Key takeaways
- Menstrual apps collect far more than period dates — sexual activity, contraception, pregnancy attempts, chronic conditions and mood are among the most sensitive data anyone holds about you.
- Most free apps are funded by your data through targeted ads, aggregated data sales, and (in some past cases) sharing specific data with third parties such as Facebook and Google.
- In 2021 the US FTC found Flo had shared sensitive health data with third parties despite promising not to — a pattern that was likely industry-wide.
- India's DPDP Act 2023 gives you real rights — consent, access, correction, deletion — but enforcement is still maturing, so active choices still matter.
- Privacy-first apps (Drip, Euki, Periodical) store data only on your phone with no ads and no cloud sync; paper tracking is the most private option of all.
- Uninstalling an app does not delete your data — you must request account deletion separately, and data already shared with third parties may persist.
What menstrual apps actually collect
When you use a period app, you usually enter far more than the first day of your period. Understanding the full scope of collection is the first step to judging the privacy trade-off.
Cycle and period data: period start dates, bleeding length, flow intensity, cramp severity, and the predicted next period, ovulation and fertile window the app calculates from them. This is the core data the app needs to do its job — much like the patterns explained in the phases of the menstrual cycle.
Symptom data: physical symptoms (cramps, breast tenderness, headache, bloating, acne, energy, sleep, appetite, cravings); mood symptoms (irritability, low mood, anxiety, mood swings, libido); discharge characteristics; cervical position; and basal body temperature if you chart it. Fertility-awareness apps collect especially detailed symptom logs.
Sexual activity data: dates of sex, type of activity, contraception used, libido and orgasm. This is among the most sensitive data any app holds.
Pregnancy and contraception data: the method you use, when you start or stop it, trying-to-conceive logs, pregnancy test results, and pregnancy outcomes including miscarriage or abortion. This data is extraordinarily sensitive, particularly in restrictive family or legal contexts.
Health data: medications (sometimes by brand name), chronic conditions such as PCOS, endometriosis, thyroid or diabetes; height, weight and BMI; diet, exercise and sleep in some apps.
Identity and contact data: name, email, phone number, date of birth, gender, location (often inferred from your IP address) and device information.
Behavioural data: how often you open the app, which screens you use, what time of day you log, and how you respond to ads.
Inferred data: from your entries the app works out your next period, your fertile window, whether you are trying for or avoiding pregnancy, whether you are sexually active, and which conditions you may have. Inferred data is treated as less sensitive but is just as revealing as what you typed in.
Free-text and chat data: apps with AI chatbots or diary features collect free-form text — relationship worries, sexual concerns, fertility anxieties. This is often less protected than structured data because people underestimate how revealing it is.
Put together, the dataset is a remarkably detailed picture of your reproductive life. The privacy implications of any leak or misuse are therefore large — which is exactly why the rest of this guide matters.
Why free apps collect so much — the business model
Most period apps are free to install, with optional paid features. "Free" is funded by data — through advertising, aggregated data sales, partnerships, and in some past cases by sharing specific user data with advertisers. Understanding this explains why privacy practices are what they are.
Targeted advertising. Generic ads earn little; ads targeted using your data earn far more. An app that knows you are trying to conceive can serve high-value baby-product or fertility-clinic ads. To deliver them, apps either build their own ad targeting or share data with third-party ad networks — and sharing is where privacy risk becomes most acute, because your data leaves the app's control.
Aggregated data sales. Even when individual records are not sold, "anonymised" aggregated insights are valuable to product companies, pharmaceutical firms and researchers. Whether anonymisation is genuinely safe depends on the data — some reproductive-health datasets can be re-identified by combining them with other sources.
Subscription model. Some apps (such as Clue Plus) charge users directly and reduce ad targeting in return. Paying with money rather than data tends to align user and business interests better.
Local-only, non-profit model. Privacy-first apps such as Drip and Euki store everything on your phone, show no ads, and are built by feminist tech collectives or NGOs funded by donations and grants. Interfaces are plainer, but privacy is excellent.
Acquisitions change the rules. Apps get bought, and a new owner can rewrite the privacy policy that governs data you entered years ago. Re-reading the policy occasionally is reasonable.
