The Mozilla Foundation published hands-on privacy testing of six period tracking apps on July 16, 2026, scoring them from 10 out of 10 down to 2 out of 10. The results describe symptom logs reaching analytics pipelines, device identifiers reaching ad networks, and in-app browsers quietly reopening the tracking that the apps themselves had closed.
The tests ran under Mozilla's Nothing Personal banner and were carried out by privacy researcher Shoshana Wodinsky, using manual testing combined with network analysis. Six apps were examined: Euki, Clue, Flo, Period Calendar, Planned Parenthood's Spot On, and Stardust. Testing time ranged from three hours per app to five, with Stardust receiving the longest session.
Two outside institutions contributed. According to Mozilla, the Transparency Hub at Harvard's Berkman Klein Center examined historical changes to the apps' privacy policies, and the Siebel School of Computing and Data Science at the University of Illinois provided additional Android testing. That second element matters, because most of the network observations described in the reviews were captured on iOS.
The scores landed as follows: Euki at 10 out of 10, Clue at 8, Flo at 7, Period Calendar at 6, Spot On at 5, and Stardust at 2.
What actually left each app
The distinction Mozilla draws throughout is not between apps that collect and apps that do not. Every one of the six collects intimate material by design. The distinction is between what stays inside a company's own systems and what travels outward through analytics, attribution, and advertising infrastructure.
Stardust, an astrology-themed tracker aimed at younger users, sat at the bottom. According to the review, the app begins sending data to third-party tracking services from the moment it opens, before any information has been entered. As the app is used, birthdate, birth control type, reproductive goals, and specific logged symptoms travel to a mix of analytics tools, attribution services, and data pipelines. Mozilla's testers reported finding no clear in-app setting that fully disables that transmission.
One partner received the health detail directly. The review names RudderStack, a platform apps use to collect and route user analytics, and describes it receiving the symptom, the timestamp, and a persistent user ID the moment a symptom was logged. Stardust characterised the tool as an intermediary pipe carrying data into its own analytics system. "Stardust does not provide RudderStack with any information that can identify the user," a company spokesperson said.
Separately, the review records basic device and usage data going to two marketing partners, AppsFlyer and Facebook, with the Facebook transmission including an ad identifier tied to the test device. That is the mechanism that lets a platform join in-app behaviour to an existing profile.
Mozilla also notes what Stardust does not do. Most of the collection observed ran through analytics and tracking systems rather than through broad device permissions such as location or contacts, and the app does not depend heavily on advertising to monetise.
The in-app browser as a second surface
Two apps scored respectably on their own logging behaviour and then leaked through a webview.
Spot On, built by Planned Parenthood, scored 5 out of 10. Core functions held up: cycle tracking, symptom logging, and birth control reminders stayed inside the app during testing, and no account is required. The problem appeared when the app handed users off to the web.
In the provider-finder flow, the review reports that search details including city and the type of care being sought were consistently sent to AB Tasty, a web analytics and personalisation company. Searches for abortion providers passed two further fields: age, and the date of the last menstrual period. When the app opened the webpage for Roo, Planned Parenthood's sexual health chatbot, roughly half a dozen trackers activated. Google, Microsoft, TikTok, and Pinterestwere among the names observed. The payloads there were largely contextual, covering operating system, page language, and visit timestamp, but they were tied to identifiers for the visit.
Euki, the top scorer at 10 out of 10, hit a milder version of the same issue. Its resource hubs on adoption, abortion, miscarriage, and sexually transmitted diseases open in an in-app browser, and those pages loaded analytics and ad trackers from Google, Meta, and Microsoft. The difference is in the plumbing: Euki's browser assigned a fresh identifier on each visit, so trackers saw a new visitor every time rather than a continuous device history. The review flags one weak point, where entering an email address into a form on those pages could allow a tracker to attach that address to the device. Euki co-founder Ana Ramirez said the product team would examine the issue.
The rest of Euki's design explains the score. There is no account, no cross-device backup, and no social layer. Health information stays on the handset. Optional controls include a PIN lock, scheduled auto-deletion, and a decoy landing page.
