Every period app says your privacy matters. Two of the best-known have settled with the US Federal Trade Commission over what they did with cycle and fertility data anyway (FTC, 2021; FTC, 2023). Most consumer health apps are not covered by the medical privacy law people assume protects them, and since the Supreme Court's decision in Dobbs (2022), reproductive-health data can carry legal weight it did not carry before. Period app privacy is therefore not a badge to trust; it is a short list of specific promises, each of which can be checked.
This article lists the seven promises worth demanding, explains what each one means in plain language, and shows how to verify it — including how AuraShield answers each, with the caveats.
First, the law probably does not cover your app
In the United States, HIPAA covers healthcare providers, insurers and their business associates. A consumer app you downloaded yourself is generally not one of those. What does apply to most health apps is the FTC's Health Breach Notification Rule, which requires them to notify you when health data is disclosed without authorisation — and which the FTC has said applies to apps that share health data with advertisers (FTC Health Breach Notification Rule). That is a floor, not a promise. The promises below are what to look for on top of it.
The seven promises
1. "We never sell your data, and we don't use it for ads."
Both FTC cases turned on data flowing to third parties for analytics or advertising while the app's policy said otherwise (FTC 2021; FTC 2023). How to check: read the privacy policy for the words advertising, partners and third parties; look for an analytics toggle that is off by default; and see whether the company publishes the third parties it uses.
2. "Sensitive data is encrypted field by field, not just on the disk."
"Encrypted at rest" can mean the whole database disk is encrypted — which protects against a stolen hard drive and nothing else, since the application reads everything in the clear. Field-level encryption means the cycle dates themselves are stored as ciphertext and decrypted only when a feature needs them. How to check: the policy should say which fields are encrypted and with what, not just "industry-standard encryption".
3. "We tell you what our servers can read."
Very few apps offer true end-to-end encryption, because features like predictions, coaching and reports need the server to read the data. An honest app says so. How to check: be suspicious of "even we can't read it" unless the app explains how its features work without reading your data.
4. "We have a written policy on law-enforcement requests, and it is public."
After Dobbs, the question "what happens if someone demands my cycle history?" has a real answer for every app, whether or not they publish it. How to check: look for a page that says the company requires legal process, will not disclose reproductive-health data voluntarily, will challenge overbroad requests, and will notify you when permitted — and that reports the requests it receives.
5. "You can export everything and delete everything, yourself, now."
Not by emailing support. How to check: find the export and delete controls in the app before you have entered a single period.
6. "There is a record of who accessed your data."
An audit log — every export, every share link opened, every time an AI feature read your cycle — is what turns a promise into something you can inspect. How to check: look for it in the app; few have one.
7. "You can lock the sensitive parts of the app on the device."
Phones get borrowed, taken and looked at. A PIN or passkey on the cycle section, a discreet mode that renames it, and a duress option are the difference between a privacy policy and a private app. How to check: the settings screen.
How AuraShield does this
Every line below is checkable, and the caveats are part of the answer.
- No ads, no data sales, no profiling. Analytics are opt-in and load nothing until you consent; cycle screens are excluded from page tracking entirely and cycle features send no analytics events. The third parties we use are listed in the privacy policy.
- Field-level encryption. Your cycle dates, journal, medications, allergies and notes are encrypted one field at a time with AES-256-GCM and versioned keys, not only on the disk.
- What our servers can read: we say so. There is no end-to-end encryption. Our servers decrypt what a feature needs — the calendar, the coach, the doctor's report — and the live transparency report shows what we can and cannot see.
- A public cycle-data policy. We will not disclose reproductive-health data voluntarily, we challenge overbroad legal process, we notify you when the law allows, and the requests we receive are counted on the transparency report. Read the policy.
- Export and delete in one tap, from the privacy centre in the app.
- A cycle audit log — every export, every share opened, every AI read — visible to you.
- A PIN or passkey lock on the cycle section, a discreet mode, and a duress PIN.
All of this is on the free plan; privacy is not a tier. What we do not promise: that the data never leaves your phone (it does, encrypted, to our servers), or that a well-formed court order can always be refused (it cannot — which is why the policy is about process and notification, not magic).
A five-minute check for any app
- Open the privacy policy and search for advertising and third parties.
- Find the analytics toggle and note its default.
- Find export and delete before you enter anything.
- Search the site for a law-enforcement or reproductive-data policy.
- Look for a lock, a discreet mode and an audit log in settings.
An app that passes all five has earned the data. One that fails the first should not get it.
FAQ
Is my period data protected by HIPAA?
Generally not. HIPAA covers healthcare providers, insurers and their contractors. A consumer app usually is not one, which is why the promises above have to come from the app itself and why the FTC's Health Breach Notification Rule matters for apps that share health data.
Does AuraShield offer end-to-end encryption?
No, and the article says why: predictions, the coach and the doctor's report need the server to read the data. What we offer instead is field-level encryption, a public disclosure policy, a live transparency report and an audit log — promises you can check rather than a claim you have to trust.
What happens if you receive a legal demand for my cycle data?
We require valid legal process, do not disclose reproductive-health data voluntarily, challenge requests that are overbroad or improper, and notify the person affected when the law permits. The number of requests received and honoured is published on the transparency report. The full text is in our cycle-data policy.
This article is general health information, not medical advice, and AuraShield is a general-wellness product, not a medical device. It screens, educates and refers; it does not diagnose. For anything about your own health, talk to a clinician who can examine you.