The Indian market. Indian-built apps (such as Maya by Plackal Tech) increasingly offer locally relevant features and fall more directly under the DPDP Act — but "Indian-made" does not automatically mean private. Practices vary widely; read each app's policy on its own merits.
The bottom line: choosing a free app means accepting the data-funded model. For many users that trade-off is fine; for others it is not. Knowing the model lets you decide on purpose rather than by default.
The Flo 2021 FTC settlement — what it revealed
The biggest public case of menstrual-app privacy failure involved Flo, the most popular global period app with over 100 million users, including a large Indian base. In January 2021 the US Federal Trade Commission (FTC) announced a settlement over allegations that Flo had shared users' sensitive health data with Facebook, Google, AppsFlyer and Flurry — despite privacy policies promising it would not.
What happened. Flo's policies said health data would not be shared with third parties for advertising. The FTC complaint alleged that, in practice, Flo transmitted specific data — including pregnancy and pregnancy-attempt status — to those companies through software development kits (SDKs): small pieces of third-party code embedded in the app that automatically send data to outside servers.
How it surfaced. A 2019 Wall Street Journal investigation reported this SDK-based sharing across several women's health apps. The FTC investigated and confirmed the allegations against Flo.
The settlement terms. Flo agreed to obtain explicit consent before sharing data, notify affected users, instruct third parties that had received the data to destroy it, and undergo independent privacy audits.
What it did not include. There was no financial penalty, no criminal charges, and no admission of wrongdoing — it was a civil case resolved through behavioural commitments rather than punishment.
Why it mattered beyond Flo. The case was a public example of a likely industry-wide pattern: many health apps used advertising and analytics SDKs that transmitted data automatically, even when the privacy policy did not clearly say so.
What changed at Flo. Flo says it has since improved its practices — explicit consent for any third-party sharing, regular privacy audits, and an "Anonymous Mode" that strips identifying information. Whether that is enough is a matter of judgment; some privacy advocates still prefer fully local-only apps.
Other documented issues. Period Tracker by GP International was criticised in 2019 reporting for extensive ad data sharing; Glow Inc. (Glow, Eve, Nurture) had a 2016 data exposure; and Stardust faced criticism in 2022 over data sharing after some users relied on it for privacy. These are part of a pattern, not isolated events.
The post-Roe context. After the US Supreme Court overturned Roe v. Wade in June 2022, US menstrual-app data became contested because it could in theory be used to identify abortions in states where they became illegal. Indian users are not in that legal situation, but the lesson is sobering: reproductive data can become consequential in ways nobody planned for.
The DPDP Act 2023 — your legal rights in India
The Digital Personal Data Protection (DPDP) Act 2023 is India's first comprehensive personal data protection law, broadly comparable to the EU's GDPR. It applies to any company processing Indian users' data, whether based in India or abroad — so it covers foreign period apps used here. Implementation has been rolling out through the mid-2020s.
What it protects. Menstrual cycle data, sexual-activity logs, pregnancy data and health symptoms are personal data of high sensitivity under the Act. Apps that handle them are "data fiduciaries" with legal duties toward you, the "data principal".
Consent. Apps must obtain free, specific, informed and unambiguous consent, separately for each purpose. You can withdraw consent at any time.
Purpose limitation. Data collected for cycle tracking cannot be reused for advertising without fresh, separate consent — a meaningful constraint on the data-monetisation model.
Data minimisation. Apps should collect only what they need. Excessive location, behavioural or lifestyle tracking beyond what cycle prediction requires may not meet this standard.
Access, correction and deletion. You can see your data, fix errors, and ask for erasure — and deletion must mean actual deletion, not just hiding the record.
Cross-border transfer. The Act regulates sending Indian users' data abroad; the government can restrict transfers to specific countries. Most foreign apps store data overseas and will be subject to whatever final transfer rules apply.
Children's data. Users under 18 require verifiable parental consent and extra protection — relevant because many app users are teenagers (see period tracking for teens).
Penalties. Breaches can attract financial penalties up to a high statutory ceiling, enforced by the Data Protection Board of India, with greater consequences for breaches of sensitive or children's data.