Advertising as the business model
Period Calendar, at 6 out of 10, was the only ad-supported app in the set, and the review treats that as structural rather than incidental.
According to the testing, the home screen sends a stream of device details to Google from the moment it loads: phone model, screen dimensions, and timezone, feeding AdMob and DoubleClick, which serve and measure the in-app inventory. Comparable information reached InMobi. Each of those requests named the originating app, and the app is called Period Calendar.
That naming is the point Mozilla presses hardest. No cycle data, symptom log, or contraception choice was observed leaving the app for advertisers. What left was the fact of the app itself, attached to a persistent identifier, which is sufficient for an ad system to file a device under a reproductive health signal. The review reports that Google and Microsoft both received enough to make that connection.
Period Calendar is built by Simple Design Ltd. The review cites a 2022 Vice report finding datasets tied to its users offered on a commercial data marketplace, and a 2025 Privacy International investigation finding data shared with multiple third parties, much of it flowing to Google's advertising and analytics systems. Period Calendar did not respond to a request for comment. Its privacy policy directs users to Google's own ad personalisation settings rather than offering in-app controls.
Flo, and the six-minute gap
Flo carries the heaviest legal history in the category and scored 7 out of 10. The app reports 81 million monthly active users.
Setup presents three agreements, according to the review: processing health data to run the service, the privacy policy and terms, and a separate optional agreement to share basic app and device data with advertising and analytics partners. Saying yes pulled in AppsFlyer, Moloco, and Google's Firebase. Declining made most of those systems disappear from the traffic, which Mozilla describes as the toggle doing what it promised. A Flo spokesperson emphasised that the company does not share health data or detailed screen-by-screen in-app navigation behaviour.
The exception is attribution. AppsFlyer was pinged on first launch whether or not tracking was permitted. Most of what it received was encrypted, but when tracking was denied, the review reports AppsFlyer also receiving the device's IDFV, Apple's vendor-scoped identifier, unhashed and in plaintext.
Flo offers a heightened setting called Anonymous Mode. Once enabled, AppsFlyer traffic stopped for the remainder of the session, and Flo's own traffic began routing through a Cloudflare relay so the company received data without the originating IP address. The catch Mozilla records is timing: the setting was switched on six minutes into the session, and AppsFlyer already held the IDFV.
The legal record behind those design choices is long. A 2019 Wall Street Journal investigation found health apps including Flo sending in-app activity to Facebook through embedded analytics. The Federal Trade Commission brought its case in 2021, settling the same year. The company later agreed to pay 8 million dollars as part of a 2025 case over data flowing through advertising and analytics systems tied to Google and Facebook. "Since 2019, Flo has made significant investments to strengthen its privacy and security program," a Flo spokesperson said.
Clue, the German app, took 8 out of 10. Its internal analytics run on Snowplow, and the review describes symptom values and timestamps being recorded there without reaching outside partners. When Clue sent data to Braze for notifications and in-app messaging, testers observed birth control and fertility details being explicitly withheld from that call. Consent for research, analytics, personalisation, and advertising is handled as separate switches that remain editable after signup. Clue did not respond to a request for comment. The reviewers still found that outside services could tell a device was running Clue, and a 2022 Motherboard investigation cited in the review had found data broker Narrative selling datasets identifying devices with period tracking apps installed, Clue among them.
Privacy policies as a moving target
The Berkman Klein contribution produces the most quantifiable finding in the package: how often these documents change, and in which direction.
Stardust's privacy policy was revised twice in roughly seven months, each revision disclosing more about device and advertising data. As of May 2026, according to the snapshots, it names Meta's and Google's ad measurement tools as partners receiving activity data. Its separate Health Data Privacy Policy has not moved since October 2025.
Flo's document has been rewritten repeatedly. The 2018 version named Facebook Analytics and Google Analytics as recipients. By 2019, both names had gone, replaced with language pledging never to share health data, arriving as the Wall Street Journal reporting broke. After the 2021 FTC settlement came a GDPR-style legal basis table, a named processor list, and a no-sale pledge. By April 2026 the policy named TikTok Ad Manager and Firebase as advertising partners and split off dedicated United States state and consumer health data notices.
