The Most Private Period Tracker: What Actually Protects You
Most privacy claims are promises. A few are architecture. This is how to tell which one you are being offered — and the seven questions that separate them.
The most private period tracker is the one that never holds your data in the first place. An app that keeps everything on your device, needs no account and makes no network request containing your cycle cannot leak it, sell it, or be made to hand it over — not because the company is trustworthy, but because there is nothing anywhere to give. Every other kind of privacy claim is a promise about future behaviour, and promises depend on the company staying the same company.
That distinction — between a promise and an architecture — is the whole of this article. Everything below is either evidence that the distinction matters, or a way of telling which one you are being offered.
What a period app can see about you
A cycle tracker holds an unusually complete picture of a life. Not just dates: bleeding, pain, mood, sex, contraception, medication, sleep, weight, whether you are trying to conceive, whether you stopped. Enough to infer a pregnancy, a loss, a diagnosis or a relationship, often before the people around you know. It is one of the most sensitive datasets an ordinary person keeps, and most of us hand it over in a sign-up flow.
Whether that is a problem depends entirely on where it goes next. There are three architectures in this market, and they are not close to equivalent:
- On your device only. The app writes to a database on the phone. No account, no sync, no server. There is nothing to breach, nothing to sell, nothing to subpoena, and nothing to inherit if the company is bought.
- On your device, backed up to the cloud. A copy exists on somebody's servers, usually encrypted at rest, usually behind an account. The company holds the keys, which means the company — or anyone who compels the company — can read it.
- On a server first. The phone is a window onto a database the company owns. This is the commonest model, because it enables sync, web access, features driven by aggregate data, and advertising.
Nothing about the third model is inherently dishonest. It is simply a different bet: you are betting on the company's policies, its security, its acquirers and the jurisdictions it operates in, for as long as your data exists.
What regulators have actually found
Here it is worth being careful, because this subject attracts more heat than evidence. What follows is limited to official actions with public documents, and the wording matters.
In January 2021 the US Federal Trade Commission announced a settlement with the developer of a widely used fertility-tracking app. The FTC's complaint alleged that the company promised to keep users' health data private while disclosing it to third-party analytics providers. The company settled, neither admitting nor denying the allegations, and agreed to obtain express consent before sharing health information in future. It is worth adding, because it is in the FTC's own complaint, that the analytics recipients were not charged with anything and were not told the data contained health information.
In May 2023 the FTC charged the developer of an ovulation app with sharing users' sensitive personal information with third parties and failing to notify them, in breach of the Health Breach Notification Rule. That matter also resolved by stipulated order, again with the company neither admitting nor denying, and carried a $100,000 civil penalty.
Two enforcement actions are not a verdict on an industry, and the honest counterweight belongs in the same paragraph: when the UK's Information Commissioner's Office reviewed period and fertility apps in 2024, it reported that no serious compliance issues or evidence of harms were identified, while urging developers to prioritise privacy. There has been no UK enforcement action against a period app.
The wider pattern in health apps generally is less comfortable. A peer-reviewed scoping review of health apps found that most of those examined — 20 out of 23 — shared user data with third parties. That is the category this genre sits in, and it is the reason to ask about architecture rather than to assume the worst about any particular name.
The law probably protects you less than you think
Most people assume health data in an app is covered by medical privacy law. In the US it generally is not. The FTC's own guidance says it plainly: many companies collecting people's health information — a fitness tracker, a diet app, a connected blood pressure cuff — are not covered by HIPAA. HIPAA governs health providers, plans and their contractors. An app you found yourself and downloaded is usually none of those.
What does apply is general consumer protection law: the FTC Act, and the Health Breach Notification Rule, which requires apps handling health data to tell users when it is disclosed without authorisation. That is real, and both actions above were brought under it. It is also a rule about telling you afterwards, which is a different sort of protection from the data never leaving your phone.
A promise, or an architecture
Read enough privacy policies and you notice they are written to be true rather than to be clear. "We do not sell your data" can coexist with sharing it for advertising, because sharing is not selling. "Your data is encrypted" usually means encrypted in transit and at rest on a server the company can decrypt. "We may share with trusted partners" is the sentence that does the work, and it never names them.
None of this is necessarily a lie. It is a promise about how a company intends to behave, and a promise has three failure modes that have nothing to do with intent: the company is acquired and the new owner's policy applies; the company is breached; or the company is compelled by a court. A promise cannot survive any of those. An architecture where the data never left the device survives all three, because there is no copy for the new owner, the attacker or the court to reach.
