Period Trackers Leak Sensitive Data | Analysis by Brian Moineau

TL;DR

  • Mozilla’s tests found one period tracker, Stardust, routing reproductive health events (pregnancy status, birth control, symptoms) to RudderStack while also pinging Meta and AppsFlyer, contradicting the app’s “Your data is private. Period.” slogan [1][2].
  • The exposure isn’t just what you type; it’s where those events travel: every third‑party SDK or data “pipe” multiplies legal risk after Dobbs v. Jackson Women’s Health Organization (2022), while HIPAA’s April 26, 2024 update shields clinical PHI but not most consumer apps [3][7].
  • Enforcement signals are clear—FTC actions involving Flo (2021), GoodRx ($1.5M in 2023), and BetterHelp ($7.8M in 2023) preview how “privacy promises vs. practice” cases will hit femtech and its vendors next [4][5][6].

What the source said

In July 2026, BBC Future reported on Mozilla Foundation’s hands‑on testing of six period trackers—Flo, Clue, Stardust, Spot On, Period Calendar, and Euki—showing stark differences in how they transmit private data from the United States and Europe [1]. Mozilla and BBC found Stardust was the only app that sent labeled reproductive health events to RudderStack, a routing service not named in Stardust’s policy, while also sharing identifiers with Meta and AppsFlyer; Stardust says RudderStack can’t identify users and is contractually barred from repurposing data [1][2]. Spot On’s in‑app links to Planned Parenthood’s site exposed visits (e.g., for HIV testing or gender‑affirming care) to AB Tasty, while Period Calendar sent device IDs to Google and InMobi without an opt‑out; Mozilla called Euki “squeaky clean” by comparison [1].

Why it matters

Two groups have the most at stake in 2024–2026. First: users whose menstrual logs can imply pregnancy, fertility struggles, or miscarriage in states that criminalize aspects of reproductive care after the 2022 Dobbs ruling; HIPAA’s April 26, 2024 reproductive‑privacy rule protects clinical PHI but does not reach most consumer trackers, creating a gap prosecutors can exploit with subpoenas or geofence warrants [3][7]. Second: the femtech stack—app publishers, attribution firms, analytics routers, and ad platforms—because one mislabeled or misrouted event can turn “we protect your privacy” into Exhibit A for the FTC or a state AG, echoing Flo (2021), GoodRx (2023), and BetterHelp (2023) outcomes [4][5][6].

Original analysis

Consensus view: “Fix period tracker privacy with end‑to‑end encryption and you’re safe.” Contrarian read: encryption helps, but the weak link is metadata exhaust and server‑side event routing that Apple’s App Tracking Transparency dialog doesn’t meaningfully police, so sensitive streams can leave at app open to partners like RudderStack, AppsFlyer, or Meta, even before a user toggles a setting [2]. In discovery, the map of who received which payloads on which dates typically matters more than whether fields were encrypted in transit [4][5][6].

Historical analogue: Flo’s 2021 settlement and GoodRx’s 2023 penalty. In Flo, the FTC alleged the app labeled events like “Pregnancy” and sent them with identifiers to Facebook, Google, Flurry, Fabric, and AppsFlyer, contrary to public promises, leading to an order requiring affirmative express consent and external assessments [6]. GoodRx paid $1.5 million and was banned from sharing health information for advertising after claiming to be “HIPAA secure” while not being a covered entity; DOJ and FTC highlighted the mismatch between claims and data flows [5]. BetterHelp paid $7.8 million and faced a ban on sharing sensitive health data for ads, reinforcing that regulators don’t need a breach to act—just a broken promise with corroborating packet logs [4].

Back‑of‑envelope calculation (example math using 13 cycles/year and 2M MAUs):

  • Assumptions: a typical user logs 8 items per cycle (bleeding, PMS, two symptoms, mood, sex, contraception, note). At 13 cycles/year, that’s ~104 health events per user/year (author’s calc).
  • If an app routes those to 3 partners (analytics, attribution, data router), that’s ~312 transmissions per user/year (author’s calc).
  • With 2 million monthly actives sustaining this cadence, that’s roughly 624 million transmissions/year—a compounding discovery, breach, and subpoena surface if IDs or device metadata allow linkage later (author’s calc).

