Is your period app safe? What "we protect your data" actually means
Reproductive health apps have had a rough few years of headlines. Class-action lawsuits over data sharing with advertising companies. Regulatory settlements. Reporting on how easily sensitive health data moves through the ordinary plumbing of the app economy (advertising networks, analytics vendors, data brokers), often without anyone at the company setting out to misuse it.
That last part is the uncomfortable detail. In most of these cases, nobody intended to expose deeply personal information. Third-party software tools, dropped into apps to power ad targeting or measure engagement, quietly transmit far more than the product team reviewed. A sincere privacy policy and an actual data leak can coexist, because the policy describes intent and the code describes what’s technically possible.
For a to-do list app, that gap is an inconvenience. For an app tracking your period, your symptoms, whether you’re trying to conceive, or your pregnancy, it’s a different category of risk. Reproductive health data can reveal things people have real, specific reasons to keep private, including in places where that inference carries legal weight.
So it’s worth being able to answer the question for yourself: is the app you’re using actually safe, or does it just say it is?
The privacy policy won’t tell you
This is the part that trips people up. Reading a privacy policy feels like due diligence, and it’s genuinely worth doing, but it has a hard limit: a policy describes what a company intends to do with your data, not what its technical setup is capable of. If your data lives on a server, the policy is a promise about how that server will be used. Promises get reinterpreted, companies get acquired, and third-party code can behave in ways that never made it into the document you read.
The more useful question isn’t “what does the policy say.” It’s “where does my data physically go.”
Four checks that actually tell you something
Does it require an account? An account means a server-side identity attached to your data: an email or phone number a database can associate with everything you log. No account is a genuine structural signal, not just a marketing claim, because there’s no such identity to begin with. We go deeper on that in why the sign-up screen is the weakest link.
Does it work in airplane mode? Ten seconds, and it’s the most concrete test available to you. Turn off wifi and cellular, open the app, log something, browse your history. If everything works exactly as normal, nothing is round-tripping to a server. If it hangs, errors, or won’t load your history, your data is going somewhere outside your phone.
Does the privacy policy mention third-party tools, analytics, or advertising partners? This is the specific mechanism behind most reproductive-health data incidents that have made headlines. A policy that only says “we don’t sell your data” hasn’t addressed it. Sharing with an ad network for targeting isn’t technically a sale, and policies are often worded precisely enough that it doesn’t have to be.
What happens if the company is acquired? Look for a clause about data as a “business asset” in a merger or acquisition. It’s extremely common, and it means the privacy commitment you agreed to may not be the one that survives a change of ownership.
What “safe” actually looks like in an app
Putting those checks together, the properties that make a reproductive health app hard to misuse (not just unlikely to, but structurally hard to) are:
- No account. Nothing to attach your data to.
- No server-side storage. If there’s no database, there’s nothing to breach, subpoena, or sell.
- No third-party analytics or advertising tools. The pathway that caused the most-reported incidents in this category doesn’t exist if the code isn’t there.
- A device-level lock, because for most people the realistic risk isn’t a remote attacker. It’s someone else picking up an unlocked phone.
For a fuller rundown of how to compare apps, see which period tracker apps actually keep your data private.
What you give up for that
Worth saying plainly, because no design choice is free of trade-offs. An app with no server can’t back up your data for you. If you lose your phone without a device backup, there’s no copy anywhere else to restore from, because there never was one. That’s not a bug in the privacy model. It’s the direct, honest cost of it. Your phone’s own backup through Apple or Google becomes the thing carrying your history forward, the same way it already does for your photos and messages.
Anyone claiming both “we hold no copy of your data” and “we can seamlessly restore your data if you lose your phone” is describing two things that can’t both be true. It’s a useful line for spotting confused or misleading marketing.
Where Lua sits
Lua has no account and no Lua server for your health logs. There’s no sign-up, nothing to verify. Everything you log (cycle, symptoms, contraception, sex, pregnancy) is written to private storage on your phone and stays there. We can’t read it, because it never reaches us. No advertising, and no analytics of what you track. A Face ID lock is available so no one else can open it either. If you buy Lua+, Apple processes the payment; that receipt is not your cycle history. The full detail is in our privacy policy.
The honest trade-off: because your data lives only on your device, we have no copy to restore it from if you lose your phone without a backup. That’s the cost of how it’s built, not a caveat we’d rather you not notice.
Lua is on the App Store for iOS. Tracking is free, with no ads. Lua+ is optional and billed by Apple: it unlocks reminders for every method and full cycle stats.
Lua is not a contraceptive and has no contraceptive effect. It helps you keep the method you already use on schedule, but it cannot prevent pregnancy. This article is general information about app privacy, not legal advice.
More from the blog
One app for your cycle, contraception, fertility and pregnancy.
Private, flexible and designed to adapt with you.