The practical reality in 2026. The rights are real but enforcement is still maturing, and app compliance is uneven. To benefit, you must act — read policies, send access or deletion requests, and choose privacy-respecting apps. The law is a floor, not a substitute for your own choices.
How to read and evaluate a privacy policy
Privacy policies are long and jargon-heavy, so most people skip them. But for an app that will hold intimate health data for years, a few minutes of review is worth it. Here is a practical framework.
Where to find it. Every app should link its policy from within the app (Settings or About) and from its store listing. If it is hard to find, that is itself a warning sign.
First-pass questions. Where is the company based? What categories of data are collected? Is data shared with third parties, and which? Is it used for advertising? Where are the servers? How long is data kept? How do you delete your account and data? What rights does the law give you?
Red-flag phrases. "We may share data with our partners" (who, for what?); "industry-standard security" (meaningless without specifics); "we may update this policy at any time"; "business transfers" clauses (your data follows the company if it is sold); broad "legal compliance" clauses; and "aggregated and anonymised" framing that still describes sharing.
Green-flag phrases. Data stored only on your device with no cloud sync; a specific, named list of any third parties; an explicit statement that data is not sold or shared for advertising; a clear retention period and deletion timeline; opt-in (not opt-out) consent; and references to independent audits or open-source code.
Menstrual-app-specific questions. Does it store data only on my phone or sync to the cloud, and where? Does it share with ad networks or research partners? Can I use it without creating an account? Can I delete my account and all data within a stated time, and what happens to my data if the company is sold or shuts down?
Look beyond the policy. Search the app name with "privacy issue" or "data leak". Check independent reviews such as Mozilla's *Privacy Not Included guide and analyses from Indian digital-rights groups. Read store reviews specifically about privacy, and check for past FTC, GDPR or DPDP actions.
Compare before you commit. The most popular app is not the most private. Line up two or three options, weigh privacy alongside features, and review your choice once a year — practices change after acquisitions and policy updates.
When words and behaviour differ. The Flo case showed that a stated policy may not match reality. There is no foolproof user-side check; independent audits, open-source code and a strong reputation among privacy advocates are partial proxies. Local-only apps are the only way to be certain no data leaves your phone.
Privacy-respecting menstrual apps in 2026
Several apps prioritise privacy through local-only storage, no advertising, transparent practices and often open-source code. These are the genuinely privacy-respecting options as of 2026.
Drip (free, open-source, Android): built by Bloody Health, a Berlin feminist tech collective. All data stays on your phone — no cloud sync, no third-party sharing, no ads. Tracks cycle, BBT, cervical mucus, mood, symptoms and sexual activity, with sympto-thermal calculations for fertility-awareness use. The privacy gold standard; functional rather than glossy.
Euki (free, open-source, iOS and Android): built by Women Help Women, an international reproductive-rights organisation. Local storage, passcode protection and a quick-delete option, plus reproductive-health information. Designed for users in restrictive environments.
Periodical (free, open-source, Android): a minimalist, local-only cycle tracker with no analytics or ads — ideal if you want basic period tracking without symptom complexity.
Clue (freemium, Berlin-based): not local-only, but has improved markedly — encrypted data, no third-party sharing for advertising, and GDPR compliance. One of the more privacy-respecting mainstream apps, though not as private as fully local options.
Health-platform tracking (Apple Health, Google Fit, Samsung Health): cycle tracking is built into these platforms. Apple Health has historically had stronger privacy protections than the others. If you already trust the platform with your health data, this may be acceptable; if not, a dedicated privacy-first app is better.
Apps to approach with caution based on documented issues: Flo (FTC settlement; improved but still cloud-based with extensive collection); Period Tracker by GP International (ad data sharing, 2019); Glow Inc. apps (2016 data exposure); Stardust (2022 criticism); and any app with an unclear policy or one based in a jurisdiction with weak data protection.
Indian-developed apps are subject to the DPDP Act, but privacy practices vary — "Indian-made" is not a guarantee. Read the specific policy and reviews.
Open-source as a signal. When source code is public, independent developers can verify what an app actually does. Drip, Euki and Periodical are therefore more verifiable than closed-source apps — not a guarantee of perfect privacy, but a strong positive sign.
