{"id":20485,"date":"2022-12-15T18:43:50","date_gmt":"2022-12-15T14:43:50","guid":{"rendered":"https:\/\/me-en.kaspersky.com\/blog\/reproductive-health-apps-privacy-and-security\/20485\/"},"modified":"2022-12-15T18:43:50","modified_gmt":"2022-12-15T14:43:50","slug":"reproductive-health-apps-privacy-and-security","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/reproductive-health-apps-privacy-and-security\/20485\/","title":{"rendered":"Privacy in reproductive health apps"},"content":{"rendered":"<p>Reproductive health apps have long since ceased to be a simple online menstrual cycle calendar. Now they\u2019re much more than that: today\u2019s apps monitor changes in the body from first menstruation to menopause, help prepare for pregnancy (or prevent an unwanted one), and much else besides. Formerly mostly electronic replacements for paper calendars and notepads, they\u2019ve become an important tool for spotting signs of mental and physical health issues in the early stages.<\/p>\n<p>To get the most out of a reproductive health app, the user must regularly provide a lot of personal information about their condition that they sure wouldn\u2019t want to become public knowledge. And so the question arises: to what degree can you trust the developers of such applications and devices? Unfortunately, the answer isn\u2019t exactly reassuring.<\/p>\n<h2>Tarnished reputation<\/h2>\n<p>Blind faith in reproductive health apps is not recommended, because developers have repeatedly betrayed the trust of users. In 2020 we <a href=\"https:\/\/www.kaspersky.com\/blog\/36c3-period-apps\/32122\/\" target=\"_blank\" rel=\"noopener nofollow\">wrote<\/a> about two quite popular apps\u00a0\u2014 Maya and MIA \u2014 that shared users\u2019 personal information with Facebook.<\/p>\n<p>Generally, apps can share their data with third parties for marketing, research, or other purposes after getting the user\u2019s consent. Usually users give this consent by accepting the privacy policy. The problem is that Maya and MIA <a href=\"https:\/\/media.ccc.de\/v\/36c3-10693-no_body_s_business_but_mine_a_dive_into_menstruation_apps%25252523t=3116\" target=\"_blank\" rel=\"nofollow noopener\">linked up<\/a> to analytics platforms when first launched, and these forwarded private data to the aforementioned social network. In other words, it happened before the user was even given the chance to read the privacy policy and agree (or not) to the transfer of their data.<\/p>\n<p>Maya and MIA are not the only apps accused of neglecting user privacy. In September 2020 journalists at <em>The Wall Street Journal <\/em><a href=\"https:\/\/techcrunch.com\/2021\/01\/13\/flo-gets-ftc-slap-for-sharing-user-data-when-it-promised-privacy\/\" target=\"_blank\" rel=\"nofollow noopener\">analyzed<\/a> the data-sharing activity of a number of apps. It revealed that Flo, another major reproductive health application, shared information directly related to users\u2019 health (for example, date of menstruation onset or start of pregnancy planning) \u2014 again with Facebook.<\/p>\n<p>But why does a major corporation need all this information, and should it bother you anyway? First of all, some data (pregnancy-related, for example), can be useful for more accurate targeted advertising. Advertising targeting pregnant people costs ten times more, as they\u2019re likely planning on spending a lot on new stuff they\u2019ll need for the new addition to the family. Second, even for those who don\u2019t see targeted advertising as a bad thing, the disclosure of such intimate information <a href=\"https:\/\/www.kaspersky.com\/blog\/36c3-period-apps\/32122\/\" target=\"_blank\" rel=\"noopener nofollow\">can impact<\/a> the cost of health insurance, potential employment, and more.<\/p>\n<p>The issue of data-sharing by reproductive health apps escalated this year with the U.S. Supreme Court\u2019s overturning of the <em>Roe v. Wade<\/em> ruling, which guaranteed people in the U.S. the right to an abortion. As a consequence of this decision, several states immediately criminalized abortion. It also sparked a debate about data protection in period tracking apps. The fear is that companies could be asked to <a href=\"https:\/\/www.techtarget.com\/searchcio\/news\/252518189\/Roe-v-Wade-reversal-could-hinder-data-privacy-rights\" target=\"_blank\" rel=\"nofollow noopener\">hand over users\u2019 health data<\/a> to law enforcement agencies. If such a request were granted, the information could be used as evidence in court.<\/p>\n<h2>Okay, so what do I do?<\/h2>\n<p>All this has inevitably prompted a wave of studies on reproductive health-app security. For example, the Mozilla Foundation <a href=\"https:\/\/foundation.mozilla.org\/en\/privacynotincluded\/categories\/reproductive-health\/\" target=\"_blank\" rel=\"nofollow noopener\">analyzed<\/a> the security and privacy of 25 popular apps and devices with the relevant features. So surely that\u2019s the solution right there: simply consult such a list, choose the most secure option, and that\u2019s it. Unfortunately, the privacy policy and security features of a single reproductive health app may differ from country to country \u2014 that is, there\u2019s no definitive data on all the apps because it depends on the region you live in. For this reason, we\u2019ve tried to compile some general tips to help you choose the safest app.<\/p>\n<h3>Read the privacy policy<\/h3>\n<p>Before downloading an app and feeding it very private information about yourself, it\u2019s vital that you read the privacy policy. This can be found in the app description in the App Store and on Google Play\u00a0\u2014 usually somewhere at the bottom of the page.<\/p>\n<p>Admittedly, this is no fun: it\u2019s likely to contain legalese. But when it comes to your reproductive health, we strongly advise that you take the time to go through it. And in doing so, pay attention to the following details:<\/p>\n<ul>\n<li>How and where the app stores the information it collects. There are two possibilities: directly on your device, or somewhere on the developer\u2019s servers. The former is definitely preferable.<\/li>\n<li>If the app of your choice does store data on a server, it\u2019s important to look at what information about you it intends to (and probably will) use for marketing and research purposes. Make sure this data is not directly health-related.<\/li>\n<li>It\u2019s also good if the app gives assurances to share your data with analytics platforms only in anonymized form. Sure, data anonymization is another gray area, and experts often note that new techniques <a href=\"https:\/\/techcrunch.com\/2019\/07\/24\/researchers-spotlight-the-lie-of-anonymous-data\/\" target=\"_blank\" rel=\"nofollow noopener\">make it possible to re-identify users<\/a>. All the same, it does offer some kind of privacy protection.<\/li>\n<li>It\u2019s not uncommon for app privacy policies to refer to specific laws. If so, look up some information about them. For example, it\u2019s a good sign if the app\u2019s policy says it complies with the EU\u2019s General Data Protection Regulation (<a href=\"https:\/\/gdpr.eu\/what-is-gdpr\/\" target=\"_blank\" rel=\"nofollow noopener\">GDPR<\/a>).<\/li>\n<\/ul>\n<h3>Check apps\u2019 reputations<\/h3>\n<p>You may find the current privacy policy satisfactory, but it\u2019s useful all the same to investigate the app\u2019s background. Maybe it used to share users\u2019 health data (like Flo did) or suffered a major leak. Of course past mistakes don\u2019t mean the app can never be trusted again. But if there are any foul-ups, it\u2019s important to find out how the developers responded, and whether they took appropriate measures to prevent a recurrence.<\/p>\n<h3>Ensure login security<\/h3>\n<p>An app needs to password or biometric authentication. After all, if your phone fell into the wrong hands, a stranger would have access to your very personal data. Moreover, having a password can help out in case of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Reproductive_coercion%2523Birth_control_sabotage\" target=\"_blank\" rel=\"nofollow noopener\">reproductive abuse<\/a>. And it\u2019s a bonus if the app checks the strength of your password. For example, the Mozilla Foundation, in its assessment of reproductive health apps and devices, looked to see if they allowed weak passwords, such as \u201c0000\u201d. Indeed, in a program you\u2019ll entrust with a lot of private data, it\u2019s better to set a <a href=\"https:\/\/www.kaspersky.com\/blog\/strong-password-day\/25519\/\" target=\"_blank\" rel=\"noopener nofollow\">strong password<\/a>.<\/p>\n<h3>Decide what you don\u2019t want to share<\/h3>\n<p>Think about what kind of data period-tracking apps generally need. Besides a simple calendar for recording your menstrual cycle, they usually offer to monitor associated symptoms, and assist with pregnancy planning (or, conversely, contraception). It\u2019s important to understand what data the app really requires for your specific needs. For example, if an app with which you\u2019re trying to plan a pregnancy is <a href=\"https:\/\/www.kaspersky.com\/blog\/36c3-period-apps\/32122\/\" target=\"_blank\" rel=\"noopener nofollow\">interested<\/a> in your preferences in manicure, most likely it shouldn\u2019t be trusted.