What happened
A new period tracker privacy audit from the Mozilla Foundation, produced with Harvard's Berkman Klein Center, just put six popular reproductive health apps under the microscope — and the results are ugly. Researcher Shoshana Wodinsky found that the astrology-themed app Stardust scored just 2 out of 10, the worst in the group, after discovering it pings third-party trackers the instant it opens, before a user has typed anything at all.
Once a user logs a symptom — birth control type, pregnancy status, mood, even something as specific as tender breasts or stomach cramps — that data is sent to an analytics firm called RudderStack, tagged with a persistent user ID, and there's no in-app toggle to turn the sharing off. RudderStack is built to forward data onward to further destinations that Mozilla's researchers couldn't even observe. Stardust also passes a Facebook ad identifier that links a user's in-app behavior to their existing ad profile. The company told reporters it has never received a legal demand for user data, but that doesn't address what its own default settings are doing.
At the other end of the scale, the nonprofit-run app Euki earned a perfect 10 out of 10. It requires no account, keeps health data on the device instead of a server, and lets users set a PIN, schedule automatic data deletion, or open a decoy screen if someone forces them to unlock the phone. Its only weak spot is an in-app browser for educational content, which loads standard web trackers — though it resets identifiers between visits.
Why it matters
This isn't an isolated story about one app. It's a snapshot of how casually sensitive personal data gets routed through ad-tech pipelines by default, often without users ever seeing a meaningful choice. Reproductive health data is uniquely risky: it can reveal pregnancy status, medication use, and intimate details that, depending on jurisdiction, could expose someone to legal or personal harm if it leaks or gets subpoenaed.
The same week this audit landed, San Francisco's City Attorney sent cease-and-desist letters demanding Apple and Google pull 13 AI "nudifying" apps used almost exclusively to target women and girls, and researchers exposed hours of unsecured police drone footage sitting on the open web. Add in state-sponsored attacks — the EU and UK just sanctioned Russia's FSB for a cyberattack that nearly knocked out Polish electric and water utilities — and a pattern emerges: the infrastructure around personal and civic data is far more porous than most people assume.
For entrepreneurs and marketers, the lesson is blunt. A privacy failure is now a brand story, not a footnote. Stardust's 2/10 score is already circulating in tech press and will likely shape how users perceive the entire period-tracking category for years.
How to use it today
If you build, market, or ship any product that touches personal data — health, finance, location, or otherwise — treat this audit as a free checklist:
- Audit what fires on app open. Check whether analytics or ad SDKs activate before a user has consented to anything.
- Separate identity from data. Persistent user IDs attached to sensitive fields (symptoms, moods, medical history) are the single biggest red flag auditors look for.
- Give users a real off switch. Euki's decoy screen and auto-delete features cost little to build but earned it a perfect score.
- Know where your data goes after the first hop. Tools like RudderStack route data onward to destinations even the vendor's own privacy policy may not name.
If you're mapping out your own data flows, drafting a clearer privacy policy, or building consent screens from scratch, free AI tools like the ones at [mykreatool.com](https://mykreatool.com) can help you generate first drafts of policy language, checklists, and user-facing disclosures quickly — a useful starting point before a lawyer or compliance review.
Who benefits
Health-tech founders and product teams benefit most directly: privacy-by-design is quickly becoming a competitive differentiator, not just a compliance box. Marketers can lean into a genuine "we don't sell your data" message the way Euki now can, backed by an independent third-party score rather than a marketing claim.
Users benefit obviously — anyone tracking a cycle, fertility, or symptoms gets a clear, ranked way to choose a safer app. And journalists, researchers, and regulators benefit from having a repeatable audit methodology they can apply to the next wave of health and wellness apps.
Risks
The flip side is real too. Publishing a scorecard like this can create a false sense that "10/10" apps are risk-free forever — audits are a snapshot, and third-party SDKs get added or changed after a review ships. Smaller apps and startups may also lack the resources to run their own privacy audits, meaning strong intentions don't always translate into strong practices.
There's also a broader risk of privacy fatigue: with drone footage leaks, AI nudify apps, facial recognition rollouts, and state-sponsored grid attacks all breaking in the same news cycle, users and even builders can become numb to the warnings, treating each new story as background noise rather than an actionable signal.
Conclusion
The gap between Stardust's 2/10 and Euki's perfect 10 shows privacy isn't a technical inevitability — it's a design choice. For anyone building or marketing a product that handles personal data, this period tracker privacy audit is a rare, concrete benchmark: it names the exact behaviors that separate a trustworthy app from a leaky one. Treat it as a checklist, not just a headline.



Comments 0