Privacy and your data

What Data Do Period Apps Actually Collect?

Three layers of collection, and only one of them is the layer you chose. What a tracker holds, what it works out from that, and what a store privacy label can and cannot prove.

9 min read Last checked 10 August 2026 7 sources, all linked

A period app collects three separate kinds of data, and only the first is the kind you meant to hand over. There is what you type: dates, flow, pain, mood, sex, medication, notes. There is what the app works out from that, including facts you never wrote down, such as a probable ovulation day or a pregnancy. And there is what arrives without you touching the screen at all: your device model, crash reports, which screens you opened, and on some apps an advertising identifier and a record of the advert you tapped before installing. Which of the three a particular app holds is not something anyone can tell you from the outside. It is written in that app's own store label and privacy policy, and those two documents are the only honest place to look.

What follows is the taxonomy in full, what the store label does and does not prove, and what regulators have actually found when they went and looked. Collection is a separate question from sharing, and this article is about the first one.

Layer one: what you type

Cycle start dates are the floor. Almost nothing else about a tracker works without them, and on their own they are already a record of something private.

Everything above the floor is optional and most apps ask for a lot of it: flow level, cramps, headaches, spotting, mood, sleep, energy, appetite, skin, sex and whether it was protected, contraception and when it was taken, medication, weight, basal body temperature, cervical mucus, ovulation test results, and a free-text note. Some ask whether you are trying to conceive, and some ask you to log a pregnancy or the end of one.

The free-text note is the part worth pausing on. Structured fields are dull by design — a number, a tick, a level. A note is whatever you were thinking at eleven at night, and it is the field least likely to be anonymised by anything, because it cannot be. Write your notes as though they are the most sensitive thing in the app, because they are.

A sheet of paper, by contrast, collects exactly what you write on it and nothing else. That is why the printable period tracker exists on this site, and why there is a longer printable symptom tracker for the people whose doctor asked for a few months of records. Paper cannot sync, cannot crash and cannot phone home.

Layer two: what the app works out

This is the layer nobody counts, and it is often the more revealing one.

  • Predicted Dates you did not enter

    Your next period, a fertile window, an estimated ovulation day. These are arithmetic on your own history, they are estimates with a range around them, and they are not contraception. But they are also new data about you that did not exist before you installed anything.

  • Inferred States you never logged

    A period that does not arrive on time, followed by silence, is a pattern. So is logging a pregnancy and then stopping. An app does not need a field labelled "miscarriage" to hold the shape of one. The inference exists in the data whether or not the app ever shows it to you or names it in its policy.

  • Derived A profile of how you behave

    Average cycle length, how much it varies, which symptoms cluster, what time of day you open the app, how many days in a row you have used it. Some of this is what makes the app useful. All of it is still a record.

The arithmetic underneath the first row is not mysterious, and you can watch it happen without giving anything to anybody: the cycle length calculator takes a few start dates, works out your average and how far your own cycles swing either side of it, and does the whole thing in your browser. That is roughly the calculation a tracker runs. The difference between the tool and an app is not the maths. It is where the maths runs and what it leaves behind.

Layer three: what arrives without you typing

The clearest evidence that this layer exists is that both app stores make developers declare it. Apple's support page describes the App Store privacy information section in two categories that are worth reading slowly. "Data Linked to You" means data collected in a way that is linked to your identity, such as to your account or device. "Data Used to Track You" means data from the app linked with data collected from other companies' apps, websites or offline properties, and used for advertising or shared with a data broker. Google says developers use the Data safety section to describe how their app collects, shares and handles data, including its security practices and its data deletion options.

In practice, the things that end up in this layer are the ordinary furniture of app development: device model and operating system version, crash reports, which features get used and for how long, an install identifier, and — where the app carries advertising or measures where its installs came from — an advertising identifier and attribution data linking your install to the advert you tapped.

None of that is sinister on its own; a crash report is how bugs get fixed. The item that differs in kind is the advertising identifier, because it is designed to be the same identifier across other companies' apps. Whether any particular tracker carries one, we cannot check for you. Its own store label is where that is declared.

