8 ms·
Period tracking app, Flo, found to be selling user data to Meta
- thom-gtdp 5mo ago[flagged]
- sdoering 5mo ago“They had to find a way to make money” is not a moral blank check. By that logic, almost anything becomes defensible. I was out of work, so I became a contract killer. I had to find a way to make money. No. Companies still have to follow the law. They also have the option of being decent and not tracking or sharing intimate data like sexual preferences with Meta, Google, TikTok, and the advertising industry. I’ve been asked as a contractor to build this kind of thing. I refused, before and after GDPR. It cost me money. Fine. I can live with that. What I cannot respect is people who decide that revenue matters more than basic privacy, then hide behind “business needs” as if that ends the conversation.
- duskdozer 5mo ago>By that logic, almost anything becomes defensible. I was out of work, so I became a contract killer. I had to find a way to make money. Ah, see, that doesn't work because you're a person not a company. The company had to find a way to make money, that's why they denied your chemotherapy. Tough luck for you.
- wat10000 5mo agoA better way to put this is: if it’s free, you’re the product.
- rocketvole 5mo agowhere do open source apps fit into this philosophy?
- jumpconc 5mo agoYou're the guinea pig
- duskdozer 5mo agoIf it's not free (like the app Flo Premium), you're still the product.
- Zak 5mo agoI need a way to make money too, but we have laws saying I can't do it by hitting you over the head with a club and taking yours. We also have laws saying Flo can't do it by lying about who they sell private data to. I would advise anyone tracking medical data with an app to use something open source and local-only or network-optional if at all possible. I know there are open source cycle tracking apps, but I do not know if they're any good.
- input_sh 5mo agoIt's not even a free app, there's like a €10/month premium.
- terrut 5mo agoMy apps are free or freemium with a one time payment. I just started publishing, and my main drive is resentment towards the current state of surveillance in software. It doesn't have to be filled with ads and trackers on top of a subscription.
- tasoeur 5mo agoI’ve also started publishing a small collection of what I call “spite apps” (a reference to Larry David’s spite store when he makes his own coffee shop to go against mocha joe). These apps are super simple in terms of privacy policy: - we don’t track you (no telemetry) - we don’t show you ads - no account - free with optional tip Sure I don’t make much money with them but I feel like I’m pushing back on making humanity worse.
- philipallstar 5mo ago> It seems like we can’t just necessarily leave it up to companies – or their ragtag teams of crackpot lawyers rewriting privacy policies every few months – to keep our private data private. It's not a medical requirement from a doctor, so just keep a diary if you want to. Not everything needs to be an app. All the money spent on regulations and regulators to cover increasingly niche opt-in services that are entirely unnecessary is a waste.
- johnny22 5mo agoprivacy legislation would just solve the problem by itself though.
- ceejayoz 5mo agoThey've been thumbing their noses at EU privacy legislation and fines for quite some time already.
- arijun 5mo agoWhat does thumbing their noses mean? They have been paying while continuing their behavior, or not paying at all? The first seems like it could be resolved with an escalating fine schedule, and the second could be mitigated by requiring Apple/Google to remove it from the app store (one of the rare cases walled gardens are on consumers' side).
- ceejayoz 5mo ago> What does thumbing their noses mean? They have been paying while continuing their behavior, or not paying at all? Malicious compliance. For example: https://en.wikipedia.org/wiki/Epic_Games_v._Apple https://en.wikipedia.org/wiki/Epic_Games_v._Apple "While Apple implemented App Store policies to allow developers to link to alternative payment options, the policies still required the developer to provide a 27% revenue share back to Apple, and heavily restricted how they could be shown in apps. Epic filed complaints that these changes violated the ruling, and in April 2025 Rogers found for Epic that Apple had willfully violated her injunction, placing further restrictions on Apple including banning them from collecting revenue shares from non-Apple payment methods or imposing any restrictions on links to such alternative payment options. Though Apple is appealing this latest ruling, they approved the return of Fortnite with its third-party payment system to the App Store in May 2025." Or https://developer.apple.com/support/dma-and-apps-in-the-eu/ https://developer.apple.com/support/dma-and-apps-in-the-eu/ "UPDATE: Previously, Apple announced plans to remove the Home Screen web apps capability in the EU as part of our efforts to comply with the DMA." (This one resulted in enough fuss they backed down.)