Switching without losing data. Most apps export to CSV, JSON or PDF, so you can move from one app to another, though import compatibility varies. For sympto-thermal charts, Drip and Euki support standard formats.
Deleting your data from apps you have used
If you have used period apps and want your data removed, the process varies a lot. Here is what is involved — and where deletion hits its limits.
Export first. Before deleting anything, export your data (usually Settings > Export) and save it somewhere private — an encrypted folder, encrypted cloud storage, or printed paper kept securely. Once it is gone, it is gone.
Step 1 — delete the account in-app. Most apps have an account-deletion option under Settings > Account. Use it; you may need to confirm with a password.
Step 2 — send a written request. If in-app deletion is unclear, email the app's privacy contact (often privacy@appname.com) or use its web form. Reference your account email, ask for complete deletion of all personal data, and request confirmation. Apps under GDPR, CCPA or the DPDP Act must respond within set timeframes (typically 30–45 days).
Step 3 — verify. Some apps confirm by email; if yours does not, follow up. If you can no longer log in but cannot confirm server-side deletion, the company's word may be your only evidence.
What deletion does — and does not — do. It removes your account and direct data and should clear backups within the company's retention period. It usually does not remove data already shared with third parties (that is now controlled by them), data in already-distributed backups, or aggregated/anonymised data derived from yours.
Third parties need separate requests. If your data went to Facebook, Google or ad networks, you may need to ask each of them separately. Facebook and Google have download and deletion tools; smaller ad networks often do not.
Clean up connected copies. Data may persist on devices where you used the app, in iCloud or Google Drive phone backups, in connected services (Apple Health, Google Fit, fitness trackers), or on a partner's account if you shared with them. Each may need separate cleanup.
Apps that make deletion hard. Burying the option, demanding repeated confirmations, or refusing to delete certain categories are themselves red flags. Under the DPDP Act, an intentionally obstructive deletion process may breach the law and can be reported to the Data Protection Board.
The honest reality. Once data is shared or backed up across many systems, removing every copy is very difficult. The realistic goal is to stop future collection now and accept some past-data persistence. The deeper lesson: choose a privacy-first app from the start so there is little to delete later.
Going fully private. If you want maximum privacy going forward, the only completely reliable option is tracking your cycle without an app at all.
Indian context — family access, insurance and culture
In India the privacy stakes have specific cultural and structural dimensions beyond global concerns about advertising and data sales.
Family access to your phone. Many phones are shared with family, partners or in-laws, or are occasionally checked by parents. A visible — or worse, unlocked — period app exposes intimate data. Practical steps: use a privacy-first app that does not show cycle notifications; hide the app using Samsung Secure Folder, Apple's app-hiding, or similar; set a strong passcode; turn off cycle-prediction notifications; and consider locking SHELY on a shared phone.
In-law and marital pressure. Where there is pressure for childbearing, in-laws or a husband may check cycle data as evidence of pregnancy or its absence. Logs showing contraception use, fertility issues or missed pregnancy attempts can be weaponised — making local-only or paper tracking especially valuable. See sharing health logs with a partner for the broader picture.
Unmarried women living with parents. Sexual-activity logs could be seen by parents who do not know about the activity, creating real safety and family-conflict risks. Hidden apps, passcodes, and paper or local-only tracking reduce this.
Insurance and employment. India does not routinely use period-app data in underwriting or hiring today, but the future is uncertain. The DPDP Act offers some protection; the precautionary principle still favours keeping your data footprint small.
Legal requests. In rare cases, app data could be sought in proceedings such as divorce or custody. The risk is low in India now, but apps based in jurisdictions with strong rule-of-law protections offer more legal insulation than those in weaker ones.
Identity linking. Apps that require email, phone or other identity verification concentrate risk by tying intimate data to your identity. Privacy-first apps that work without an account (Drip, Euki) avoid this entirely.
Low-connectivity advantage. In rural areas with patchy internet, local-only apps work better than cloud apps — and the privacy benefit comes free. Paper works fully offline.
