Privacy and your data

Period Tracker Privacy Check: Judge Any App in Ten Minutes

Six checks, ten minutes, one score out of ten. The drill for judging any period app yourself — and an honest account of what it can and cannot tell you.

9 min read Last checked 10 August 2026 6 sources, all linked

You can judge a period tracker in ten minutes with six checks, and none of them requires trusting the marketing. Read the store privacy label and note that it is the developer's own declaration. See whether the app makes you create an account. Use it for a few minutes in airplane mode. Search the privacy policy for four words: sell, share, partners, acquisition. Find the delete and the export, and check that deletion is possible from outside the app if there is an account. Then set an app lock and turn off lock-screen previews. What you get at the end is an honest picture of what the app is built to be able to do — which is not the same as knowing how the company behaves, and the last section says why.

This is the drill. The longer argument behind it, including the seven questions worth asking and the reason an architecture beats a promise, is in what actually makes a period tracker private. Read that if you want to understand the reasoning. Read this if you want to open the app now and decide by lunchtime.

0 to 2

The store privacy label

2 to 5

Account wall, then airplane mode

5 to 8

Four words in the policy

8 to 10

The exits, and the phone

Minutes 0 to 2: read the label, then discount it

Open the app's store listing and find the privacy section — App Privacy on the App Store, Data safety on Google Play. You are looking for two things: whether anything is declared under tracking or advertising, and whether health data appears at all.

Apple defines the two categories worth understanding. "Data Linked to You" means data collected in a way that is linked to your identity, such as to your account or your device. "Data Used to Track You" means data from the app linked with data collected from other companies' apps, websites or offline properties, and used for advertising or shared with a data broker. An app that declares nothing in the second category has told you something concrete.

Now the discount, in the platforms' own words. Apple states that the information in this section is self-reported by the developer. Google's Data safety section is likewise the developer's own declaration of how its app collects, shares and handles data, including its security practices and its deletion options; Google adds that where an app displays an independent security review, that review does not verify the accuracy and completeness of the developer's disclosure.

So the label is a commitment, not an audit. Two minutes well spent, and no more weight than that. If the categories on it read as a foreign language, the three kinds of data a tracker can hold are set out in what period apps actually collect.

Minutes 2 to 5: the account wall, and airplane mode

Install it and watch what the first screen asks for. An account exists so data can live somewhere other than your phone; an app that opens straight into the tracker with no email and no sign-up has told you where your data is going before you have typed a date. Note which one you got.

Then the test that no marketing survives. Put the phone in airplane mode and use the app properly for a few minutes: log a period start, open the history, look at the prediction, change a setting. If everything works, the calculations are running on your device. If it stalls, spins or shows an error, they are not.

One honest caveat, because this test is often oversold. Working offline proves the arithmetic is local. It does not prove that nothing is sent later, when the connection comes back. It narrows the question from "does this app depend on a server" to "does this app also talk to one", which is what the next three minutes are for.

Minutes 5 to 8: four words in the privacy policy

Open the policy in a browser and use the find function. You are not reading it end to end — nobody does, and that is the point of writing them the way they are written. Four words, in this order.

  1. Sell. Most policies say they do not sell your data. Read the next clause anyway, because sharing is not selling, and a company can honestly decline to sell while sharing for advertising.
  2. Share. This is where the substance is. Ask one question of every sentence you find: are third parties named, or described as a category? "Analytics partners" can mean anybody. A list of company names is something you can go and check.
  3. Partners. Search it separately, because it often appears where "share" does not, and it is usually the sentence doing the real work.
  4. Acquisition. Try "merger" and "sale of assets" too. Nearly every policy says your data transfers with the business if the company is sold, and that one clause quietly outranks every promise above it, because the buyer writes the next policy.

A fifth search is worth thirty seconds: the word health. A good policy names your cycle data separately from crash logs and usage statistics. A vague one lumps everything into "information we collect", and the interesting part hides in the gap.

Minutes 8 to 10: the exits, and the phone in your hand

Deletion, in two places. Find the delete in the app's settings. Then, if the app has accounts, look for a deletion route on the web. This is not a wish: Google Play requires an app that lets users create an account to provide both an in-app path to delete the account and its associated data, prominent enough to be found in account settings or similar, and a web link where account and data deletion can be requested — the web route exists precisely so you can still ask after uninstalling. An account app offering only the in-app path is a gap you can name.

Export. Can you get your history out, in a format you can open? This is the exit, and an app confident in its own value lets you leave with what you put in. It also matters on a device-only app for the opposite reason: local storage has no automatic backup, so the export is the only copy that survives a lost phone.

The lock. Set a PIN or Face ID on the tracker if it offers one, then send yourself a test reminder and look at your lock screen. The likeliest way a period log is read by somebody else is that they pick up your unlocked phone, and the second likeliest is that a notification announced something on a screen anyone can see. The full map of who else could reach it is in who can see your period data.

Score it out of ten

  • 2No account required. You reached the tracker without an email address.
  • 2Everything works in airplane mode. Logging, history and predictions, with no connection.
  • 1Nothing under tracking or advertising on the store privacy label.
  • 1Health data is named separately from usage data in the policy.
  • 1Third parties are named, not described as a category.
  • 1Delete works from both places if there is an account, or from the app alone if there is not.
  • 1Export produces a file you can read.
  • 1App lock, and nothing specific on the lock screen.

