comparisons

Published by Floriva · Updated 2026-04-29 · How Floriva checks its guides

Period Tracker Data Breach and Privacy Incident History (2016-2026)

Documented period app data breaches and privacy incidents from 2016 to 2026, including the Flo FTC action, Premom settlement, and Ovia acquisition.

The documented incidents in period app privacy aren't hypothetical. Flo's FTC action (2021) confirmed analytics SDK sharing of fertility-intent data. Glow's 2016 security researcher report found account enumeration vulnerabilities. Ovia was acquired by Labcorp, changing the data context for all users who had consented to Ovia's original terms. The recurring pattern: the risk isn't primarily from external hackers, it's from the company itself.

The standard framing of period app privacy risk focuses on hypothetical future threats: what if there's a data breach, what if law enforcement requests data, what if the company is acquired. This framing misses the documented record. The incidents are not hypothetical. They span a decade and establish a clear pattern.

What follows is a factual chronicle of documented incidents, organized chronologically. Each entry includes what happened, what data was exposed or shared, and what changed afterward.


2016: Glow. Security Vulnerability Report

What happened. Security researchers at MedSec examined the Glow period tracking app and published a vulnerability report that found multiple security issues. The most significant: an account enumeration vulnerability that allowed an attacker to determine whether a specific email address had a Glow account. This is not a trivial disclosure, knowing that someone's email is registered with a menstrual health app reveals that they use one, which is itself sensitive information.

The second documented issue involved Glow's friend-request feature. The feature allowed users to share health data with partners or friends. The vulnerability meant that data could potentially be exposed to unauthorized users through the feature's implementation.

What was exposed. The account enumeration vulnerability exposed the fact of health app registration, not cycle data directly, but the fact of using the app. In post-Dobbs terms, knowing that someone uses a period app is precisely the kind of auxiliary information that contributes to re-identification of individuals in other datasets.

What changed. Glow patched the identified vulnerabilities following the MedSec disclosure. Consumer Reports documented the incident. No regulatory action followed.

Pattern note. This is a traditional security vulnerability, an external party could exploit implementation flaws to access information. It is categorically different from the incidents that follow.


What happened. Between 2016 and 2019, Clue (developed by BioWink, a Berlin-based company) received repeated scrutiny from US legislators and EU privacy researchers regarding its third-party data sharing practices. In 2019, the Swedish Data Protection Authority (Datainspektionen) examined the consent mechanism Clue used for its Facebook analytics SDK integration and found it insufficient under GDPR standards.

The core finding: users were not clearly informed that health-specific behavioral data transmitted through the app was also being transmitted to Facebook's analytics infrastructure. The consent mechanism for Facebook's SDK was bundled into general terms of service rather than presented as a specific, granular consent for health data sharing.

What was exposed. Behavioral event data passed through the Facebook SDK. The specific events transmitted varied by app version and SDK configuration, but included app-level interactions that, in a menstrual health context, constitute health-adjacent behavioral data.

What changed. Clue updated its consent mechanism following the Swedish DPA examination. The underlying data-sharing practice, using analytics SDKs that transmit behavioral data to third parties, continued in some form, as it does across most free apps that rely on analytics infrastructure.

Pattern note. The consent gap between UI language and actual SDK behavior appears here for the first time in this chronology. It recurs in each of the two major FTC enforcement cases that follow.


2021: Flo Health. FTC Administrative Complaint (Case 192 3107)

What happened. This is the most clearly documented case in period app privacy history. The Federal Trade Commission filed an administrative complaint against Flo Health establishing that Flo transmitted health-specific event data to third-party analytics companies, including Facebook, AppsFlyer, and Google, through SDK integrations embedded in the Flo app.

The FTC's complaint specifically identified the event TRYING_TO_CONCEIVE, a status marker that users set in the Flo app to indicate they were attempting pregnancy, as among the data transmitted. Additional behavioral events tied to fertility and menstrual health were included in the complaint. These events were transmitted to advertising and analytics infrastructure that Flo did not own or control.

The gap between Flo's stated policy and its practice was the center of the FTC's case. Flo's privacy-facing language stated: "We will never sell your personal data." The FTC's complaint established that transmitting health data to third-party advertising and analytics companies through SDK integrations was functionally equivalent to the sharing the policy claimed not to do, regardless of whether money changed hands.

What was exposed. Fertility intent data (TRYING_TO_CONCEIVE), behavioral events tied to reproductive health, and related health markers. This data was transmitted to Facebook, AppsFlyer, and Google advertising infrastructure. The audience for this data was advertising systems designed to build behavioral profiles for ad targeting.

