menstrual tracker: Who sees your health data? Who sees that you used the app? Where is the data stored? Extend those questions to fitness apps, sleep trackers, and any tool that touches your body or mind. Check whether the app requires an account, whether it says data is stored locally, and whether it lists advertising or analytics partners. Look for options to disable tracking and limit health data sharing—then assume that anything sent to a server could someday surface in a breach or a legal request. If you cannot clearly answer “who can see this and where it lives,” you should think twice before logging your cycle, symptoms, or sexual health in that app.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!