What happens to the health data you put in an app?
It depends entirely on the app, and the track record in this category is not reassuring.
In 2021 the FTC settled with Flo Health over allegations that it shared sensitive health information with third parties including Facebook and Google, having told users it would keep that data private. The order was finalised in June 2021.
The three architectures, and what they mean for you
| Where data lives | What it means |
|---|---|
| On your device only | Entries never leave your phone. Nothing to breach on a server, nothing to sell, no account to subpoena. Trade-off: if you lose the phone and have no backup, you lose the data. |
| On the developer's servers | Syncs across devices and survives a lost phone. Also means a company holds your health history, and its policies can change, as can its ownership. |
| Servers plus third-party SDKs | The category that produced the enforcement action above. Analytics and advertising SDKs can transmit data as a side effect of being present, sometimes without the developer fully intending it. |
How to actually check, rather than trust a marketing line
"Your data is safe" is not information. These are:
- Read the App Store privacy label. Apple requires developers to declare what data is collected and whether it is linked to you. Compare the label with what the marketing says — the label is the one with consequences attached.
- Check whether an account is required. An app that works with no account, no email and no login generally cannot be building a server-side profile of you.
- Test it in airplane mode. If the app fully works offline, the data is on the device. This is the most direct test available and it takes a minute.
- Look for a stated retention and deletion policy, and check that deletion is available in the app. Apple requires that any app supporting account creation also offers account deletion within the app.
What the research found about this category specifically
The 2023 BMC Women's Health review of 28 menopause apps reported that 71% had a privacy policy, 64% required a login, only 7% offered two-factor authentication, and 32% indicated third-party data sharing. Roughly a third of the apps in a sensitive health category shared data onward.
Where HormoneLog stands
HormoneLog is being built local-first: entries stay on the device, and the app is designed to work without an account. We are stating this as a design commitment for an app that has not shipped yet, not as a verified property of a released product — and when it does ship, the airplane-mode test above will work on it too. Please use it.
HormoneLog. "What happens to the health data you put in an app?." Baker Ventures LLC, September 4, 2026. https://hormonelog.bakerventuresstudio.com/guides/health-app-privacy