Lua vs Flo, Clue, Euki, and drip: which period trackers keep data private?
Most period apps say they protect your privacy. What separates them is not the promise. It is how the app is built underneath. This page compares five apps on three structural questions only: no account, no servers for health logs, and no health telemetry. Those are not the only things that matter, but they are the ones you can verify without trusting a slogan.
Before the table, one piece of history worth knowing. Between roughly 2016 and 2019, court filings described Flo users’ cycle, sexual activity, and pregnancy data reaching advertising platforms through standard software development kits. Flo, Google, and the analytics firm Flurry later settled related claims for a combined sum of roughly $59.5 million, none of them admitting wrongdoing. In August 2025, a California jury found Meta had violated state privacy law in connection with reproductive health information from Flo users; Meta said it would appeal. That record is about the server-plus-SDK model of that era, not a claim about how any specific product works today. It does explain why people ask harder questions than marketing copy usually answers.
The comparison
| App | No account | No servers for health logs | No health telemetry | Notes |
|---|---|---|---|---|
| Lua | Yes | Yes | No | iOS only. Anonymous usage via PostHog (see privacy policy). Optional Lua+ receipts go to Apple and RevenueCat, not cycle logs. |
| Euki | Yes | Yes | Yes | Nonprofit, open source, iOS and Android. PIN lock. Mozilla has recommended it. |
| drip | Yes | Yes | Yes | Open-source fertility-awareness. iOS, Android, F-Droid. Password protection and local import/export. |
| Flo | No (typical use) | No (typical use) | No | Default is account plus cloud. Unregistered on-device mode exists; Anonymous Mode still stores health data on Flo servers, unlinked from name/email. |
| Clue | No | No | No | Account required. Health data on AWS in Ireland and Germany. |
“No health telemetry” here means no advertising SDKs, crash reporters, or third-party analytics on what you log. Lua uses PostHog for anonymous usage analytics while your entries stay on your device, so it is marked No for this column. A purchase receipt is not a health log.
The three kinds of “private”
When a health app says it protects your data, it is usually making one of three very different claims.
“We promise not to misuse it.” Your data goes to the company’s servers. They hold it, they can read it, and their privacy policy describes what they intend to do with it. This is the most common model, and it is the one the Flo litigation history was about. The promise may be entirely sincere. But policies get rewritten, companies get acquired, and third-party tools bundled into the app can send data in ways the product team did not fully map. You are trusting an intention, and intentions can change.
“We encrypt it so we can’t read it.” Your data still goes to servers, but it is encrypted on your device first with a key the company does not hold. This is a real, meaningful improvement. The company cannot read your logs even if subpoenaed. The caveats are that metadata often is not encrypted (the fact that you have an account, when you opened the app, what device you are on), and that you are trusting the implementation to be correct, which you generally cannot verify.
“It never leaves your phone.” There is no server for it to go to. The app writes to storage on your device and that is the end of the journey. Nothing to breach, nothing to subpoena, nothing to sell in an acquisition, nothing to accidentally leak through an ad tool.
The third model is the strongest, and it is rare, because it is commercially inconvenient. No server for health logs means no cross-device sync you can charge for and no big health dataset to build features on or sell access to. A company can still add limited anonymous usage analytics without pulling logs off the device. Most companies are not willing to give up cloud health storage.
Lua
Lua is built on the third model. There is no Lua account and no Lua server for your health logs. Everything you log (periods, symptoms, contraception, sex, pregnancy) is written to private storage on your iPhone. We cannot read it because it never reaches us. No ads and no crash reporters. The app sends anonymous usage analytics through PostHog; your entries stay on your phone. Face ID lock is optional. Reminders are scheduled locally and work in airplane mode.
Optional Apple Health integration is off by default and exchanges menstrual flow only. If you buy Lua+, Apple processes payment; RevenueCat sees purchase receipts, not your cycle history. You can read the full story in our privacy policy.
The trade-off is honest: we have no copy to restore if you lose your phone without a device backup. That is the cost of nothing sitting in our database.