<\/p>\n<h3>Be careful with external links<\/h3>\n<p>The authors of almost every application integrate links to resources of external partners. As regards, reproductive health apps, these can be, among others, online stores or medical institutions. Remember that the program\u2019s privacy policy doesn\u2019t apply to them. So, when following external links \u2014 even from a trusted app \u2014 be on your guard.<\/p>\n<h2>So, what to choose?<\/h2>\n<p>Selecting the right reproductive health application is no easy task and requires a fair bit of research. If you lack the time or inclination, you could do far worse than heeding the advice of those who\u2019ve already investigated the topic. For example, among the apps studied by the Mozilla Foundation, the <a href=\"https:\/\/foundation.mozilla.org\/en\/privacynotincluded\/euki\/\" target=\"_blank\" rel=\"nofollow noopener\">standout<\/a> is Euki, created by the international non-profit <a href=\"https:\/\/womenhelp.org\/\" target=\"_blank\" rel=\"nofollow noopener\">Women Help Women<\/a>. It meets all the criteria we\u2019ve touched upon, and has other interesting privacy features to boot.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-generic\">\n","protected":false},"excerpt":{"rendered":"<p>Why you shouldn\u2019t trust a random period-tracking app, and what to look out for when choosing one.<\/p>\n","protected":false},"author":2684,"featured_media":20486,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1225],"tags":[893,187,43,131],"class_list":{"0":"post-20485","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-privacy","8":"tag-health","9":"tag-passwords","10":"tag-privacy","11":"tag-tips"},"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/reproductive-health-apps-privacy-and-security\/20485\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/reproductive-health-apps-privacy-and-security\/24990\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/reproductive-health-apps-privacy-and-security\/10492\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/reproductive-health-apps-privacy-and-security\/27557\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/reproductive-health-apps-privacy-and-security\/25319\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/reproductive-health-apps-privacy-and-security\/26168\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/reproductive-health-apps-privacy-and-security\/28415\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/reproductive-health-apps-privacy-and-security\/27464\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/reproductive-health-apps-privacy-and-security\/34385\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/reproductive-health-apps-privacy-and-security\/46570\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/reproductive-health-apps-privacy-and-security\/20137\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/reproductive-health-apps-privacy-and-security\/20740\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/reproductive-health-apps-privacy-and-security\/29775\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/reproductive-health-apps-privacy-and-security\/33169\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/reproductive-health-apps-privacy-and-security\/28809\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/reproductive-health-apps-privacy-and-security\/25679\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/reproductive-health-apps-privacy-and-security\/31365\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/reproductive-health-apps-privacy-and-security\/31067\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/privacy\/","name":"privacy"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/20485","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2684"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=20485"}],"version-history":[{"count":0,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/20485\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/20486"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=20485"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=20485"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=20485"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}