Your Period Tracker Says It Protects Your Privacy. But What Happens If a Court Asks for Your Data?
The safest period tracker isn’t necessarily the one with the strongest privacy promise. It’s the one with the least information to hand over.
Your period tracker might know when you bled last month.
It might also know when you had sex. Whether it was protected. Whether your period was late. Whether you took a pregnancy test. Whether you experienced spotting, cramps, unusual discharge, a miscarriage, or symptoms that could suggest a pregnancy.
In other words: what looks like a cute little calendar can become an extraordinarily detailed record of your reproductive life.
That doesn’t mean everyone needs to panic-delete their period tracker. It does mean we should understand what we’re giving these apps — and what happens to that information after we hit “save.”
Because there’s one question we don’t ask nearly enough:
If a court, government agency, or law-enforcement authority demanded my data, what could this company actually give them?
And when you start asking that question, period-tracker privacy looks very different.
SKIP TO THE END FOR OUR OFFICIAL SCORES BUT WE HOPE YOU’LL READ THE IN-BETWEEN.
First: “We protect your data” can mean two very different things
Imagine two period-tracking companies.
Company A stores your reproductive-health information on its servers along with information that identifies you. It has an excellent privacy policy and promises to fight government requests for your data.
Company B never receives your cycle history at all. Everything you track stays on your phone.
Both companies may genuinely care about privacy.
But only one can say:
We don't have your period history to give them.
That distinction matters.
Privacy policies are important. So are encryption, company jurisdiction, security practices and an organization's willingness to challenge government requests.
But there is an even stronger form of protection:
Don't collect the data in the first place.
The Federal Trade Commission has long encouraged health-app developers to minimize the sensitive information they retain, noting that companies should consider whether they even need to collect certain information at all. Read the FTC's guidance for mobile health apps
It's a principle worth borrowing as consumers, too.
So we looked at some of the biggest and most privacy-conscious period trackers through a slightly different lens:
Not just “Is this app private?”
But:
“What could this company actually produce if somebody came asking?”
1. Euki: The company doesn't have your cycle data
If minimizing the amount of reproductive-health information held by a company is the goal, Euki stands out.
Euki is a nonprofit reproductive-health and period-tracking app designed around local data storage.
That means the information you enter — periods, symptoms, sexual activity, pregnancy information and other health details — is stored on your device rather than Euki's servers.
According to Euki:
“We do not collect or store anything you track in the app.”
Euki says there is no cloud database containing your tracking history, no user account attached to the app and no email address required to use it. Read Euki's Privacy FAQs
That creates an important form of legal protection.
If someone serves Euki with a demand for your period-tracking history, Euki says it doesn't possess that history in the first place.
No database.
No account tied to your email.
No cloud backup of your cycle.
No period history for Euki to search.
Mozilla independently tested six period and ovulation trackers in July 2026 and gave Euki a 10/10 privacy score — the highest of the apps it tested. Its researchers found that the health information they entered into Euki appeared to remain on their device and that its core tracking features did not transmit that information to third parties. Read Mozilla's 2026 Euki privacy review
There is, however, a tradeoff.
If you lose your phone or delete the app, Euki can't magically restore your tracking history from its servers.
Because — again — it doesn't have it.
That's less convenient.
It's also the point.
Our privacy read: ★★★★★
Best for: Someone whose highest priority is minimizing the amount of reproductive-health information held by a third-party company.
2. Apple Cycle Tracking: Apple can store it without being able to read it
There's another privacy model worth understanding.
Instead of never receiving the data, a company can store it in a way that prevents the company itself from decrypting it.
Apple's built-in Cycle Tracking feature is a strong example.
When the appropriate security settings are enabled — including a device passcode and two-factor authentication — Apple says health information synced through iCloud is end-to-end encrypted.
More importantly, Apple says:
Apple does not possess the key needed to decrypt that health data.
That includes information stored through Cycle Tracking. Read Apple's explanation of Cycle Tracking and health-data privacy
Think about how different that is from ordinary cloud storage.
The information can exist on Apple's infrastructure while remaining unreadable to Apple.
So from a court-request perspective, the interesting question becomes not simply:
Does Apple store the information?
but:
Can Apple decrypt and read the information being requested?
For end-to-end encrypted Health data configured as Apple describes, Apple says it cannot.
One major caveat: your privacy is only as strong as the ecosystem around the data.
If you give another app permission to access information from Apple Health, that company may have its own privacy policy, servers and data-retention practices.
Using Apple Health doesn't automatically make every connected app equally private.
Our privacy read: ★★★★★
Best for: iPhone users who want sophisticated cycle tracking without giving the platform provider readable access to their Health data.
