Live data from Hacker News

Period tracking app, Flo, found to be selling user data to Meta

femtechdesigndesk.substack.com

191–200 of 285 posts

Re: Period tracking app, Flo, found to be selling user data to Meta

#191

Earlier quoted context omitted.

Yes, it is useful for me as a partner to know, ideally without having to ask her, and not important for her to be notified, since without the notification she'll notice it anyways sooner or later...

I'm sorry but this is bordering on parody to me. The way she would notice it "sooner or later" is by her bleeding on her clothes and possibly even furniture. In what world is it important for you to just know about it and somehow not important for her to avoid that?

> The way she would notice it "sooner or later" is by her bleeding on her clothes and possibly even furniture.

No, many can feel it beforehand, and you notice it when you go to the bathroom before as well, as certain things change their properties slightly, it's not a "nothing" phase and then "floods out of your body".

It's borderline parody how little education there is for males when it comes to things like this.

Re: Period tracking app, Flo, found to be selling user data to Meta

#193

Earlier quoted context omitted.

Lots of reasons why you would miss a period that aren't pregnancy related. But that's not the point. Missing a period opens you up to further scrutiny and investigation by the state. Now they will start seeing if you've made out of town trips or perhaps subpoena your chat log to see what you've said to friends and family. It's not enough to prosecute, it is enough to start an investigation.

Is there any precedent of subpoena-ing chat logs, or locale information, based on (illegally obtained information of) a missed period; or is this Handmaid's-Tale-fantasy territory?

> illegally obtained information

It's not illegal to purchase bulk data without a warrant. [1]

It should be.

So yes, there is precedent of prosecutors buying bulk data and using it in prosecutions.

In fact, that's basically a huge part of the "value add" of palantir.

[1] https://www.npr.org/2026/03/25/nx-s1-5752369/ice-surveillanc...

Re: Period tracking app, Flo, found to be selling user data to Meta

#194
post #105
post #97

Earlier quoted context omitted.

A comparable FOSS app called Drip has been on F-Droid since forever.

Drip has a paradoxical flaw: by trying to be extremely inclusive and making a "gender-neutral" app (without the colour pink) to include trans people, it discourages some people from using it. At least, my friend told me she thought the design was ugly and was looking for a "cute" app, so she ended up using Flo instead of Drip despite my many warnings. I think FLOSS apps often forget that not everyone is a developer o…

I seriously doubt that the vast majority of women would avoid using a period tracking app just because it's not pink and stereotypically girly. Frankly, I find the notion vaguely offensive.

iOS/watchOS has had period tracking functionality with completely sterile design and people use it just fine.

Re: Period tracking app, Flo, found to be selling user data to Meta

#196

Earlier quoted context omitted.

That seems entirely unironic and reasonable, though?

100% reasonable (and often necessary - pill shopping, psychiatric concerns, etc. And not irony in the Act itself, more people's perception of its intent.

It is not reasonable to disregard patients' consent so generally. Specific purposes could have specific exceptions.

Re: Period tracking app, Flo, found to be selling user data to Meta

#197

If the app could make another $0.05 selling your location to kidnapping gangs, they'd do it. There's no such thing as an app that cares about your privacy or your interests.

They'd only do it as long as the risk of getting caught and the punishment when caught made it worth it.

If the authorities that are supposed to enforce GDPR (and other data protection laws around the world) were doing their job, app makers would be a lot more careful with what they embed and what data they send where. Because these authorities don't seem to have been doing anything useful, it's now so normalized that you could probably send a $20M fine to every major app and be right about it.

Re: Period tracking app, Flo, found to be selling user data to Meta

#198
post #137

Earlier quoted context omitted.

I did a quick review of what FOSS options are currently out there https://news.ycombinator.com/item?id=47936103

There are a plethora of open-source implementations available on F-Droid. They need to be looked at for privacy before choosing one, but there are completely offline ones.

If I had confidence I could maintain it, I would love to work on a PWA one

Re: Period tracking app, Flo, found to be selling user data to Meta

#199

Earlier quoted context omitted.

The spying part requires a server. If you use GrapheneOS, you can enable or disable internet access for each app.

> If you use GrapheneOS, you can enable or disable internet access for each app. Not sure what information you're expecting the app in question to surface if you disable internet access for it.

geo-positioning, maps, way-finding, directions, time of day, calendar, lunar cycle, calculator, notes, language translation, calculator, games, contacts, etc.

Re: Period tracking app, Flo, found to be selling user data to Meta

#200
Yikes - selling "When did I last Orgasm" to Mark Zuckerberg's team seems like an undesirable "leak" of information.

.. To be clear, "wired app to standard ad-tech surveillance plumbing, sending concepts like user logged period and pregnancy mode entered, through its pipes, to improve ad revenues through Meta's targeting platform" .. ad-events .. this is the kind of behavior that happened, in plain-ish speaking terms, per what I read in my non-expert capacity.

Q: (answered) Now I want to know who runs (ran?) Flo - can we find their Board of Directors & C-level people on LinkedIn to profile what kind of industries lead to this kind of (I believe) privacy violating behaviors? It's a biased question on my part, as Correlation is not Causality! Onwards ..

My limited, biased, AI-driven research suggests the violating behavior ran from June 2016 through February 2019, and that generally the Company was designed to be consumer-app with subscriptions and is healthcare-adjacent, targeting an unregulated non-HIPPA market.

- INVESTORS = consumer subscription apps with ad-driven growth loops

- BUSINESS MODEL =

(1) free or freemium consumer apps where

(2) growth depends on paid acquisition through Meta/Google/TikTok ad platforms, which

(3) requires sending conversion events back to those platforms to optimize ad spend, and

(4) the SDKs that do this are designed by ad networks to hoover up everything by default.

- EXECUTIVE =

* No Privacy / Data Protection C-level officers during violating period

Post reply on HN