Language trade-offs. Drip, Euki and Periodical may have limited Indian-language support, while some Indian-built apps offer better language coverage but weaker privacy. Weigh both.
Emotional support. Navigating family pressure on personal health decisions can be hard. For free confidential counselling, call iCall on 9152987821 or the Vandrevala Foundation on 1860-2662-345. Drawing healthy boundaries connects to understanding consent and personal agency.
Read further. Indian digital-rights groups — the Internet Freedom Foundation, the Software Freedom Law Centre and the Centre for Internet and Society — publish useful analysis of the DPDP Act and health-data privacy.
Decision framework — should you use a menstrual app?
There is no single right answer; it depends on your priorities. Use these questions to decide which path fits you.
1. How important is privacy to you? If it is paramount (restrictive family context, specific reproductive-data concerns), use a local-only app (Drip, Euki, Periodical) or paper only. If it matters but so do features, use a privacy-improved mainstream app (Clue Plus, or native Apple Health). If it is a low priority, mainstream apps may be acceptable — with eyes open.
2. What do you need it for? Basic tracking: a simple local-only app or paper is enough. Fertility-awareness charting: Drip or paper-based methods work well. Trying to conceive with detailed ovulation prediction: a more specialised app plus a basal thermometer may help — see how to track ovulation. For contraception decisions, read about your contraception options before relying on an app's predictions to avoid pregnancy.
3. Who else can access your phone? A fully private phone with a strong passcode lowers the family-access risk. If others occasionally use it, prioritise hidden notifications and passcode protection. If it is genuinely shared, paper in a private notebook is safest.
4. What is the regulatory environment? In India in 2026, the DPDP Act offers meaningful but still-maturing protection. International apps may answer to their home country's rules rather than yours — sometimes better, sometimes worse.
5. How technically comfortable are you? If you are happy with open-source apps and stores like F-Droid, the privacy-first options are easy to reach. If you prefer polished one-tap apps, mainstream options are simpler — at a privacy cost you should accept consciously.
Hybrid approaches. Many privacy-conscious users combine methods — paper for core cycle data, a local-only app for daily logging, and occasionally a feature-rich app for a specific need such as a few months of detailed TTC tracking.
A simple checklist. Write your top three priorities; compare three apps against them; check each policy for storage location, third-party sharing and deletion; trial your top choice for two or three cycles; and review yearly.
When in doubt, default to paper or local-only. It is the lowest-regret choice — you can always add a cloud app later, but you cannot un-collect data that has already been gathered and shared.
Trust the mission, not just the policy. Companies built around privacy (Drip, Euki) are more aligned with your interests than companies built around data monetisation, even when their policies read similarly.
Beyond the app — broader ecosystem risks
Privacy risk does not end with your app choice. Several ecosystem-level factors affect the data even when the app itself behaves well.
Phone operating system. Android and iOS themselves collect usage, location and behavioural data. Even a fully local app reveals to the OS that you have a menstrual app, and when you use it. Apple's protections are generally stronger than Google's, though both collect substantial data.
Cloud backups. If your phone backs up to iCloud or Google Drive, local app data — including menstrual data — may be included. Backups are usually encrypted but live on the provider's servers, so a leak of your Apple or Google account could expose years of data even from a local-only app. Review your backup settings.
Wearables and connected services. Apple Watch, Fitbit (now Google), Garmin and Samsung watches sync cycle data to their own servers, each with its own practices. Every connected service adds another data holder.
Family-sharing accounts. Being on a family iCloud or Google account that an in-law or parent administers is a privacy risk regardless of which app you use. Check your account structure.
Healthcare and insurance apps. Data shared with your gynaecologist's portal becomes part of the hospital record (generally well protected by medical confidentiality). Insurer wellness apps with cycle features come with insurance-company access — separate from ad risk but potentially more consequential.
Browser-based trackers. Period tracking done through websites can be tracked via cookies and pixels. Use private browsing and an ad-blocker for web-based tools.
Government data requests. In rare cases, governments can seek data through legal process; apps in strong rule-of-law jurisdictions may resist or limit such requests more than others.