- 2OEH8eoCRo0 5mo agoIt's really sad that we have all this technology but we can't trust any of it.
- jumpconc 5mo agoI'll make a period tracker for you for 5 bucks a month. You won't buy it, because it costs 5 bucks a month. So I'll have to find alternative monetisation strategies.
- deltoidmaximus 5mo agoWhy would me giving you 5 bucks a month assure you didn't also sell all of the data from the period tracker app? That's money you'd just be leaving on the table.
- postalrat 5mo agoNobody is going to trust your $5 a month service.
- nemomarx 5mo agoDoesn't flo charge ten dollars a month? https://help.flo.health/hc/en-us/articles/4411278780564-What-is-the-price-for-a-Flo-subscription https://help.flo.health/hc/en-us/articles/4411278780564-What...
- mghackerlady 5mo agowhy does it have to be 5 bucks a month and not a one time purchase?
- GuinansEyebrows 5mo agothere is a third option: don't make one at all if you feel your only recompense involves selling this data. that's what creeps do.
- Schiendelman 5mo agoI think that kind of thinking is similar to the "both sides" stuff in politics. There's a meaningful difference in trustworthiness between different options. For instance, if you need to track your period, the built in iOS apps are secure, especially if you're using advanced icloud encryption.
- moffers 5mo agoI don’t have the right configuration of equipment to use an app like this, but does anyone know why this needs to be a service-driven app? What piece of functionality requires a server to track your health?
- jumpconc 5mo agoThe spying part requires a server. If you use GrapheneOS, you can enable or disable internet access for each app.
- embedding-shape 5mo ago> If you use GrapheneOS, you can enable or disable internet access for each app. Not sure what information you're expecting the app in question to surface if you disable internet access for it.
- antiframe 5mo agoAn error? It's useful to know if/when an app wants to access the Internet. So if an app says it's local only you can disable network permissions. Trust but verify.
- bonoboTP 5mo agoLocally stored info
- ludicrousdispla 5mo agogeo-positioning, maps, way-finding, directions, time of day, calendar, lunar cycle, calculator, notes, language translation, calculator, games, contacts, etc.
- noir_lord 5mo agoMotorola needs to hurry up and release their GrapheneOS devices, I need a new phone soon(TM) (next year or two) and I refuse to give google money to buy hardware to avoid Google.
- childofhedgehog 5mo agoWhy would anyone think that a non-HIPPA compliant app would keep medical information private to the level of security needed for medical data? Flo has definitely breached user trust, but that trust seems misplaced from the get-go.
- john_strinlai 5mo ago>Why would anyone think that a non-HIPPA compliant app would keep medical information private to the level of security needed for medical data? because lots of people dont know what HIPPA is, and (naively to us more familiar with tech) assume that a medical-related app on a curated app store would be safe for medical-related stuff.
- ceejayoz 5mo ago> lots of people dont know what HIPPA is Ironically, it's HIPAA. You're right, though; it's much more limited than people think. During COVID people claimed everything violated HIPAA (masks, vaccine requirements, testing), but it only applies in a very narrow subset of patient/provider relationships.
- FireBeyond 5mo agoVery much so. Also ironically, as a healthcare provider (paramedic), HIPAA expressly allows me to get your healthcare information without your consent (as needed for your care). A lot of facilities have you sign paperwork to explicitly authorize sharing, but that's really just a CYA. "Does the HIPAA Privacy Rule permit doctors, nurses, and other health care providers to share patient health information for treatment purposes without the patient’s authorization? Answer: Yes. The Privacy Rule allows those doctors, nurses, hospitals, laboratory technicians, and other health care providers that are covered entities to use or disclose protected health information, such as X-rays, laboratory and pathology reports, diagnoses, and other medical information for treatment purposes without the patient’s authorization." Source: https://www.hhs.gov/hipaa/for-professionals/faq/481/does-hipaa-permit-doctors-to-share-patient-information-for-treatment-without-authorization/index.html https://www.hhs.gov/hipaa/for-professionals/faq/481/does-hip...
- frankdenbow 5mo agoits crazy to me that Flo is used so widely, as its started by Russian men and their treatment of data has bee public for a while, it just hasnt spread fast enough. I know theres at least one other option called Calessa (http://Calessa.app http://Calessa.app)
- sevenseacat 5mo agoThere's a whole heap of different period tracking apps these days. I've been using Clue for probably a decade.
