Live data from Hacker News

Period tracking app, Flo, found to be selling user data to Meta

femtechdesigndesk.substack.com

261–270 of 285 posts

Re: Period tracking app, Flo, found to be selling user data to Meta

#261
post #258

Earlier quoted context omitted.

That sounds not so much as a flaw, as a conscious product decision. And to be honest, doesn't sound like a bad one, not every app needs to work or look the same way, as long as people have choices, they can be responsible for the choices they make. If someone wants a safer but boring app or if someone wants a cute "who gives a fuck about privacy" app, both should be fine.

The problem is that there is literally no other free and open-source app to track your periods, so you're forced to use some proprietary piece of shit that sells all possible medical information about its users.

There seem to be lots of FOSS period tracking apps available, look at the other comments in this submission!

What seems to be lacking, is a FOSS period-tracking app that also lets you share stuff with a partner, which is the reason me and my partner use Flo in the first place.

Re: Period tracking app, Flo, found to be selling user data to Meta

#262

Earlier quoted context omitted.

More "experienced" it than anything, everyone is different of course which is why I'm not saying that everyone needs/don't need it. Thank you but no need for any assurances, my partner lives with me and shares her experience and thoughts about it freely, and I'll continue to listen to what she says she needs/doesn't need :)

Hm. Well, congratulations on being the first man to mansplain menstruation to me. Somebody already knocked out breastfeeding years ago. Pregnancy is still up for grabs, if any men out there want to take a whack at telling me what that's like.

I'm not even explaining anything, just telling you there are other perspectives out there, and sharing my partner's perspective. No need to try to paint yourself as a victim here, and I'm sorry if you took it as "This is how you feel according to me", I was just trying to explain another persons perspective.

Re: Period tracking app, Flo, found to be selling user data to Meta

#263

If the app could make another $0.05 selling your location to kidnapping gangs, they'd do it. There's no such thing as an app that cares about your privacy or your interests.

That's what I'm really trying to convey to many people (I work in privacy products) but people keep talking to me about "trust" which is non-sense, I keep arguing that if the data is on the server of someone, you must always assume that they'll use it somehow, it's a bit ridiculous imo to think otherwise, imagine you are a company and you sit with literal gold in a sqlite DB and you are like hmmm no let's not do this query, that makes no sense from a business standpoint.

Re: Period tracking app, Flo, found to be selling user data to Meta

#264

Earlier quoted context omitted.

Motorola needs to hurry up and release their GrapheneOS devices, I need a new phone soon(TM) (next year or two) and I refuse to give google money to buy hardware to avoid Google.

Buy a used Pixel - it's better for the environment, anyway

+1, I'm pretty happy with my used Pixel, but I feel that buying used is still supporting the manufacturer somewhat. People are more likely to buy another if they got a good price for their old one. And you're driving up used prices which may contribute to others buying new. I don't have a rigorous understanding of this though, would be interesting to see an economist's take.

Re: Period tracking app, Flo, found to be selling user data to Meta

#265

If the app could make another $0.05 selling your location to kidnapping gangs, they'd do it. There's no such thing as an app that cares about your privacy or your interests.

That's what I'm really trying to convey to many people (I work in privacy products) but people keep talking to me about "trust" which is non-sense, I keep arguing that if the data is on the server of someone, you must always assume that they'll use it somehow, it's a bit ridiculous imo to think otherwise, imagine you are a company and you sit with literal gold in a sqlite DB and you are like hmmm no let's not do this…

> imagine you are a company and you sit with literal gold in a sqlite DB and you are like hmmm no let's not do this query, that makes no sense from a business standpoint.

I expect all humans to treat other humans with dignity and respect. I acknowledge that many people will likely fail to meet that expectation, quite often I'm sure. But I'm never going to accept or become an apologist for this asshattery.

It's wrong to violate the privacy and dignity of other people. The correct response when you see people hurting others is not to make up an excuse about "business need", instead some anger, disappointment, and loud condemnation is required.

Stop making excuses for those hurting others so they can make money.

Re: Period tracking app, Flo, found to be selling user data to Meta

#266

Earlier quoted context omitted.

That's what I'm really trying to convey to many people (I work in privacy products) but people keep talking to me about "trust" which is non-sense, I keep arguing that if the data is on the server of someone, you must always assume that they'll use it somehow, it's a bit ridiculous imo to think otherwise, imagine you are a company and you sit with literal gold in a sqlite DB and you are like hmmm no let's not do this…

> imagine you are a company and you sit with literal gold in a sqlite DB and you are like hmmm no let's not do this query, that makes no sense from a business standpoint. I expect all humans to treat other humans with dignity and respect. I acknowledge that many people will likely fail to meet that expectation, quite often I'm sure. But I'm never going to accept or become an apologist for this asshattery. It's wrong…

Yes, I agree that it's wrong, my point is really about the data itself being in their servers. Let's be real, a service nowadays DO have the choice to enable client-side encryption or methodology to be unable to consult data themselves, so any company that chose against that during development phase might have eventual motives of processing the data, my point is really about the blind trust from users which is just wrong from a security standpoint, every trust step added that you can't verify is just "faith" at this point, not security.