Eight or more and the app is built so that most routes out of your phone are closed. Five to seven and it is a reasonable app whose privacy depends on the company continuing to behave as its policy says. Below five you are trusting the policy entirely, which some people will do knowingly and that is their call to make.

What the drill cannot tell you

Here is the ceiling, stated plainly, because a checklist that pretends to be more than it is would be worse than none.

Every check above measures capability and declarations. None of them measures conduct. An app can score nine and still be run by a company that does something its policy does not describe, and you would have no way of seeing it from the outside. That is not a hypothetical: the two documented enforcement matters against cycle-tracking apps were both about what was allegedly done rather than about what was declared, and both were visible only because a regulator went and looked.

The counterweight is also worth keeping in view. When the UK's Information Commissioner's Office reviewed period and fertility apps in 2024, it reported that no serious compliance issues or evidence of harms were identified, while urging developers to prioritise privacy. And the wider category is the reason to run the drill at all: a peer-reviewed scoping review of health apps found that most examined, twenty out of twenty-three, shared user data with third parties.

Nor is the law the backstop most people assume. The FTC's own guidance says that many companies collecting people's health information — a fitness tracker, a diet app, a connected blood pressure cuff — are not covered by HIPAA, and that the FTC Act and the Health Breach Notification Rule apply to them instead. Useful, real, and largely about telling you afterwards.

So the drill answers one question well: what is this app able to do with what I give it? That is the question with an answer. "Will they behave?" does not have one, which is why an app that holds nothing is worth more than an app that promises everything.

Where Athena stands, and what to use meanwhile

Athena is the app this site is being built for. It is in development, it is in no store, and there is nothing here to buy or sign up to, so run this drill on it the day it ships rather than taking a description on trust. The design it is being built to: cycle data written to a private database on the phone, predictions calculated on the device, no account and no server copy. What leaves is anonymous diagnostics to Firebase — which features get used, crashes, device model — carrying nothing you log, and this website uses web analytics with IP anonymisation. Local-only also means no automatic backup, so the export is not a nicety there; it is the only copy.

Until then, the tools here run in your browser and send nothing anywhere. The period calculator estimates your next few periods from your last one and your usual cycle length, with the range printed next to every date, and those are estimates rather than promises and never contraception. And the printable period tracker scores ten out of ten on the drill above by the least interesting method available: it is a sheet of paper.

Questions

Questions people ask

Six steps in ten minutes. Read the store privacy label. See whether the app forces you to create an account. Use it for a few minutes in airplane mode. Search the privacy policy for sell, share, partners and acquisition. Find the in-app delete and the export, plus a web deletion route if there is an account. Then set an app lock and turn off lock-screen previews.
Treat it as a commitment rather than an audit. Apple states that the information in the App Store privacy section is self-reported by the developer, and Google's Data safety section is the developer's own declaration. Google adds that where an app displays an independent security review, that review does not verify the accuracy and completeness of the developer's disclosure.
Four words. Sell, because declining to sell is compatible with sharing for advertising. Share, and then ask whether third parties are named or merely described as a category. Partners, which often appears where share does not and usually carries the substance. And acquisition, along with merger, because that clause transfers your data to whoever buys the company.
It proves the arithmetic is running on your device, which is worth knowing and takes three minutes. It does not prove that nothing is sent later, once the connection returns. Think of it as narrowing the question from whether the app depends on a server to whether it also talks to one, which is what reading the policy is for.
If it has accounts, yes. Google Play requires an app that lets users create an account to provide both an in-app path to delete the account and its associated data, prominent enough to be found in account settings or similar, and a web link where deletion can be requested. The web route exists so you can still ask after uninstalling the app.
Eight or more out of ten and the app is built so that most routes off your phone are closed. Five to seven means a reasonable app whose privacy rests on the company continuing to behave as its policy says. Below five you are trusting the policy entirely, which is a choice some people will make knowingly.
Conduct. Every check measures what an app is capable of and what its developer has declared, never what a company actually does. The two documented enforcement matters against cycle-tracking apps concerned alleged behaviour rather than declarations, and were visible only because a regulator looked. That is why an app holding nothing is worth more than an app promising everything.

Where this comes from

  1. Apple Support (2026). About privacy information on the App Store and the choices you have to control your data. https://support.apple.com/en-us/102399
  2. Google Play Help (2026). Understand app privacy & security practices with Google Play's Data safety section. https://support.google.com/googleplay/answer/11416267
  3. Google Play Console Help (2026). Understanding Google Play's app account deletion requirements. https://support.google.com/googleplay/android-developer/answer/13327111
  4. US Federal Trade Commission (2024). Complying with FTC's Health Breach Notification Rule. https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0
  5. Information Commissioner's Office (UK) (2024). ICO urges all app developers to prioritise privacy. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/02/ico-urges-all-app-developers-to-prioritise-privacy/
  6. PubMed Central (2022). Data sharing practices of medicines-related and health apps: a scoping review. https://pmc.ncbi.nlm.nih.gov/articles/PMC9123546/

Every link above was checked when this page was last updated. Athena is not affiliated with any of these organisations, and none of them has reviewed this page. Nothing here is medical advice.

The app this site is for

Athena keeps all of this on your phone.

The calculators here forget you the moment you close the tab. Athena is the same arithmetic living on your device — the moon ring, an honest calendar with ranges instead of false precision, and a database that never leaves the phone because there is no account and no server behind it.

In development for iPhone and Android. Not released yet — when it is, it will be on this site.

What Athena is