- culi 5mo agoThat one is good I think. It's German and adheres to EU privacy laws. The main FLOSS one is called drip. Has some funding from the German government as well as Mozilla https://bloodyhealth.gitlab.io/ https://bloodyhealth.gitlab.io/
- aboringusername 5mo agoI don't actually see this as a problem, and instead it's a PSA everyone needs to internalize: If you put data onto a networked device it may be sent to some place else. If you don't want your data being shared: Use a device that does not have any networking capability (both hardware and software wise) Use a pen and paper, you can shred and destroy as you see fit. If you're using an application on a mobile device with mobile data/wifi, the chances are, your data is being uploaded.
- boesboes 5mo agothat is a really fucked up view
- defrost 5mo agoLess a f-u-view, more a f-u-world, the above is pragmatic advice about the actual IRL challenges of keeping data secure. Further, a view that ignores many real world digital data risks faced by those considered to be useful targets; eg: compromised supply chains delivering "pre hacked" hardware with discreet wifi chips or hidden out of band comms, etc.
- dspillett 5mo agoNah. A healthy view when dealing with the fucked up situation that is modern life.
- elsjaako 5mo agoThere are four open source period tracking apps on F-droid. I didn't do a full investigation of the source code, but unless your data is being uploaded outside the app (e.g. for backups), I feel safe assuming it will stay local only.
- reorder9695 5mo agoIt sounds like the real solution to this is to be able to control permissions at an OS level for network per app, as you would be able to do if you had root access. I have no idea why regular Android distros don't allow you to do this, it seems like a really sensible thing to expose in app settings given the permissions model of Android.
- ronbenton 5mo agoHey surely Meta wouldn’t send that data to a government interested in regulating women’s reproductive rights
- juggina 5mo ago[flagged]
- forgotaccount3 5mo agoPeople in power want the information to identify a narrower set of people who may have been pregnant and then did not have a child and so may have had an abortion. And facebook doesn't care about people's rights when those people in power are able to block Facebook from acquiring some new startup they want to buy, so facebook is willing to share the information.
- euroderf 5mo agoHandmaids, assemble! Gilead is in your device.
- lagniappe 5mo agoAre we assuming the lack of a recorded period is the criteria? If yes, what if you just forgot to add it that month, or have hormonal issues, or abnormal BMI?
- pavel_lishin 5mo agoYou're welcome to suggest to your lawyer this particular defense. The people prosecuting women for abortions aren't looking for reasons not to arrest and prosecute them.
- joe_mamba 5mo ago>The people prosecuting women for abortions aren't looking for reasons not to arrest and prosecute them. Who are these people doing this?
- arkwin 5mo agoNow is a good time to bring up. https://bloodyhealth.gitlab.io https://bloodyhealth.gitlab.io A secure open source period tracking app.
- DauntingPear7 5mo agoA nontrivial issue is how the app looks, unfortunately
- jeffbee 5mo agoDoes anyone happen to know if Meta and Google have ever recovered these judgements from the app developers? All of the industry terms of service specifically forbid SDK licensees from sending sensitive personal data to the platforms, and they require the licensee to indemnify the platform against any judgement that arises from violating those terms. See Meta's statement on this verdict, which seems pretty reasonable to me. This 100% looks like the fault of the app developer: “User privacy is important to Meta, which is why we do not want health or other sensitive information and why our terms prohibit developers from sending any.” Meta maintains that any transmission of sensitive health data is due to a failure to comply with its terms of use.
- ozlikethewizard 5mo agoI mean this seems like an attempt at a get out of jail free card. If meta didnt want this info, why are they accepting and processing it?
- jeffbee 5mo agoIt's just a generic key-value API.
- ndriscoll 5mo agoThat doesn't answer the question. It just restates the problem. Why aren't they doing diligence on what they're accepting from their business partners, or what types of partners they're working with? There's no reason they couldn't know the company deals with health data and place it under additional scrutiny.
- WarcrimeActual 5mo ago[flagged]
- dspillett 5mo agoThat ridiculous bit of “modern” slang… that has been in use for a few hundred years? Not a word I use much myself except when referring to “yappy little dogs”, but it is definitely common among those the generation above me and that above them.
