privacydeep-dive

Fertility Apps Collect Your Most Sensitive Data. Most of It Isn't Protected.

HIPAA doesn't cover fertility apps, the FTC has already acted on one for sharing data without consent, and data brokers want this information. Here's what's at stake.

Fertility tracking apps collect some of the most intimate data that exists about a person. Menstrual cycle timing, sexual activity, ovulation predictions, pregnancy attempts, IVF treatment schedules, pregnancy loss. This information goes to the heart of someone’s reproductive health, family plans, and medical situation.

There is a widespread belief that health data is protected. In the United States, many people associate that protection with HIPAA — the Health Insurance Portability and Accountability Act. That belief is wrong for fertility apps, and the consequences of that misunderstanding are serious.

HIPAA applies to covered entities: hospitals, clinics, health insurance companies, and their business associates. It does not apply to consumer health apps. The Glow fertility tracker, Premom, Flo, Clue, Natural Cycles — none of them are covered by HIPAA. They are governed, where they are governed at all, by their own privacy policies and by consumer protection law.

That gap matters enormously.


The Premom Enforcement Action

In 2023, the Federal Trade Commission took action against Easy Healthcare Corporation, the maker of Premom — a fertility tracking app that had millions of users. The FTC found that Premom had shared sensitive reproductive health data, including pregnancy status, with advertising firms and with Google, without user consent.

The sharing violated Premom’s own privacy promises. The company had told users their data would not be shared with third parties in ways they had not agreed to. It shared it anyway — specifically to enable targeting for advertising purposes.

The FTC settlement required Easy Healthcare to stop the unauthorized sharing, pay a fine, and implement a data deletion program. It was a meaningful enforcement action. But it also illustrated the fundamental problem: enforcement comes after the data has already been shared, with parties who may have retained, processed, or onward-shared it in the intervening period.

Knowing that the FTC might eventually catch a violating app does not help you once your reproductive health data has entered an advertising ecosystem.


What Data Brokers Want With This Information

Data brokers — companies that aggregate personal information and sell it — have a specific interest in reproductive health data. The reasons are economic: this data is useful for marketers (baby product companies, fertility clinics, adoption agencies), for insurance underwriters, and for employers who might make coverage decisions based on anticipated health costs.

Epic’s research has documented cases where location data brokers received data from pregnancy-related apps. Once that data reaches a broker, it can be aggregated with other data points — income, address history, shopping behavior, social media activity — to build a profile that is far more detailed than what you shared with the original app.

The broker does not know you personally. They know a demographic profile that includes your reproductive status, derived from the app you used to track your health.

In 2022, the US Supreme Court’s Dobbs decision eliminated federal constitutional protections for abortion access, and enforcement shifted to state law. In states with criminal or civil penalties related to reproductive healthcare, this data takes on an additional dimension: it could be subpoenaed, purchased by investigators, or used to infer behavior that is legal in one state and subject to prosecution in another.

Legal scholars and privacy researchers have raised this concern directly. Fertility app data, which might show cycle irregularities, missed periods, or a sudden stop in cycle tracking, could in some legal interpretations constitute circumstantial evidence about reproductive decisions. The EPIC and EFF have both published analyses on this point.


The “Health Data” Illusion

Many fertility apps use health-adjacent branding: clinical-looking interfaces, doctor partnerships, integration with Apple Health or Google Fit. This aesthetic creates a sense of medical legitimacy.

It is largely illusory from a privacy standpoint.

Apple Health and Google Fit store data on-device (or encrypted in iCloud / Google account) and give you control over what apps can access. But the fertility app itself — once it has received data through that integration — operates under its own privacy policy, not Apple’s or Google’s. The data leaves the health framework and enters the app’s commercial framework.

Some apps have improved significantly in recent years. Flo, under FTC scrutiny, updated its policy to commit to not sharing identifiable health data for advertising. Natural Cycles, which is FDA-cleared as a contraceptive method, operates under different regulatory obligations. The landscape is not uniformly bad.

But “better than the worst case” is not the same as “protected.” Even well-intentioned apps face acquisition risk, policy change risk, and data breach risk. The structural problem — that HIPAA does not cover these apps — remains.


