By Dr. Brandon Bright, DAOM, LAc · Doctor of Acupuncture & Oriental Medicine · Functional Medicine University-certified · Tustin, CA · Last reviewed: August 31, 2026
Here’s a fact that surprises almost every patient I say it to: the cycle tracking app on your phone is not covered by HIPAA. Not partially, not “sort of” — not at all. The privacy law you assume protects your health information applies to healthcare providers, insurers, and their business associates. A consumer wellness app is none of those things. Your ovulation dates, symptoms, pregnancy status changes, and the intimate details you’ve logged for years sit in a commercial database governed mostly by a privacy policy the company wrote and can revise. With period-tracker use at an all-time high, femtech consolidating fast, and a major telehealth company currently facing an FTC lawsuit over health-data sharing, this is the plain-language guide to who can actually see your cycle data — and what to do about it.
The 55-second answer
HIPAA protects health information held by covered entities — providers, health plans, and their vendors. Consumer wellness apps fall outside that perimeter, so your cycle data’s protection is whatever the app’s privacy policy grants, enforced mainly by the FTC’s general authority over deceptive practices — after the fact, if at all. In practice the category runs on a spectrum: some apps genuinely minimize and encrypt data; others share device identifiers and usage data with third parties even while marketing themselves on privacy — a marketing-versus-data-label tension you can check yourself in two minutes. What to do: read the app-store data-safety label (not the marketing page), minimize what you log where, prefer local-only storage where offered, and know that the strongest version of “private” is data held inside an actual clinical relationship, where confidentiality is a legal duty rather than a brand promise.
Why HIPAA doesn’t cover your period app
HIPAA’s privacy rule attaches to the holder of the data, not the data itself. The same ovulation date is legally protected when it sits in your doctor’s chart and legally unprotected when it sits in a wellness app’s cloud. The app isn’t your provider, doesn’t bill your insurance, and isn’t a business associate of anyone who does — so the statute simply doesn’t reach it. What governs instead:
- The privacy policy — a contract the company drafts, that you clicked through, and that typically reserves the right to change.
- FTC enforcement — the Federal Trade Commission can act against deceptive data practices (and its Health Breach Notification Rule now reaches health apps), but this is enforcement after the harm, not protection before it. The FTC’s ongoing lawsuit against a major telehealth company — alleging member health data was shared with advertising platforms without adequate consent — shows both that the FTC is active here and that the practices worth worrying about are alleged at the biggest names in the space, not just fly-by-night apps. Those allegations are unresolved and the company disputes them; the full telehealth privacy breakdown is here.
- State laws — a patchwork; a few states (notably Washington) have passed consumer-health-data acts that meaningfully raise the bar, but coverage depends on where you live.
What actually happens to cycle data
Without naming and shaming any single app — the pattern is what matters, and it repeats across the category:
- The marketing-vs-label gap. An app’s homepage says “your data is never sold” while its own app-store data-safety label discloses sharing of device identifiers and app-activity data with third parties. Both statements can be technically true at once — “selling” has a narrow definition; “sharing for advertising and analytics” is a different bucket. The label is the more honest document. Check it.
- Acquisitions change everything. Femtech is consolidating. When an app is acquired, its database goes with it — and the acquirer’s incentives, ad platforms, and jurisdiction come attached. The privacy policy you originally accepted rarely survives intact.
- Aggregated and “de-identified” isn’t anonymous. Cycle data plus location plus device ID is notoriously re-identifiable. “We only share de-identified data” deserves scrutiny, not relief.
- Sensitive inferences are the product. A cycle database can infer pregnancy, pregnancy loss, menopause status, and more — inferences advertisers pay premium rates for and that, post-Dobbs, carry stakes beyond advertising in some states. This is why several apps now offer local-only or anonymous modes; the feature exists because the risk does.
The two-minute privacy audit
- Open the data-safety label (Google Play “Data safety” / Apple “App Privacy”) for your cycle app. Compare it to the marketing page. A gap tells you how the company communicates.
- Check for a local-only or offline mode and turn it on if it exists. Data that never leaves your phone is the only data no breach, subpoena, or acquisition can touch.
- Minimize what you log. The app needs period dates to do its job; it does not need your sexual activity, moods, and medications. Log the sensitive layers somewhere you control — even paper.
- Use the delete-everything control before abandoning any app — and know that deletion requests are another brand promise unless you’re in a state whose law makes them enforceable.
- Ask the HIPAA question about every health service you use: “Is this a covered entity?” Telehealth prescribing platforms generally are for the clinical piece — but their marketing and app layers may not be, which is exactly the seam the current FTC litigation sits in.
What “clinical-grade” actually means — and what to demand of it
You’ll increasingly see health apps advertise “clinical-grade” data handling. The honest definition: handling data to the standards HIPAA requires of covered entities — encryption, access controls, audit trails, no advertising use — even where the law doesn’t technically compel it. That’s a real, meaningful commitment when it’s true, and a marketing phrase when it isn’t. The test is specificity: does the company say what standards, who is accountable, and whether a licensed clinician stands behind the service? Data inside an actual clinical relationship carries duties no app policy matches — a licensed clinician’s confidentiality obligations don’t get revised in a terms-of-service update.
For transparency: this is the standard we’re building to in my own work. At the Tustin practice, your records live where records belong — in a clinical relationship. And AI Longevity Pro, the health app I’m building (currently in beta), is architected to clinical-grade data-handling standards — no ads, no data sale, delete-everything control — precisely because cycle and health data deserve better than the consumer-app default. I’d rather state the standard publicly and be held to it.
Frequently asked questions
Are period tracking apps safe to use?
Most are safe in the everyday sense; the question is privacy, and it varies enormously by app. Run the two-minute audit above — the data-safety label answers more than any review.
Is my Oura or Apple Watch cycle data covered by HIPAA?
No — same consumer-wellness category, same answer. Platform policies differ meaningfully on encryption and on resisting data requests, but that’s company policy, not HIPAA protection.
Can my cycle data be subpoenaed?
Data a company holds can be legally demanded from that company, subject to its policies and jurisdiction. Local-only data on your device has stronger legal protections. This is not legal advice — for concerns at this level, consult a lawyer; for app choice, prefer local-only modes.
Does deleting the app delete my data?
No — deleting the app removes it from your phone, not from the company’s servers. Use the in-app account-deletion flow first, then delete the app.
What’s the most private way to track my cycle?
Paper or a local notes file is unbeatable. Among apps: local-only mode, minimal logging, no third-party login. And if you’re tracking because something feels wrong — cycles changing, symptoms mounting — the better question may be what the changes mean, which is a clinical conversation, not an app feature.
Dr. Brandon Bright is a Doctor of Acupuncture and Oriental Medicine (DAOM), Licensed Acupuncturist in California, and Functional Medicine University-certified. He runs a multi-modality holistic medicine practice at 13732 Newport Ave STE 2, Tustin, CA 92780. Phone: 714-206-7883. He is the founder of AI Longevity Pro (in beta). He is not a medical doctor and not a lawyer; this article is educational, is not legal advice, and describes the regulatory landscape as of August 2026. The FTC lawsuit referenced is an unresolved allegation, not a finding of wrongdoing.