What a store privacy label proves, and what it does not

Both labels are useful and both are commonly misread, so here is the limit in each company's own terms.

Apple states that the information in the App Store privacy section is self-reported by the developer. Google's Data safety section is likewise the developer's own declaration about its app. Google goes further and says that where an app displays an independent security review, that review does not verify the accuracy and completeness of the developer's Data safety disclosure.

A privacy label is a statement the developer made about itself. It is not an audit, and neither store says it is.

That does not make labels worthless. A declaration is a commitment a company can be held to, and reading one takes a minute. It does mean the label belongs at the start of your checking rather than the end of it. If you want the procedure rather than the principle, the ten-minute privacy check is the drill: what to open, in what order, and what each answer is worth.

What regulators have actually found

This subject attracts far more heat than evidence, so what follows is limited to official actions with public documents, and the wording is the wording.

In January 2021 the US Federal Trade Commission announced a settlement with the developer of a widely used fertility-tracking app. The FTC's complaint alleged that the company promised to keep users' health data private while disclosing it to third-party analytics providers. The company settled, neither admitting nor denying the allegations, and agreed to obtain express consent before sharing health data in future.

In May 2023 the FTC charged the developer of an ovulation app with sharing users' sensitive personal information with third parties and failing to notify them, in breach of the Health Breach Notification Rule. That matter resolved by stipulated order, again with the company neither admitting nor denying the charges, and carried a civil penalty of one hundred thousand dollars.

Two enforcement actions are not a verdict on an industry, and the counterweight belongs in the same breath. When the UK's Information Commissioner's Office reviewed period and fertility apps in 2024, it reported that no serious compliance issues or evidence of harms were identified, while urging developers to prioritise privacy.

The wider picture for health apps generally is less comfortable, and it is the reason to check rather than to assume. A peer-reviewed scoping review of health apps found that most of those examined, twenty out of twenty-three, shared user data with third parties.

One more thing that surprises people: in the US, health data in an app you downloaded yourself is usually not covered by medical privacy law. The FTC's own guidance says that many companies collecting people's health information — a fitness tracker, a diet app, a connected blood pressure cuff — are not covered by HIPAA, and that the FTC Act and the Health Breach Notification Rule apply to them instead.

Holding it and sending it are different questions

Everything above is about what a tracker has. Where it goes next is a separate map, with its own routes: the company, its analytics and crash-reporting suppliers, advertisers where there is an advertising model, an acquirer if the business is sold, and the person who picks up your unlocked phone. That map is drawn in who can see your period data, and it is worth reading alongside this one, because an app can collect a great deal and send almost none of it, or collect little and send all of it.

The structural argument for why the two questions collapse into one when data never leaves the phone is in the difference between a privacy promise and an architecture. Short version: a promise has three failure modes that have nothing to do with intent, and an app holding nothing survives all three.

Four things you can do this week

  1. Read your own tracker's label. It sits on the store listing under App Privacy or Data safety. Note whether anything appears under tracking or advertising.
  2. Turn the connection off and use the app for a day. If logging, history and predictions still work in airplane mode, the work is happening on your device.
  3. Empty the notes field of anything you would not want read aloud. Structured fields can be dull. Free text never is.
  4. Find the export before you need it. An app you can leave with your history intact is one you can change your mind about.

Where Athena stands

Athena is the app this site is being built for. It is in development, it is in no store, and there is nothing here to buy or sign up to — so what follows describes how it is built, not something you can verify today.

Layer one is written to a private database on the phone. Layer two is calculated on the device from layer one. There is no account, so neither layer has a server copy. Layer three is not nothing, and pretending otherwise would fail this article's own test: when the app ships it will send anonymous diagnostics to Firebase — which features get used, crash reports, device model — carrying nothing you log and no advertising identifier. This website uses web analytics with IP anonymisation. That is the whole list.

