Quick Answer
This article outlines a checklist for assessing the privacy of cycle tracking apps, emphasizing data storage, third-party SDKs, and deletion policies.
A 10-point checklist for evaluating any cycle app privacy in 2026: data location, third-party SDKs, deletion, subpoena policy, and what independent audits found. Sourced and dated.

This article outlines a checklist for assessing the privacy of cycle tracking apps, emphasizing data storage, third-party SDKs, and deletion policies.
Direct answer: Check five things before trusting any cycle app: where data is stored local-only beats cloud , whether every third-party SDK is named in the privacy policy, whether you can delete all data permanently, how the company answers legal data requests, and whether its business model depends on your data. Independent audits in 2025 found popular trackers embedding
Direct answer: Check five things before trusting any cycle app: where data is stored (local-only beats cloud), whether every third-party SDK is named in the privacy policy, whether you can delete all data permanently, how the company answers legal data requests, and whether its business model depends on your data. Independent audits in 2025 found popular trackers embedding third parties their policies never mentioned — the policy, not the marketing page, is what counts.
After the 2022 Dobbs decision, US users started reading cycle-tracker privacy policies for the first time. Four years later, the landscape has shifted but not settled. Privacy International published a follow-up audit in May 2025. The FTC's 2021 consent order against Flo wellness led to a $59.5 million class action settlement in September 2025. New state wellness-data laws are in effect. And the core problem remains: most period trackers store your data on servers, embed third-party code their policies do not fully disclose, and have a business model that depends on keeping it.
This is a practical checklist for evaluating any cycle app. It is not legal advice. It is not a doom scroll. It is a framework for asking the right questions and treating vague answers as warning signs.
Period tracking apps know some of the most sensitive wellness information you have: cycle dates, sexual activity, pregnancy attempts, experiences, and mood patterns. After the Dobbs decision in 2022, this data became legally relevant in ways most users never considered when they first downloaded a free app.
The problem is not that every app is actively selling your data. Some are. But the bigger issue is that many apps store your data in ways that make it accessible to third parties — whether through embedded advertising SDKs, analytics platforms, or simply by keeping it on a server that can be subpoenaed. A subpoena does not care about the company's privacy values. It cares about what data exists on their servers.
This is not theoretical. US law enforcement has used online data — including Facebook chat logs and Google search history — in cases involving reproductive wellness support. The cases are still unfolding, but the pattern is clear: data that exists on a server can be compelled. Data that lives only on your phone cannot.
Each point tells you what to check and where to find it in a typical privacy policy. If an app cannot answer clearly, that is the answer.
What to check: Does the privacy policy say "on our servers," "cloud-based storage," or "transmitted to our systems"? Or does it say "stored locally on your device"?
Why it matters: If data is on a company server, it can be accessed by the company, subpoenaed by courts, or exposed in a breach. Local-only storage means there is no cloud copy to reach.
Strongest signal: Data is stored only on your device, with no cloud sync. If cloud sync exists, it is optional and off by default. If cloud storage is used, data is end-to-end encrypted before leaving your device.
What to check: Search the privacy policy for "third-party," "partners," "ad networks," "analytics providers," "marketing partners," and "service providers." Does the policy name every third-party SDK embedded in the app, or does it use vague language like "we may share data with our partners"?
Why it matters: The most common audit finding is undisclosed third-party SDKs. Privacy International's 2025 investigation found that while apps were no longer sharing cycle data directly with Facebook, many still embedded advertising and analytics SDKs that processed device identifiers and usage data. The FTC's case against Flo wellness was specifically about embedded SDKs transmitting wellness context to Facebook and Google — despite Flo's policy promising not to share wellness data.
Strongest signal: The policy names every third-party SDK, or the app has no third-party SDKs at all. Apps with advertising revenue almost never meet this bar.
What to check: Does the app offer permanent account deletion (not just uninstalling)? Does the policy specify a timeframe? Does deletion include backups and analytics data?
Why it matters: Uninstalling an app does not delete your data from the company's servers. Under GDPR and several US state privacy laws, companies must delete your data upon request — but the question is whether they actually do, including in backups.
Strongest signal: The vendor commits in writing to completing erasure within a specific window (24 hours is strong; 30 days is standard) and explicitly includes backups and any derived data (like AI vector embeddings).
