Technology

A Period Tracking App Said Your Data Was Private. It Wasn't.

Martin HollowayPublished 6d ago4 min readBased on 2 sources
Reading level
A Period Tracking App Said Your Data Was Private. It Wasn't.

A period tracking app called Stardust has been sending sensitive user health data to a separate analytics company, according to research published by Mozilla on July 16, 2026. Mozilla security researcher Shoshana Wodinsky looked at the network traffic of several period and ovulation tracking apps and found that Stardust was the only one out of six tested that shared users' health data with another company TechCrunch.

The information Stardust sent to the analytics company, RudderStack, included users' birthdates, birth control types, reproductive goals, and specific symptoms. Mozilla published its findings on the Mozilla Foundation website under a project called 'Nothing Personal' TechCrunch.

Stardust's website displayed the claim 'Your data is private. Period.' Stardust founder Rachel Moranis did not respond to TechCrunch's request for comment. A Stardust spokesperson told BBC News that RudderStack is contractually prohibited from selling or using the shared data for its own purposes TechCrunch.

This is not the first time Stardust's privacy claims have been questioned. In June 2022, TechCrunch found that Stardust's claim of end-to-end encryption was false after examining the app's network traffic TechCrunch.

The problem extends beyond one app. A 2025 academic study published in PMC found that Mozilla had labeled 18 of 25 popular period and pregnancy tracking apps with a '*Privacy Not Included' warning PMC. Mozilla recommended a different app called Euki, which does not share any data with other companies and keeps users' health data stored only on their own device TechCrunch.

The data Stardust sent to RudderStack was not directly labeled with a user's name or email. Instead, it was tied to a unique identifier, which is a code that acts like a serial number for a user. In practice, these codes can often be matched back to a real person by comparing them with other data sets. The ban on RudderStack selling or using the data is a legal rule written into a contract, not a technical barrier built into the software. The data still leaves the user's phone and travels to another company's server.

This difference between a legal promise and a technical protection is the heart of the issue. A contract depends on the analytics company following the rules and the app maker enforcing them. It does not provide any built-in, software-level guarantee. If the data were truly private, as Stardust's marketing suggested, the app would keep it on the user's phone or encrypt it with a key only the user controls. Sending raw health details like birth control type and reproductive goals to another company's server is a deliberate design choice that puts data collection ahead of user privacy.

The history makes this harder to dismiss. When a company has already been caught misrepresenting its encryption, finding that it also shares sensitive data with an analytics firm raises a basic question about whether its public statements can be trusted at all.

The fact that five of the six apps Mozilla tested did not share this data is the most useful takeaway. Building a period tracker that keeps health information on the device is entirely possible. Euki's approach shows that tracking a menstrual cycle does not require sending data to other companies' servers. Apps that do send that data are making an active choice to do so.

Health data is some of the most personal information a person can create. Details like birth control type and reproductive goals carry meaning that goes well beyond targeted advertising. When my own children were young adults installing apps without much thought, I saw how a clean interface and a comforting privacy slogan can replace any real checking a user might otherwise do. Most people, no matter how tech-savvy, will not monitor their own phone's network traffic to see what an app is actually sending.

Mozilla's research does that checking for us. Both the 'Nothing Personal' project and the PMC study point to an app category where weak data practices are common enough that many popular apps carry explicit privacy warnings. For anyone choosing a tracker, the question that matters is not what the privacy policy says but where the data actually goes. An app that stores everything on your device and sends nothing to other companies remains the strongest option available.