Live data from Hacker News

Period tracking app, Flo, found to be selling user data to Meta

femtechdesigndesk.substack.com

31–40 of 285 posts

Re: Period tracking app, Flo, found to be selling user data to Meta

#31

I don't actually see this as a problem, and instead it's a PSA everyone needs to internalize: If you put data onto a networked device it may be sent to some place else. If you don't want your data being shared: Use a device that does not have any networking capability (both hardware and software wise) Use a pen and paper, you can shred and destroy as you see fit. If you're using an application on a mobile device with…

There are four open source period tracking apps on F-droid. I didn't do a full investigation of the source code, but unless your data is being uploaded outside the app (e.g. for backups), I feel safe assuming it will stay local only.

Re: Period tracking app, Flo, found to be selling user data to Meta

#32

Why would anyone think that a non-HIPPA compliant app would keep medical information private to the level of security needed for medical data? Flo has definitely breached user trust, but that trust seems misplaced from the get-go.

People just wanna track stuff, they don't really look into is something HIPPA compliant or read the ToS. App store push, recommendation, word of mouth are what makes the app like this spread, not really details HIPPA compliance.

Re: Period tracking app, Flo, found to be selling user data to Meta

#34

I don't actually see this as a problem, and instead it's a PSA everyone needs to internalize: If you put data onto a networked device it may be sent to some place else. If you don't want your data being shared: Use a device that does not have any networking capability (both hardware and software wise) Use a pen and paper, you can shred and destroy as you see fit. If you're using an application on a mobile device with…

that is a really fucked up view

Less a f-u-view, more a f-u-world, the above is pragmatic advice about the actual IRL challenges of keeping data secure.

Further, a view that ignores many real world digital data risks faced by those considered to be useful targets; eg: compromised supply chains delivering "pre hacked" hardware with discreet wifi chips or hidden out of band comms, etc.

Re: Period tracking app, Flo, found to be selling user data to Meta

#35
post #19

I don’t have the right configuration of equipment to use an app like this, but does anyone know why this needs to be a service-driven app? What piece of functionality requires a server to track your health?

The spying part requires a server.

If you use GrapheneOS, you can enable or disable internet access for each app.

Re: Period tracking app, Flo, found to be selling user data to Meta

#36
post #11
post #5

Earlier quoted context omitted.

privacy legislation would just solve the problem by itself though.

Privacy legislation by itself does not solve the problem; what Flo did was already illegal. Effective enforcement is also necessary.

They need to make an example out of these companies. If your whole business model is built around handling sensitive data, and you are caught shipping off that data to brokers, you should be liquidated or at least fined to within an inch of bankruptcy, as basically all of your profits are a sham.

Re: Period tracking app, Flo, found to be selling user data to Meta

#37

It's really sad that we have all this technology but we can't trust any of it.

I'll make a period tracker for you for 5 bucks a month. You won't buy it, because it costs 5 bucks a month. So I'll have to find alternative monetisation strategies.

Re: Period tracking app, Flo, found to be selling user data to Meta

#40

I don't actually see this as a problem, and instead it's a PSA everyone needs to internalize: If you put data onto a networked device it may be sent to some place else. If you don't want your data being shared: Use a device that does not have any networking capability (both hardware and software wise) Use a pen and paper, you can shred and destroy as you see fit. If you're using an application on a mobile device with…

It sounds like the real solution to this is to be able to control permissions at an OS level for network per app, as you would be able to do if you had root access. I have no idea why regular Android distros don't allow you to do this, it seems like a really sensible thing to expose in app settings given the permissions model of Android.
Post reply on HN