AV TEST
  • Tests
    • Particuliers
      • Windows Antivirus
      • MacOS Antivirus
      • Android Antivirus
    • Entreprise
      • Windows Antivirus
      • MacOS Antivirus
      • Android Antivirus
    • Internet of Things
      • Smart Home
      • Caméras IP
      • Smart Watches & Fitness-Tracker
      • Autre
      • Tous les tests IoT
    • Produit de sécurité informatique
  • Nouvelles
    • Toutes les actualités
    • Awards
    • Antivirus pour Android
    • Antivirus pour MacOS
    • Antivirus pour Windows
    • Tests mandatés
    • Tests de réparation pour Windows
    • Recherche
    • Internet des objects (IoT)
    • Contrôle parental
    • Tests de VPN
    • Autres tests
    • Divers
  • Services
  • Resources
    • À propos de l'institut
      • Institut
      • Certification
      • Procédés de test
      • Emplois
    • Statistiques
      • AV-ATLAS.org
      • Logiciels malveillants
      • Spam
    • Media
      • Presse
      • Rapports de Test
      • Publications
    • Newsletter
    • FAQ
  • Contact
    • Contact
    • Conditions générales
    • Mentions légales
    • Confidentialité

©  2026 AV-TEST  | SITS Deutschland GmbH

AV TEST AV TEST
  • Tests
    • Particuliers
    • Entreprise
    • Internet of Things
    • Produit de sécurité informatique
    • Windows Antivirus
    • MacOS Antivirus
    • Android Antivirus
    • Windows Antivirus
    • MacOS Antivirus
    • Android Antivirus
    • Smart Home
    • Caméras IP
    • Smart Watches & Fitness-Tracker
    • Autre
    • Tous les tests IoT

    Contactez-nous

    Pour toute demande adressée à l'institut AV-TEST, veuillez utiliser le formulaire de contact ci-dessous.

    Kontakt
  • Nouvelles
    • Toutes les actualités
    • Awards
    • Antivirus pour Android
    • Antivirus pour MacOS
    • Antivirus pour Windows
    • Tests mandatés
    • Tests de réparation pour Windows
    • Recherche
    • Internet des objects (IoT)
    • Contrôle parental
    • Tests de VPN
    • Autres tests
    • Divers
    Service

    Network Threat Protection -
    Testé et certifié par AV-TEST

    SAVOIR PLUS >

    Contactez-nous

    Pour toute demande adressée à l'institut AV-TEST, veuillez utiliser le formulaire de contact ci-dessous.

    Contactez-nous
  • Services
  • Resources
    • À propos de l'institut
    • Statistiques
    • Media
    • Newsletter
    • FAQ
    • Institut
    • Certification
    • Procédés de test
    • Emplois
    • AV-ATLAS.org
    • Logiciels malveillants
    • Spam
    • Presse
    • Rapports de Test
    • Publications

    Abonnez-vous à
    la Newsletter AV-TEST

    savoir plus
  • Contact
    • Contact
    • Conditions générales
    • Mentions légales
    • Confidentialité
  • IOT-TESTS.ORG
  • AV-ATLAS.ORG

Dernières Actualités

11 août 2010

Women’s Health – Android Privacy

Apps for tracking menstrual cycles and personal health have become part of everyday life for many people. With just a few taps, users can log their periods, record symptoms, or calculate fertile days. These applications promise better insights into personal health and an easy way to monitor changes over time.

But as these apps continue to grow in popularity, an important question arises: What actually happens to all the sensitive data users enter? Information about menstrual cycles, sexual health, or even family planning intentions is among the most personal data imaginable. That makes it essential to understand how this information is collected, stored, processed, and potentially shared with third parties.

Using our relatively new Android Privacy Analysis methodology, we examined 17 of the most popular Android applications in this category. In this article, we take a closer look at the results, assess how well these apps respect user privacy, and highlight which applications stand out positively—and which may be better avoided.

The figure below shows all applications analyzed so far, including version numbers and download counts at the time of testing. We aimed to cover a broad range of popular and widely used apps to ensure relevance. While we make no claim of completeness—there are simply too many apps in this space—we believe the selection provides a representative overview. Detailed analysis results for these and all other applications we have tested are available on the AV-TEST Thread Intelligence Platform AV-ATLAS under Android Privacy. 

