guides

Published by Floriva · Updated 2026-05-01 · How Floriva checks its guides

How to Request Your Own Data from Period Tracker Companies

You can request a copy of all data a period tracker company holds about you using CCPA, GDPR, or state privacy laws. Here is how to submit a data access request with template language.

Most period tracker users have never seen the full record a company holds on them. Under GDPR (EU), CCPA (California), and other state privacy laws, you have the right to request a complete copy. Companies must respond within specific timeframes. The response often reveals data categories you did not know were being collected.

Why Request Your Data

Most period tracker users have a vague understanding that the app stores their cycle dates. The reality is usually more extensive. Companies collect and retain:

  • Every cycle start and end date you ever logged

  • Every symptom, mood, and physical observation entry

  • Sexual activity logs and contraception tracking

  • Pregnancy test results and fertility window interactions

  • In-app content you viewed (articles, tips, product recommendations)

  • Session timestamps, device information, and behavioral analytics

  • Third-party SDK data transmission logs (in some cases)

  • Advertising identifiers and cross-app tracking data

A data access request reveals the full picture. It often surprises users with the volume and granularity of what was retained, including data from years ago that they assumed was deleted when they stopped using the app.

EU/EEA/UK Residents: GDPR

Legal basis: Article 15 (right of access), Article 20 (right to data portability)

What you can request: A complete copy of all personal data the company holds about you, the purposes for processing, the categories of recipients who received your data, the retention period, and information about any automated decision-making or profiling.

Timeline: One calendar month from receipt of request. Can be extended by two additional months for complex requests, but the company must notify you of the extension within the first month.

Cost: Free for the first copy. Companies may charge a reasonable fee for additional copies.

Format: Structured, commonly used, machine-readable format (CSV, JSON, XML).

California Residents: CCPA/CPRA

Legal basis: CCPA Section 1798.100 (right to know)

What you can request: The categories of personal information collected, the specific pieces of personal information collected, the categories of sources, the business purposes for collection, and the categories of third parties with whom data was shared or sold.

Timeline: 45 calendar days. Can be extended by an additional 45 days with notice.

Cost: Free.

Period covered: The 12 months preceding your request (though some companies provide data beyond this period voluntarily).

Other US States

Colorado, Connecticut, Virginia, Utah, Oregon, Texas, Montana, and other states have enacted consumer privacy laws with data access rights. Timelines and scope vary. Check your state attorney general's website for specific requirements and complaint procedures.

How to Submit the Request

Step 1: Find the Privacy Contact

Open the app's privacy policy (usually linked in the app's settings or on the company's website). Search for "data request," "access request," "privacy rights," or "DPO." The policy should list an email address for privacy requests, typically [email protected], [email protected], or a web form.

Step 2: Write the Request

Your request should be clear, cite the applicable law, and specify what you want. Here is template language you can adapt:

For GDPR (EU/UK residents):

Subject: Data Subject Access Request. GDPR Article 15

I am exercising my right of access under Article 15 of the General Data Protection Regulation. Please provide a complete copy of all personal data you hold about me, in a structured, commonly used, machine-readable format per Article 20.

Specifically, I request: (1) all personal data associated with my account, (2) the purposes of processing, (3) the categories of recipients to whom my data has been disclosed, (4) the envisaged retention period, and (5) information about any automated decision-making or profiling.

My account email is: [your email]

Please respond within one calendar month as required by Article 12(3).

For CCPA (California residents):

Subject: Right to Know Request. CCPA Section 1798.100

I am a California resident exercising my right to know under the California Consumer Privacy Act. Please disclose: (1) the categories of personal information collected about me, (2) the specific pieces of personal information collected, (3) the categories of sources, (4) the business purposes for collection, and (5) the categories of third parties with whom my information was shared or sold.

My account email is: [your email]

Please respond within 45 days as required by the CCPA.

Step 3: Verify Your Identity

Companies will require identity verification before releasing your data. This typically means responding from the email address associated with your account, or providing additional verification through the app. Respond promptly to verification requests to avoid delays.

Step 4: Review the Response

When the data arrives, review it carefully. Look for:

  • Data categories you did not expect: Did the company store device identifiers, advertising IDs, or location data you did not know was collected?