The cost of that design is worth stating plainly, because it is a real one. Data that lives only on your phone has no automatic backup. If the phone is lost and you never exported anything, the history is gone. An app built this way owes you a proper export, and you owe yourself the habit of using it.

Questions

Questions people ask

Three kinds. What you type: cycle dates, flow, symptoms, mood, sex, contraception, medication and free-text notes. What the app works out from that, including predictions and states you never logged. And what arrives without you typing at all, such as device model, crash reports, which features you use and, on some apps, an advertising identifier. Which of the three a given app holds is declared on its store listing.
Some have been formally accused of sharing it, which is not the same thing as selling it. The US Federal Trade Commission brought two matters against cycle-tracking apps over sharing users' health information with outside companies; both were resolved by agreement, with the companies neither admitting nor denying the allegations. The UK regulator reviewed period and fertility apps in 2024 and reported no serious compliance issues or evidence of harms.
Quite a lot. Predictions are data you did not enter: a next period, an estimated fertile window, a likely ovulation day, all of them estimates with a range around them and none of them contraception. So are inferences. A late log followed by silence has a shape, and an app needs no field named for a pregnancy or a loss to hold the pattern of one.
No. Apple states that the information in the App Store privacy section is self-reported by the developer, and Google's Data safety section is likewise the developer's own declaration about its app. Google adds that where an app displays an independent security review, that review does not verify the accuracy and completeness of the developer's disclosure. A label is a commitment, not an audit.
In the US, usually not. The FTC's own guidance says that many companies collecting people's health information — a fitness tracker, a diet app, a connected blood pressure cuff — are not covered by HIPAA, and that the FTC Act and the Health Breach Notification Rule apply to them instead. That is real protection of a different kind: much of it is about being told after something has gone wrong.
The free-text note. Structured fields are dull by design: a level, a tick, a number. A note is a sentence in your own words, and nothing can strip the meaning out of it, because the meaning is the words. If you change one habit after reading about period app data collection, make it that one.
Open its store listing and read the privacy label, then search the privacy policy for the words sell, share, partners and acquisition. Then use the app for a day with the connection turned off. If logging, history and predictions all still work in airplane mode, the calculations are running on your device rather than on somebody's server.

Where this comes from

  1. US Federal Trade Commission (2021). Developer of Popular Women's Fertility-Tracking App Settles FTC Allegations that It Misled Consumers About the Disclosure of their Health Data. https://www.ftc.gov/news-events/news/press-releases/2021/01/developer-popular-womens-fertility-tracking-app-settles-ftc-allegations-it-misled-consumers-about
  2. US Federal Trade Commission (2023). Ovulation tracking app Premom will be barred from sharing health data for advertising under proposed FTC order. https://www.ftc.gov/news-events/news/press-releases/2023/05/ovulation-tracking-app-premom-will-be-barred-sharing-health-data-advertising-under-proposed-ftc-order
  3. US Federal Trade Commission (2024). Complying with FTC's Health Breach Notification Rule. https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0
  4. PubMed Central (2022). Data sharing practices of medicines-related and health apps: a scoping review. https://pmc.ncbi.nlm.nih.gov/articles/PMC9123546/
  5. Information Commissioner's Office (UK) (2024). ICO urges all app developers to prioritise privacy. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/02/ico-urges-all-app-developers-to-prioritise-privacy/
  6. Apple Support (2026). About privacy information on the App Store and the choices you have to control your data. https://support.apple.com/en-us/102399
  7. Google Play Help (2026). Understand app privacy & security practices with Google Play's Data safety section. https://support.google.com/googleplay/answer/11416267

Every link above was checked when this page was last updated. Athena is not affiliated with any of these organisations, and none of them has reviewed this page. Nothing here is medical advice.

The app this site is for

Athena keeps all of this on your phone.

The calculators here forget you the moment you close the tab. Athena is the same arithmetic living on your device — the moon ring, an honest calendar with ranges instead of false precision, and a database that never leaves the phone because there is no account and no server behind it.

In development for iPhone and Android. Not released yet — when it is, it will be on this site.

What Athena is