What changed. The FTC settlement required Flo to obtain affirmative user consent before sharing health data with third parties in the future. No monetary fine was imposed. Flo was required to notify affected users. The consent order does not address what happened to data already transmitted.

Pattern note. The SDK data flow mechanism, described in the definitions above, was the specific vehicle for the data sharing. The same mechanism appears in the Premom case two years later.


2022: Eve by Glow. Post-Dobbs Analytics Audit

What happened. Following the Supreme Court's Dobbs decision in June 2022, the Electronic Frontier Foundation and Disconnect conducted audits of period and reproductive health apps, examining which analytics and advertising SDKs were integrated and what data those SDKs could access. Eve by Glow, a separate app from Glow's core product, positioned at a younger demographic, was among the apps identified as containing advertising tracker integrations.

What was exposed. The audit identified SDK integrations capable of transmitting behavioral health data to advertising infrastructure. The specific data transmitted at any given time depends on SDK configuration, which is not visible to users.

What changed. The audit generated press coverage and app store scrutiny. App developers came under pressure to remove or reconfigure advertising SDKs from sensitive health apps. Some made public commitments to do so. Tracking the follow-through is difficult because SDK configurations change with app updates and are not publicly disclosed.

Pattern note. The post-Dobbs audit wave revealed that the Flo FTC case was not an isolated incident, the SDK data flow pattern was present across multiple period apps, not just the app that happened to be investigated.


2021: Ovia Health Acquisition by Labcorp

What happened. Ovia Health, a period and fertility tracking app with over 10 million users, was acquired by Labcorp, a major clinical diagnostics and laboratory services company. This is not a data breach in any conventional sense. It is a change in corporate custodian for an existing user dataset.

The reason it appears in this chronology: Ovia's pre-acquisition business model included selling corporate wellness packages to employers. Under these arrangements, employers that offered Ovia as an employee benefit could access aggregate reproductive health data about their employees. The aggregate data was intended to help employers offer better fertility benefits. The practical consequence was that employers had visibility into aggregate employee reproductive health data.

When Labcorp acquired Ovia, the user data collected under Ovia's terms transferred to Labcorp's corporate context. Labcorp is in the business of clinical diagnostics, a context with its own data use patterns and business relationships. Users who originally consented to Ovia's terms did not consent to that context.

What was exposed. No external exposure event occurred. The concern is the changed corporate context for existing data. Users who logged fertility and cycle data under Ovia's original terms found their data held by a diagnostics company they had not affirmatively chosen to share with.

What changed. Terms of service updates governed the transition. Users who reviewed those updates could choose to delete their accounts. Users who did not notice the acquisition, likely the majority, had their data context change without any active notification designed to prompt a decision.

Pattern note. Corporate acquisitions are a routine mechanism for data context change. A privacy policy written for one business context does not protect users when the company is acquired by a company with a different business model. No regulatory framework currently requires user consent for data transfer in acquisitions.


2023: Premom. FTC Action with Civil Penalty

What happened. The FTC charged Easy Healthcare Corporation, makers of the Premom ovulation tracking and fertility monitoring app, with sharing reproductive health data with analytics companies without user consent. The charged data recipients included AppsFlyer, the same analytics company involved in the Flo case, and two Chinese analytics firms: Jiguang (also known as Aurora Mobile) and UMeng (an Alibaba-owned analytics platform).

The FTC's complaint cited the Health Breach Notification Rule as the basis for civil penalties, in addition to the standard Section 5 unfair and deceptive practices claims. This was notable: the Health Breach Notification Rule had not been regularly used as an enforcement mechanism, and the Premom case signaled that the FTC was willing to use it against apps that transmitted health data to third parties without adequate notice.

What was exposed. Reproductive health data, ovulation tracking information, and behavioral health events were transmitted to AppsFlyer, Jiguang/Aurora, and UMeng, advertising and analytics infrastructure, including companies with servers in China.

What changed. The case settled with a $100,000 civil penalty, the first civil penalty in a period/fertility app privacy case, and a prohibition on sharing health data for advertising purposes. The settlement terms also addressed the international data transfer aspect.

Pattern note. The Premom case confirms that the Flo FTC action was not a one-off edge case but an established enforcement posture. The same SDK data flow mechanism appeared in a different app, with a different analytics company roster, producing the same result: reproductive health data transmitted to advertising infrastructure without user knowledge.


The Recurring Pattern

Across ten years of documented incidents, three mechanisms appear repeatedly:

Third-party SDK data flows. In Flo, Clue, Eve, and Premom, the specific vehicle for health data exposure was analytics and advertising SDKs integrated into the apps. These SDKs intercept behavioral events and transmit them to third-party infrastructure. Users see the app's UI. Users don't see the SDK layer.