Differentiators versus other local-first apps: contraception reminders for pill, ring, patch, shot, IUD, and implant; one app for cycle, contraception, trying to conceive, and pregnancy. Lua is on the App Store. Everyone starts with a free trial of Lua+, billed by Apple. After it, there’s a free version for bleeding, sex, symptoms, and mood, with no ads.
Lua is not a contraceptive method. It sends informational reminders only.
Euki
Euki is a fair peer on all three axes. The nonprofit app requires no account, stores logs locally, and has no backend for them. Mozilla has recommended it. PIN lock, optional scheduled data deletion, open source. iOS and Android.
Lua is not “more private” than Euki in that structural sense. The difference is product: Lua is an iOS app for cycle tracking plus contraception-method reminders, trying to conceive, and pregnancy in one private app. Euki is a privacy-first tracker plus a reproductive-health resource library, including abortion care information.
drip
drip is also a fair local-first peer. The open-source cycle and fertility-awareness tracker keeps data on the phone. App Store privacy labels list Data Not Collected. No ads, non-commercial. Password protect, import/export. iOS, Android, and F-Droid.
The difference is product focus: drip implements sympto-thermal fertility awareness in the open. Lua is a private cycle and contraception reminder app. Lua is not a fertility-awareness contraceptive method and must not be described as one.
Flo
Flo’s typical use is an identified account plus cloud storage. Health data goes to Flo’s servers so features like insights, chatbots, and predictions can run there.
Flo also offers unregistered on-device mode, so it would be wrong to say Flo currently requires an account in every case. Anonymous Mode goes further: it decouples name, email, and IP from health data using OHTTP via a Cloudflare relay. Flo still stores health data on its servers so those features work. That is identity unlinked on a server, not data that never leaves your phone. Flo’s privacy policy effective 9 April 2026 still describes Anonymous Mode as a mode of the server product.
It would also be wrong to claim Flo currently sends cycle, sexual activity, or pregnancy events to Meta. That conduct belongs to the 2016–2019 SDK era described in court filings. Flo’s current policy states health data is not shared with AppsFlyer, Firebase, or TikTok; non-health marketing SDKs remain. The $59.5 million settlement involving Flo, Google, and Flurry came without any party admitting wrongdoing. The August 2025 Meta jury verdict is not described here as a finally approved settlement.
Clue
Clue exists only as an online service. You must create an account (username, email, password). Clue’s terms state data is stored locally and on their servers.
Health data is processed on AWS servers in Ireland and Germany under GDPR. Clue says it does not sell to ad networks. Braze processes some tracked health data for notifications; that processing is not optional. Datadog is also not optional. Optional toggles exist for research, analytics, and advertising in privacy settings.
Clue is more transparent than many peers, and EU hosting is a real choice. GDPR is real and not the same as having no copy. It is still not local-only.
Four checks you can run yourself
You do not have to take any app’s word for it. These checks support the table above.
Does it require an account? No email or password means no server-side identity for your logs. Some apps offer optional anonymous modes on top of identified products. That is different from never needing an account at all. More on that in why the sign-up screen is the weakest link.
Does it work in airplane mode? Turn off wifi and cellular, open the app, log something. If it works normally, the core product is not waiting on a server.
Are there ads or obvious SDKs? Ad networks are a common route for health data to leak without anyone intending it.
What happens in an acquisition? Search the privacy policy for language about your data as a transferable business asset. Structural privacy sidesteps that question; server products inherit it. For a broader safety checklist, see is your period app safe?.
The trade-off nobody advertises
Local-only storage has a real cost. If the company holds no copy of your data, they cannot restore it when you lose your phone. Your history lives or dies with your device backup. Any app that promises perfect privacy and effortless recovery across devices is doing something more complicated than it is telling you.
That is the honest deal for Lua, Euki, and drip. It is also why server-backed apps exist: recovery, cross-device sync, and cloud predictions are conveniences that require a copy somewhere else.
Lua is not a contraceptive and has no contraceptive effect. Reminders cannot prevent pregnancy. Predictions are estimates, not a diagnosis. This page is not legal or medical advice.
More from the blog
One app for your cycle, contraception, fertility and pregnancy.
Private, flexible and designed to adapt with you.