Is Your Period Tracking Data Private? A 5-Minute Audit
By the Phase team · · 7 min read
Short answer
It depends on one thing: where the data lives. If an app stores your cycle on its own servers, it holds a copy that can be shared, sold, breached or subpoenaed. If it keeps everything on your device and in your private iCloud, it cannot hand over what it never received. Everything else in a privacy policy is secondary to that.
Cycle data is unusually sensitive — it can imply pregnancy, pregnancy loss, fertility treatment, health conditions and sexual activity. It is also unusually casual to hand over: most people tap through an onboarding flow in under a minute without ever learning where the data ends up.
This is a five-minute audit you can run on any tracker, including ours. No legal expertise needed.
First, understand the three storage models
| Model | How to spot it | Who can access your data |
|---|---|---|
| Server-stored | Requires an account (email, Google, Apple sign-in); works on a new phone after logging in; has a web version | The company, its staff, its processors and analytics vendors, anyone who breaches it, and anyone with a valid legal demand |
| Device-only | No account; data disappears if you delete the app without a backup | Only you — but you carry the backup risk yourself |
| Device + your own private cloud | No account, but syncs across your devices using your iCloud account | Only you. The developer never receives a copy; the cloud is your account, not theirs |
Most large period trackers are server-stored, because that model supports accounts, web apps, cross-platform sync and — for some — advertising. None of that is inherently sinister. It just means a copy exists outside your control, and copies are what get shared.
That risk is not hypothetical
Two public enforcement records make the point better than any argument:
- In January 2021 the US Federal Trade Commission announced a settlement with Flo Health over allegations that it shared users’ health data with third parties including Facebook and Google despite promising to keep it private. The order was finalised in June 2021 and required affirmative consent before sharing health data, an independent privacy review, and notification of affected users.
- In May 2023 the FTC settled with Easy Healthcare, maker of the Premom app, over allegations it shared users’ health information with third parties through software development kits — including a $100,000 civil penalty and a permanent ban on sharing personal health data for advertising.
In both cases the data left because the data was there to leave. That is the whole argument for caring about the storage model rather than the promises.
The seven questions — and how to check each one
1. Does it force me to create an account?
An account almost always implies a server, and a server implies a copy. Check by installing and looking at the first screen: is there a "continue without an account" path?
2. What does the App Store privacy label say?
Scroll to App Privacyon the App Store listing. "Data Not Collected" is the strongest possible answer. If you see Health & Fitness or Sensitive Infounder "Data Linked to You," the developer is telling Apple it receives that data tied to your identity.
3. Does the privacy policy name third parties?
Search the policy for third part, partner, analytics, advertis and affiliate. Vague phrasing like "we may share with trusted partners to improve our services" is doing a lot of quiet work.
4. Is there advertising anywhere in the app?
Ads generally require an advertising SDK, and advertising SDKs are how health data has historically leaked. A subscription-funded app has no structural reason to carry one.
5. Can I export and delete everything?
Look for a data export (CSV or similar) and a genuine "delete all my data" control in settings — not just "delete account," which sometimes means deactivation. Export also means you are not locked in.
6. What happens if the company is acquired or shuts down?
Search the policy for merger or acquisition. Almost every server-stored app lists user data as an asset that transfers with the business. Worth knowing before you log five years of cycles.
7. What is the minimum it needs to know?
A tracker that reads your cycle from Apple Health does not need your email, your location, your contacts or your name. Every extra field is extra exposure for no functional gain.
Where Apple Health fits
Apple Health data is encrypted on device and — when iCloud sync is on — in transit and on Apple’s servers. Apps only see the categories you explicitly grant, and you can revoke any of them at any time in Settings → Privacy & Security → Health.
One honest caveat: granting an app read access to your menstrual data means that app can then do whatever its own policy permits with what it reads. Apple’s guarantees cover Apple’s storage, not the app’s. So the storage-model question survives even for a HealthKit-based app — which is exactly why it is question one.
Where Phase stands
We would rather be checkable than reassuring, so here are the specifics you can verify yourself:
- No servers. There is no Phase backend. There is nowhere for your data to be sent, because nothing was built to receive it.
- No accounts. You never give us an email address. Sync happens through your own private iCloud, using your Apple account, not ours.
- No analytics or advertising SDKs. The only network traffic is Apple’s own StoreKit for the subscription.
- App Store label: Data Not Collected. That is the claim we filed with Apple, and it is the one you should hold us to.
- Export and delete built in — CSV export and a delete-all control in Settings.
- Full detail in our privacy policy.
This is also why Phase reads from Apple Health rather than asking you to keep a second period log: the fewer places your cycle exists, the fewer places it can go. If you are comparing options, the workout tracker comparison covers the feature side of the same decision.
This article is general information about app privacy practices, not legal advice. Enforcement records referenced above are public FTC announcements; settlements are not findings of liability.
Frequently asked
Are period tracking apps safe to use?+
It depends entirely on where the data is stored. An app that keeps cycle data on your device and in your own private iCloud cannot hand over what it never received. An app that stores it on company servers holds a copy that can be shared, sold, breached or subpoenaed — which is why the storage model is the first thing to check.
How do I tell whether a period app sends my data anywhere?+
Check three things in about five minutes: the App Store privacy label (does it say Data Not Collected, or list Health & Fitness under data linked to you?), whether the app forces you to create an account (an account implies a server), and whether the privacy policy names third parties, analytics providers or advertising partners.
Has any period tracking app actually been caught sharing health data?+
Yes. In 2021 the US Federal Trade Commission settled with Flo Health over allegations it shared users' health data with third parties including Facebook and Google despite privacy promises, and in 2023 the FTC settled with the maker of the Premom app over similar allegations, including a $100,000 civil penalty. Both are public enforcement records.
Is data in Apple Health private?+
Health app data is encrypted on device and, when iCloud sync is on, in transit and on Apple's servers. Apps can only read categories you explicitly grant, and you can revoke access per category at any time in Settings → Privacy & Security → Health. Granting an app access does mean that app can then do what it likes with what it reads — which is why the app's own storage model still matters.
Does Phase store my cycle data on its servers?+
Phase has no servers. Cycle, training and check-in data stays on your device and syncs only through your own private iCloud, there are no accounts to create, no analytics SDKs and no ads. The App Store privacy label is Data Not Collected.
Sources
- [1] FTC (2021). Developer of Popular Women's Fertility-Tracking App Settles FTC Allegations that It Misled Consumers About the Disclosure of their Health Data.
- [2] FTC (2021). FTC Finalizes Order with Flo Health, a Fertility-Tracking App that Shared Sensitive Health Data with Facebook, Google, and Others.
- [3] FTC (2024). Health Breach Notification Rule — final rule extending breach notification duties to health apps.
Keep reading

Train with your cycle.
Phase builds this plan for you automatically — a real strength tracker with cycle-aware programming, on iPhone & Apple Watch.
Meet Phase →Phase provides general training education, not medical advice. Cycle responses vary widely between individuals; consult a healthcare provider for medical concerns. Cycle estimates are for training planning only — never for contraception or family planning.