Privacy and your data

How to Delete Your Period Tracker Data — Properly

Deleting the app is the weakest of the three things people mean by deleting. Here is the order that reaches the copy a company holds, and what the published rules say about how long it takes.

9 min read Last checked 10 August 2026 7 sources, all linked

Do it in this order: export your history first if you want to keep it, delete the account inside the app, then delete the app from the phone, and then send a written deletion request to the company if you want the backup copies covered too. Most people do only the last step of that as the first one — they drag the icon to the bin — and that removes the copy on the phone while leaving everything the company holds exactly where it was. The three things people mean by "delete" are genuinely different, and only one of them reaches a server.

This page is a description of published rules and published company policies, not legal advice. It is also written from two frameworks — the UK and EEA's data protection law and California's — because those are the two with clear published deletion rights. Wherever else you live, the rules will differ.

Three different things called deleting

Untangling these is most of the work, because the word covers three actions with three different reaches.

Removing the app from the phone. This takes four seconds and does the least. It removes the app and whatever it stored locally. If the app had no account and never sent anything anywhere, that may be all of it. If it had an account, it is closing a laptop lid — what uninstalling actually removes has a page of its own here, because the answer catches people out.

Deleting the account inside the app. This is the one that is supposed to reach the company's copy. It is usually somewhere in account or profile settings, and it is the step worth finding before you uninstall anything, because once the app is gone the in-app route is gone with it.

Asking the company to erase you. This is a legal request rather than a button, it is made in writing, and it is the only one of the three that can cover the copies you cannot see — backups, archives, and anything a company kept after you closed the account.

The order that works

  1. Export first, if you want to keep the history. Deletion is meant to be permanent, and a year of start dates is useful — to you, and to a clinician if your pattern changes. Look for an export or "your data" option before you touch anything else. If there is none, copy the start dates onto paper by hand; that is the part you cannot get back.
  2. Delete the account inside the app. Do this while the app is still installed. Read what the confirmation screen says rather than tapping past it, because that screen is usually where a company states its own timeline, and it is the sentence you may want later.
  3. Then remove the app from the phone. Now it is a tidy-up rather than the main event. Doing it in this order is the whole point of the list.
  4. Send a written request if you want the backups covered. Deleting an account and asking a company to erase your personal data are not the same act. If you want the second one, say so in writing, keep a copy of what you sent and the date you sent it, and use the privacy or data-protection contact address in the company's own policy.

What published deletion timelines look like

Two of the most-used period apps publish what happens after you ask. Both of the entries below are those companies describing their own products in their own policies. They are quoted here as worked examples of what a published timeline reads like, not as a recommendation, and not as a claim about what happens inside anybody's servers — nobody outside those companies can check that.

Flo's privacy policy states

that an account can be deleted in the app's settings; that a request is handled within one month; that complete deletion from backup systems may take up to 90 days; and that the process cannot be undone once it has begun.

Clue's privacy policy states

that a request for complete deletion of your data is actioned within one month. The same policy says all data is stored on servers located in the European Union, and that profile data is stored separately from health data.

Take three things from that. A published timeline is measured in weeks, not seconds. Backups are named separately from the live database, because they are a separate system and they take longer. And "cannot be undone" is doing real work: if you have not exported, export before you start.

Where the delete control usually lives

This page will not print a menu path for a named app, and be sceptical of any page that does. Menus change with every release, and following stale instructions is how people conclude that a deletion option does not exist. What can be said is where these controls are required to be.

Google Play publishes a requirement for apps that let you create an account: the developer must provide both an in-app route to delete the account and its associated data, prominent enough to be found in account settings or somewhere similar, and a web link where account and data deletion can be requested. Google's stated reason for the web route is exactly the situation this article is about — so that a user can still ask after the app has been uninstalled. So if you have already deleted the app and think you have lost your chance, look on the company's website for a deletion page.

On the phone side, Apple's guide distinguishes removing an app from the Home Screen, which keeps it in the App Library, from deleting it — a distinction worth knowing, because one of those is not a deletion at all. Apple's guide also notes that a deleted app can be downloaded again later if it is still available in the App Store.

The dull advice works: open the app's own settings and look under account, profile, privacy or data, then open the company's privacy policy and search it for the word "delete". The policy is the document the company is accountable for, and it usually names both the route and the address to write to.

The right to have your data erased

If asking politely does not work, or you want more than an account closure, there is a formal right behind it in some places.

The UK's Information Commissioner's Office describes the right this way: you can ask an organisation that holds data about you to delete it, and in some circumstances it must. Those circumstances, as the ICO sets them out, are where the organisation no longer needs the data for the reason it was collected; where you withdraw the consent it relied on; where you object and your interests outweigh theirs; where the data was collected or used unlawfully; or where it was collected from you as a child. The ICO also says the request can be made verbally or in writing, to any part of the organisation, and that a full response should come within one calendar month.

Two details there are more useful than they look. "To any part of the organisation" means you need not hunt for the right department — support counts. And a verbal request still counts, though writing gives you what matters in an argument: a dated record of what you asked for.

If you are in California

The California Attorney General sets out the rights California consumers have under the CCPA: the right to know what personal information a business collects and how it is used and shared, the right to delete personal information collected from them, with some exceptions, the right to opt out of the sale or sharing of their personal information, the right to correct inaccurate personal information, and the right to limit the use and disclosure of sensitive personal information. On timing, the published rule is that a business must respond within 45 calendar days and may extend that by a further 45 days if it tells you — so up to about 90 days in total.