- WarcrimeActual 5mo agoI think it's pretty obvious that it's being used differently here. And in a way that is annoying enough to me to guarantee that I don't make it past that word.
- dspillett 5mo ago> I think it's pretty obvious that it's being used differently here. How differently? Please describe the obviousness I am missing, oh enlightened linguist: Yapping: present participle of yap Yap [verb, informal, often indicates a disapproving tone]: to talk continuously Example: “I've just had my mother on the phone, yapping away for half an hour!” > And in a way that is annoying enough to me to guarantee that I don't make it past that word [makes mental note to increase use of the word “yapping” in future writing…]
- rocketpastsix 5mo agoseriously? a single word is going to prevent you from reading an article that is well informed and well articulated?
- WarcrimeActual 5mo agoYes. I'm not saying it's how it should work. But it is how it does.
- mghackerlady 5mo agoI don't have a period, so I'm not the best person to do it, but there really needs to be a solid FOSS alternative to flo. If GNU had more women, it'd probably already exist
- xorvoid 5mo agoI don't know how many more examples people need to see of big tech not respecting privacy... it's just becoming a farce now. Big tech tracking woman's cycles? Of course they are. (sigh) If this doesn't gross people out enough to seriously pursue alternatives, I literally don't know what will.
- TFNA 5mo agoA comparable FOSS app called Drip has been on F-Droid since forever.
- xzjis 5mo agoDrip has a paradoxical flaw: by trying to be extremely inclusive and making a "gender-neutral" app (without the colour pink) to include trans people, it discourages some people from using it. At least, my friend told me she thought the design was ugly and was looking for a "cute" app, so she ended up using Flo instead of Drip despite my many warnings. I think FLOSS apps often forget that not everyone is a developer or a nerd who prioritizes privacy and ethics over design, which is a real problem since people end up using proprietary apps that data-mine them.
- embedding-shape 5mo agoThat sounds not so much as a flaw, as a conscious product decision. And to be honest, doesn't sound like a bad one, not every app needs to work or look the same way, as long as people have choices, they can be responsible for the choices they make. If someone wants a safer but boring app or if someone wants a cute "who gives a fuck about privacy" app, both should be fine.
- 5mo ago
- deleted 5mo ago[deleted]
- theptip 5mo agoThis one seems clear cut as a HIPAA violation. Glad to hear that interpretation was upheld. However, regardless, we really need to just kill the data broker business model. Speaking as someone who implemented GDPR for my startup when the law first came into effect, there were certainly rough edges. But the core premise that you simply cannot sell user data to sub-processors without consent is a powerful one that I believe would fix a lot of broken things in the US system. (Not least because the USG buys private data that would be unconstitutional for it to directly collect, but also things like the incentives for your cell phone provider to sell your location data to advertisers.)
- Cider9986 5mo agoHIPAA makes our medical privacy worse, unfortunately. Same video, different platforms: (https://odysee.com/@NaomiBrockwell:4/HIPAA:7 https://odysee.com/@NaomiBrockwell:4/HIPAA:7) (https://invidious.nerdvpn.de/watch?v=4sfIBRTcRpU https://invidious.nerdvpn.de/watch?v=4sfIBRTcRpU) (https://youtube.com/watch?v=4sfIBRTcRpU https://youtube.com/watch?v=4sfIBRTcRpU)
- culi 5mo agoGreat video, thanks for sharing. TL;DW: HIPAA was actually created to allow insurance companies to share patient data without having to get patient consent. Before HIPAA, data was more fractured and less commonly shared. The only privacy protections it offers is, e.g., your doctor not giving your data to your boss. But about 1.5 million private entities can legally access your data (everything from health startups to insurance companies to hospitals)
- FireBeyond 5mo ago> But about 1.5 million private entities can legally access your data Somewhat. They are allowed to access it "for treatment purposes", not just to nose around out of curiosity. I found myself explaining this to a number of my patients (I used to be a paramedic) who were irate about disclosures they'd made to their therapist, doctor, etc., that they had said they didn't want revealed to other providers (but were actually germane to their care). "Does the HIPAA Privacy Rule permit doctors, nurses, and other health care providers to share patient health information for treatment purposes without the patient’s authorization? Answer: Yes. The Privacy Rule allows those doctors, nurses, hospitals, laboratory technicians, and other health care providers that are covered entities to use or disclose protected health information, such as X-rays, laboratory and pathology reports, diagnoses, and other medical information for treatment purposes without the patient’s authorization." https://www.hhs.gov/hipaa/for-professionals/faq/481/does-hipaa-permit-doctors-to-share-patient-information-for-treatment-without-authorization/index.html https://www.hhs.gov/hipaa/for-professionals/faq/481/does-hip...
