alternatives
Published by Floriva · Updated 2026-04-02 · How Floriva checks its guides
Stardust Alternative: Period Trackers With Local Storage
Stardust markets itself on privacy but stores data server-side. Here are period tracker alternatives that genuinely keep your cycle data on your device.
Stardust attracted users leaving Flo by positioning itself on privacy, but it requires an account and stores data server-side. If you want a tracker built around local storage, Floriva, Euki, and Drip are the structural alternatives.
The Post-Roe Period Tracker Migration
After the Supreme Court's 2022 Dobbs decision eliminated federal abortion protections and Flo's FTC enforcement history became more widely discussed, a number of users began actively looking for period trackers with stronger privacy postures. Stardust was one of several apps that gained visibility during this migration by explicitly positioning on privacy.
The positioning worked. Stardust saw download growth from users specifically looking to leave Flo. Whether the app delivers on the privacy premise is a different question.
The 72-Hour Privacy Collapse
On June 24, 2022, the day Dobbs was decided, CEO Rachel Moranis posted a TikTok claiming Stardust was "the first period tracker to implement end-to-end encryption." Downloads surged from roughly 3,000/day to 200,000 on June 25. Sensor Tower reported 82% of Stardust's total 400,000+ lifetime installs came in just two days. The app hit #1 on the US App Store.
Within 72 hours, the claim fell apart. TechCrunch reporters Sarah Perez and Zack Whittaker ran a network traffic analysis on June 27 and found Stardust shared users' phone numbers with Mixpanel. When pressed, Moranis described standard SSL in transit and AES-256 at rest, not end-to-end encryption. Stardust silently removed all E2E encryption references from its privacy policy.
The same day, Vice/Motherboard reporter Samantha Cole found Stardust's privacy policy allowed data disclosure "whether or not legally required." After Motherboard contacted the company at approximately 4:00 PM EST, the clause was changed within hours to "when legally required."
On June 30, Whittaker analyzed an updated version of the app and found that locally-generated encryption keys were being uploaded to Stardust's own servers, meaning the company could decrypt all user data.
Privacy International identified at least 6 third-party services processing user data (Rownd, Firebase, Mixpanel, OneSignal, RevenueCat, Cloudflare) that were not disclosed in the privacy policy. Only AppsFlyer was named. No FTC enforcement action has been taken. Milberg LLC is investigating potential Federal Wiretap Act violations.
The Account Problem
Genuine on-device storage means no account. If an app requires you to create an account, it has to create a server-side record linking your identity to your data. That is not on-device storage, regardless of what the marketing says.
Stardust requires account creation. This means your cycle data is tied to an identifiable account on Stardust's servers. The company may have good commercial privacy practices, but the architecture is the same as other cloud-based trackers: your data lives on a server that can receive a subpoena.
How to Verify Privacy Claims
Privacy marketing is not the same as privacy architecture. When evaluating any period app's privacy claims, go to the privacy policy and look for the data architecture section. Specifically, look for:
Where is the data stored? If the policy says "our servers" or "cloud-based infrastructure," the data is not local. What happens if you delete the app? If the policy says data persists on their servers until account deletion, the data was never local. What third-party SDKs are embedded? Analytics and advertising SDKs share usage data with third parties regardless of what the privacy policy says about the company's own practices.
The FTC found that Flo's SDK data sharing contradicted its privacy policy. The SDKs were doing what SDKs do, and Flo did not clearly disclose this. Any app with third-party SDKs has the same structural exposure.
On-Device Storage: What It Actually Means
Floriva stores core cycle data in encrypted local storage on your phone. No account is needed for core tracking, and there are no third-party SDKs. Floriva cannot sell readable cycle data it does not have. Device access is a separate legal path.
The trade-off is that there is no automatic cloud backup. If you lose your phone, you lose your tracking history unless you have a manual export. For users whose primary concern is who can access their reproductive health data, this trade-off is often acceptable.