3. Clue: “If we are subpoenaed… we will not comply.”
Then there's Clue.
Clue takes a different approach.
The company does process user data. But it is based in Germany and says its users benefit from German and European data-protection laws, including GDPR protections, regardless of where they live.
And in July 2026, Clue published one of the clearest statements we've seen from a mainstream period tracker:
“If we are subpoenaed by any authority demanding access to your data, we will not comply.”
Read Clue's July 2026 statement on data privacy
That is unusually strong language.
Clue also gives users granular controls over whether information can be used for things like research, recommendations, analytics and advertising.
Mozilla's 2026 privacy review gave Clue 8/10, second only to Euki among the six trackers it evaluated. Read Mozilla's 2026 Clue privacy review
But there's still an important difference between Clue and something like Euki.
Clue's protection partly depends on law and corporate resistance.
Euki's protection partly depends on architecture.
Clue can say:
We have the data, but we will fight to protect it.
Euki can say:
We don't have the data.
Those are both meaningful protections.
They are not identical protections.
No company can guarantee what every future court in every jurisdiction will do, and privacy policies can evolve as laws and products change.
Which is why we still give architectural protections an edge.
Our privacy read: ★★★★☆
Best for: Someone who wants a polished, full-featured period tracker from a company taking an unusually aggressive public position on reproductive-data privacy.
4. Flo: Anonymous Mode completely changes the privacy calculation
Flo deserves a more nuanced conversation than it often gets.
The company has baggage.
In 2021, the Federal Trade Commission alleged that Flo had shared sensitive health information with outside analytics companies including Facebook and Google despite representations to users about how that information would be protected. Flo settled the FTC case. Read the FTC's consumer guidance discussing the Flo case
That history is relevant.
But so is what happened afterward.
Following the overturning of Roe v. Wade, Flo accelerated the development of Anonymous Mode, which fundamentally changes how user identity and health information are handled.
In Anonymous Mode, Flo says it does not connect reproductive-health data with identifying information such as your:
name
email address
IP address
advertising identifier
Apple or Google account identifier
Flo's servers can still receive health information, but the system is designed so that Flo cannot determine whose health information it is.
The company uses a technology called Oblivious HTTP to separate a user's identity and network information from the health information being transmitted.
Flo now states explicitly:
Even with a court order, it cannot identify Anonymous Mode users.
See how Flo's Anonymous Mode works
And in its explanation of law-enforcement requests, Flo says that if it received a legally valid demand or subpoena concerning an Anonymous Mode user, it could not identify that person and therefore could not fulfill the request for that user's information. Read Flo's policy for responding to data requests
That's a meaningful architectural protection.
It also illustrates an important point:
Regular Flo and Flo in Anonymous Mode should not be treated as the same privacy product.
Flo acknowledges that for people using its regular mode, the possibility of legally compelled disclosure exists.
The company says it would review requests, challenge requests it considers invalid or overbroad, attempt to narrow what must be produced and notify the user when legally permitted. Read Flo's current law-enforcement FAQ
With Anonymous Mode enabled, however, the company says it cannot connect a person's identity to their reproductive-health record.
That's a much stronger position.
There are usability tradeoffs here too. Features requiring your identity — including certain cross-device, partner, wearable and account features — may not work in Anonymous Mode.
Again:
Privacy and convenience are frequently pulling in opposite directions.
Our privacy read:
Flo in Anonymous Mode: ★★★★★
Regular Flo: ★★★☆☆
Best for: Someone who likes Flo's features but wants to disconnect their identity from their reproductive-health history.
5. Stardust: Privacy branding deserves scrutiny
Stardust has made privacy a particularly visible part of its brand.
The period tracker has promoted encryption and data separation as protections against reproductive-health surveillance.
And its current privacy policy provides extensive information about how it handles user information. Read Stardust's current privacy policy
But this is exactly where marketing shouldn't be the end of the investigation.
Mozilla's independent 2026 review gave Stardust 2/10 — the lowest privacy score of the six period trackers it evaluated.
Researchers said that although Stardust presents itself as privacy-conscious, they found important questions around how information was collected and handled. Read Mozilla's full 2026 Stardust privacy investigation
That doesn't automatically mean the app is unsafe.
It does mean we wouldn't choose it as our example of the gold standard for reproductive-health privacy simply because privacy features prominently in its messaging.
Our privacy read: Don't judge an app's privacy by its aesthetic.
Read what it collects.
Read what leaves your device.
Read what can be connected to your identity.
Read what independent researchers find when they actually test it.
Wait. Isn't all health information protected by HIPAA?
No.
And this misconception is probably more important than any individual app recommendation.
HIPAA protects health information handled by certain covered entities — such as healthcare providers, insurers and their business associates.
