Is your period-tracking app covered by health privacy law?
In the United States, almost certainly not. HIPAA’s Privacy Rule protects health information handled by “covered entities”: healthcare providers, health plans, and clearinghouses. A consumer app you downloaded yourself is none of these. The FemTech apps used by tens of millions of women to track their cycles, hormones, and symptoms operate, as a rule, outside HIPAA’s scope.
That surprises most people, because the data involved is some of the most intimate that exists. Menstrual-tracking apps such as Flo and Clue are thought to have been downloaded more than 200 million times.
What the research actually found
A peer-reviewed scoping review of the 23 most popular women’s mHealth apps found that 20 of them shared data with third parties, and that current practices do not comply with the GDPR. Several major cycle-tracking apps have shared user data with advertising and analytics companies, and the US Federal Trade Commission has acted against at least two of them, Flo Health in 2021 and Premom in 2023, for disclosing sensitive reproductive information.
The pattern is structural: the apps that collect the most intimate data about women’s bodies are, as a category, among the least accountable. In Europe the GDPR does apply to these apps, and classifies cycle data among its “special categories”, but the review above shows how far practice lags behind the law.
What to look for in any cycle-tracking app
- Who is legally accountable? Look for a named Data Controller and where it is established, not just a privacy policy.
- Can you get your data out? Real portability means a usable export, not a screenshot.
- Can you delete it, verifiably? Deletion should be a right you can exercise, with confirmation.
- Is the data monetised? If the business model is advertising or data sales, your cycle data is the product.
A different structure is possible
Health Data Safe exists to give cycle data the same governance as medical records: held by the person, on open-source infrastructure, with explicit and revocable consent, under a Swiss non-profit foundation whose statutes treat health data as a common good that is neither bought nor sold. The platform already supports cycle-data file imports for FEMM, Cyclefeminin.net, and Read Your Body.
If you build or run a FemTech product and want consent, audit and compliance machinery you can inherit instead of building alone, see Join as a partner.
Sources
- U.S. Code of Federal Regulations, 45 CFR § 160.103, Definitions (“covered entity”). ecfr.gov
- Rampazzo F, Raybould A, Rampazzo P, Barker R, Leasure D (2024). ‘UPDATE: I’m pregnant!’: inferring global downloads and reasons for using menstrual tracking apps. Digital Health 10. doi:10.1177/20552076241298315
- Alfawzan N, Christen M, Spitale G, Biller-Andorno N (2022). Privacy, data sharing, and data security policies of women’s mHealth apps: scoping review and content analysis. JMIR mHealth and uHealth 10(5): e33735. doi:10.2196/33735
- U.S. Federal Trade Commission (2021). In the Matter of Flo Health, Inc., File No. 192 3133, complaint 13 January 2021, decision and order 22 June 2021. ftc.gov
- U.S. Federal Trade Commission (2023). United States v. Easy Healthcare Corporation (Premom), Matter No. 202 3186, stipulated order 26 June 2023. ftc.gov
- Regulation (EU) 2016/679 (General Data Protection Regulation), Art. 4(15) and Art. 9. EUR-Lex, English and French.