More information about our privacy analysis methodology and certification process can also be found on our website.

Analyzed FemTracker Apps in overview.

prev slider
next slider

Mobile women’s health apps such as Clue, Flo, and Clover have evolved from simple period calendars into sophisticated, data-driven health platforms. At their core, they rely on users regularly entering information such as the start and duration of periods, symptoms, moods, and physical changes. The apps then process this data to identify patterns and predict future events such as menstruation, ovulation, or fertile windows.

Technically, these predictions are usually based on a combination of statistical models and rule-based algorithms. Some apps also employ machine learning to improve accuracy as more individual and anonymized user data becomes available. Depending on the application, external data sources such as smartwatches or fitness trackers may also be integrated to incorporate factors like body temperature, heart rate, or sleep patterns.

The collected information often extends far beyond basic cycle data. Many apps store highly personal details including sexual activity, contraceptive methods, and emotional states. While this allows for more accurate predictions and personalized insights, it also creates extensive collections of sensitive information that reach deep into users’ private lives.

This is where the balance between convenience and privacy becomes critical. The more personalized an app becomes, the more data it requires—and the greater the responsibility to handle that data appropriately. One thing users certainly do not want is to see their intimate information shared with third parties.

The Analysis

We have already described our privacy analysis methodology in detail in previous articles, including our examination of dating apps. In short, the goal is to assess how the use of a particular app may negatively impact a user’s privacy.

Certain app categories naturally pose greater privacy risks because they require highly sensitive information to provide their intended functionality. This makes it especially important that these apps avoid collecting unnecessary data and, above all, refrain from sharing sensitive information with third parties. The collection of advertising-related data would also seem questionable—and arguably inappropriate—for apps in this category.

At the same time, transparency is essential. Users must be clearly informed about what data is collected, how it is processed, and whether it is shared. Only then can they make an informed decision about whether the benefits of the app justify the disclosure of their personal information.

Permissions

Reviewing the permissions requested by an app is often the first indication of potential unnecessary data collection. In theory, the apps examined here require very few permissions. Access to local storage is reasonable, and internet access is obviously necessary. If the app supports external devices such as health-tracking wristbands, Bluetooth access may also be justified. Beyond that, permissions granting access to sensitive device functions or user data should generally not be required.

Requested permissions per app

prev slider
next slider

However, our analysis revealed that many apps request considerably more than that. One of the first things that stands out is that nearly all applications—except Premom and Read Your Body—access Android’s Advertising ID (Ad ID). This pseudonymous identifier allows apps to recognize users for personalized advertising purposes. While it does not directly use personal information such as names or email addresses, it enables cross-app tracking and the creation of detailed user profiles.

Android has introduced Privacy Sandbox and AdServices to reduce data sharing and cross-app tracking by moving more processing onto the device itself. Most of the analyzed apps support these newer, more privacy-friendly advertising technologies. Only Premom and Read Your Body avoid both the traditional Ad ID and the newer AdServices entirely. Lady Cycle and Ada still rely solely on the older Ad ID. Importantly, neither advertising identifier is actually necessary for the core functionality of these applications. We were therefore pleasantly surprised to find at least two apps—Premom and Read Your Body—that completely avoid advertising-related user profiling.

Another notable finding is that four of the seventeen apps analyzed include permissions for location access. Maya, Read Your Body, Premom, and Ovy all reserve the right to access both approximate and precise GPS location data. Of these, only Maya’s privacy policy explicitly mentions collecting location information, although it does not explain why. While we did not observe active location tracking during our tests, that does not necessarily mean it never occurs under specific circumstances. Regardless, location access seems unusual for this type of application.

Third-Party Trackers

Today, almost every Android application contains third-party software components integrated for various purposes. Common examples include Google Crashlytics and Firebase Analytics, which collect crash reports and application diagnostics. However, many third-party components are specifically designed to analyze user behavior. Examples include AppsFlyer, AppLovin, and Facebook tracking technologies.