The consent gap. In every case involving a regulatory finding, the gap was between what the privacy policy or UI language implied and what the SDK layer was actually doing. Flo said it would never sell personal data; its SDKs were transmitting fertility intent data to advertising platforms. The consent gap is a structural feature of ad-supported apps, not an individual company's ethical failure.

Corporate transaction risk. The Ovia case illustrates a different vector: even without any active data-sharing incident, an acquisition changes who holds the data and under what business purpose. User consent obtained under the original company does not transfer as a binding constraint on the acquirer.

The common thread across all categories: the primary risk to period app data is not an external hacker. It is the company itself, its monetization choices, its SDK integrations, and its corporate transactions.

What this means for Floriva users

Floriva's local-first architecture addresses the structural conditions that enabled each of the documented incidents above.

The SDK data flow mechanism (Flo, Premom) requires a server-side record or event stream to transmit. Floriva does not create one. Your cycle data stays on your device. There is no event stream flowing from Floriva's app to advertising infrastructure, because Floriva's app does not connect to advertising infrastructure.

The acquisition risk (Ovia) requires readable user data to sit inside company systems. Floriva keeps core cycle records local-first, and optional sync is end-to-end encrypted. That reduces readable health records that could transfer in an acquisition.

The consent gap mechanism operates by hiding SDK behavior behind UI-level privacy language. Floriva reduces that gap with architecture: no advertising SDKs handle health events, and core records stay local-first.

The documented history above is not a reason to avoid period tracking. It is a reason to care about architecture, not promises.

Definitions

FTC administrative complaint
A formal enforcement action filed by the Federal Trade Commission alleging violations of Section 5 of the FTC Act (unfair or deceptive acts or practices). Administrative complaints can result in consent orders requiring behavioral changes, but the FTC's administrative process cannot impose civil penalties directly, those require separate litigation or a referral to the Department of Justice. The Flo and Premom cases both involved administrative complaints; Premom's also included a civil penalty under the FTC's Health Breach Notification Rule.
SDK data flow
The mechanism at the center of the Flo and Premom cases. Third-party software development kits (SDKs), analytics libraries from companies like Facebook, Google, AppsFlyer, and others, are integrated into apps to collect usage data. These SDKs intercept events generated by the app (button taps, screen views, feature use) and transmit them to the SDK provider's servers. When an app transmits a health-specific event like PERIOD_STARTED or TRYING_TO_CONCEIVE through an analytics SDK, that health data travels to the SDK provider's infrastructure, often without users' knowledge that this specific data was transmitted.

Quick answers to the obvious questions.

Have period apps had data breaches

Yes, though the documented incidents span two types: traditional security vulnerabilities (unauthorized external access) and internal data-sharing incidents where the company itself transmitted health data to third parties. The Flo FTC action (2021) and Premom FTC action (2023) both document the second type, the company sharing sensitive health data with advertising and analytics platforms, contrary to stated privacy policies.

What happened with the Flo privacy case

The FTC filed an administrative complaint (case 192 3107) against Flo Health in 2021. The complaint established that Flo transmitted health-specific event data, including TRYING_TO_CONCEIVE status markers and related behavioral events, to Facebook, AppsFlyer, and Google through analytics SDK integrations, despite Flo's stated policy of never selling personal data. The settlement required affirmative user consent for future data sharing. No monetary fine was imposed.

Was Premom investigated for privacy violations

Yes. In 2023, the FTC charged Easy Healthcare Corp, makers of the Premom ovulation tracking app, with sharing reproductive health data with analytics companies including AppsFlyer and two Chinese analytics firms (Jiguang/Aurora and UMeng) without user consent. The case settled with a $100,000 civil penalty and a prohibition on sharing health data for advertising purposes.

Did Ovia sell user data

Ovia's documented data practice was selling aggregate reproductive health data to employers through corporate wellness packages, employers could access aggregate employee data. In 2021, Ovia Health was acquired by Labcorp, a clinical diagnostics company. User data collected under Ovia's original terms transferred to Labcorp's corporate context. This is not a traditional 'sale' but a change in data custodian that users did not affirmatively consent to.

Are period apps safe to use after Dobbs

The post-Dobbs risk is real and stems from the pre-existing data infrastructure these incidents document. Apps that store cycle data on servers, share it with analytics SDKs, or have it accessible to corporate parents create records that could be requested in states with abortion restrictions. The FTC cases establish that data-sharing was happening without meaningful user knowledge. Local-first apps reduce readable company-side records by design, but device access, backups, exports, and legal process remain separate risks.