A period tracker ends up holding a very personal record. It knows when you bleed, when you might be ovulating and whether you’re trying to conceive, along with symptoms, moods and sometimes sexual activity. Advertisers pay for exactly that kind of data, and regulators fight over it. The checks below take about ten minutes.
What has already gone wrong
The best-documented case involves Flo, one of the most popular cycle apps in the world. In 2021, the US Federal Trade Commission announced a settlement with Flo Health over allegations that the app had shared users’ health details, including pregnancy status, with third-party analytics and marketing services run by Facebook, Google and other companies. Flo had promised to keep that information private. Under the settlement, Flo agreed to notify affected users and get their consent before sharing health data. It didn’t admit wrongdoing.
Flo users also brought a class action. In 2025, the California federal jury in that case found Meta liable under the California Invasion of Privacy Act for collecting sensitive health data that the Flo app had sent through an analytics tool. Other defendants, including Flo itself and Google, settled before the verdict. Whatever happens on appeal, the trial record showed that cycle data has flowed from period apps into ad-tech systems at massive scale.
Free apps ship with analytics SDKs wired into advertising businesses by default. An app’s marketing copy can say one thing while its data flows do another. So the checklist below looks at what a company commits to in writing and how it makes money.
The checklist
1. Make the privacy policy answer two questions
Open the policy and search for what happens to personal data. You want two plain sentences, one saying the company doesn’t sell personal data and one saying it doesn’t use your data for advertising. Clear, unqualified sentences are a good sign. Watch for hedges like sharing with trusted partners, affiliates, or for improving relevant offers. Wording like that can cover a lot of sharing. If the policy won’t say either thing plainly, treat that as your answer.
2. Treat ads in the app as a disclosure
If the app shows ads, an advertising SDK is running inside it. At the very least, some data about what you do in the app is leaving it. That doesn’t make the developer malicious. It does mean your cycle app runs the same kind of software the Flo case was about. For health data like this, pick an app with no ads.
3. Follow the money
If you pay for the app or a subscription, your money is the business model. If an app is free forever and shows no way of making money, the model is something else, and your data is the most likely source. Every app needs a business model. Make sure you know which one you’re agreeing to.
4. Know where your data lives, and be honest about tradeoffs
Some trackers keep data only on your phone, and most sync it to servers. Neither choice is automatically private. On-device storage means your history never sits on a company server, but it can vanish with a lost phone and rules out multi-device use or sharing features. Synced storage means the company holds your data, so its encryption, retention, and deletion practices decide how safe it is. In exchange you get backup and the features that need a server. Check whether the app says clearly where data is stored, whether it’s encrypted in transit and at rest, and how long the policy says it’s kept.
5. Check the delete path before you need it
A trustworthy tracker lets you delete your account from inside the app. Its policy says that deleting removes your data from the company’s servers. If you have to email support to delete, or the policy doesn’t say what deletion removes, think twice before you trust the app with years of history.
6. Skim the App Store privacy label
On iOS, every listing has an App Privacy section. It shows what data the app collects and which of that data it uses to track you across other companies’ apps. Developers fill in the labels themselves, so treat them as a first check. Still, a health app whose label lists data used to track you deserves harder questions.
What to ask the developer
If anything is unclear, email the developer three questions. Do you sell or share personal data with advertisers or data brokers? What happens when I delete my account? How do you respond to legal demands for user data? Small teams often answer quickly and plainly. If you get marketing boilerplate back, trust the app less. A developer that collects less also has less to hand over, whatever its intentions.
Which period tracking apps don’t sell data?
Plum and Clue both say in writing that health data is never sold or shared with advertisers. Euki keeps everything on the phone and holds nothing to sell. Apple’s Cycle Tracking stores Health data Apple can’t read once two-factor authentication is on. Flo has the 2021 settlement above on its record, and it now offers an Anonymous Mode that separates your data from your identity. We read the privacy policies of these five apps for our comparison of period tracker apps, checked on August 30, 2026. Policies change, so the comparison shows the date we last read them. The checklist on this page works on any app that isn’t in it.
Where Plum stands
We build Plum, an iPhone period tracker, so grade us against the same list. Plum shows no ads and never sells personal data. Our money comes from an optional subscription. Plum does sync your data to our servers, encrypted in transit and at rest. That’s what makes backup and shared groups work, and it’s why we’ll never claim your data stays only on your phone. You can delete your account and its data from inside the app at any time. The details are in our privacy policy, which we wrote to pass the two-question test above. Our page on what Plum does with your period data lists every outside service that gets anything at all, in plain words.
Picking one
Ten minutes with the privacy policy and the App Store label rules out most of the risk. If you’re new to tracking, our guide to normal cycle length is a good place to start.