Which period tracker apps actually keep your data private?
In August 2025, a California jury found that Meta had violated state privacy law by collecting reproductive health information from users of the period tracking app Flo. Flo, Google and the analytics firm Flurry settled related claims for a combined sum of roughly $59.5 million, none of them admitting wrongdoing. Court filings described menstrual cycle, sexual activity and pregnancy data flowing to advertising platforms through standard software development kits, even though the privacy policy told users that information wouldn’t be shared.
If you tracked your cycle in an app during those years, that is a strange thing to sit with. And it raises a question that is harder to answer than it should be: how do you tell which apps are actually private?
The short answer is that you mostly can’t tell from the marketing. Nearly every period app claims to take privacy seriously. What separates them is not the promise. It is how the app is built underneath.
The three kinds of “private”
When a health app says it protects your data, it is usually making one of three very different claims.
“We promise not to misuse it.” Your data goes to the company’s servers. They hold it, they can read it, and their privacy policy describes what they intend to do with it. This is the most common model, and it is the one the Flo case was about. The promise may be entirely sincere. But policies get rewritten, companies get acquired, and third-party tools bundled into the app can send data in ways the product team did not fully map. You are trusting an intention, and intentions can change.
“We encrypt it so we can’t read it.” Your data still goes to servers, but it is encrypted on your device first with a key the company does not hold. This is a real, meaningful improvement. The company can’t read your logs even if subpoenaed. The caveats are that metadata often isn’t encrypted (the fact that you have an account, when you opened the app, what device you’re on), and that you are trusting the implementation to be correct, which you generally can’t verify.
“It never leaves your phone.” There is no server for it to go to. The app writes to storage on your device and that is the end of the journey. Nothing to breach, nothing to subpoena, nothing to sell in an acquisition, nothing to accidentally leak through an ad tool.
The third model is the strongest, and it is rare, because it is commercially inconvenient. No server means no analytics on how people use your product, no cross-device sync you can charge for, no big dataset to build features on or sell access to. Most companies aren’t willing to give that up.
How to check for yourself
You don’t have to take any app’s word for it. Four questions get you most of the way.
Does it require an account?
This is the fastest signal. If you have to give an email address and create a password, your data is on a server somewhere, associated with an identity. An account exists so a server can recognise you. No account means no server-side profile, and nothing sitting in a database waiting to be breached, sold, or handed over.
What does the privacy policy say about third parties?
Search the policy for “partners,” “advertising,” “analytics,” and “affiliates.” Vague language about sharing with “trusted partners to improve our services” is doing a lot of work. Also look for what happens in an acquisition. Many policies contain a clause saying your data is a transferable business asset if the company is sold, which means the privacy promise you agreed to isn’t the one that binds the next owner.
Does the app work in airplane mode?
Genuinely useful test, and it takes ten seconds. Turn off wifi and cellular, then open the app and log something. If everything works normally, the app isn’t depending on a server. If it hangs, shows an error, or won’t load your history, your data is round-tripping somewhere.
Are there ads?
Ad networks are the most common route for health data to leak, and it usually isn’t deliberate. An advertising tool dropped into an app to make money can transmit far more context about user behaviour than the developers reviewed. An app with no advertising has removed that pathway entirely.
What to look for in a genuinely private app
If you’re switching, these are the properties worth holding out for:
- No account required. No email, no password, no server-side identity.
- Local storage only. Your logs live on your device, not in a cloud database.
- No third-party analytics or ad tools on your logs. Not “we don’t sell data.” Period, sex, and contraception entries should not enter a marketing or crash-reporting pipeline.
- Device-level lock. Face ID or passcode protection, because the realistic threat for most people isn’t a distant hacker. It is someone picking up an unlocked phone.
- Honest limitations. An app that tells you the trade-offs is more trustworthy than one that claims to have none.
That last point deserves a moment. Local-only storage has a real cost: if the company holds no copy of your data, they can’t restore it when you lose your phone. Your history lives or dies with your device backup. Any app that promises perfect privacy and effortless recovery across devices is doing something more complicated than it’s telling you.
Where Lua sits
We built Lua on the third model, and we’ll be direct about what that means in both directions.
There is no Lua account, and no Lua server holding your logs. Everything you log (periods, symptoms, contraception, sex, pregnancy) is written to private storage on your own phone. We can’t read it, because it never reaches us. There’s no advertising, and no analytics of what you track. You can turn on a Face ID lock so nobody else can open it. If you buy Lua+, Apple processes the payment; that receipt is not your cycle history.
Apple Health integration is available if you want it, off by default, and it only ever exchanges menstrual flow. Your symptoms, notes and sex logs are never written to Health. You can read the full story in our privacy policy.
The trade-off: because your data lives only on your device, we have no copy to restore from. Backing up your phone through Apple is what carries your history to a new device. No cloud copy means nothing to leak, but also nothing for us to recover. That’s the honest deal, and we’d rather you know it now than discover it later.
Lua is on the App Store for iOS. Tracking is free, with no ads. Lua+ is optional and billed by Apple: it unlocks reminders for every method and full cycle stats.
Lua is not a contraceptive and has no contraceptive effect. It helps you keep the method you already use on schedule, but it cannot prevent pregnancy. Always follow your prescriber’s instructions.
More from the blog
One app for your cycle, contraception, fertility and pregnancy.
Private, flexible and designed to adapt with you.