Mozilla study ranks Euki as the most private period tracker

Mozilla's 'Nothing Personal' investigation reveals that Euki stores all data locally, earning a perfect privacy score.

By Central
Euki is the only period tracker to store all data locally on the user's device.
Highlights
  • Euki scored a perfect 10 out of 10 in Mozilla's privacy analysis of period-tracking apps.
  • The app stores all cycle data locally on the device and requires no account.
  • Mozilla found that Stardust ranked last due to pervasive tracking and data sharing.

The Mozilla Foundation has published a critical privacy analysis of six popular period-tracking applications, revealing a stark divide between services designed to minimize data collection and those that extensively share user data with third-party advertising and analytics platforms. The study, conducted in partnership with Harvard University’s Berkman Klein Center and the University of Illinois, assigned Euki the only perfect privacy score, while the astrology-themed Stardust ranked last due to pervasive tracking. In the post-Dobbs legal landscape, where reproductive health data carries heightened legal and personal risks, the findings serve as an essential guide for users seeking to protect their most sensitive information.

The Mozilla Period Tracker Privacy Investigation

Mozilla’s “Nothing Personal” investigation combined hands-on testing with deep network traffic analysis to examine what data Euki, Clue, Flo, Period Calendar, Planned Parenthood’s Spot On, and Stardust transmitted during setup, symptom logging, and routine use. Researchers analyzed historical changes to privacy policies and scrutinized the behavior of third-party software development kits (SDKs) embedded in each app. The result is a clear ranking that separates apps genuinely designed for privacy from those that treat reproductive health data as a commodity.

Euki Achieves the Only Perfect Score for Local Storage Privacy

Euki, an open-source tracker managed by a nonprofit, scored 10 out of 10 by storing all cycle data, symptoms, and notes locally on the user’s device. The app requires no account and requests no unnecessary permissions, such as location or contacts. This architecture means Euki’s servers never possess the health information users log, effectively eliminating the risk of a data breach or subpoena targeting that data. Mozilla praised additional security features, including PIN protection, automatic data deletion, and a decoy screen for situations where a user is compelled to unlock their phone.

Researchers identified one notable exception: Euki’s in-app browser loaded analytics and advertising trackers from Google, Meta, and Microsoft when users accessed external educational resources. While the browser assigned a fresh identifier for each session, limiting long-term profiling, users who submitted personal information on those external sites could still be identified. Euki’s co-founder stated the issue would be reviewed.

Clue and Flo Offer Partial Privacy Protections

Germany-based Clue earned the second-highest score of 8 out of 10, largely due to its granular consent controls that separate permissions for research, analytics, recommendations, and advertising. Mozilla found no evidence that Clue broadly shares reproductive health records with third parties. However, the app still builds detailed long-term user profiles containing cycle history, symptoms, and lifestyle data to power its predictions.

Flo, which reports 81 million monthly active users, received a score of 7. Mozilla found that declining Flo’s optional advertising and analytics settings significantly reduced communications with services such as AppsFlyer, Moloco, and Google Firebase. Flo’s Anonymous Mode routed connections through a Cloudflare relay to hide IP addresses and stopped some observed traffic. However, Mozilla noted that the device’s Apple Identifier for Vendor (IDFV) was already transmitted to AppsFlyer before Anonymous Mode could be activated. Flo’s score also reflects its history of privacy controversies, including a 2021 FTC settlement over health data sharing and an $8 million settlement reached in 2025.

Stardust and Period Calendar Present High Privacy Risks

Stardust ranked last with a score of 2, as Mozilla observed third-party tracking beginning immediately after launch. Data relating to birth dates, birth control methods, reproductive goals, and symptoms was transmitted to the analytics platform RudderStack, along with persistent user identifiers. Mozilla also found device and usage data shared with AppsFlyer and Facebook, including advertising identifiers that could link activity inside Stardust to existing user profiles. Stardust told Mozilla that RudderStack routes data only to its internal analytics systems, but the transmission of symptoms alongside persistent identifiers remains a significant privacy risk.

Period Calendar, the only advertising-supported app in the review, scored 6. While it did not appear to share cycle logs or symptom data with advertisers, it immediately transmitted device details such as phone model, screen dimensions, and time zone to Google AdMob and DoubleClick. Because the app’s name clearly identifies it as a period tracker, these persistent identifiers can reveal that a user relies on a reproductive health app, even without exposing actual health records.

Planned Parenthood’s Spot On and the Webview Risk

Planned Parenthood’s Spot On scored 5. Its core tracking features performed well, with Mozilla finding no evidence of external data sharing. However, significant privacy concerns arose when users accessed Planned Parenthood web services through the app’s built-in browser. Provider searches transmitted data such as the user’s city and requested care type to the analytics company AB Tasty. Searches for abortion providers also transmitted the user’s age and last menstrual period. Additional trackers from Google, Microsoft, TikTok, and Pinterest were detected when using the Roo chatbot.

How to Choose a Privacy-Focused Period Tracker

The Mozilla study confirms that significant privacy differences exist between period tracking applications. For users prioritizing data protection, the following features are essential:

  • Local data storage: Apps that store information on the device rather than on cloud servers eliminate the risk of server-side breaches and legal demands for data.
  • No account requirement: Services that do not require an email address or phone number prevent the creation of a persistent user profile tied to health data.
  • Minimal third-party SDKs: Applications should avoid integrating advertising or analytics SDKs that can transmit device identifiers and app usage data to third parties.
  • Transparent privacy controls: Look for apps that offer granular consent options and clearly explain what data is collected and shared.
  • Open-source code: Open-source applications can be independently audited to verify privacy claims.
  • Disable in-app browsers: When possible, avoid using built-in browsers for web searches, as they often load third-party trackers.

Users in the US, UK, Australia, and Canada should treat period-tracking apps with the same caution they apply to password managers or VPNs: choose audited, transparent solutions that minimize data collection. For those seeking maximum privacy, an app that stores data locally and requires no account remains the safest option. Additionally, using a reputable VPN with a verified no-logs policy and strong encryption when browsing reproductive health resources online can help prevent device-level exposure by internet service providers or third-party trackers.

Share This Article