Period tracker privacy: a 2×2 that predicts risk based on Mozilla/BBC’s 2026 findings [1]

  • Axes: “Visibility of data flows” (transparent logs, partner lists, on‑device options such as iOS 17’s App Privacy Report) vs. “Third‑party dependence” (count and criticality of external SDKs/pipes on iOS 17 and Android 14).
Quadrant What defines it Example placement (from reporting/tests)
High visibility + Low dependence Clear partner registry, minimal SDKs, local storage by default Euki (“squeaky clean” per Mozilla/BBC) [1]
High visibility + High dependence Lots of SDKs but a detailed map and user controls Few period apps today; a target state
Low visibility + Low dependence Few partners but opaque disclosures Gap apps not audited this round
Low visibility + High dependence Multiple partners, event routing, limited controls Stardust (RudderStack for health data; AppsFlyer/Meta identifiers) [1][2]; Period Calendar (Google, InMobi, no user opt‑out per report) [1]; Spot On’s linked web features leaking to AB Tasty [1]

Named‑stakeholder breakdown (4 groups, 2024–2026):

  • App publishers (Stardust, Period Calendar, Spot On): if your privacy page and packet captures diverge, you are replaying Flo/GoodRx’s storyline in a harsher legal climate spanning Washington to Texas [1][5][6].
  • Data routers/SDKs (RudderStack, AppsFlyer, Meta): you are “processors,” and Washington’s My Health My Data Act (RCW 19.373, 2023) regulates processors via contracts, logs, and retention duties that will surface in discovery [7].
  • Regulators (FTC, state AGs, HHS OCR): toolkits and precedent—Flo (2021), BetterHelp (2023), GoodRx (2023)—align with HIPAA’s 2024 rule that clarifies covered‑entity limits and spotlights the consumer‑app gap [3][4][5][6].
  • Users: the safest default is local‑only logging or apps proven to avoid third‑party transmission of health events (Mozilla highlighted Euki in 2026 testing) [1][2].

What others are missing

The overlooked angle is vendor‑chain accountability one layer downstream of the app: event‑routing platforms that shuttle payloads between mobile clients and data warehouses in Seattle‑to‑San Francisco stacks. Washington’s My Health My Data Act (RCW 19.373) binds publishers and processors alike and compels a homepage‑linked health data policy, opt‑in consent, and deletion rights with concrete effective dates (large entities by March 31, 2024; small businesses by June 30, 2024) [7]. HIPAA’s April 26, 2024 reproductive‑privacy rule tightens disclosures inside clinics yet explicitly doesn’t cover fertility/period apps that aren’t regulated entities, so compliance pivots on state law and SDK contracts instead of hospital playbooks [3][7].

What to watch next

  1. By Q4 2026, at least one state attorney general will file a My Health My Data Act action against a consumer reproductive‑health app or a processor for undisclosed sharing of cycle or pregnancy events, citing packet logs and partner contracts as evidence.
  2. By Q2 2027, a top‑5 mobile analytics or attribution vendor (by market share in North America) will ship a “reproductive‑health safe mode” that rejects cycle‑ or pregnancy‑labeled events and enforces 30‑day deletion SLAs, and at least one major tracker will announce adoption in a press release.
  3. By Q1 2027, Apple or Google will update platform policy to restrict server‑side routing of sensitive health events to non‑clinical processors without explicit, in‑context consent and an in‑app partner list, with enforcement via app rejections.

My take

If you ship a period tracker in 2026, you can’t outsource privacy to your SDKs or routers. The rule of thumb is simple: if your network logs show pregnancy or symptom events leaving the device, you’re building a plaintiff’s timeline for the FTC or a state AG. Build a data diode now: keep health events on‑device, publish a partner bill of materials, and ban reproductive‑health labels in analytics streams. HIPAA’s 2024 fix protects clinic charts, not your app; FTC precedent punishes broken promises; Washington’s MHMD creates direct exposure for processors—choose the “squeaky clean” quadrant or budget for discovery [1][3][5][6][7].

Sources

  1. The privacy problems hidden in your period tracker — BBC (https://www.bbc.com/future/article/20260715-how-period-trackers-share-womens-private-details) — Core report from July 2026 based on Mozilla’s testing; details on Stardust–RudderStack, Spot On’s AB Tasty issue, Period Calendar’s tracking, and Euki’s “squeaky clean” status.

  2. Privacy Review: Stardust Period Tracker — Mozilla Foundation (https://www.mozillafoundation.org/en/nothing-personal/stardust-privacy-review/) — Confirms health‑event transmission to RudderStack and identifiers to AppsFlyer/Meta; explains why Apple’s ATT doesn’t constrain these pipes.

  3. The HIPAA Privacy Rule (incl. Apr 26, 2024 Final Rule to Support Reproductive Health Care Privacy) — HHS.gov (https://www.hhs.gov/hipaa/for-professionals/privacy/index.html) — Establishes scope and the 2024 reproductive‑privacy update; clarifies covered entities/business associates vs. consumer apps.

  4. FTC Gives Final Approval to Order Banning BetterHelp from Sharing Sensitive Health Data for Advertising, Requiring It to Pay $7.8 Million — Federal Trade Commission (https://www.ftc.gov/news-events/news/press-releases/2023/07/ftc-gives-final-approval-order-banning-betterhelp-sharing-sensitive-health-data-advertising) — Shows FTC bans on ad uses of sensitive health data and monetary relief.

