Period-tracking app Stardust came under fire after a Mozilla investigation found it was sharing sensitive user information with analytics company RudderStack. The flagged data included birth date, birth control method, reproductive goals, and logged symptoms.

What information was reportedly shared

According to the findings, the records were tied to a unique identifier rather than the person's actual name. However, using identifiers doesn't necessarily eliminate every privacy risk, especially when different types of personal information are combined.

Health apps can store particularly sensitive data. That's why any transfer to outside companies raises concerns about who can access the information and how it's being used.

Why this case matters

Users typically hand over intimate information to apps expecting it to be used only to provide the requested service.

When an app uses outside analytics tools, it's essential that it clearly explains what data it sends, why it sends it, and how long it's retained.

Advertisement ยท in-article

The risk of digital health data

Reproductive information can reveal deeply personal aspects of someone's life. Exposure, a leak, or misuse could lead to consequences that go well beyond targeted ads.

The case is another reminder of how important it is to review permissions, privacy policies, and options for deleting an account and its stored data.

What users can do

Anyone using health apps should check:

  • What information the app requests.
  • Which outside companies receive data.
  • Whether the service can be used without providing unnecessary data.
  • How to request that information be deleted.
  • Whether there are options to opt out of analytics tracking.

A wake-up call for the industry

Health and wellness apps need to offer clearer privacy controls than a typical app.

User trust will depend on companies minimizing data collection to what's strictly necessary and clearly explaining how each piece of data is processed.