What Your Fertility App Actually Stores

The data collected by a typical fertility tracking app includes:

  • Cycle data: Period start/end dates, flow intensity, spotting
  • Physical symptoms: Cramps, headaches, mood, energy levels
  • Sexual activity: Frequency, protection method used
  • Ovulation data: Basal body temperature, LH test results, cervical mucus observations
  • Pregnancy tracking: Conception attempts, positive pregnancy tests, pregnancy progression
  • Medical context: Diagnoses like PCOS or endometriosis, fertility treatment schedules

Many apps also collect or request:

  • Location data
  • Device identifiers
  • IP address
  • App usage patterns (which features you use, how often)

That last category — behavioral and device data — is often less appreciated. Even if the app committed never to share your period data, usage metadata can itself be revelatory. Someone who opens a fertility app daily for several months, then stops opening it for nine months, has told the app something significant through behavior alone.


What “Account Deletion” Actually Means

A common response to data privacy concerns is: “I’ll just delete the account.” This is harder than it sounds.

Data deletion in consumer apps is inconsistently implemented. Some apps delete account data from their active systems but retain it in backups for months or years. Some delete your data but have already shared it with third parties who are not obligated to delete their copies. Some comply with CCPA deletion requests (if you are in California) but treat users in other states differently.

Before relying on deletion as a safeguard:

  • Check whether the app offers a verifiable deletion request (not just account deactivation)
  • Review the privacy policy for retention schedules — look for language like “we may retain data in backups for up to X days/months”
  • If you are in a GDPR jurisdiction, you have a right to erasure that carries legal weight — send a formal deletion request referencing Article 17
  • For US users outside California, deletion rights depend on the app’s voluntary policy

In most cases, you cannot be certain that deletion is complete.


Practical Steps to Limit Your Exposure

You may use a fertility app because it is genuinely useful. The goal is not to abandon that utility, but to be deliberate about what you share and where.

Before you enter data:

  • Read the privacy policy, specifically for: data sharing with third parties, advertising use, AI training language, and what happens to data if the company is acquired
  • Look for explicit commitments against selling reproductive health data
  • Check the app’s data minimization practices — do they ask for more than they need?

While using the app:

  • Disable location access unless there is a clear functional reason for it
  • Review which third-party integrations (advertising SDKs, analytics tools) are mentioned in the policy
  • Consider using a device-level approach: some trackers allow local-only storage with no cloud sync

For your most sensitive records:

The specific data points your fertility journey generates — test results, appointment notes, treatment schedules, correspondence with providers — should live somewhere with a clear, unconditional privacy commitment.

Storing these records in a private file app, rather than embedded in a consumer health platform with advertising relationships, is a meaningful separation. The distinction between “a product designed to help you” and “a product designed to help advertisers learn about you” is not always visible in the UI.


The Specific Risk of AI Training on Reproductive Data

Several fertility apps have introduced AI-powered features: predicted fertile windows, cycle anomaly detection, personalized health insights. These features require training data, and the training data is users’ reproductive health records.

Most apps are not transparent about whether the AI they use is trained on identifiable user data, anonymized user data, or fully external datasets. Some have explicit policies; most do not.

The EU AI Act (enforcement began mid-2026) categorizes certain health AI applications as high-risk and subjects them to additional transparency requirements. Apps operating in the EU will increasingly need to disclose how their AI systems use personal health data. Apps operating only in the US face no equivalent requirement as of now, though the New York AI Training Data Transparency Act (passed in 2026) begins to move in that direction.


What Better Looks Like

There is no fertility tracking app that is perfectly private in the sense of offering zero risk. But meaningful differences exist between apps that treat user data as an asset to be monetized and those that treat it as information held in trust.

Markers of better practice:

  • Explicit prohibition on selling reproductive health data, not just “we do not currently sell data”
  • Clear data retention limits with verifiable deletion on request
  • No advertising SDK integrations (you can check this with tools like Exodus Privacy)
  • Transparency about AI training: whether, on what, under what anonymization conditions
  • GDPR compliance as a baseline, applied globally rather than only to EU users

The record you keep of your own reproductive health deserves the same care as any other sensitive personal file. Choosing where to keep it should be deliberate — not defaulted to whichever app was top of the App Store the day you started tracking.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts