Period Tracker Privacy Check: Judge Any App in Ten Minutes
Six checks, ten minutes, one score out of ten. The drill for judging any period app yourself — and an honest account of what it can and cannot tell you.
You can judge a period tracker in ten minutes with six checks, and none of them requires trusting the marketing. Read the store privacy label and note that it is the developer's own declaration. See whether the app makes you create an account. Use it for a few minutes in airplane mode. Search the privacy policy for four words: sell, share, partners, acquisition. Find the delete and the export, and check that deletion is possible from outside the app if there is an account. Then set an app lock and turn off lock-screen previews. What you get at the end is an honest picture of what the app is built to be able to do — which is not the same as knowing how the company behaves, and the last section says why.
This is the drill. The longer argument behind it, including the seven questions worth asking and the reason an architecture beats a promise, is in what actually makes a period tracker private. Read that if you want to understand the reasoning. Read this if you want to open the app now and decide by lunchtime.
The store privacy label
Account wall, then airplane mode
Four words in the policy
The exits, and the phone
Minutes 0 to 2: read the label, then discount it
Open the app's store listing and find the privacy section — App Privacy on the App Store, Data safety on Google Play. You are looking for two things: whether anything is declared under tracking or advertising, and whether health data appears at all.
Apple defines the two categories worth understanding. "Data Linked to You" means data collected in a way that is linked to your identity, such as to your account or your device. "Data Used to Track You" means data from the app linked with data collected from other companies' apps, websites or offline properties, and used for advertising or shared with a data broker. An app that declares nothing in the second category has told you something concrete.
Now the discount, in the platforms' own words. Apple states that the information in this section is self-reported by the developer. Google's Data safety section is likewise the developer's own declaration of how its app collects, shares and handles data, including its security practices and its deletion options; Google adds that where an app displays an independent security review, that review does not verify the accuracy and completeness of the developer's disclosure.
So the label is a commitment, not an audit. Two minutes well spent, and no more weight than that. If the categories on it read as a foreign language, the three kinds of data a tracker can hold are set out in what period apps actually collect.
Minutes 2 to 5: the account wall, and airplane mode
Install it and watch what the first screen asks for. An account exists so data can live somewhere other than your phone; an app that opens straight into the tracker with no email and no sign-up has told you where your data is going before you have typed a date. Note which one you got.
Then the test that no marketing survives. Put the phone in airplane mode and use the app properly for a few minutes: log a period start, open the history, look at the prediction, change a setting. If everything works, the calculations are running on your device. If it stalls, spins or shows an error, they are not.
One honest caveat, because this test is often oversold. Working offline proves the arithmetic is local. It does not prove that nothing is sent later, when the connection comes back. It narrows the question from "does this app depend on a server" to "does this app also talk to one", which is what the next three minutes are for.
Minutes 5 to 8: four words in the privacy policy
Open the policy in a browser and use the find function. You are not reading it end to end — nobody does, and that is the point of writing them the way they are written. Four words, in this order.
- Sell. Most policies say they do not sell your data. Read the next clause anyway, because sharing is not selling, and a company can honestly decline to sell while sharing for advertising.
- Share. This is where the substance is. Ask one question of every sentence you find: are third parties named, or described as a category? "Analytics partners" can mean anybody. A list of company names is something you can go and check.
- Partners. Search it separately, because it often appears where "share" does not, and it is usually the sentence doing the real work.
- Acquisition. Try "merger" and "sale of assets" too. Nearly every policy says your data transfers with the business if the company is sold, and that one clause quietly outranks every promise above it, because the buyer writes the next policy.
A fifth search is worth thirty seconds: the word health. A good policy names your cycle data separately from crash logs and usage statistics. A vague one lumps everything into "information we collect", and the interesting part hides in the gap.
Minutes 8 to 10: the exits, and the phone in your hand
Deletion, in two places. Find the delete in the app's settings. Then, if the app has accounts, look for a deletion route on the web. This is not a wish: Google Play requires an app that lets users create an account to provide both an in-app path to delete the account and its associated data, prominent enough to be found in account settings or similar, and a web link where account and data deletion can be requested — the web route exists precisely so you can still ask after uninstalling. An account app offering only the in-app path is a gap you can name.
