The advice going around this week is blunt: if you live in one of 13 US states, delete your period tracking app. It is well intentioned, it is getting a lot of shares, and it is incomplete in a way that matters.
Dragging an icon to the trash removes the software from your phone. It does not touch the copy of your data sitting on a company server, and it does not claw back anything that was already sold, shared or syndicated to a third party. If the goal is to reduce exposure, the uninstall is the last step, not the first.
The short version
- What triggered it: renewed warnings aimed at women in the 13 states with the strictest abortion laws
- The research: a University of Cambridge Minderoo Centre report calling cycle tracking data a “gold mine” for advertisers
- The gap: uninstalling an app does not delete your account or the server side records
- The better fix: delete the account through the app or the company’s privacy portal, then uninstall
- The safest apps: the ones that never upload anything, because there is nothing on a server to request or subpoena
Why 13 states, and why now
On June 24, 2022, the Supreme Court ruled 6 to 3 in Dobbs v Jackson Women’s Health Organization, overturning Roe v Wade and handing abortion regulation back to individual states. Four years on, the states with the most restrictive laws are the ones where privacy advocates argue that intimate health data carries the most legal risk.
The 13 states named in the current warnings
Worth being precise about what has and has not happened. There is no publicly documented case of a US prosecutor building a case primarily on data pulled from a menstrual tracking app. The concern is structural rather than retrospective. The data exists, it is commercially valuable, it is held by private companies, and in the United States it generally does not receive the heightened legal protection it gets in Europe.
What these apps actually know about you
A cycle tracker is not a calendar with a nicer interface. The category collects some of the most sensitive material any consumer app touches, and users tend to be extremely honest with it, because inaccurate entries make the predictions useless.
The University of Cambridge’s Minderoo Centre for Technology and Democracy examined the business model behind these apps and concluded that “the financial worth of this data is vastly underestimated by users who supply profit driven companies with highly intimate details in a market lacking in regulation.”
From the lead researcher
“Menstrual cycle tracking apps are presented as empowering women and addressing the gender health gap. Yet the business model behind their services rests on commercial use, selling user data and insights to third parties for profit.”
“There are real and frightening privacy and safety risks to women as a result of the commodification of the data collected by cycle tracking app companies.”
Dr Stefanie Felsberger, Minderoo Centre for Technology and Democracy, University of Cambridge
The report lists the downstream risks in order of likelihood, and prosecution is not at the top of it. Job prospects, workplace monitoring, health insurance discrimination and cyberstalking all rank as more probable outcomes of intimate health data circulating through the ad ecosystem.
How the data travels
Most people picture a single company holding a single database. The real path is longer, and every hop makes the data harder to recall.
This is the same broker economy that quietly assembles profiles from loyalty cards, location pings and app telemetry. If the idea of that pipeline is new to you, our writeup on what a data broker removal service actually does is a decent primer on how far the resale chain runs.
What the app companies say
Not every developer in this category behaves the same way, and it is worth reading the specific commitments rather than the category reputation.
Clue, which is based in Berlin and therefore falls under GDPR, has been the most explicit. Co-CEOs Carrie Walter and Audrey Tsang published a statement promising users that “we will never turn your private health data over to any authority that could use it against you,” adding that data on pregnancies, pregnancy loss or abortion “is kept private and safe. We don’t sell it, we don’t share it for anyone else’s use, we won’t disclose it.”
That distinction matters more than it sounds. In the UK and EU, menstrual data is classified as special category data, the same tier as genetic and ethnic information, and carries heavier legal safeguards. The US has no federal equivalent. HIPAA covers your doctor, not the app on your phone.
Flo, the largest app in the category, settled with the Federal Trade Commission in 2021 over allegations it shared user data with third parties despite promising otherwise. It has since introduced an Anonymous Mode that lets users detach their identity from their records. Treat that as an improvement rather than a guarantee.
Which apps actually keep data off the network
The only architecture that removes the risk entirely is one where the data never leaves your device. No account, no server, no sync, nothing to hand over.
| App | Where data lives | Account needed | Notes |
|---|---|---|---|
| Euki | On device only | No | Scored a perfect 10 in Mozilla’s 2026 privacy testing. Reviewers noted there is almost nothing to leak. |
| Drip | On device only | No | Open source, no trackers, no ads. |
| Periodical | On device only | No | Minimal Android app, available through open source repositories. |
| Clue | Company servers, EU based | Yes | Governed by GDPR, explicit public commitment against disclosure. |
| Flo | Company servers | Yes | Anonymous Mode available. FTC settlement in 2021 over third party sharing. |
| Paper calendar | Your kitchen drawer | No | Still undefeated. No predictions, no reminders, no subpoena surface. |
The tradeoff with local only apps is real and worth stating. If you lose your phone without a backup, the history is gone. Some people will decide that is a fair price. Others will not, and that is a legitimate choice rather than a failure of caution.
How to actually remove your data
If you decide to leave a cloud based tracker, order of operations matters. Do this before you uninstall anything.
The sequence that actually works
- Export anything you want to keep first. Most apps offer a data export in settings. Once deletion goes through, it is final.
- Delete the account, not just the data. Look for “delete account” rather than “clear history.” Clearing history often only wipes the local cache.
- Send a written deletion request. Email the company’s privacy address citing your state law if you have one. California, Colorado, Connecticut, Virginia and Washington all give residents a deletion right, and Washington’s My Health My Data Act is specifically written for this kind of information.
- Wait for written confirmation. Companies typically have 30 to 45 days to respond depending on the statute.
- Then uninstall. Uninstalling first can lock you out of the account tools you need for steps 2 through 4.
- Reset your advertising ID. On Android, Settings then Privacy then Ads. On iPhone, Settings then Privacy and Security then Tracking. This breaks the link between old ad profiles and your device going forward.
The uncomfortable part
Cycle apps are the visible target, which makes them a satisfying thing to delete. They are also nowhere near the largest source of inference about someone’s reproductive health.
Search queries, browser history, location data showing repeat visits to a clinic, pharmacy loyalty records, text messages and payment history all sit in the same commercial ecosystem, mostly with weaker attention and looser handling. A person who deletes their period app and keeps everything else untouched has narrowed the exposure by a slice.
The tools that move the needle across all of it are the boring ones. Content blockers that cut third party tracking, which is exactly what makes Chrome’s removal of the last real ad blockers such a bad development for anyone thinking about this seriously. Encrypted messaging. Location permissions set to “while using” instead of “always.” A browser that is not owned by an advertising company.
Legislative movement has been slower than the technology, though the pattern from this year suggests lawmakers are finally treating app data as a category worth writing rules about, which is roughly the same energy behind the recent congressional push on AI chatbots and children’s data. Whether any of it produces a federal health data standard is another question.
The practical bottom line
- If you want the convenience: use a local only app like Euki, Drip or Periodical. Nothing leaves the phone, so nothing can be requested from a server.
- If you want cloud sync: pick a company subject to GDPR and read its published stance on law enforcement requests.
- If you are leaving an app: delete the account and file a written deletion request before you uninstall.
- If you are worried in general: the app is one input among many. Treat browser, location and payment data as part of the same problem.
The instinct behind “just delete it” is sound. The execution is where most people leave their data exactly where it was.