Two records held still. Clue's Supplemental Notice for U.S. users and its Consumer Health Data Policy were word-for-word identical to versions captured nearly a year earlier. Euki's Privacy Policy and Consumer Health Data Privacy Policy, both dated to its mid-2024 spinoff from Women Help Women into an independent nonprofit, remained textually identical through June 2026.
The privacy notice covering Spot On is governed by Planned Parenthood Direct's notice rather than a policy of its own, last revised in April 2024. Planned Parenthood did not respond to a request for comment.
Why this lands on media buyers
The findings describe ordinary ad tech components doing ordinary jobs in an extraordinary context. Mobile measurement partners, in-app mediation, product analytics pipelines, and webview tracking are the same building blocks used across every app category. What changes is the inference attached to the bundle ID.
Legal exposure in this specific category is already established. A federal jury in San Francisco found in August 2025 that Meta violated the California Invasion of Privacy Act by collecting menstrual and reproductive health data through Flo's SDK integration, the first jury decision of its kind against a large platform. That case sat alongside a Federal Trade Commission complaint against Flo Health in January 2021 and a class action filed later that month.
Regulators have applied the same logic beyond apps. California secured a 1.55 million dollar settlement with Healthline over continued data sharing with advertisers after opt-out, and fined a data broker 45,000 dollars for reselling lists organised by health condition. The FTC closed its Kochava case with an order restricting sales of sensitive location data. Each of those actions turned on inference from identifiers rather than on explicit medical records.
Platform policy has moved in the same direction. Google tightened sensitive category serving rules across Demand Gen and Discovery in June 2026, restricting advertiser-curated audiences where sensitive signals might be embedded. A federal judge approved the Google real-time bidding settlement in March 2026, forcing a control that strips identifiers from bid requests. The FTC has warned since 2024 that hashed identifiers do not qualify as anonymous.
There is an additional wrinkle in the publisher of this research. Mozilla now sells advertising. Its foundation arm produced these reviews while its corporate side has built out a programmatic business, naming Index Exchange as first U.S. partner in October 2025, adding Equativ as full-stack partner in November 2025, and running privacy-preserving measurement through Anonym. The organisation is arguing that the tracking observed in these six apps is not a technical necessity, and it has a commercial position that depends on that argument holding.
For buyers, the practical read is narrower. Six apps, tested for a combined 22 hours, produced one clean result. The other five showed some form of outbound signal, ranging from a device identifier attached to an app name to logged symptoms travelling through a routing platform. In-app inventory in health-adjacent categories carries an inference risk that placement-level exclusions were never built to describe.
Timeline
- 2018: Flo's privacy policy names Facebook Analytics and Google Analytics as data recipients
- 2019: Wall Street Journal reports health apps including Flo sending in-app activity to Facebook; Flo's policy replaces named recipients with a pledge not to share health data
- January 2021: Federal Trade Commission files a complaint against Flo Health, settled the same year
- 2021: The Markup finds Planned Parenthood's website running more than two dozen ad trackers
- 2022: Washington Post reports Planned Parenthood's website sharing appointment-search details with Google and TikTok
- 2022: Vice reports datasets tied to Period Calendar users offered on a commercial data marketplace
- 2022: Motherboard reports data broker Narrative selling datasets identifying devices with period tracking apps installed
- April 2024: Planned Parenthood Direct's privacy notice, which covers Spot On, is last revised
- Mid-2024: Euki spins out of Women Help Women into an independent nonprofit and publishes its current policies
- July 2024: FTC warns that hashed identifiers are not anonymous
- July 2025: Healthline settles with California for 1.55 million dollars over post-opt-out data sharing
- August 4, 2025: A federal jury finds Meta violated the California Invasion of Privacy Act by collecting health data through Flo
- October 2025: Stardust's Health Data Privacy Policy reaches its current version and stops changing
- 2025: Flo agrees to pay 8 million dollars in a case over data flowing to advertising and analytics systems
- 2025: Privacy International publishes its investigation into Period Calendar's third-party data sharing
- January 2026: California fines a data broker 45,000 dollars for selling health condition lists
- March 2026: A federal judge approves the Google real-time bidding settlement requiring an identifier-stripping control
- April 2026: Flo's privacy policy names TikTok Ad Manager and Firebase as advertising partners
- May 2026: The FTC closes its Kochava case with consent rules covering sensitive location data
- May 2026: Stardust's privacy policy names Meta's and Google's ad measurement tools as recipients of activity data
- June 2026: Google tightens sensitive category serving across Demand Gen and Discovery
- June 2026: Euki's policies remain textually identical to their mid-2024 versions
- July 16, 2026: Mozilla Foundation publishes reviews of six period tracking apps
Related PPC Land coverage
- Jury finds Meta violated privacy law collecting health data covers the August 2025 verdict over reproductive health data collected through Flo's SDK integration, the closest legal precedent to the data flows described in these reviews.