The question worth asking is not "would they share it?" but "could they, if they wanted to or were made to?"
Seven questions to judge any period tracker
You can run this list in about five minutes, mostly from the app's store listing and its privacy policy, before you type a single date.
- Can you use it without an account? An account exists so data can live somewhere other than your phone. If the app opens straight into the tracker with no email and no sign-up wall, it has told you something concrete before you have entered anything.
- Does it work in airplane mode? Turn the connection off and use it for a day. If everything still works — logging, predictions, history — the calculations are happening on the device. If it stalls, they are not.
- Is health data named separately in the policy? Good policies distinguish your cycle data from crash logs and usage analytics. Vague ones lump everything into "information we collect", and the interesting part hides in the gap.
- Are third parties listed by name or by category? "Analytics partners" can mean anything. A policy that names the companies is one you can actually check.
- What happens if the company is sold? Almost every policy has this clause and almost nobody reads it. It usually says your data transfers with the business, which quietly overrides everything above it.
- Can you export everything, in a format you can read? This is the exit. An app confident in its own value lets you leave with your history; an app that holds your data hostage has told you what it thinks that data is worth.
- Does deleting the app delete the data? On a device-only app, yes, because there is nowhere else. On an account-based app, deleting removes the copy on your phone and leaves the copy on the server. Look for an in-app delete that names the server copy specifically.
Two more things worth checking that are not questions for the policy. First, whether the app has a lock — a PIN or Face ID — because the likeliest way a period log is read by someone else is that they pick up your unlocked phone. Second, what the notifications say on the lock screen, since a helpful reminder is also an announcement.
What "no ads, no subscription, no account" is actually worth
These three phrases get bundled together in searches, and they are worth separating.
No ads matters most, because advertising is the business model that creates a reason to share data. An app funded by ads has an incentive that points away from you; an app funded by a one-off purchase or an optional upgrade does not.
No subscription is about cost, not privacy, and the two are sometimes in tension. A free app with no ads and no subscription has to be paid for somehow, and it is fair to ask how.
No account is the one that changes the architecture rather than the incentives, which is why it is the first question on the list above.
Where Athena stands
Athena is the app this site exists for, and it is in development — it has not been released, there is no store listing, and there is nothing here to buy or sign up for. So this is a description of how it is built rather than a claim you can go and verify today, and it should be read as exactly that.
It is built to the first architecture on this page. Periods, symptoms, notes and temperatures are written to a private database on the phone. Predictions are calculated on the device. There is no account, so there is nothing to log in to and nothing on a server to breach, sell or hand over. Everything can be exported, and deleting the app deletes the data because there is no second copy. When it ships, the way to check all of that is question two: turn the connection off and see whether anything stops working.
In the meantime, the tools on this site work the same way for a different reason: they run in your browser, and nothing you type into them is transmitted anywhere. If you would rather not trust software at all, the printable period tracker produces a sheet of paper, which cannot be synced, breached or requested by anyone.
Questions people ask
Where this comes from
- US Federal Trade Commission (2021). Developer of Popular Women's Fertility-Tracking App Settles FTC Allegations that It Misled Consumers About the Disclosure of their Health Data. https://www.ftc.gov/news-events/news/press-releases/2021/01/developer-popular-womens-fertility-tracking-app-settles-ftc-allegations-it-misled-consumers-about
- US Federal Trade Commission (2023). Ovulation tracking app Premom will be barred from sharing health data for advertising under proposed FTC order. https://www.ftc.gov/news-events/news/press-releases/2023/05/ovulation-tracking-app-premom-will-be-barred-sharing-health-data-advertising-under-proposed-ftc-order
- US Federal Trade Commission (2024). Complying with FTC's Health Breach Notification Rule. https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0
- Information Commissioner's Office (UK) (2024). ICO urges all app developers to prioritise privacy. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/02/ico-urges-all-app-developers-to-prioritise-privacy/
- PubMed Central (2022). Data sharing practices of medicines-related and health apps: a scoping review. https://pmc.ncbi.nlm.nih.gov/articles/PMC9123546/
- NHS (2025). Periods. https://www.nhs.uk/conditions/periods/
Every link above was checked when this page was last updated. Athena is not affiliated with any of these organisations, and none of them has reviewed this page. Nothing here is medical advice.