The opt-out right is worth noticing next to the deletion one. Deletion addresses what a company holds now; opting out of sale or sharing addresses where it goes next, which is often the more useful right for anybody staying with an app rather than leaving it.

What none of this covers

Say the honest thing twice: everything above is a description of published rules and published policies, not legal advice, and the two frameworks named here cover the UK and EEA and California. Plenty of people reading this live under neither.

It is also worth knowing what kind of law this is. The US Federal Trade Commission's own guidance states plainly that many companies collecting people's health information — a fitness tracker, a diet app, a connected blood pressure cuff or something else — are not covered by HIPAA; the FTC Act and the Health Breach Notification Rule apply to them instead. So the medical-privacy protection people assume is wrapped around a cycle app is usually consumer-protection law wearing a different hat, and the Breach Notification Rule in particular is largely about being told after something has gone wrong.

The last limit is the plainest. Once data has been copied to somewhere else — an analytics provider, an advertising partner, a backup you cannot see — a deletion request goes to the company you asked, and what happens further down the chain is not something you or this page can verify. That is an argument for choosing carefully at the start, which is what the difference between a promise and an architecture is about.

Keep the record, lose the account

Leaving an app does not have to mean losing the history. The simplest handover is the oldest: print a paper period tracker, copy across the start dates you exported, and carry on from there. Paper cannot be synced, breached or requested from anybody.

If what you actually wanted from the app was the arithmetic, the cycle length calculator on this site takes your last few start dates and gives back your average, your shortest, your longest and how much your cycles swing. It runs in your browser, keeps nothing on a server, and there is no account to delete afterwards — which is the only version of this article that ends in one step.

Where Athena stands

Athena is the app this site is being built for. It is in development, it is in no store, and there is nothing here to buy or sign up for. When it ships, cycle data will be written to a private database on the phone, predictions calculated on the device, with no account and no server copy of what you log — which means there is no account deletion to perform and no erasure request to send, because there is nothing on our side to erase. The app will send anonymous diagnostics — features used, crashes, device model, never anything you log — to Firebase, and this website uses IP-anonymised web analytics.

The cost of that design is the one worth stating in an article about deletion: local-only means no automatic backup. If the phone is lost and nothing was exported, the history is gone, in exactly the same way and for exactly the same reason that nobody else can reach it.

Questions

Questions people ask

In this order. Export your history first if you want to keep it, since deletion is meant to be permanent. Then delete the account inside the app, while the app is still installed and the control still exists. Then remove the app from the phone. Then, if you want backup copies covered as well, send a written deletion request to the company.
No. Removing an app from a phone removes the app and what it stored locally. It sends no message to the company, starts no clock and triggers no obligation. An account left behind is an account still open, which is why the in-app deletion step belongs before the uninstall rather than after it.
Published timelines are measured in weeks. Flo's privacy policy states that a deletion request is handled within one month, that complete deletion from backup systems may take up to 90 days, and that it cannot be undone once begun. Clue's privacy policy states that a request for complete deletion is actioned within one month. Both are companies describing themselves, which nobody outside them can verify.
In some places and some circumstances. The UK Information Commissioner's Office says you can ask an organisation holding data about you to delete it, and that it must where it no longer needs the data, where you withdraw consent, where you object and your interests outweigh theirs, where the data was collected unlawfully, or where it was collected from you as a child. This is a description of published rules, not legal advice.
The California Attorney General publishes rights under the CCPA to know what a business collects, to delete personal information collected from you with some exceptions, to opt out of the sale or sharing of it, to correct inaccurate information and to limit the use of sensitive information. A business must respond within 45 calendar days and may extend that by a further 45 days if it tells you.
Look in the app's own settings under account, profile, privacy or data, then search the company's privacy policy for the word delete. No page should print menu paths for named apps, because menus change with every release. Google Play requires apps with accounts to offer an in-app deletion route and a web link where deletion can be requested after uninstalling.
Yes, if you want to keep it, because deletion is meant to be permanent and at least one published policy says the process cannot be undone once it has begun. A year of start dates is genuinely useful, to you and to a clinician if your pattern ever changes. If the app has no export, copy the start dates onto paper by hand.

Where this comes from

  1. Information Commissioner's Office (UK) (2025). Your right to get your data deleted. https://ico.org.uk/for-the-public/your-right-to-get-your-data-deleted/
  2. California Attorney General (2024). California Consumer Privacy Act (CCPA). https://oag.ca.gov/privacy/ccpa
  3. Google Play Console Help (2026). Understanding Google Play's app account deletion requirements. https://support.google.com/googleplay/android-developer/answer/13327111
  4. Apple (iPhone User Guide) (2026). Remove or delete apps from iPhone. https://support.apple.com/guide/iphone/remove-or-delete-apps-iph248b543ca/ios
  5. US Federal Trade Commission (2024). Complying with FTC's Health Breach Notification Rule. https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0
  6. Flo Health (2026). Flo Privacy Policy. https://flo.health/privacy-policy
  7. BioWink (Clue) (2026). Clue Privacy Policy. https://helloclue.com/privacy

Every link above was checked when this page was last updated. Athena is not affiliated with any of these organisations, and none of them has reviewed this page. Nothing here is medical advice.

The app this site is for

Athena keeps all of this on your phone.

The calculators here forget you the moment you close the tab. Athena is the same arithmetic living on your device — the moon ring, an honest calendar with ranges instead of false precision, and a database that never leaves the phone because there is no account and no server behind it.

In development for iPhone and Android. Not released yet — when it is, it will be on this site.

What Athena is