Privacy and your data

Offline Period Tracker vs Cloud Sync: The Honest Trade

Local-only removes the server, the account and the subpoena. It removes the backup with them. Here is the trade, argued against this site's own app.

9 min read Last checked 10 August 2026 6 sources, all linked

Local-only is the private choice, and it is the fragile one. An app that keeps your cycle on the phone has no server to breach, no account to compromise, no third party to hand it to and nothing for a court to ask for — and, for exactly the same reason, no copy of your history anywhere else. Sync buys you a new phone, a second device and a working answer to a cracked screen, and it pays for that with a copy of the most sensitive record you keep sitting on somebody else's servers under whatever policy applies at the time. If you choose local-only, exporting is not a nice extra. It is the whole backup plan.

This page is written against its own app, because the trade only means something if both halves are stated at full strength.

What sync genuinely buys you

Three things, and none of them is imaginary.

A new phone. People replace a handset every few years, and moving to it should not cost you a record you have kept for a decade. With sync it is a login. Without it, it is a file you had better have made.

A second device. If you log on a phone and read on a tablet, or want your history on a laptop when you are filling in a form for a clinic, a synced account does that and a local database does not.

A disaster. Dropped, drowned, stolen, wiped by a failed update. A phone is a small object with a hard life, and the difference between an annoyance and a loss is whether the data existed anywhere else.

None of that is marketing. Those are the reasons sync exists, and why most trackers are built on an account.

What local-only costs, said plainly

If the phone goes in a canal and you never exported anything, your cycle history is gone. Not recoverable by support, not restorable from a receipt, not sitting in a backup somebody can dig out for you. There is no reset-password route to a database that only ever existed in one place. That is not a bug in the design; it is the design, seen from the other side.

How much that matters depends on what the history is for. A few months of dates can be rebuilt from memory badly and from a calendar reasonably well. Ten years of start dates, symptom patterns and temperatures cannot be rebuilt at all, and it is usually the long record that has any value — the thing you take to an appointment, the thing that shows a change happened rather than that you feel it did.

Local-only

No server copy, no account, nothing to breach or subpoena, no third party in the path.

No automatic backup, no second device, no recovery if the phone is lost. Your export is the only copy.

Cloud sync

A new phone is a login. A second device works. A lost handset costs you nothing but the handset.

A copy of your cycle exists on somebody's servers, under a policy that can change and a company that can be sold.

Three middle grounds, and what each one actually promises

The choice is not really binary, and the honest version of this article says so.

End-to-end encrypted sync. The strongest of the middle options, when the company documents it. Apple's guide states that when the iPhone is locked with Face ID, Touch ID or a passcode, all health and fitness data other than Medical ID is encrypted, and that with two-factor authentication health data synced to iCloud is encrypted end to end and Apple does not have the key to decrypt it. Read that carefully, because the last clause is the whole thing: a company that says it cannot read your data is making a much narrower claim than one that says it will not. Apple's Health app is also where a phone-based log lives if you never install a tracker at all, which is the subject of tracking your cycle in Apple Health.

A company-held encrypted copy. The commonest shape. The data sits on servers the company can read, protected by its policies and its security rather than by mathematics. Clue's privacy policy describes its version: it states that creating a Clue account processes personal data such as a username, date of birth and email address, that all data is securely stored on servers located in the European Union, that profile data is stored separately from health data, that the health data tracked in the app is never shared with or sold to advertisers, and that a request for complete deletion is actioned within one month. Separating profile data from health data is a real measure and it is worth naming as one. It is still a promise about how a company behaves, made by the company, and you cannot audit it from where you are standing.

Manual export you control. The unglamorous one. No account, no server, and a file you make deliberately and put somewhere you have chosen. It has the privacy of local-only and it removes the single point of failure, at the cost of you remembering to do it. That last clause is where it usually fails.

There is a fourth thing that is not really a middle ground but often gets treated as one: your phone's own backup. The drip privacy policy is unusually straight about it, stating that cycle data is stored locally on the device and cannot be accessed by other apps, and that an automatic cloud backup may still take place depending on your device settings. A local-only app does not put your data in the cloud. Your operating system might, and that is a setting worth looking at whichever app you use.

An export habit that survives contact with real life

Advice to "export regularly" is worthless because it names no moment. A habit needs an occasion and a place.

  1. Pick an event, not an interval. The day you change your phone, the day you see a clinician, and one fixed date a year — a birthday works, because you will not forget it. Anything you have to remember on a schedule you will stop doing by March.
  2. Send the file somewhere it will still be in five years. An email to yourself is fine and it survives losing the phone. A copy on a laptop is fine. A copy that lives only on the same phone as the app is not a backup; it is the same egg in the same basket.
  3. Open it once. An export you have never looked at is a file of unknown quality. Read it, check the dates are dates, and then you know what you have.
  4. Keep a paper line for the part that matters most. Start dates take a second to write and are the one column everything else is calculated from. The printable period tracker is a year on a sheet, and it does not care whether your phone survives.

If you are choosing paper as the main record rather than the backstop, the method is a subject of its own and is set out in tracking your cycle without an app.

What this trade is not about

It is tempting to frame local-versus-cloud as a fight between a trustworthy company and an untrustworthy one. It is not. It is a question about where a copy exists, and copies have their own risks regardless of anybody's intentions.

