1 min readfrom TechCrunch

Period tracker Stardust shares users’ health data with analytics firm, says Mozilla research

Our take

Mozilla’s recent research highlights a critical disparity in period tracker app privacy. While one tested app, Stardust, demonstrated responsible data handling, another revealed concerning practices. Specifically, Stardust shares user health data with an analytics firm, raising significant privacy concerns. This underscores the urgent need for users to critically evaluate the privacy policies of these apps, as vast differences exist in how sensitive health information is managed and protected. Prioritize apps committed to transparent and secure data practices.
Period tracker Stardust shares users’ health data with analytics firm, says Mozilla research

## The Uneven Landscape of Period Tracking Privacy: Why This Matters

The recent Mozilla research highlighting significant discrepancies in user privacy among period tracker apps – with one deemed "squeaky clean" and another sharing data with an analytics firm – serves as a stark reminder of the inherent risks in entrusting sensitive health information to mobile applications. This isn't simply about a single app’s questionable practices; it’s indicative of a much larger problem within the burgeoning digital health space, where user data is frequently treated as a commodity rather than a protected asset. The sheer volume of personal data collected by these apps – menstrual cycles, ovulation predictions, mood tracking, sexual activity – paints an incredibly intimate portrait of a user’s life. To then learn that this information is potentially being shared with third-party analytics companies, often without explicit and fully transparent consent, is deeply concerning. This echoes broader concerns about data privacy in the health tech sector, as detailed in The Markup’s investigation into fertility apps, and highlights the need for greater regulatory oversight and user awareness. Furthermore, the normalization of data sharing practices, even under seemingly benign terms and conditions, can lead to unforeseen consequences, particularly as AI algorithms become more sophisticated and capable of drawing inferences from seemingly unrelated data points.

The fact that such a wide gulf exists between privacy practices within this category underscores the lack of consistent standards and enforcement. While some developers prioritize user privacy and implement robust security measures, others appear to prioritize monetization through data sharing, often relying on vague or misleading privacy policies to obscure their practices. The Mozilla report’s findings are particularly impactful considering the increasing legal and social scrutiny of reproductive health data, especially in light of recent legislative changes in the United States. Period tracking apps have become essential tools for many individuals managing their reproductive health, and the potential for this data to be misused or accessed by those seeking to restrict abortion access is a very real and alarming possibility. As explored in a recent Wired article on the risks to period tracking apps, the information collected by these apps, even when anonymized, could be used to infer reproductive intentions or track menstrual cycles, potentially jeopardizing user safety and privacy. The divergence in practices also highlights the limitations of relying solely on app store reviews and developer claims to assess privacy risks; independent research and advocacy groups like Mozilla are crucial in holding companies accountable.

Beyond the immediate privacy concerns, this situation raises fundamental questions about the business models underpinning many digital health applications. The reliance on data monetization as a primary revenue stream creates an inherent conflict of interest between the app developer’s financial incentives and the user’s right to privacy. A more sustainable and ethical approach would involve exploring alternative revenue models, such as subscription fees, premium features, or partnerships with healthcare providers, that do not require compromising user data. The increasing prevalence of AI-native spreadsheet tools, capable of handling sensitive health data securely and privately, offers a potential alternative. These tools can empower users to retain control over their data while still benefiting from advanced analytics and insights, effectively shifting the paradigm from data exploitation to user empowerment. Companies building these solutions have a responsibility to prioritize data security and transparency, establishing a new standard for privacy in the digital health space, as discussed in this article from TechCrunch about data privacy and AI.

Ultimately, the Mozilla report serves as a critical wake-up call for both users and regulators. Individuals need to be more vigilant about the privacy policies and data sharing practices of the apps they use, seeking out alternatives that prioritize user privacy and data security. Regulators, on the other hand, need to establish clear and enforceable standards for data privacy in the digital health sector, ensuring that sensitive health information is protected from misuse and exploitation. The question moving forward is whether the industry will proactively embrace a more ethical and privacy-centric approach, or whether it will require significant regulatory intervention to safeguard user rights and foster trust in the digital health ecosystem.

One period tracker app tested by Mozilla was 'squeaky clean,' while another app was seen sharing users' health data with an analytics company, underscoring vast differences in user privacy among these apps.

Read on the original site

Open the publisher's page for the full experience

View original article