  5. Digital Healthcare Platform Ordered to Pay Civil Penalties… (GoodRx) — U.S. Department of Justice (https://www.justice.gov/archives/opa/pr/digital-healthcare-platform-ordered-pay-civil-penalties-and-take-corrective-action) — Details $1.5M penalty and advertising bans for sharing health data despite privacy claims.

  6. FTC Finalizes Order with Flo Health, a Fertility‑Tracking App that Shared Sensitive Health Data — Federal Trade Commission (https://search.ftc.gov/news-events/news/press-releases/2021/06/ftc-finalizes-order-flo-health-fertility-tracking-app-shared-sensitive-health-data-facebook-google) — Lays out how labeled pregnancy/period events went to analytics firms and the remedial order (consent, audits).

  7. Protecting Washingtonians’ Personal Health Data and Privacy (My Health My Data Act FAQ) — Washington State Attorney General (https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy) — Clarifies RCW 19.373 scope, effective dates (Mar 31 and Jun 30, 2024), policy‑link requirement, and that processors are in scope.




Related update: We recently published an article that expands on this topic: read the latest post.

Firefox adds free 50GB built‑in VPN | Analysis by Brian Moineau

A pleasant surprise in your toolbar: Firefox now has a free built‑in VPN with 50GB monthly data limit

Firefox just got a privacy upgrade that’s hard to ignore: a free, built‑in VPN that gives users up to 50GB of monthly traffic. This addition lands in Firefox 149 and is delivered as a browser‑level VPN — no separate app required — which makes privacy easier for casual users and gives power users another tool in their kit. (firefox.com)

Why this matters now

Browsers have become battlegrounds for user trust. As adtech and cross‑site tracking grow more sophisticated, companies like Mozilla are trying to regain ground by leaning into privacy features. Adding a built‑in VPN is a clear, visible signal: Firefox isn’t just blocking trackers — it’s offering to hide your IP and mask location from sites you visit. Mozilla’s rollout of this feature with Firefox 149 marks a shift from optional, paid VPN products toward making privacy a default, discoverable browser capability. (firefox.com)

  • It’s a browser‑only VPN — it protects web traffic inside Firefox, not all traffic on your machine. (ghacks.net)
  • The free tier caps usage at 50GB per month, enough for typical browsing, light streaming, and everyday anonymity. (firefox.com)
  • The rollout is phased by region, and account sign‑in may be required to track the 50GB usage. (firefox.com)

What Firefox’s built‑in VPN actually does

This is a browser‑level proxy that routes your Firefox web requests through Mozilla’s VPN backend, obfuscating your IP address and encrypting the connection between the browser and the VPN server. It’s not a system‑wide VPN, so apps outside Firefox (like games, email clients, or torrent clients) won’t use it. That makes it less of a catch‑all privacy tool, but also simpler and less intrusive for users who mainly want private browsing without installing extra software. (ghacks.net)

The practical tradeoffs:

  • Pros: Quick setup, no third‑party client, easy to toggle, and generous 50GB monthly allowance for a free offering. (firefox.com)
  • Cons: Browser‑only protection, potential performance variance depending on server load, and limitations compared with paid, system‑wide VPNs. (ghacks.net)

How Mozilla’s move fits the larger browser landscape

Mozilla isn’t inventing the wheel here — other browsers (Opera, Vivaldi, Brave) have offered integrated VPN/proxy features for years. But Mozilla brings something different: a long track record of privacy messaging and an independent non‑profit ethos that many users trust. That trust matters, because "free VPN" has a fraught history; shady providers have been caught collecting data or inserting trackers under the guise of privacy. Mozilla’s approach—integrated, account‑managed usage and transparency about how usage is measured—aims to avoid those pitfalls. (techradar.com)

At the same time, the move looks strategic. With Firefox’s global market share small compared to Chromium‑based rivals, a high‑profile privacy feature gives Mozilla a marketing hook to woo users who prioritize privacy but don’t want to fiddle with extensions or third‑party services. (techradar.com)

Practical tips if you want to try it

If you see the feature in your Firefox toolbar or settings, here’s how to treat it:

  • Sign in with your Mozilla account if prompted — the account tracks the 50GB allowance. (firefox.com)
  • Remember it’s browser‑only: if you need system‑level privacy (e.g., protecting a torrent client or a game), keep using a full VPN app. (ghacks.net)
  • Expect gradual rollout: not every Firefox 149 install will see the VPN right away; Mozilla is enabling it by region and in phases. (firefox.com)

Safety and privacy: what to ask before trusting any “free VPN”