What to check: Does the policy have a section on legal requests? Does it commit to notifying users when legally possible? Does it publish a transparency report?
Why it matters: Every company will comply with valid legal process. The question is whether the company has your data to share. A cloud-first app has everything. A local-only app has nothing.
Strongest signal: The app is local-only, so there is nothing to hand over. Or the company publishes transparency reports and commits to user notification when legally permitted.
What to check: Can you use the app's core features without creating an account or entering an email address? If the app says "no account needed," verify this — some apps let you skip initially but nag you or lock features behind registration.
Why it matters: If an app requires an account, your cycle data is linked to your identity on their servers. Account creation is not technically necessary for period tracking. Apps that require it are making a product choice, not a technical necessity.
Strongest signal: Full functionality without an account, no nag screens, no feature gates.
What to check: If the app has a premium tier, does the payment processor link your billing identity to your wellness data? Or is payment handled separately from wellness data storage?
Why it matters: If your name, card, and cycle history are in the same database, a breach or subpoena exposes everything at once.
Strongest signal: Payment is handled by a third-party processor (Stripe, Apple/Google), and the app does not link billing records to wellness data internally.
What to check: Where is the company based? What wellness-data laws apply? In the US, Washington's My wellness My Data Act and Nevada's consumer wellness-data law are now in effect. GDPR Article 9 covers wellness data in the EU.
Why it matters: A company based in a jurisdiction with strong wellness-data laws is more accountable. A company based in a jurisdiction with no specific wellness-data protections is a higher risk.
Strongest signal: The company is subject to GDPR (EU), the UK Data Protection Act, or US state wellness-data laws (WA, NV, and growing), and its policy references them specifically.
What to check: Search "app name breach" or "app name security incident." Check Have I Been Pwned for the app's domain.
Why it matters: Even apps that do not sell data can leak it. wellness and fertility apps as a category have had documented security incidents — from misconfigured APIs to unsecured databases. The only protection against breach is to not have your data on a server in the first place.
Strongest signal: No breach history, or the company has been transparent about past incidents and what they fixed.
What to check: Does the app offer data export? Is it in a readable format (CSV, JSON)? GDPR requires this for EU users, and many apps extend it to all users.
Why it matters: If you decide to switch apps, you want your history. If you decide to delete everything, you want a copy first.
Strongest signal: One-tap export in a standard format, available without contacting support.
What to check: Is the app free with ads? Subscription-only? Freemium? Does the privacy policy mention advertising, data monetization, or "de-identified data sharing"?
Why it matters: If the app is free and ad-supported, it is likely embedding advertising SDKs that collect behavioral data. "De-identified" or "aggregated" data sharing is harder to anonymize than companies claim — a dataset of cycle-related cycles linked to age, zip code, and device type is not truly anonymous.
Strongest signal: The app is funded by subscriptions, not advertising. The policy explicitly states "we do not sell your data" and "we do not share data with advertising partners."
Privacy International's May 2025 report ("No Body's Business But Mine: Vol. 2") re-examined the period tracking landscape five years after their original 2019 investigation. Key findings:
The FTC's 2021 consent order against Flo wellness required Flo to obtain affirmative consent before sharing wellness data, undergo independent privacy assessments for 20 years, and notify users whose data was shared. A combined class action settlement against Flo, Google, and Flurry reached $59.5 million in September 2025.
The lesson from both: the privacy policy is necessary but not sufficient. You also need to know what third-party code is in the app and what that code does.
| Red flag | Green flag |
|---|---|
| "We may share data with our partners" | "We do not share data with advertising partners" |
| Account required for basic tracking | Full functionality without an account |
| No deletion option or vague timeframe | One-tap deletion with stated completion window |
| Advertising SDKs in the app | No third-party SDKs, or all named explicitly |
| Data stored on company servers | Data stored locally on device |
| App does not work offline | App works in airplane mode |
| No transparency report | Published transparency reports |
| Free with ads | Funded by subscriptions |
| "De-identified data may be shared" | "We do not sell or share your data" |
| Vague "local processing" language | Explicit "no data leaves your device" |
Here is the honest self-positioning. A reflective, non-wellness cycle companion like Soulwise Natural Cycles needs less sensitive data by design. It does not predict ovulation, fertility, or pregnancy. It does not make wellness claims. It is a 20-second daily check-in that logs how the day felt and spots patterns over time, with optional moon phase or transit context for reflection.