- culi 5mo ago[drip.](https://bloodyhealth.gitlab.io/ https://bloodyhealth.gitlab.io/) [source](https://gitlab.com/bloodyhealth/drip https://gitlab.com/bloodyhealth/drip) - around since 2019. Last update 2 months ago - iOS, Android - React Native Mensinator [source](https://github.com/EmmaTellblom/Mensinator https://github.com/EmmaTellblom/Mensinator) - around since 2024. Last update 2 weeks ago - Android - Kotlin [Menstrudel](https://menstrudel.app/ https://menstrudel.app/) [source](https://github.com/J-shw/Menstrudel https://github.com/J-shw/Menstrudel) - around since 2015. Last updated 3 weeks ago. - iOS and Android - Dart [Tyd](https://unobserved.io/tyd/ https://unobserved.io/tyd/) [source](https://github.com/unobserved-io/tyd https://github.com/unobserved-io/tyd) - around since 2023. Last updated 2 years ago. - iOS - Swift EDIT: Someone else pointed out this closed-source alternative that got a 92% by ORCHA: https://www.my28x.com/ https://www.my28x.com/ I think the biggest thing I'd like to see is a data format standard defined. You should be able to "take your data with you" and go anywhere you like. If you decide an app is unethical or if your favorite OSS app stops being updated, it should be simple to switch. Many apps let you export your data. Maybe someone can make a converter between popular proprietary apps and a common data structure spec
- culi 5mo agoOops I meant to write that Menstrude has been around since 2025 not 2015
- josefritzishere 5mo agoThat's incredibly creepy.
- pascal-maker 5mo agoAt this point, if you don't trust that they share your data with third parties with the AI tools available and open-source LLMs, just vibe-code your own health apps and keep them stored on a Mac mini or something else for the female devs here.
- DauntingPear7 5mo agoI will say, with codex/cc access and a free weekend you could make an app that covers like 99% of this app’s purpose. The harder part would be the art/making it cutesy, as some other commenters have pointed out. Plain SwiftUI or compose just isn’t eye catching enough
- freediddy 5mo agoMeta only cares about ad revenue so could they be researching or have discovered a link between buying trends and links to a woman's cycle?
- OJFord 5mo agoAre you joking? There's loads of trivial links. Most obviously: it's stopped (pregnancy, menopause) and therefore so too will stop purchases of certain 'female hygiene products'.
- phoronixrly 5mo agoAnd will be targeted by an avalanche of childbirth-related ads... Isn't this an old story now? We've already seen this happening even before evidence of women's health data being sold to ad companies...
- OJFord 5mo agoI think even Flo's behaviour is not news, but it is worth distinguishing I think between more organic and generic targeting behaviour based on say searches for health advice or other products, and selling 'first-class' health data as it were which is a much stronger signal and feels more personal.
- BoneShard 5mo agoa very old story - https://www.forbes.com/sites/kashmirhill/2012/02/16/how-target-figured-out-a-teen-girl-was-pregnant-before-her-father-did/ https://www.forbes.com/sites/kashmirhill/2012/02/16/how-targ...
- throwaway81523 5mo ago> Meta only cares about ad revenue I can't accept that premise. They'll take any revenue they can get, including reselling that same data to Palantir or to RFK Jr's health department. Did you skip several periods and then suddenly start having them again? Sounds like you've had an illegal abortion. SWAT raid on your home, incoming. And so on.
- gowld 5mo agoThis article is about a lawsuit filed in 2021. https://www.labaton.com/cases/frasco-v-flo-health-inc https://www.labaton.com/cases/frasco-v-flo-health-inc
- deferredgrant 5mo ago[flagged]
- Cider9986 5mo agoPrivacyguides has some recs for private health apps (https://www.privacyguides.org/en/health-and-wellness/#menstrual-cycle-tracking https://www.privacyguides.org/en/health-and-wellness/#menstr...)