  • Third-party sharing disclosures: Which companies received your data? Were advertising networks, analytics firms, or data brokers listed?

  • Retention periods: How long does the company keep your data? Is data retained after account deletion?

  • Data you thought was deleted: Old entries, past accounts, or data from before the company changed its privacy policy.

Step 5: Decide What to Do Next

After reviewing your data, you have several options:

  • Request deletion: Submit a separate deletion request under GDPR Article 17 or CCPA's right to deletion. Note that deletion from the company's servers does not affect data already shared with third parties.

  • Switch to a privacy-focused alternative: If the data response reveals collection practices you are uncomfortable with, migrate to an app with on-device-only storage.

  • File a complaint: If the company does not respond within the legal deadline, provides an incomplete response, or refuses your request without valid justification, file a complaint with the relevant authority (your country's DPA for GDPR, the California Privacy Protection Agency for CCPA, or your state's attorney general).

What Companies Must Provide vs. What They Actually Provide

In practice, the quality and completeness of data access responses varies. Some companies provide comprehensive JSON exports with every data point. Others provide a sparse PDF summary that likely omits categories of data they hold.

If you believe the response is incomplete, reply citing the specific legal requirement for a complete response. Under GDPR, companies must provide all personal data, not just the data you entered, but also derived data, inferences, and data received from third-party sources. Under CCPA, the right to know covers specific pieces of information, not just categories.

The On-Device Alternative

An app that stores all data on your device gives you something no data access request can: certainty about where your data is. There is no server to query, no third-party sharing to investigate, no retention policy to parse. Your data is in one place, under your control, and you can verify this by examining the app's network activity.

Data access requests are a valuable tool for understanding what companies already have. For data you generate going forward, architecture determines whether you will need to submit these requests at all.

This guide is general information, not legal advice. Specific statutes, deadlines, and remedies vary by jurisdiction and change over time. For a specific situation, consult a qualified attorney.

Definitions

Data Subject Access Request (DSAR)
Under GDPR, a formal request from an individual to an organization asking for a copy of all personal data the organization holds about them. The organization must respond within one month, free of charge, with a complete and comprehensible copy of the data.
Right to Know (CCPA)
Under the California Consumer Privacy Act, a California resident's right to request that a business disclose the categories and specific pieces of personal information it has collected about them, the sources of that information, the business purposes for collection, and the third parties with whom the data was shared.
Data portability
The right to receive your personal data in a structured, commonly used, machine-readable format. Under GDPR Article 20, this allows you to transfer your data to another service. Period tracker companies must provide data in a format like CSV or JSON, not just a PDF summary.

Quick answers to the obvious questions.

How do I request my data from a period tracker app?

Submit a written request to the company citing the applicable privacy law: GDPR Article 15 for EU residents, CCPA Section 1798.100 for California residents, or your state's equivalent law. Send the request to the email address listed in the app's privacy policy, usually a privacy@ or dpo@ address. Include your account email, specify you want all personal data in a machine-readable format, and request a list of third parties your data was shared with.

How long does a company have to respond to a data request?

Under GDPR, companies must respond within one calendar month, with a possible one-month extension for complex requests. Under CCPA, the deadline is 45 calendar days, with a possible 45-day extension. If the company does not respond within these timeframes, you can file a complaint with the relevant enforcement authority.

Questions people ask before they switch.

What if I'm not in California or the EU?

Several other states have enacted privacy laws with data access rights, including Colorado, Connecticut, Virginia, Utah, Oregon, Texas, Montana, and others. Check whether your state has a consumer privacy law. Even without a legal requirement, many companies honor data access requests from all users as a matter of policy. Submit the request anyway, the worst outcome is no response.

What format should I expect the data in?

GDPR requires data in a structured, commonly used, machine-readable format. CCPA requires disclosure but is less specific about format. In practice, companies provide data as CSV files, JSON exports, PDF reports, or through an in-app export tool. Machine-readable formats (CSV, JSON) are more useful because you can analyze the data yourself.

Can I also request deletion after seeing my data?

Yes. Both GDPR (Article 17, right to erasure) and CCPA (right to deletion) allow you to request that a company delete your data after you have reviewed it. You can submit the access request first, review what was collected, and then submit a deletion request. Some companies combine both into a single process.