This means the data surface is smaller. There is no cycle prediction data, no fertility window, no experiences log tied to a wellness context. The privacy posture follows from the product posture: if you do not collect sensitive wellness data, you do not have to protect it.
Soulwise uses AES-256-GCM envelope encryption with per-user keys, destroys the encryption key on deletion within 24 hours, never puts cycle-related content in push notifications, and offers an anonymous mode. These commitments are concrete and falsifiable. For the full spec, see the Soulwise privacy page.
For the broader privacy-first positioning, see privacy-first period tracker post-Roe and period tracker no wellness claims. For inclusive defaults, see cycle tracker for non-binary users.
If you do not have time for the full 10-point checklist, run these four questions before installing any period app:
An app that answers no, no, yes, yes is structurally safer. An app that answers yes, yes, no, no is structurally riskier, no matter what the marketing says.
This article is product criteria and educational information, not legal advice. It does not describe what is or is not protected from any specific legal process. If you have specific legal concerns about cycle data, consult an attorney licensed in your jurisdiction. The findings cited from Privacy International and the FTC are public records dated as noted; check current sources for updates.
Most period trackers do not directly sell cycle data. The more common issue is that they embed third-party advertising and analytics SDKs (from Google, Meta, AppsFlyer, and others) that collect device identifiers and usage data, which can reveal wellness context. Privacy International's 2025 audit found several apps integrating third parties their policies did not explicitly name. The FTC took action against Flo wellness in 2021 for sharing wellness data with Facebook and Google via embedded SDKs. Check the privacy policy for "third-party," "partners," and "analytics providers" — anything beyond basic platform services means data is leaving the device.
That depends on your threat model. If you are in an US jurisdiction where cycle data could be subpoenaed in reproductive wellness cases, and your app stores data on company servers, switching to a local-only tracker is a reasonable precaution. If your primary concern is ad targeting, check whether your app embeds advertising SDKs and whether you can opt out. You do not have to stop tracking — you can switch to a privacy-first app and export your history first.
Local-only tracking means your cycle data is stored on your device and never transmitted to a company server. Apps like Drip, Euki, and Apple wellness Cycle Tracking work this way. The advantage is that there is no cloud copy to subpoena, breach, or sell. The trade-off is no cross-device sync and limited AI features. A local-only app should work in airplane mode — if it does not, data is leaving your device.
Ask four questions: Does it require an account? (If yes, your identity is tied to your data.) Does the privacy policy mention third-party partners or ad networks? (If yes, data is leaving the device.) Does the app work offline? (If no, data is syncing somewhere.) Is the company based in a jurisdiction with strong wellness-data law? (If you do not know, look it up.) An app that answers no, no, yes, yes is structurally safer.
Most period trackers do not directly sell cycle data. The more common issue is that they embed third-party advertising and analytics SDKs (from Google, Meta, AppsFlyer, and others) that collect device identifiers and usage data, which can reveal wellness context. Privacy International's 2025 audit found several apps integrating third parties their policies did not explicitly name. The FTC took action against Flo wellness in 2021 for sharing wellness data with Facebook and Google via embedded SDKs. Check the privacy policy for "third-party," "partners," and "analytics providers" — anything beyond basic platform services means data is leaving the device.
That depends on your threat model. If you are in an US jurisdiction where cycle data could be subpoenaed in reproductive wellness cases, and your app stores data on company servers, switching to a local-only tracker is a reasonable precaution. If your primary concern is ad targeting, check whether your app embeds advertising SDKs and whether you can opt out. You do not have to stop tracking — you can switch to a privacy-first app and export your history first.
Local-only tracking means your cycle data is stored on your device and never transmitted to a company server. Apps like Drip, Euki, and Apple wellness Cycle Tracking work this way. The advantage is that there is no cloud copy to subpoena, breach, or sell. The trade-off is no cross-device sync and limited AI features. A local-only app should work in airplane mode — if it does not, data is leaving your device.
Ask four questions: Does it require an account? (If yes, your identity is tied to your data.) Does the privacy policy mention third-party partners or ad networks? (If yes, data is leaving the device.) Does the app work offline? (If no, data is syncing somewhere.) Is the company based in a jurisdiction with strong wellness-data law? (If you do not know, look it up.) An app that answers no, no, yes, yes is structurally safer.
Get personalized insights based on your birth chart