- Google tightens Demand Gen and Discovery ad serving for sensitive categories sets out the restrictions on advertiser-curated audiences where health signals may be embedded.
- FTC closes Kochava location data case with strict consent rules documents the order limiting sales of location data revealing visits to medical facilities.
- California data broker fined 45,000 dollars for selling health condition lists describes enforcement against resale of consumer lists organised by health condition.
- Healthline settles largest CCPA violation case for 1.55 million dollars reports the penalty for continued advertiser data sharing after users opted out.
- FTC warns hashed data not anonymous explains why hashed and pseudonymous identifiers still support identification.
- Judge approves Google RTB settlement forcing new user privacy control covers the court-ordered control stripping identifiers from bid requests.
- Ninth Circuit shuts door on late Google Incognito class damages bid includes the Firebase SDK verdict over data collected after users disabled activity tracking.
- Mozilla Ads selects Index Exchange as first programmatic partner documents the first U.S. supply partnership in Mozilla's advertising business.
- Mozilla Ads partners with Equativ for privacy-first programmatic covers the full-stack partnership across Firefox and MDN Web Docs properties.
- Anonym brings privacy-protected measurement to Pinterest advertisers describes the measurement arm Mozilla acquired and its platform partnerships.
- Apple fined 150 million euros as ATT framework ruled anticompetitive covers the French decision on the consent framework that governs iOS identifier access.
- Starlink users can be tracked and identified using ad data, Israeli firms show illustrates how advertising identifiers travel beyond their intended use.
Summary
Who: The Mozilla Foundation, through its Nothing Personal project and researcher Shoshana Wodinsky, with historical policy analysis from the Transparency Hub at Harvard's Berkman Klein Center and Android testing from the Siebel School of Computing and Data Science at the University of Illinois. The apps examined were Euki, Clue, Flo, Period Calendar, Planned Parenthood's Spot On, and Stardust.
What: Six published privacy reviews scoring each app out of 10, based on manual testing and network analysis. Euki scored 10, Clue 8, Flo 7, Period Calendar 6, Spot On 5, and Stardust 2. Findings include symptom detail and reproductive goals reaching third-party services from Stardust, device identifiers reaching Google ad systems from Period Calendar, search details reaching AB Tasty through Spot On's in-app browser, and an unhashed IDFV reaching AppsFlyer from Flo before Anonymous Mode was enabled.
When: The reviews were published on July 16, 2026, following testing sessions of three to five hours per app and policy snapshot analysis covering documents dating back to 2018.
Where: Testing covered iOS builds with additional Android analysis from the University of Illinois. The apps operate globally, with Clue storing data under European rules and Spot On operating primarily in the United States.
Why: Reproductive health logging carries consequences in the post-Dobbs United States that ordinary app telemetry does not, and the reviews test whether privacy claims in this category match observable network behaviour. For advertising professionals, the findings describe how standard measurement and analytics components turn an app name and a persistent identifier into a health inference without any medical data changing hands.
Discussion