Offline Period Tracker vs Cloud Sync: The Honest Trade
Local-only removes the server, the account and the subpoena. It removes the backup with them. Here is the trade, argued against this site's own app.
Local-only is the private choice, and it is the fragile one. An app that keeps your cycle on the phone has no server to breach, no account to compromise, no third party to hand it to and nothing for a court to ask for — and, for exactly the same reason, no copy of your history anywhere else. Sync buys you a new phone, a second device and a working answer to a cracked screen, and it pays for that with a copy of the most sensitive record you keep sitting on somebody else's servers under whatever policy applies at the time. If you choose local-only, exporting is not a nice extra. It is the whole backup plan.
This page is written against its own app, because the trade only means something if both halves are stated at full strength.
What sync genuinely buys you
Three things, and none of them is imaginary.
A new phone. People replace a handset every few years, and moving to it should not cost you a record you have kept for a decade. With sync it is a login. Without it, it is a file you had better have made.
A second device. If you log on a phone and read on a tablet, or want your history on a laptop when you are filling in a form for a clinic, a synced account does that and a local database does not.
A disaster. Dropped, drowned, stolen, wiped by a failed update. A phone is a small object with a hard life, and the difference between an annoyance and a loss is whether the data existed anywhere else.
None of that is marketing. Those are the reasons sync exists, and why most trackers are built on an account.
What local-only costs, said plainly
If the phone goes in a canal and you never exported anything, your cycle history is gone. Not recoverable by support, not restorable from a receipt, not sitting in a backup somebody can dig out for you. There is no reset-password route to a database that only ever existed in one place. That is not a bug in the design; it is the design, seen from the other side.
How much that matters depends on what the history is for. A few months of dates can be rebuilt from memory badly and from a calendar reasonably well. Ten years of start dates, symptom patterns and temperatures cannot be rebuilt at all, and it is usually the long record that has any value — the thing you take to an appointment, the thing that shows a change happened rather than that you feel it did.
Local-only
No server copy, no account, nothing to breach or subpoena, no third party in the path.
No automatic backup, no second device, no recovery if the phone is lost. Your export is the only copy.
Cloud sync
A new phone is a login. A second device works. A lost handset costs you nothing but the handset.
A copy of your cycle exists on somebody's servers, under a policy that can change and a company that can be sold.
Three middle grounds, and what each one actually promises
The choice is not really binary, and the honest version of this article says so.
End-to-end encrypted sync. The strongest of the middle options, when the company documents it. Apple's guide states that when the iPhone is locked with Face ID, Touch ID or a passcode, all health and fitness data other than Medical ID is encrypted, and that with two-factor authentication health data synced to iCloud is encrypted end to end and Apple does not have the key to decrypt it. Read that carefully, because the last clause is the whole thing: a company that says it cannot read your data is making a much narrower claim than one that says it will not. Apple's Health app is also where a phone-based log lives if you never install a tracker at all, which is the subject of tracking your cycle in Apple Health.
A company-held encrypted copy. The commonest shape. The data sits on servers the company can read, protected by its policies and its security rather than by mathematics. Clue's privacy policy describes its version: it states that creating a Clue account processes personal data such as a username, date of birth and email address, that all data is securely stored on servers located in the European Union, that profile data is stored separately from health data, that the health data tracked in the app is never shared with or sold to advertisers, and that a request for complete deletion is actioned within one month. Separating profile data from health data is a real measure and it is worth naming as one. It is still a promise about how a company behaves, made by the company, and you cannot audit it from where you are standing.
Manual export you control. The unglamorous one. No account, no server, and a file you make deliberately and put somewhere you have chosen. It has the privacy of local-only and it removes the single point of failure, at the cost of you remembering to do it. That last clause is where it usually fails.
There is a fourth thing that is not really a middle ground but often gets treated as one: your phone's own backup. The drip privacy policy is unusually straight about it, stating that cycle data is stored locally on the device and cannot be accessed by other apps, and that an automatic cloud backup may still take place depending on your device settings. A local-only app does not put your data in the cloud. Your operating system might, and that is a setting worth looking at whichever app you use.
An export habit that survives contact with real life
Advice to "export regularly" is worthless because it names no moment. A habit needs an occasion and a place.
