The group chat has a new question, and it arrives the way these questions always do: as a screenshot, at night, with no context. "Millions of women's intimate health data has been sold by menopause apps - and it's still happening." Someone read it. Someone forwarded it. And someone else - the one who logs every hot flash at 3 a.m. like it's a part-time job - has gone very quiet.
That quiet one is probably you. Because the moment the sentence lands, you do the math: you have three years of hot-flash logs, sleep scores, medication notes, and mood entries in an app you chose because it felt responsible. Logging felt like taking control. And now the investigation says the log itself was the product.
The investigation is real. The Independent's August 2026 IN FOCUS report found that menopause and period-tracking apps have sold millions of women's intimate health data to data brokers and advertisers - and that the practice continues despite the privacy scandals and regulatory pressure that supposedly ended it Reported: The Independent. This is not a hypothetical. This is the category's track record, now extending to menopause apps as they boom - symptom logs, medication records, and cycle dates are the commodity.
So let's do the audit. Ten minutes, no jargon, no scare headlines - just what they collect, who buys it, what to check on your phone right now, and what to use instead.
What they're actually collecting
Here's the inventory, from the app's point of view. The obvious: hot flashes, night sweats, sleep, mood, periods, bleeding, medications, supplements. The less obvious: sexual activity, weight, alcohol, exercise, skin changes, and - via the phone itself - device identifiers, approximate location, and the metadata of when you open the app and how long you stay.
Researchers at Royal Holloway, University of London surveyed 310 UK users and found that the fear isn't abstract. Users reported deep fears that intimate health data - including emotional symptoms and sexual activity history - could be accessed by insurance companies or employers, and the study warns the data is vulnerable to exploitation ranging from targeted financial scams to workplace discrimination Established: Royal Holloway. The same study found many menopause apps fall short of GDPR standards by burying privacy notices - hard to find, harder to understand Established: Royal Holloway.
Translation: the app knows your body better than your insurance company does - and the Royal Holloway researchers found women are right to worry about what a company might do with that information.
Where it goes (and the receipt from last time)
The pattern has a paper trail. In August 2025, period-tracking app Flo settled a four-year-old claim accusing the company of sharing the personal health data of millions of US women with Meta, Google, and other third parties. The settlements: Google paid $48 million, Flo paid $8 million Reported: The Independent.
Read that again. Google paid $48 million. That's the going rate for the receipt. And the Independent's reporting makes the point bluntly: the menopause app version of this isn't a historical scandal - it's happening now, in a category that is growing precisely because women have been failed by the healthcare system and are hungry for help.
That's the part that stings, and it's worth naming: we downloaded the app because the doctor's office wasn't taking us seriously, and somewhere in that transaction, our symptom log became inventory.
What happens when the app dies
The data problem doesn't end when you stop opening the app. It ends when the company does.
Meet Play Health - a perimenopause platform that launched in 2025 and let patients track symptoms, medications, cycles, and habits between appointments. On August 12, 2026, it announced it's winding down both the patient app and the clinician dashboard. The platform goes inactive on September 9, 2026. After 5 p.m. ET that day, all account data will be permanently deleted and cannot be recovered - users were told to sign in and download their data before then Primary: Play Health.
That's the friendly version of app death: a deadline, a download button, a warning. The unfriendly version is the app getting acquired and your data becoming an asset in the deal - sold again, to someone you never agreed to. Either way, the lesson is the same: if your data matters to you, it should live somewhere you control, and you should be able to export it in one click. If you can't do that, the app doesn't own your data - it's just borrowing it.
The 10-minute audit
Here's what to do with your phone right now. Not a purge - an audit. Ten minutes, three steps, zero judgment about past choices.
Step 1: Check the label before you open anything. Every app store page now carries a privacy label - "Data Linked to You" and "Data Used to Track You" on the App Store, the "Data safety" section on Google Play. Open the store page for each app you use and read what it declares. You're looking for two categories: Data Used to Track You (the app cross-linking your data with other apps and advertisers) and Health & Fitness or Sensitive Info in the linked-data list. Both together is the combination you care about.
Step 2: Check permissions on the phone, not in the app. On iPhone: Settings → Privacy & Security, then walk through Health, Location, and Tracking. On Android: Settings → Privacy → Permission manager. Revoke anything that doesn't need to be there. A symptom tracker does not need your microphone, your contacts, or your precise location. The tracking app list (Settings → Privacy → Tracking) shows exactly which apps are following you across other apps - and that's the list that matters.
Step 3: Delete the account, not just the app. Deleting the app from your home screen is a shrug. Deleting your account is a statement - and most apps have an "export my data" option in settings before you do it. Export what you want to keep, then delete the account through the app or a web request. If the app makes account deletion genuinely hard to find, that's the same GDPR shortfall the Royal Holloway researchers documented - and it's data about the app, not about you Established: Royal Holloway.
What to use instead
Here's the freedom part: you do not need a commercial app to track anything. The evidence that brought you to the app in the first place - your symptoms, their pattern, what helps - works just as well in systems that aren't in the business of monetizing you.
- Paper, properly. A notebook by the bed, one line per night: date, flashes, sleep, mood, the thing that helped. The Royal Holloway researchers noted self-tracking apps are genuinely useful for personal advocacy and doctor conversations Established: Royal Holloway - paper does the same job without the analytics SDK.
- A spreadsheet you own. One file, on your computer or in a cloud account you actually control, columns for date/symptom/severity/notes. Exportable by definition. Boring in the best way.
- On-device health data, with eyes open. Apple Health added perimenopause and menopause tracking in June 2026 - the tech finally acknowledged the transition exists - and it stores health data encrypted on your device. The caveat: if you enable iCloud, health data syncs to your Apple account - so check what you're syncing, and know that "on my phone" and "in my Apple account" are different answers to "where does this live?"
- Nothing. You are not required to track. If logging makes you feel in control, great - log in a way that stays yours. If it makes you feel surveilled, stop, and take the same observations you already carry in your head into the doctor's visit. The bring-a-witness playbook works with zero apps installed.
And if you do keep an app, keep it on a leash: free tiers, paid subscriptions, and "premium" plans are all still data businesses. The question isn't what you paid - it's what the app is allowed to do with what you logged. That's the permission check from Step 2, and it's the only part of the app that actually belongs to you.
The bottom line
The investigation is real, the practice is current, and the receipt from last time - $48 million from Google, $8 million from Flo - says this isn't an accident Reported: The Independent. Your hot flash log is worth money. Not because it's wrong to keep one - it's genuinely useful, and bringing real data to a doctor's appointment is how you get taken seriously. But the log should work for you, not for the highest bidder.
Check the labels. Trim the permissions. Export what you love. Delete the account if you're done. And if you want the data to follow you into the doctor's office without following you into a data broker's spreadsheet - paper, a file you own, or the peri data dashboard guide for the version that stays in your control.
The app got your logs because you trusted it. Now you know what trust is worth in this economy. The audit takes ten minutes, and you've already spent more than that on the app this month.