Nor does the law close the gap for you. The FTC's own guidance says plainly that many companies collecting people's health information — a fitness tracker, a diet app, a connected blood pressure cuff or something else — are not covered by HIPAA; the FTC Act and the Health Breach Notification Rule apply instead. That is real protection, and it is largely protection of the kind that tells you after something has gone wrong.

The wider category is worth knowing too: a scoping review of health apps found that most of those examined, 20 of 23, shared user data with third parties. That is not a verdict on any named tracker, and it is the reason to ask what an app is architecturally capable of doing rather than what its marketing says. The longer version of that argument is the difference between a promise and an architecture, and the vocabulary around it — no account, unlinked, never transmitted — is pulled apart in what anonymous tracking can and cannot mean.

Choosing, without pretending there is a right answer

Sync is the sensible default if losing your history would upset you more than a company holding it, if you use more than one device, or if you are tracking for a medical reason where continuity matters. Local-only is the sensible default if you would rather no copy existed, if your situation makes a server copy a risk rather than a convenience, or if you have ever hesitated before logging something honestly. That hesitation is worth listening to: a record you edit for safety is a record that is no use to you or to a clinician.

Either way, the history is only worth what you can read out of it. The cycle length calculator turns a handful of start dates into your own average and how much it moves, and the period calculator turns that into an estimated window with the uncertainty printed next to it. The NHS puts the usual range at a period roughly every 28 days, commonly anywhere from every 21 to every 35 — where you sit in it is a fact only your own record can show. Predictions from either tool are estimates, not certainties.

Where Athena stands

Athena is the app this site is being built for. It is in development, it is in no store, and there is nothing here to buy or sign up for.

It has no sync. Periods, symptoms, notes and temperatures are written to a private database on the phone, predictions are calculated on the device, and there is no account and no server copy of health data — which means all of the protection described above and all of the fragility. If the phone is lost and nothing was exported, the history is gone, and no one can get it back for you. That is why export is not an optional extra in an app built this way, and why an export habit sits in the middle of this page rather than at the end of it.

Two things do leave the phone, and this page would be doing what it complains about if it left them out. The app will send anonymous diagnostics to Firebase — which features get used, crash reports, device model and OS version — with nothing you log in them, and this website uses IP-anonymised web analytics. Neither carries any cycle data, because there is none to carry. What happens to the on-device copy when you remove the app is a separate question with a separate answer: does deleting the app delete your data.

Questions

Questions people ask

It is more private and less durable. With nothing on a server there is no breach, no account to compromise, no third party in the path and nothing for a court to ask for. There is also no automatic backup, no second device and no recovery if the phone is lost. Which is better depends on whether a copy existing worries you more than a copy disappearing.
If you never exported anything, the history is gone. Support cannot recover it, there is no password to reset, and nothing was stored anywhere else by design. A few months of dates can be rebuilt from a calendar. Ten years of start dates, symptoms and temperatures cannot, which is why an export habit matters more in a local-only app than in any other kind.
Only if you use more than one device, change phones often, or are tracking for a medical reason where an unbroken record matters. If none of those apply, a local app plus a deliberate export gives you most of what sync provides without a copy on anyone else's servers. The catch is that the export only works if you actually make it.
It is the strongest of the middle options where the company documents it. Apple states that with two-factor authentication, health data synced to iCloud is encrypted end to end and Apple does not have the key to decrypt it. That is a narrower and stronger claim than a promise not to look, though you are still trusting a description you cannot audit.
It depends on the company, and the policy is the only place to find out. Clue's privacy policy states that all data is securely stored on servers located in the European Union, that profile data is stored separately from health data, and that health data tracked in the app is never shared with or sold to advertisers. Other apps publish different arrangements.
Tie it to events rather than to an interval you will forget. Export when you change phones, before an appointment, and once a year on a date you already remember. Keep the file somewhere that survives losing the phone, such as an email to yourself or a laptop, and open it once to check the dates read as dates.
Not automatically. The drip privacy policy is straight about this: it states cycle data is stored locally and cannot be accessed by other apps, and that an automatic cloud backup may still take place depending on your device settings. The app is not putting your data in the cloud, but your operating system might, so that setting is worth checking.

Where this comes from

  1. Apple (iPhone User Guide) (2026). View menstrual cycle predictions and history in Health on iPhone. https://support.apple.com/guide/iphone/view-menstrual-cycle-predictions-and-history-iph1a4a00aa0/ios
  2. drip (2022). drip — Privacy Policy. https://dripapp.org/privacy-policy
  3. BioWink (Clue) (2026). Clue Privacy Policy. https://helloclue.com/privacy
  4. US Federal Trade Commission (2024). Complying with FTC's Health Breach Notification Rule. https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0
  5. PubMed Central (2022). Data sharing practices of medicines-related and health apps: a scoping review. https://pmc.ncbi.nlm.nih.gov/articles/PMC9123546/
  6. NHS (2025). Periods. https://www.nhs.uk/conditions/periods/

Every link above was checked when this page was last updated. Athena is not affiliated with any of these organisations, and none of them has reviewed this page. Nothing here is medical advice.

The app this site is for

Athena keeps all of this on your phone.

The calculators here forget you the moment you close the tab. Athena is the same arithmetic living on your device — the moon ring, an honest calendar with ranges instead of false precision, and a database that never leaves the phone because there is no account and no server behind it.

In development for iPhone and Android. Not released yet — when it is, it will be on this site.

What Athena is