- Pick an event, not an interval. The day you change your phone, the day you see a clinician, and one fixed date a year — a birthday works, because you will not forget it. Anything you have to remember on a schedule you will stop doing by March.
- Send the file somewhere it will still be in five years. An email to yourself is fine and it survives losing the phone. A copy on a laptop is fine. A copy that lives only on the same phone as the app is not a backup; it is the same egg in the same basket.
- Open it once. An export you have never looked at is a file of unknown quality. Read it, check the dates are dates, and then you know what you have.
- Keep a paper line for the part that matters most. Start dates take a second to write and are the one column everything else is calculated from. The printable period tracker is a year on a sheet, and it does not care whether your phone survives.
If you are choosing paper as the main record rather than the backstop, the method is a subject of its own and is set out in tracking your cycle without an app.
What this trade is not about
It is tempting to frame local-versus-cloud as a fight between a trustworthy company and an untrustworthy one. It is not. It is a question about where a copy exists, and copies have their own risks regardless of anybody's intentions.
Nor does the law close the gap for you. The FTC's own guidance says plainly that many companies collecting people's health information — a fitness tracker, a diet app, a connected blood pressure cuff or something else — are not covered by HIPAA; the FTC Act and the Health Breach Notification Rule apply instead. That is real protection, and it is largely protection of the kind that tells you after something has gone wrong.
The wider category is worth knowing too: a scoping review of health apps found that most of those examined, 20 of 23, shared user data with third parties. That is not a verdict on any named tracker, and it is the reason to ask what an app is architecturally capable of doing rather than what its marketing says. The longer version of that argument is the difference between a promise and an architecture, and the vocabulary around it — no account, unlinked, never transmitted — is pulled apart in what anonymous tracking can and cannot mean.
Choosing, without pretending there is a right answer
Sync is the sensible default if losing your history would upset you more than a company holding it, if you use more than one device, or if you are tracking for a medical reason where continuity matters. Local-only is the sensible default if you would rather no copy existed, if your situation makes a server copy a risk rather than a convenience, or if you have ever hesitated before logging something honestly. That hesitation is worth listening to: a record you edit for safety is a record that is no use to you or to a clinician.
Either way, the history is only worth what you can read out of it. The cycle length calculator turns a handful of start dates into your own average and how much it moves, and the period calculator turns that into an estimated window with the uncertainty printed next to it. The NHS puts the usual range at a period roughly every 28 days, commonly anywhere from every 21 to every 35 — where you sit in it is a fact only your own record can show. Predictions from either tool are estimates, not certainties.
Where Athena stands
Athena is the app this site is being built for. It is in development, it is in no store, and there is nothing here to buy or sign up for.
It has no sync. Periods, symptoms, notes and temperatures are written to a private database on the phone, predictions are calculated on the device, and there is no account and no server copy of health data — which means all of the protection described above and all of the fragility. If the phone is lost and nothing was exported, the history is gone, and no one can get it back for you. That is why export is not an optional extra in an app built this way, and why an export habit sits in the middle of this page rather than at the end of it.
Two things do leave the phone, and this page would be doing what it complains about if it left them out. The app will send anonymous diagnostics to Firebase — which features get used, crash reports, device model and OS version — with nothing you log in them, and this website uses IP-anonymised web analytics. Neither carries any cycle data, because there is none to carry. What happens to the on-device copy when you remove the app is a separate question with a separate answer: does deleting the app delete your data.
Questions people ask
Where this comes from
- Apple (iPhone User Guide) (2026). View menstrual cycle predictions and history in Health on iPhone. https://support.apple.com/guide/iphone/view-menstrual-cycle-predictions-and-history-iph1a4a00aa0/ios
- drip (2022). drip — Privacy Policy. https://dripapp.org/privacy-policy
- BioWink (Clue) (2026). Clue Privacy Policy. https://helloclue.com/privacy
- US Federal Trade Commission (2024). Complying with FTC's Health Breach Notification Rule. https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0
- PubMed Central (2022). Data sharing practices of medicines-related and health apps: a scoping review. https://pmc.ncbi.nlm.nih.gov/articles/PMC9123546/
- NHS (2025). Periods. https://www.nhs.uk/conditions/periods/
Every link above was checked when this page was last updated. Athena is not affiliated with any of these organisations, and none of them has reviewed this page. Nothing here is medical advice.