A Mozilla investigation into six popular menstrual cycle apps found some apps quietly routing intimate health details to outside companies, while others keep everything locked to the device
Millions of women log their periods, moods, symptoms and fertility windows into apps every month, often trusting that the information stays private. A new investigation from the Mozilla Foundation, the nonprofit behind the Firefox browser, suggests that trust isn’t always earned. Mozilla tested six popular period trackers, Flo, Clue, Stardust, Spot On, Period Calendar and Euki, and found a wide range of privacy practices, from apps that keep everything locked to a user’s own phone to ones that quietly send detailed health information to outside companies most users have never heard of.
None of what Mozilla found appears to be illegal. But the stakes around this kind of data have shifted since 2022, when the US Supreme Court overturned federal abortion protections. Privacy researchers and legal advocates say that shift has made period tracking data more sensitive than it used to be, since law enforcement has already obtained other types of digital records from tech companies and used them in criminal cases tied to reproductive health.
Which app shares the most sensitive data
Of the six apps tested, Stardust, which blends cycle tracking with astrology and horoscope content, stood out for sharing the most detailed health information with an outside company. According to Mozilla, Stardust sends data including pregnancy status, birth control use, mood entries, alcohol consumption and physical symptoms like tender breasts or stomach cramps to a data management company called RudderStack, which isn’t disclosed by name in the app’s privacy policy.
A Stardust spokesperson told Mozilla the company only uses RudderStack as a technical pipeline to route information into its own internal analytics systems, and said the data sent can’t be tied back to a user’s name or contact details. The spokesperson also said RudderStack is contractually barred from selling the data or using it for its own purposes, and doesn’t retain it long term.
Privacy researchers say the concern isn’t necessarily that any of these companies are misusing the data today. It’s that every additional company with access to sensitive health information creates another potential point of failure, whether through a data breach or a future legal request. Shoshana Wodinsky, the privacy analyst who ran Mozilla’s tests, argues that users deserve to at least know where their information is going, even if they ultimately decide the tradeoff is acceptable.
Spot On, an app built by Planned Parenthood, presented a more layered problem. The app itself doesn’t share health data with outside companies or attempt to track users, according to Mozilla. But certain features inside the app, including an AI chatbot called Roo and a tool for finding healthcare providers, open Planned Parenthood’s website in a browser, and Mozilla found that website considerably less locked down. In one notable example, the site shares details about the specific type of care a visitor is searching for, including whether someone is looking into HIV testing or gender affirming care, with an analytics company called AB Tasty. Wodinsky said the issue looked like something Planned Parenthood could likely fix in an afternoon with more careful configuration. The organization did not respond to a request for comment on the findings.
Who knows you’re even using the app
Beyond detailed health data, Mozilla also looked at a subtler category of information: whether an app simply reveals that someone is using a reproductive health tool at all, regardless of what’s inside it. Several of the apps send basic identifying information, typically a device or advertising ID, to major ad and analytics platforms including those run by Google, Meta, Microsoft and TikTok. That data can be used for targeted advertising and, in some cases, to track a person’s activity elsewhere on the internet.
Sara Geoghegan, who directs the Consumer Privacy Program at the Electronic Privacy Information Center, says that even this seemingly minor signal, the simple fact that someone uses a period or fertility app, can matter more than people assume. She notes it can become one thread in a much larger picture that other data sources help fill in, particularly for anyone already facing scrutiny from law enforcement.
Mozilla’s report found specific examples of this kind of sharing. Period Calendar, also listed under the name Period Tracker Period Calendar, sends device identifiers to both Google and an advertising firm called InMobi, with no way for users to opt out, according to the report. Stardust shares similar identifying data with Facebook and an analytics company called AppsFlyer, though users can limit this through their phone’s own privacy settings. Visiting Planned Parenthood’s website through the Spot On app triggers sharing with Google, Microsoft, TikTok and Pinterest as well, again with no opt out available. A Stardust spokesperson said the company doesn’t share health data with advertising platforms specifically, and uses AppsFlyer and Meta only to measure and optimize its ad campaigns. Period Calendar did not respond to a request for comment.
The app that keeps everything local
One app broke clearly from the pack. Mozilla recommends Euki without reservation, describing its approach as effectively spotless. Unlike the other five apps tested, Euki stores all health information directly on a user’s device and never sends it to the company’s own servers. Users don’t need to create an account, which means the app can be used entirely anonymously, and it includes a decoy mode that displays fake, harmless data if someone else picks up the phone and opens the app.
Geoghegan points to Euki as proof that period tracking doesn’t have to come with these tradeoffs, arguing that better designed technology built without relying on invasive data practices is entirely possible.
Flo and Clue, two of the more widely used trackers, landed in the middle. Mozilla found no evidence that either app shares actual health information with third parties under any circumstances. Both do notify their advertising and analytics partners when someone opens the app, something disclosed in their privacy policies and consent prompts, but that sharing can be switched off through privacy settings. The bigger concern Mozilla raised is that Flo and Clue both collect considerably more health detail than the other apps and store it on their own servers rather than only on the user’s device, which creates a standing pool of sensitive data that could be exposed in a breach or targeted by a legal request.
Representatives for both companies pushed back on the idea that this amounts to a meaningful tradeoff, saying cloud storage is necessary to deliver their core features and that strong safeguards are already in place. A Flo spokeswoman said users concerned about government data requests can turn on the app’s Anonymous Mode, which is designed so that no one, including Flo itself, can hold both a user’s identity and their health data together at the same time. She added that Flo has never received a subpoena for user data and would contest one if it happened. Clue’s chief executive, Rhiannon White, said the company has never disclosed private health data to any authority and never will. Both Flo and Clue are based in Europe, which the companies note would complicate any legal request originating from US authorities.
A history that still matters
Mozilla’s researchers argue that a snapshot of current practices only tells part of the story, and that a company’s track record matters just as much. Flo settled with the US Federal Trade Commission in 2021 over allegations that it shared sensitive user data, including menstrual and pregnancy information, with Meta, Google and other companies despite promising to keep it private. A Flo spokesperson said the practices covered by that settlement ended roughly five years ago, that the company did not admit wrongdoing, and that its current privacy standards exceed those typical across the industry. Mozilla’s researchers note that Flo’s protections have genuinely improved since then, though its privacy policy has also expanded over time to include new advertising partnerships, all of which remain adjustable through in app settings.
Other apps carry their own history. A 2022 investigation found lists of individual devices tied to Clue, Period Calendar and other trackers being sold through online data marketplaces. White said that data originated from the broader mobile advertising ecosystem rather than Clue’s own app, and reiterated that Clue has never sold user data and never will. Stardust, meanwhile, once advertised end to end encryption on its website, a strong technical guarantee of privacy, before quietly removing those claims after reporters began asking questions. The company’s spokesperson did not directly address why the language was dropped.
Geoghegan says the underlying anxiety driving all of this scrutiny is straightforward: people are living in a moment where widespread digital surveillance and the criminalization of abortion in parts of the US now overlap, which raises the stakes on data that once seemed relatively low risk. She argues the pattern strengthens the case for stronger federal privacy regulation, since the US, unlike the European Union, still has no comprehensive national privacy law covering this kind of information. Beyond the direct legal risk, she adds that uncertainty over how personal health data might be used can itself discourage people from using tools that are otherwise meant to support their health.