Term of services are irrelevant as they are breached all the time, major companies are getting fined all the time for it, we must rely on cryptography, not human trust and people needs to stop being surprised the moment they learn that the data they accepted to leave in cleartext is used, that would be a first step toward forcing the change and using proper security standards.

Want a useful action? Let's change the law to force cryptography regarding user data, attestation, SGX or whatever method (there is plenty), that would be a great start, the fact that in 2026 it's still legal to process user chats in plaintext is mindblowing.

Re: Period tracking app, Flo, found to be selling user data to Meta

#267
post #227

Earlier quoted context omitted.

Unfortunately, companies like Apple (and soon Google as well) are making this unnecessarily hard in their phone ecosystems.

It is actually a perfectly practical choice to completely ignore those ecosystems. I am the founder and active engineer at two companies and two large open source projects and have a family, travel a lot, and have an active social life in Silicon Valley. I also do not use any Apple, Google, Meta, or Microsoft products and exclusively use open source software for all of my work. It turns out none of this is incompatib…

Congrats on your independence! What you're describing is my goal state, but sadly I'm not there yet. It seems like it's the last 10-20% of "sticky" dependencies that always trip me up (granted, some of those are merely "nice to haves" like tap-to-pay, not actually hard barriers). If you get a second, would you mind sharing any general advice and/or specific recommendations that might help me and other like-minded people follow in your footsteps?

Re: Period tracking app, Flo, found to be selling user data to Meta

#268

Earlier quoted context omitted.

It's scary and all, but does it actually happen?

Does what actually happen? Prosecutions for abortions? Yes. Warrants related to people getting an abortion? Yes. A period tracker being used as the jump off point for those prosecutions/investigations? Hard to say, maybe? If the data is being sold it isn't hard to imagine that prosecutors and busybodies aren't currently mining that data.

>Does what actually happen?

The latter. Somebody in a town of dumbfucknowhere, OH wakes up, downloads this data from a commercial company obtained legally or not and then charges an actual person with getting an abortion. It is technically possible, I would factor it in my threat model if it was my problem, but does it actually happen?

I see a potential motive for the person doing this -- either promotion, quota hitting, number bullshitting or religious zeal. They can probably get something out it?

Re: Period tracking app, Flo, found to be selling user data to Meta

#269

Earlier quoted context omitted.

Not just executives. They don't will these things into existence. Someone had to build functionality to send user data to Facebook.

Not to side with this behaviour, but I think if you consent to it in the Ts & Cs then it's legal. And that makes sense - otherwise how else do you agree to things or not agree to them?

The point of laws is that T&Cs don't matter if the law has something to say. If the law e.g. were to criminalize sharing health information in this way, then it doesn't matter if the users agreed; you still go to prison for doing it.

Re: Period tracking app, Flo, found to be selling user data to Meta

#270
post #227

Earlier quoted context omitted.

It is actually a perfectly practical choice to completely ignore those ecosystems. I am the founder and active engineer at two companies and two large open source projects and have a family, travel a lot, and have an active social life in Silicon Valley. I also do not use any Apple, Google, Meta, or Microsoft products and exclusively use open source software for all of my work. It turns out none of this is incompatib…

Congrats on your independence! What you're describing is my goal state, but sadly I'm not there yet. It seems like it's the last 10-20% of "sticky" dependencies that always trip me up (granted, some of those are merely "nice to haves" like tap-to-pay, not actually hard barriers). If you get a second, would you mind sharing any general advice and/or specific recommendations that might help me and other like-minded peo…

First thing is nuke tap to pay. That is surveillance capitalism dependence masquerading as convenience.

Step one, and I am serious, is just use cash. Every time you pay with cash at a drug store, a liquer store, a casino, donation boxes, clothes, that is a tiny bit less information corpos and politicians can buy about how healthy you are, what causes you support, and how to manipulate you.

Just use cash, falling back to cash-purchased prepaid gift cards for edge cases like parking. You will pay more attention to how much you spend, you are helping ensure the unbanked can still participate in society, you are opting out of funding surveillance capitalism with your data, and at a busy restaurant you can just leave cash on the table and leave whenever you want.

From there when you are making a quick trip to the grocery store or something, just leave your phone at home.

Meanwhile, keep your phone in airplane mode full time. Use wifi when you must but do not use cell and see if you can go a month or two without actually having to be reachable every second of every day, but only when you choose to be on wifi.

Whenever you are connected to a cell tower your location is being actively documented and sold at all times, and even worse, you are mentally always ready to be contacted, for a new dopamine hit of information or a new decision to make. When it is off, and you know it is off, you can just focus on driving, on thinking, on processing the shit in the back of your head that wont go away on its own.

Anyway, once you are wifi only, and no longer dependent on your phone for commerce, its just a boring wifi tablet. Now, delete your least productive of your top ten ten most used apps every month until your phone is so boring you find you only use it a couple times a day.

At that point, tackle those final things like GPS and flashlight which could be handled by your own brain plus printed maps, paper maps, and an actual flashlight, a mechanical watch... and then you are free to move about the world comfortably without any electronics at all whenever you want.

People will ridicule you constantly for not having a phone, but those are just addicts feeling threatened.

Post reply on HN