ANALYSIS

What cycle-tracking apps do with your data, and the patchy rules that cover it

A review of 23 women's health apps found 87% shared user data with outside firms. The main US rule that covers them orders breach disclosure — it does not stop the sharing.

Privacy practices found across 23 women's mHealth appsShared data with third parties: 87%; Displayed a privacy policy: 70%; Allowed location tracking: 61%; Gave data-security information: 57%; Requested user consent: 52%0%45%90%Shared data with third parties87%Displayed a privacy policy70%Allowed location tracking61%Gave data-security information57%Requested user consent52%
Privacy practices found across 23 women's mHealth apps
GroupValue (%)
Shared data with third parties87
Displayed a privacy policy70
Allowed location tracking61
Gave data-security information57
Requested user consent52
Privacy practices found across 23 women's mHealth apps Scoping review and content analysis of the 23 most popular women's mHealth apps on the App Store and Google Play; each bar is the share of the 23 apps. Source: JMIR mHealth and uHealth

Most popular women's health apps share the data their users enter with outside companies, and the main US federal rule that applies to them requires telling people after a breach rather than limiting the sharing itself. A scoping review of the 23 most popular women's mobile-health apps found that all 23 collected personal health data and 20 of them — 87% — shared user data with third parties [s1].

The apps in question track menstrual cycles, ovulation and pregnancy, and the information they hold is unusually sensitive: a logged late period, a recorded pregnancy, a note about contraception. This piece is about where that information goes and what law governs it — not about how accurately any app predicts a fertile day, which a separate analysis of ovulation prediction addresses.

What the app reviews found

The scoping review, published in JMIR mHealth and uHealth in 2022, had two independent reviewers assess the 23 apps against a fixed set of privacy, data-sharing and security criteria [s1]. Every app collected health-related data and every app allowed behavioural tracking; 14 of the 23 (61%) allowed location tracking [s1]. Only 16 (70%) displayed a privacy policy at all, only 12 (52%) requested consent from the user, and one app (4%) operated on what the authors called a pseudoconsent [s1]. Three of the 23 (13%) began collecting data before any consent was obtained [s1].

The headline figure is the sharing. Twenty of the 23 apps (87%) passed user data to third parties, and for the remaining three the authors could not determine what was shared [s1]. Just 13 apps (57%) gave users any information about how their data was secured [s1]. The review is a content analysis of what the apps and their policies disclose, not a network teardown of every packet they send — it describes stated practice and observable behaviour, not the full downstream chain.

A later qualitative analysis, published in the Journal of Medical Internet Research in 2025, examined four widely used reproductive-health apps — Clue, Flo, Period Tracker by GP Apps, and Stardust — chosen to set US-based apps against EU-based ones [s2]. Its framing is explicitly post-Dobbs: the authors note that protection of this data in the United States is shaped by shifting rules, including the overturning of Roe v Wade and the patchwork of state abortion laws that followed [s2]. The concern is not abstract. Cycle data can speak to whether someone is pregnant or has stopped being pregnant, in jurisdictions where that has become a legal question.

Why HIPAA usually does not apply

The instinct that health data is protected by HIPAA is, for most of these apps, wrong. HIPAA binds "covered entities" — clinicians, hospitals, insurers — and their business associates. A consumer app a person downloads themselves is generally none of those, so the data sits outside HIPAA's reach.

What fills part of that gap is the Federal Trade Commission's Health Breach Notification Rule, which the FTC amended in a final rule effective 29 July 2024 [s3]. The rule requires vendors of personal health records and related entities that are not covered by HIPAA to notify affected individuals, the FTC, and in some cases the media when unsecured identifiable health data is breached [s3]. The 2024 amendments were written in part to make clear the rule reaches health apps. But a breach-notification rule is exactly what it says: it governs disclosure after the fact. It does not, on its own, prohibit an app from sharing data with advertisers in the ordinary course of business.

The enforcement that has actually happened

The sharp end of US oversight has been case-by-case FTC enforcement. In 2021 the FTC settled allegations against Flo Health over its Flo Period & Ovulation Tracker app [s4]. According to the FTC's complaint, Flo told users it would keep their health data private and use it only to provide the app, but in fact disclosed data from millions of users to third parties that provided marketing and analytics services — including the analytics divisions of Facebook and Google, Google's Fabric service, AppsFlyer and Flurry [s4]. The agency alleged Flo passed sensitive information such as the fact of a user's pregnancy to those firms as "app events," and did not limit how they could use it, stopping only after a news article revealed the practice in February 2019 [s4]. The settlement required Flo to obtain an independent review of its privacy practices and to get users' consent before sharing health information [s4].

That is the pattern: a specific company, a specific set of promises, a specific failure to keep them. Enforcement of that kind punishes deception and can force consent and audits on one firm, but it does not set a general ceiling on data sharing across the category.

What it adds up to

The evidence is consistent across studies separated by several years: sharing user data with outside companies is the norm, not the exception, among women's health apps, and disclosure to users is uneven [s1][s2]. The regulatory response in the United States has two main parts — a breach-notification rule that now clearly covers apps outside HIPAA [s3], and enforcement actions that turn on whether a company kept its own privacy promises [s4]. Neither converts a cycle-tracking app into a HIPAA-protected medical record.

For a reader, the practical consequence is that an app's own privacy policy — and whether it is shown at all before data is collected — remains the document that matters most, because for now it is closer to the binding contract than any blanket statutory protection. Wearable-derived reproductive signals, such as the wrist-temperature estimates some smartwatches use for ovulation, raise the same data questions in a different wrapper.

Sources

  1. Privacy, Data Sharing, and Data Security Policies of Women's mHealth Apps: Scoping Review and Content AnalysisJMIR mHealth and uHealth , May 6, 2022
  2. Exploration of Reproductive Health Apps' Data Privacy Policies and the Risks Posed to Users: Qualitative Content AnalysisJournal of Medical Internet Research , March 5, 2025
  3. Health Breach Notification Rule (final rule, 89 FR 47028)US Federal Trade Commission , May 30, 2024
  4. Developer of Popular Women's Fertility-Tracking App Settles FTC Allegations that It Misled Consumers About the Disclosure of their Health DataUS Federal Trade Commission , January 13, 2021
Related coverage