lunabia

Cycle app privacy: where your data actually lives

· 6 min read

Cycle data reveals more about you than almost anything else you type into a phone. Seven questions to ask any cycle app, and how Lunabia answers them.

A woman sits in bed in the evening, holding her phone in her hand.
Photo: cottonbro studio, Pexels (Pexels License)

A cycle app knows when you have your period. Which means it also knows when you don't. It knows whether you're trying to get pregnant, whether it worked, and sometimes whether the pregnancy didn't last. It knows when you had sex, if you log it, and how you feel on which days. Hardly anything you type into a phone is this intimate. And yet very few people ever read where that data goes. This piece helps you ask the right questions.

Why cycle data is different from other data

Legally, it counts as health data. The General Data Protection Regulation gives it special protection in Article 9, alongside data about religion, sex life or ethnic origin. An app may only process it with your explicit consent, and it may not use it for purposes you haven't agreed to.

In practice, it's valuable. Anyone who knows a woman is pregnant knows she will spend a lot of money over the next two years, and knows it months before anyone else does. That's why cycle and pregnancy data is so interesting to advertising networks, and why several large providers have run into trouble in recent years: data from their apps went to Facebook, Google or analytics companies while the privacy policy claimed something else. In 2021, the US Federal Trade Commission held one of the biggest providers to account for exactly that.

And depending on the country, it's dangerous. In places where abortion is a crime, data from apps and search histories has already been used as evidence. In Germany that isn't an issue today. But data that ends up on someone else's servers tends to stay there longer than laws stay the same.

Seven questions for any cycle app

You don't have to read a privacy policy from start to finish. These seven questions are enough, and you can usually find the answers in five minutes.

1. Does the app work without an account?

The best kind of data sharing is the kind that never happens. An app that keeps everything on your phone has nothing to sell, lose or hand over. If an app forces you to create an account the first time you open it, it has already decided that it wants your data on its servers.

2. Where are the servers?

Inside the EU, the GDPR applies directly. Outside it, you need additional contracts, and courts have struck down the validity of those more than once. "We take privacy very seriously" is not a location. "Data centre in Frankfurt" or "EU region" is.

3. Are there advertising or analytics components inside?

Most apps include third party components: for crash reports, for usage statistics, for advertising. Each one of them sends data to its maker, often more than the app provider itself knows about. The privacy policy has to name them. If you see Google Analytics, the Facebook SDK, Firebase or an ad network listed, data is leaving the app, no matter what the rest of the text says.

4. Does the app ask for things it doesn't need?

A cycle can be calculated from the date of your last period. Nobody needs your name, your date of birth, your phone number or your contacts for that. Every detail an app asks for that the feature doesn't actually require is a detail someone else wants.

5. Can you delete everything?

Not just the account, but the data behind it. The GDPR gives you that right. A trustworthy app has a button or an address for it, and it tells you how long it takes and what remains afterwards, in backups for example.

6. What happens if the company is sold?

This is in almost every privacy policy, usually under "business transfers", and it's there because it happens. If your data is part of what gets sold, the buyer's rules apply from then on. Look at whether the app promises to ask you in that case, or only to inform you.

7. Is the policy written so you can understand it?

This isn't a side issue. A privacy policy that runs twenty pages and mentions "legitimate interests" on every other page is written that way so you won't read it. A company that does very little with your data can say so on a single page.

How Lunabia handles it

We build a cycle app ourselves, so the seven answers belong here.

Lunabia works without an account. Everything you enter sits on your phone first, and if you never create an account, that's where it stays. You only need an account if you want to see your data on a second device or protect it against loss. It consists of an email address and a six digit code we send you. No password, no name, no phone number, no advertising ID.

The database and the photo storage are hosted with Cloudflare in data centres in the EU, with the photo storage locked to the EU jurisdiction. Lunabia is operated by Fluxera LLC, and the privacy policy states openly what that means and what the processing is based on. We think it's better to write that down than to invent a seal of approval.

The app contains no advertising components, no analytics components and no tracking pixels. Neither does this website: it sets no cookies and loads nothing from third party servers, not even the fonts. We don't know how often you open the app, and we don't want to know.

The app asks for what each feature needs, and nothing else. For your cycle, that's the first day of your period. From your second entry onwards, the prediction uses your own cycles instead of 28 days, and that calculation happens on your phone.

For locking, there's a code inside the app, separate from your phone's lock screen. Someone holding your phone doesn't automatically see your calendar.

And on deleting: without an account, you delete the app and everything is gone. With an account, you write to the address in the privacy policy and we delete the account along with everything attached to it.

What you can do yourself

A few things that apply no matter which app you use:

  • Take a look at old cycle apps on your phone. If you no longer use one, don't just delete the app, have the account deleted too. Otherwise the data stays where it is.
  • Check the permissions. A cycle app needs no access to your location, your contacts or your microphone.
  • Use your phone's lock screen and, if the app has one, its own lock too.
  • With a new app, read the privacy policy using the seven questions above. Five minutes is enough to rule most of them out.

You don't have to trust anyone who tells you they take your data seriously. You can go and check.

Frequently asked questions

Are cycle apps safe?

That depends on the app. A safe app works without an account, contains no advertising or analytics components, keeps its servers in the EU and makes deletion easy. You can check all of this in the privacy policy in a few minutes.

Which cycle app is GDPR compliant?

Any app offered in the EU has to comply with the GDPR. The difference lies in how much data it collects in the first place and where it sends that data. Less data and servers in the EU are the two points that matter most.

Can I use a cycle app without an account?

With some apps yes, with many no. Lunabia works without an account, and in that case all your data stays on your phone. You only need an account to sync between several devices.

What happens to my data if I delete the app?

Without an account, it goes with the app. With an account, it stays on the server until you have the account deleted. That's why it's worth knowing how that works for any app before you install it.

This text does not replace a visit to your doctor or midwife. If something hurts or worries you, call them, even at night.

Keep reading