Compare

What cycle apps say they do with your data

Not what I think they do. What they told Apple, and what they wrote in their own privacy policies. Every cell below links to the source it came from, so you can check any of it yourself.

Checked on 2026-08-19.

7 of 9

tell Apple their data may be used to track you across apps and websites owned by other companies.

6

declare that health or sensitive information is linked to your identity, not held anonymously.

1

says deleting your account also pulls back the data it already sent to other companies. One, out of 9.

The table

Ordered by how many kinds of data each app tells Apple may be used to track you, then by whether health data is linked to your identity. Fewest first.

App Tracks you across other companies Health linked to your identity Where your health data lives Sells data Deletion reaches data already shared
Apple Cycle Tracking United States, EEA controller in Ireland Declares none Not declared On your device, end to end encrypted if it syncs to iCloud with two-factor on source Says it does not source No source
Ovia United States Declares none Yes Company servers, AWS in the US source Partly source No source
Moody Month England and Wales Identifiers Not declared Company and supplier servers, inside and outside the EEA including the US source Says it does not source Not addressed source
Clue Germany Identifiers Yes Company servers, in the EU source Says it does not source Yes source
Natural Cycles Sweden Contact Info Yes Company servers, may be processed outside the EEA including the US source Says both source Not addressed source
Bearable England and Wales Contact Info, Identifiers Yes On your device and on company servers once you have an account source Says it does not source Not addressed source
Stardust United States, New York Purchases, Identifiers, Usage Data Not declared Company servers, health data stored against a random account ID source Does not say source Not addressed source
Flo United Kingdom, data processed in the US Purchases, Location, Identifiers, Usage Data Yes Company servers, transferred to and processed in the US source Says it does not source Not addressed source
Glow United States, California Purchases, Location, Contact Info, Identifiers, Usage Data Yes Company servers by default. An opt-in setting keeps health data on the device only. source Partly source Not addressed source

"Declares none" means the app's App Store label has no "Data Used to Track You" section. It is their declaration, not my audit.

If someone asks for your data

A court order is the case where the difference between these policies stops being abstract. Here is what each one commits to, in its own words.

Apple Cycle Tracking
Not addressed for health data. The general policy allows disclosure for law enforcement. source
Ovia
Requires a valid court order or subpoena, rejects invalid requests, and emails you unless legally gagged. source
Moody Month
May disclose to a court, the police or other law enforcement. No notice commitment. source
Clue
No law enforcement or subpoena section in the policy at all. source
Natural Cycles
Only under valid legal process. Commits to contest where it can and to give prior notice where allowed. source
Bearable
Discloses on court order and to police. Says a UK company need not comply with US criminal subpoenas. source
Stardust
Discloses on lawful requests by public authorities for national security or law enforcement. source
Flo
Discloses on subpoena or court order, including to meet national security or law enforcement needs. source
Glow
Shares with law enforcement and private parties on a good faith belief standard. source

Where their own sources disagree

Each app declares itself three times: to Apple, to Google, and in its own policy. Those three do not always match. Every one of these is the company against itself.

  1. Flo

    Three primary sources, three different pictures. Google Play says no data is shared at all. Apple says four categories are used to track you across other companies' apps. Flo's own policy names AppsFlyer, Firebase and TikTok Ad Manager.

    source 1source 2source 3

  2. Natural Cycles

    One document says both things. The main policy says it never sells your personal data. The US addendum in the same document carries the statutory notice that it may sell sensitive personal data.

    source 1

  3. Stardust

    Google Play declares no data shared and does not list health data as collected at all. Apple's label lists Health and Fitness, and Stardust's own health policy describes sharing health data with vendors and in a sale or bankruptcy.

    source 1source 2source 3

  4. Moody Month

    The policy says it will never sell your data and that health data is not shared with any third party. Apple says Identifiers are used to track you across other companies' apps, and Google Play says Device IDs are shared for advertising.

    source 1source 2source 3

  5. Moody Month

    Its own Apple label puts Health and Fitness, Sensitive Info and Contact Info under data not linked to your identity, while only Identifiers are linked. The policy describes health logs saved to an account with your email address.

    source 1source 2

  6. Glow

    It says it does not sell or share health information, which reads reassuring until you notice the scope. The same policy discloses that identifiers and network activity are sold or shared with analytics and advertising providers.

    source 1

Where Niyora sits, held to the same standard

Niyora is not in the table above, and I want to be straight about why. It is not publicly listed on the App Store yet, so it has no App Store privacy label. You cannot check my claims the same way you can check theirs. Take what follows as my statement, not as an independent declaration.

There is no account, so there is nothing to tie your writing to a name. Your history stays in the app's private storage on your phone, and the text you wrote is encrypted with AES-256 using a key held in the iOS Keychain that does not sync to iCloud or to backups. There is no copy on a server I control, because there is no such server.

One thing does leave your phone. To turn what you wrote into a reflection, the text is sent to Google's Vertex AI. Before it goes, an automatic scrub swaps certain personal details for stand-ins, and swaps them back in the reply. That scrub is careful but not exhaustive: a bare name with no cue around it will go through, and the emotional content of what you wrote always goes through. Google also sees your device's IP address, as it would with any request. Under the enterprise terms, that text is not used to train Google's models and is not reviewed by a human by default.

So the honest version is not "nothing leaves your phone". It is "one thing leaves, you can read exactly what and why, and none of it is tied to an account".

How I checked this

Three source types only: each app's Apple App Store privacy label, its Google Play data safety entry, and its own privacy policy on its own domain. No news articles, no reviews, no reputation. Where a source did not answer a question, the cell says so instead of guessing.

These labels are self-declared. Apple and Google do not verify them, and a label can be out of date. That cuts both ways: an app may be doing less than its label suggests, or more. What the table shows is what each company chose to declare, on 2026-08-19.

I left out Cara Care, which appears elsewhere on this site as a comparison. Its iOS and Android builds have not been updated since October 2020, it carries no App Store privacy label at all, and it is a gut-health tracker rather than a cycle app. Putting it in this table would have padded the count without telling you anything true.