Export. Can you get your history out, in a format you can open? This is the exit, and an app confident in its own value lets you leave with what you put in. It also matters on a device-only app for the opposite reason: local storage has no automatic backup, so the export is the only copy that survives a lost phone.
The lock. Set a PIN or Face ID on the tracker if it offers one, then send yourself a test reminder and look at your lock screen. The likeliest way a period log is read by somebody else is that they pick up your unlocked phone, and the second likeliest is that a notification announced something on a screen anyone can see. The full map of who else could reach it is in who can see your period data.
Score it out of ten
- 2No account required. You reached the tracker without an email address.
- 2Everything works in airplane mode. Logging, history and predictions, with no connection.
- 1Nothing under tracking or advertising on the store privacy label.
- 1Health data is named separately from usage data in the policy.
- 1Third parties are named, not described as a category.
- 1Delete works from both places if there is an account, or from the app alone if there is not.
- 1Export produces a file you can read.
- 1App lock, and nothing specific on the lock screen.
Eight or more and the app is built so that most routes out of your phone are closed. Five to seven and it is a reasonable app whose privacy depends on the company continuing to behave as its policy says. Below five you are trusting the policy entirely, which some people will do knowingly and that is their call to make.
What the drill cannot tell you
Here is the ceiling, stated plainly, because a checklist that pretends to be more than it is would be worse than none.
Every check above measures capability and declarations. None of them measures conduct. An app can score nine and still be run by a company that does something its policy does not describe, and you would have no way of seeing it from the outside. That is not a hypothetical: the two documented enforcement matters against cycle-tracking apps were both about what was allegedly done rather than about what was declared, and both were visible only because a regulator went and looked.
The counterweight is also worth keeping in view. When the UK's Information Commissioner's Office reviewed period and fertility apps in 2024, it reported that no serious compliance issues or evidence of harms were identified, while urging developers to prioritise privacy. And the wider category is the reason to run the drill at all: a peer-reviewed scoping review of health apps found that most examined, twenty out of twenty-three, shared user data with third parties.
Nor is the law the backstop most people assume. The FTC's own guidance says that many companies collecting people's health information — a fitness tracker, a diet app, a connected blood pressure cuff — are not covered by HIPAA, and that the FTC Act and the Health Breach Notification Rule apply to them instead. Useful, real, and largely about telling you afterwards.
So the drill answers one question well: what is this app able to do with what I give it? That is the question with an answer. "Will they behave?" does not have one, which is why an app that holds nothing is worth more than an app that promises everything.
Where Athena stands, and what to use meanwhile
Athena is the app this site is being built for. It is in development, it is in no store, and there is nothing here to buy or sign up to, so run this drill on it the day it ships rather than taking a description on trust. The design it is being built to: cycle data written to a private database on the phone, predictions calculated on the device, no account and no server copy. What leaves is anonymous diagnostics to Firebase — which features get used, crashes, device model — carrying nothing you log, and this website uses web analytics with IP anonymisation. Local-only also means no automatic backup, so the export is not a nicety there; it is the only copy.
Until then, the tools here run in your browser and send nothing anywhere. The period calculator estimates your next few periods from your last one and your usual cycle length, with the range printed next to every date, and those are estimates rather than promises and never contraception. And the printable period tracker scores ten out of ten on the drill above by the least interesting method available: it is a sheet of paper.
Questions people ask
Where this comes from
- Apple Support (2026). About privacy information on the App Store and the choices you have to control your data. https://support.apple.com/en-us/102399
- Google Play Help (2026). Understand app privacy & security practices with Google Play's Data safety section. https://support.google.com/googleplay/answer/11416267
- Google Play Console Help (2026). Understanding Google Play's app account deletion requirements. https://support.google.com/googleplay/android-developer/answer/13327111
- US Federal Trade Commission (2024). Complying with FTC's Health Breach Notification Rule. https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0
- Information Commissioner's Office (UK) (2024). ICO urges all app developers to prioritise privacy. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/02/ico-urges-all-app-developers-to-prioritise-privacy/
- PubMed Central (2022). Data sharing practices of medicines-related and health apps: a scoping review. https://pmc.ncbi.nlm.nih.gov/articles/PMC9123546/
Every link above was checked when this page was last updated. Athena is not affiliated with any of these organisations, and none of them has reviewed this page. Nothing here is medical advice.