A free VPN can be a huge convenience, but privacy is not just about a locked padlock icon. When evaluating the new Firefox option, consider:

  • Logging policy: what connection metadata is recorded and for how long? Mozilla has historically published transparency details for services; look for those statements. (theregister.com)
  • Who runs the servers? Some privacy services partner with third parties for infrastructure. Knowing the operator helps when assessing jurisdiction and data risks. (ghacks.net)
  • Is the protection audited? Independent audits and technical writeups increase confidence in a VPN’s claims. (theregister.com)

The user experience — a quick read

The beauty of a built‑in, browser‑level VPN is simplicity. Toggle it on, surf with a masked IP, and the browser handles the rest. For many users, that will be "good enough" privacy without extra installs or subscription signups. For power users, it won’t replace a full VPN, but it’s a welcome tool in the privacy toolbox. And the 50GB monthly cap is far more generous than many free VPNs’ paltry allowances, making the feature practical for real use. (firefox.com)

My take

Mozilla’s built‑in VPN is a smart, pragmatic step. It lowers the barrier to stronger browsing privacy and aligns with Firefox’s brand. It also signals a shift in how browsers compete: not just on speed or features, but on trust and default protections. If you’re an occasional user who wants better privacy without complexity, this is worth exploring. If your needs include system‑wide traffic or heavy streaming and downloads, keep a dedicated VPN on standby.

Sources




Related update: We recently published an article that expands on this topic: read the latest post.

Mozilla flamed by Firefox fans after promises to not sell their data go up in smoke – The Register | Analysis by Brian Moineau

Mozilla flamed by Firefox fans after promises to not sell their data go up in smoke - The Register | Analysis by Brian Moineau

### Mozilla’s Privacy Promises: When the Smoke Alarm Goes Off

In a world where digital privacy often feels like a unicorn prancing through a forest of data trackers, the news from Mozilla has left many Firefox fans singed and searching for a fire extinguisher. According to a recent report from The Register, the open-source browser maker has sparked controversy by seemingly backtracking on its staunch promises not to sell user data. Cue the collective sighs and raised eyebrows from privacy-conscious netizens everywhere.

Mozilla, long-hailed as the champion of user privacy among browsers, has found itself entangled in a web of legal jargon and explanations that seem to contradict its foundational ethos. For years, Mozilla waved the banner of privacy, often pointing fingers at tech giants like Google and Facebook for their more cavalier attitudes toward user data. Yet, this recent development has left many wondering if the Firefox fox has turned its gaze toward the same tempting data-driven treasure chest.

### The Fine Print

The issue arises from Mozilla’s updated privacy policy, which, according to critics, muddles the waters with legalese that suggests user data might be up for grabs after all. This has led to an uproar among users who feel betrayed, akin to finding out that your favorite organic juice brand is secretly owned by a soda giant. Mozilla’s response has been to clarify, stating that user data is still protected and not sold in the way the headlines suggest. However, the damage appears to have been done, with trust—an ever-fragile commodity in the tech world—taking a hit.

### A Broader Context

This kerfuffle comes at a time when the tech industry is under intense scrutiny over privacy practices. Just this year, Apple made headlines with its App Tracking Transparency feature, which allows users to opt out of being tracked by apps, much to the chagrin of companies relying on ad revenue. Similarly, Google has been slowly phasing out third-party cookies in its Chrome browser, albeit with some delays and pushback from advertisers.

Mozilla's predicament also echoes the broader societal debate about privacy versus convenience. As people increasingly rely on digital tools for everything from shopping to socializing, the question of how much privacy we’re willing to trade for the sake of convenience becomes ever more relevant. It's a dance as old as time—or at least as old as the internet—where users are both the passengers and the fuel for the digital economy.

### Lessons from the World of Sports

In the realm of sports, transparency and trust are equally pivotal. Consider the world of professional cycling, which has been marred by doping scandals. Teams and athletes must work tirelessly to rebuild trust with fans and sponsors. Mozilla, in a similar vein, must now pedal hard to prove its commitment to privacy and regain the confidence of its user base.

### The Final Thought

As the dust settles, it’s clear that Mozilla has some work to do to reassure its loyal users. This incident serves as a reminder of the complex dance between privacy, transparency, and business interests in the digital age. Whether Mozilla will manage to extinguish the flames or let them smolder remains to be seen. For now, as users, we must remain vigilant and advocate for stronger privacy protections across the board.

In a landscape where data is the new currency, navigating the digital world requires more than just a robust browser; it demands an informed and critical approach to the services we choose to trust. Keep your wits about you, dear reader, and remember that in the quest for privacy, you are your own best advocate.

Read more about AI in Business

Read more about Latest Sports Trends

Read more about Technology Innovations