Evaluating the Alternatives
If you left or are considering leaving Flo and are evaluating privacy-positioned alternatives, the key question is not which app has the best privacy marketing. It is which app has an architecture that avoids a readable central cycle database. Floriva, Euki, and Drip are the apps where that claim is structural rather than promotional.
Strengths and trade-offs
Stardust
Pros
- Privacy-positioned marketing during post-Roe migration
- Simple, accessible interface
- Free tier
Cons
- Account required
- Server-side storage despite privacy claims
- Privacy is policy-based, not architectural
- E2E encryption claim debunked by TechCrunch within 72 hours
- 6 undisclosed third-party data processors identified by Privacy International
- No scientific backing for astrology-cycle integration
Quick answers to the obvious questions.
What are the best Stardust alternatives with real local storage?
Floriva stores core data in encrypted local storage on your device with no account required for core tracking. Optional sync is end-to-end encrypted. Euki (free, nonprofit) and Drip (free, Android only, open source) are local-only.
Is Stardust a safe period tracker post-Roe?
Stardust positioned itself as a privacy-safe option following the Dobbs decision. However, Stardust is cloud-based, meaning your reproductive health data is stored on their servers. In states where abortion is criminalized, a valid subpoena could compel Stardust to provide user data. Privacy by policy is not the same as privacy by architecture.
Why do privacy-marketed apps still use server storage?
Cloud storage enables cross-device sync, which most users expect. It also lets the app developer aggregate usage data, improve algorithms with pooled data, and maintain backup capabilities. These are real product advantages that on-device trackers give up. When an app markets on privacy but still uses server storage, the privacy claim is usually about commercial data practices, not technical architecture.
Did Stardust actually implement end-to-end encryption?
No. On June 24, 2022 (Dobbs day), CEO Rachel Moranis claimed on TikTok that Stardust was the first period tracker with end-to-end encryption. Downloads hit 200,000 on June 25, up from roughly 3,000 per day. Within 72 hours, TechCrunch ran a network traffic analysis and found the app shared phone numbers with Mixpanel. When pressed, Moranis described standard SSL in transit and AES-256 at rest. By June 30, Whittaker found that locally-generated encryption keys were being uploaded to Stardust's own servers, meaning the company could decrypt all user data. Stardust silently removed E2E encryption claims from its privacy policy.
What third parties receive Stardust user data?
Privacy International identified at least 6 third-party services processing Stardust user data: Rownd, Firebase, Mixpanel, OneSignal, RevenueCat, and Cloudflare. Only AppsFlyer was disclosed in the privacy policy. Vice/Motherboard also found that Stardust's original privacy policy allowed data disclosure 'whether or not legally required,' a clause changed within hours after press inquiry. No FTC enforcement action has been taken. Milberg LLC is investigating potential Federal Wiretap Act violations.
Questions people ask before they switch.
Does Stardust actually store data locally?
Stardust markets on privacy and local storage, but the app requires account creation, which means your identity is tied to your data on their servers. Genuine local storage means the core record starts on your device. Check any app's privacy policy for the data architecture section, not just the marketing language.
What should I look for to verify a period app stores data locally?
Three things: the app should work without an internet connection after setup, it should not require an email or account, and the privacy policy should explicitly state that no data is sent to company servers. If an app requires an account, your data is linked to an identity on a server somewhere.
Is Stardust safer than Flo?
Stardust has no documented enforcement history like Flo's 2021 FTC action and $59.5M settlement. But safety relative to Flo is a low bar. The structural question is whether your data reaches a server at all. If it does, company promises can change, companies can be acquired, and courts can issue subpoenas.
Is Stardust period tracker private?
Stardust markets itself as privacy-conscious and has built a community around post-Roe privacy concerns. However, Stardust is cloud-based. Your data is stored on Stardust's servers, which means it can be subpoenaed. The app's privacy protections are policy-level, not architectural.
What's the difference between Stardust and Floriva?
Both apps market privacy. The difference is architecture. Stardust stores data on cloud servers. Floriva keeps core records on your device and has no readable central cycle database. Architectural privacy cannot be changed by a policy update.