- everdrive 5mo agoIf the app could make another $0.05 selling your location to kidnapping gangs, they'd do it. There's no such thing as an app that cares about your privacy or your interests.
- lrvick 5mo agoThere is such a thing. FOSS.
- sigmoid10 5mo agoUnfortunately, companies like Apple (and soon Google as well) are making this unnecessarily hard in their phone ecosystems.
- lrvick 5mo agoIt is actually a perfectly practical choice to completely ignore those ecosystems. I am the founder and active engineer at two companies and two large open source projects and have a family, travel a lot, and have an active social life in Silicon Valley. I also do not use any Apple, Google, Meta, or Microsoft products and exclusively use open source software for all of my work. It turns out none of this is incompatible, everyone just convinces themselves it is.
- brokenmachine 5mo agoDo you have only a dumb phone?
- lrvick 5mo agoI do own android devices for development and testing, but I do not have a cell phone plan and I do not carry any electronics when leaving home unless my explicit goal is working away from home, in which case I bring a laptop.
- sundarurfriend 5mo ago
- ncr100 5mo agoYikes - selling "When did I last Orgasm" to Mark Zuckerberg's team seems like an undesirable "leak" of information. .. To be clear, "wired app to standard ad-tech surveillance plumbing, sending concepts like user logged period and pregnancy mode entered, through its pipes, to improve ad revenues through Meta's targeting platform" .. ad-events .. this is the kind of behavior that happened, in plain-ish speaking terms, per what I read in my non-expert capacity. Q: (answered) Now I want to know who runs (ran?) Flo - can we find their Board of Directors & C-level people on LinkedIn to profile what kind of industries lead to this kind of (I believe) privacy violating behaviors? It's a biased question on my part, as Correlation is not Causality! Onwards .. My limited, biased, AI-driven research suggests the violating behavior ran from June 2016 through February 2019, and that generally the Company was designed to be consumer-app with subscriptions and is healthcare-adjacent, targeting an unregulated non-HIPPA market. - INVESTORS = consumer subscription apps with ad-driven growth loops - BUSINESS MODEL = (1) free or freemium consumer apps where (2) growth depends on paid acquisition through Meta/Google/TikTok ad platforms, which (3) requires sending conversion events back to those platforms to optimize ad spend, and (4) the SDKs that do this are designed by ad networks to hoover up everything by default. - EXECUTIVE = * No Privacy / Data Protection C-level officers during violating period
- rdevilla 5mo agoI don't really give a shit at this point. In Toronto it's legal to even record into your condo neighbor's unit 24/7 and livestream your recording to the Internet, unbeknownst to the inhabitants. It has been demonstrated that nobody will enforce anything. At this point I am a privacy nihilist, and I expect all information about anyone to be exploited all the time. Everyone should do the same.
- derwiki 5mo agoI live in America so I can’t speak to Canadian laws, but what you’re describing is the same in the States. If you are in public, or can be seen by someone who is in public, you do not have a reasonable expectation of privacy. It’s how paparazzi work.
- malfist 5mo agoApathy is a poor response to this. Especially when you tell others to also be apathetic
- msarrel 5mo agoHaven't we known this for years? There's been thorough documentation of the violation of privacy in period tracking apps as far back as 2021. It's even been written about when it comes to Meta. Meta ‘eavesdropping’ on Flo exposes how period apps are a data… | TBIJ https://share.google/qYTopS5goSKE0Dyna https://share.google/qYTopS5goSKE0Dyna
- 2OEH8eoCRo0 5mo agohttps://www.plannedparenthooddirect.org/spot-on-period-tracker https://www.plannedparenthooddirect.org/spot-on-period-track...
- TZubiri 5mo ago"Flo, through the Flo App, unlawfully shared users’ sensitive health data – including menstrual cycle, ovulation, and pregnancy-related information – with third parties such as Meta, Google, and Flurry for their own commercial us" If the app sold the data to Meta through extremely automated Meta platforms. Doesn't the bulk of legal liability and social backlash lie on the app instead of on Meta? Like sure if a company is caught buying stolen goods, maybe they could tighten up due diligence, but the actual thief is the main culprit.
- fragmede 5mo agoPeriod tracking is a perfect use case for homomorphic encryption, so there's a server that holds the data and can operate on it, without knowing the data itself.