These trackers can collect a wide range of information, including device characteristics, installed applications, usage patterns, and interactions with advertisements. Such data is extremely valuable for advertising platforms and marketers.

For developers, integrating trackers—especially when combined with advertising networks—can provide a significant source of revenue. In general, the more tracking solutions an app integrates, the greater its monetization potential.

Integrated trackers and number of trackers with observed activity

prev slider
next slider

What makes this particularly noteworthy in the context of women’s health apps is that nearly all of them already require a paid subscription to unlock their full functionality. Read Your Body, for example, cannot be used at all without a subscription. In our view, this significantly weakens any justification for advertising-based user profiling. Nevertheless, only a small number of developers choose to avoid it.

Positive examples include Read Your Body, Clue, Lady Cycle, and Ada. These apps contain very few third-party components, and the ones they do use are primarily limited to crash reporting and diagnostics. We found no evidence of explicit advertising tracking. All other applications contained at least one tracker whose activity could be clearly verified.

One issue we repeatedly encounter—and which affected every app analyzed in this study—is that third-party components often begin communicating and collecting data before the user has had a chance to read and accept the privacy policy. Strictly speaking, this may constitute a GDPR violation. While we would not classify this as a severe issue in most cases, it is worth highlighting.

User Information and Privacy Policies

A key part of our analysis involves evaluating the information provided to users regarding data collection, processing, and sharing. In many ways, this is the most important aspect of privacy protection. Users can only make informed decisions if they clearly understand the consequences of using a particular application. All apps examined in this study deserve credit for providing comprehensive privacy policies. In fact, listing an app on the Google Play Store without one is no longer possible.

In most cases with the apps analyzed, the descriptions of data collection practices are reasonably detailed. However, a recurring issue is that many privacy policies fail to disclose all integrated trackers, including some that we were able to verify as active. This is especially problematic when those trackers are designed for advertising and behavioral profiling, as users have a right to know about such data collection. We generally attribute these omissions to insufficient diligence rather than deliberate concealment.

Apps that performed particularly well in this area include both versions of My Period Calendar, Premom, Ovy, Clue, and Lady Cycle. While some of these applications—Ovy, for example—contain a substantial number of third-party components, they also disclose each of them transparently in their privacy policies. On the negative side, Maya and Musa stood out for apparently failing to mention any of their integrated trackers at all.

Conclusion

Overall, our findings show that this category includes several applications that handle privacy reasonably well.

In particular, Lady Cycle impressed us with its almost complete absence of tracking. Clue and Ada also performed well. While none of these apps are entirely free from minor privacy shortcomings, the issues we identified are generally limited in scope and not especially critical. For users who value both functionality and privacy, these applications currently represent some of the better options available in the women’s health app market.

The Clue app on the Google Play Store and in the analysis on avatlas.org

The Flo app on the Google Play Store and in the analysis on avatlas.org

prev slider
next slider

Résultats
actuels

  • Windows
  • MacOS
  • Android
  • Archives

  • Windows
  • MacOS
  • Android
  • Archives

  • Smart Home
  • Caméras IP
  • Smart Watches
  • Autre
Service

Network Threat Protection - Testé et certifié par AV-TEST

En savoir plus
Service

Threat Intelligence Platform par AV-TEST

Démarrer AV-ATLAS.org
Service

AV-TEST et la loi sur la cyber-résilience

En savoir plus

Abonnez-vous à la newsletter AV-TEST

Inscrivez-vous maintenant
Abonnez-vous à la newsletter AV-TEST
Inscrivez-vous maintenant
AV TEST

Contactez-nous

Pour toute demande adressée à l'institut AV-TEST, veuillez utiliser le formulaire de contact ci-dessous

Vers le formulaire de contact

Plan du site

  • Institut
  • Tests
  • Nouvelles
  • Certification
  • Publications
  • Contact

Contact

  • SITS Deutschland GmbH
  • Klewitzstraße 7
  • 39112 Magdeburg, Germany
  • E-Mail: info@av-test.com
  • Telefon: +49 391 6075460
  • Fax: +49 391 6075469

Conditions générales | Protection des données | Mentions légales

©  2026 AV-TEST  | SITS Deutschland GmbH