Downloading a consumer health app does not automatically transform the company running that app into a HIPAA-covered entity.
The FTC specifically identifies menstruation and fertility apps among consumer health technologies that may instead fall under other federal privacy and breach-notification requirements. Explore the FTC's Mobile Health Apps privacy tool
That's why saying:
“Don't worry, it's health information.”
isn't enough.
Your doctor's medical record and the information you type into an ordinary consumer app may exist under very different legal frameworks.
So what should you actually look for in a period tracker?
Forget the giant PRIVACY 🔒 headline on the download page for a minute.
Ask these questions instead:
1. Where does my reproductive-health data actually live?
On your phone? On the company's servers? Both?
Local-only storage dramatically reduces what the company itself can produce.
2. Can the company read it?
“Encrypted” doesn't necessarily mean the company can't decrypt it.
End-to-end encrypted data where the company does not possess the key is a much stronger protection.
3. Can my health information be connected to my identity?
Your name isn't the only thing that identifies you.
An email address, phone number, IP address, advertising identifier, device information or account login can potentially connect activity back to a person.
4. What happens if law enforcement asks?
Look for the company's actual legal-request policy.
Does it say:
“We may disclose information where required by law”?
Does it say:
“We will challenge government requests”?
Or has the system been designed so the company cannot identify the user or access the requested data?
Those are very different answers.
5. Who else gets information from the app?
Analytics companies.
Advertising technology.
Research partners.
Third-party SDKs.
Every additional company receiving information potentially creates another place where information about you exists.
6. Can I permanently delete my information?
And does “delete” mean delete?
Find out whether information disappears immediately, after a retention period or only from your visible account while remaining elsewhere.
Our privacy ranking
If the specific question is:
“Which period trackers minimize what could be handed over about me?”
Here's where we'd start.
Euki — ★★★★★ Your tracked health information stays locally on your device. Euki says it doesn't have your cycle history to produce.
Apple Cycle Tracking — ★★★★★ With the proper security settings enabled, Health data synced through iCloud is end-to-end encrypted and Apple says it cannot decrypt it.
Flo Anonymous Mode — ★★★★★ Flo still receives health data, but Anonymous Mode is designed to prevent Flo from knowing whose health data it is.
Clue — ★★★★☆ Clue possesses user data but operates under European privacy laws and has publicly pledged that it will not comply with subpoenas seeking user data.
Regular Flo — ★★★☆☆ Flo says it will challenge inappropriate government requests and has strengthened its privacy posture considerably, but regular-mode data can still be associated with an account.
Stardust — ★★☆☆☆ Strong privacy positioning, but independent testing from Mozilla in 2026 raised enough concerns that we'd want users to look closely before assuming the marketing equals the strongest protection.
Mozilla's broader July 2026 investigation reached a similar overall conclusion, ranking Euki first at 10/10, followed by Clue at 8/10, Flo at 7/10, Period Calendar at 6/10, Planned Parenthood's Spot On at 5/10 and Stardust at 2/10. Read Mozilla's complete comparison of period-tracker privacy
But no period tracker can make your reproductive life “subpoena-proof”
This is the part that gets lost when the conversation becomes:
DELETE YOUR PERIOD APP.
Your period tracker is only one piece of your digital footprint.
Even if an app company has absolutely nothing useful to hand over, reproductive-health information may exist elsewhere.
Depending on the situation and jurisdiction, digital evidence could potentially come from things like:
your physical phone
texts or DMs
emails
browser history
search history
location information
purchase history
healthcare records
other apps
people you've communicated with
So switching period apps isn't a magical privacy shield.
And deleting one app shouldn't create a false sense that every other part of your digital life has suddenly become invisible.
The better goal is data minimization.
Fewer companies collecting sensitive information.
Less identifying information attached to it.
More information remaining on devices rather than corporate servers.
More end-to-end encryption.
And better awareness of where our most intimate digital records actually go.
The safest data may be the data a company never receives.
We've become accustomed to evaluating privacy by asking whether we trust a company.
Maybe that's the wrong question.
You shouldn't have to trust a period-tracking company to courageously protect you someday.
Technology can be designed so that courage isn't required.
A company can't sell information it never collected.
It can't accidentally leak a database that doesn't exist.
And it can't hand a court readable reproductive-health information it cannot access.
So before you tell another app when you bled, when you had sex, when your period was late or when something felt different, ask one more question:
Who else gets to know this?
Your body generates enough information already.
You don't have to give everyone a copy.
This article is for general educational purposes and is not legal advice. Privacy protections, court procedures and reproductive-health laws vary by jurisdiction and can change. App features and privacy policies can also change, so review the current policies of any service you use.