Practical mitigations. Use a privacy-first app as your primary tracker; minimise connected services; review backup settings; use family-account features carefully; consider a separate account for sensitive apps; use private browsing for web tools; and periodically audit which apps and services can reach your health data. Perfect privacy is impossible on a modern smartphone — the realistic goal is reducing exposure to a level that fits your risk.
Myths vs facts — menstrual app privacy
Myth: Period data is not sensitive enough to worry about
- Myth: Period dates and cycle data are not particularly private.
- Fact: Menstrual-app data includes sexual activity, contraception, pregnancy attempts, chronic conditions and mood — among the most personal data anyone holds about you.
- Fact: This data can be used for targeted advertising, sold in aggregate, leaked in breaches, or sought in legal proceedings.
- Fact: The Flo 2021 FTC settlement confirmed that menstrual apps had shared this kind of data with third parties despite privacy promises.
Myth: Popular free apps must be safe
- Myth: An app this popular would not have privacy problems.
- Fact: Flo has over 100 million users and was the subject of the 2021 FTC settlement.
- Fact: Popularity reflects marketing and features, not privacy practices.
- Fact: Privacy-first alternatives (Drip, Euki, Periodical) have smaller user bases but far better practices.
Myth: Deleting the app removes all your data
- Myth: Uninstalling the app deletes your data.
- Fact: Uninstalling does not delete data already on the company's servers.
- Fact: A separate account-deletion request (in-app or by email) is needed for server-side deletion.
- Fact: Data already shared with third parties may persist even after account deletion.
Myth: The DPDP Act fully protects all Indian users' data
- Myth: Indian law automatically and fully protects menstrual-app data.
- Fact: The DPDP Act 2023 provides meaningful protections, but implementation and enforcement are still maturing.
- Fact: International apps store data on foreign servers, and protection depends on cross-border transfer rules still being finalised.
- Fact: Practical privacy still requires active choices about which apps you use and how.
Frequently asked questions
Are period-tracking apps safe to use in India?
It depends on the app. Local-only, open-source apps such as Drip, Euki and Periodical keep all data on your phone and are very safe for privacy. Mainstream cloud apps collect more and may share data, though India's DPDP Act 2023 now gives you rights to consent, access and deletion. If privacy is your priority, choose a local-only app or paper tracking.
Did Flo really sell my data to Facebook?
The 2021 FTC settlement alleged Flo shared sensitive health data — including pregnancy-attempt status — with Facebook, Google and others through embedded SDKs, despite policies promising not to. Flo did not admit wrongdoing and says it has since improved its practices, including obtaining consent and offering an Anonymous Mode. The case showed this was likely an industry-wide pattern, not unique to Flo.
Can my family or in-laws see my menstrual app data?
Yes, if they can access your phone or shared accounts. Protect yourself with a strong passcode, by turning off cycle notifications, hiding the app (Samsung Secure Folder or Apple's app-hiding), avoiding family-shared cloud accounts for sensitive data, and choosing a local-only app or private paper tracking.
How do I delete my data from a period app?
Export your data first, then delete your account from Settings > Account in the app. If that is unclear, email the app's privacy contact and request complete deletion with confirmation; under the DPDP Act they must respond within a set time. Note that uninstalling alone does not delete server data, and data already shared with third parties may persist.
Which is the most private way to track my cycle?
Paper tracking in a private notebook is the most private option, as no data leaves your possession. Among apps, local-only open-source ones (Drip, Euki, Periodical) are best because data stays on your phone with no cloud sync or advertising.
Does the DPDP Act 2023 protect my period-app data?
Yes, menstrual, sexual and pregnancy data are sensitive personal data under the Act, which requires consent, purpose limitation and data minimisation, and gives you rights to access, correct and delete your data. However, enforcement is still maturing, so you should still read policies and exercise your rights actively.
Sources
- US Federal Trade Commission — Flo Health settlement (2021)
- Digital Personal Data Protection Act, 2023 — Ministry of Electronics and IT, Government of India
- Mozilla — *Privacy Not Included: reproductive health and period-tracking apps
- Internet Freedom Foundation — Digital Personal Data Protection analysis
- Office of the Australian Information Commissioner / WHO — guidance on health data and consent (general reference)




