The Cycle Tracking app built into iOS’s Health app is E2EE.
That's really helpful! I just checked on this and you need to enable 2FA as well: "Health data can be stored in iCloud. End-to-end encryption for Health data requires iOS 12 or later and two-factor authentication. Otherwise, the user’s data is still encrypted in storage and transmission but isn’t encrypted end-to-end. After the user turns on two-factor authentication and updates to iOS 12 or later, the user’s health…
Ask HN: E2E Encrypted Period Trackers?
21–23 of 23 posts
Re: Ask HN: E2E Encrypted Period Trackers?
#22Re: Ask HN: E2E Encrypted Period Trackers?
#23If Apple cared more about privacy, they could address this with a category of enforced local-only apps. A local-only app would not be able to access the network or interact with other apps. It’s data could be backed up and synced via iCloud but not by any other means. Side channels aside, this would avoid data leaks.
Except if Apple receives a warrant for the iCloud data surely?
(a) Company that wants to make as much money as possible from the use of their app. They will use tracker SDKs, sell data directly, sell data through aggregators, etc. And they’ll cooperate with subpoenas (but probably try to charge for it). And they might even cooperate with Texans who want to sue people under their bizarre law.
(b) Apple, which makes money off hardware, iCloud services, and to a limited extent, advertising. They will cooperate with subpoenas, but they also have the legal resources to fight them. And, for something like their customers’ health data, they quite likely will fight.
With choice (a), law enforcement and anyone else who wants to pay gets the data. With choice (b), law enforcement might get the data. I know what I would choose.
Obviously I would prefer (c), the hypothetical version of Apple with stronger iCloud backup encryption.