Close Menu
    Facebook X (Twitter) Instagram
    Tuesday, July 21
    • Home
    • About Us
    • Contact Us
    • Submit Your Story
    • Terms of Use
    • Privacy Policy
    Facebook X (Twitter) Instagram
    Fortune Herald
    • Business
    • Finance
    • Politics
    • Lifestyle
    • Technology
    • Property
    • Business Guides
      • Guide To Writing a Business Plan UK
      • Guide to Writing a Marketing Campaign Plan
      • Guide to PR Tips for Small Business
      • Guide to Networking Ideas for Small Business
      • Guide to Bounce Rate Google Analyitics
    Fortune Herald
    Home»Business»Stardust Period Tracker Data Reached Analytics Firm Despite Privacy Pledge
    Stardust period tracker data
    Business

    Stardust Period Tracker Data Reached Analytics Firm Despite Privacy Pledge

    Funke AdeyemiBy Funke Adeyemi20/07/2026No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    New research by SC Media and Mozilla has confirmed that Stardust period tracker data, including users’ birthdates, birth-control types, reproductive goals, and specific symptoms, was being transmitted to a third-party analytics company while the app’s own website carried the slogan: ‘Your data is private. Period.’

    The company in question is RudderStack, Inc., a US-incorporated analytics firm. Stardust tied each batch of health information to a unique identifier in place of the user’s name, a technique the company may have considered sufficiently protective. It is not.

    Why Unique Identifiers Are Not the Same as Anonymity

    The Federal Trade Commission (FTC) has long held that converting a name into a hashed string of characters does not constitute anonymisation. Under the standard the FTC applies, data is only anonymous when it can never be associated back to a person. A unique identifier tied to a birthday, a reproductive health goal, and a symptom list does not clear that bar.

    The finding comes from Mozilla security researcher Shoshana Wodinsky, who analysed the network traffic of six period-tracking apps. Stardust was the only one of the six that transmitted sensitive health data to another company. Mozilla recommended Euki as ‘squeaky clean’: its core features generated no outbound data transfers, and users’ health information did not leave their device.

    Stardust, for its part, said through a spokesperson (as quoted by BBC News) that RudderStack is ‘contractually prohibited from selling or using it for its own purposes.’ That contractual restriction, however, does not extend to law enforcement. As US-based companies, both Stardust and RudderStack remain subject to demands for user data from American authorities. Stardust founder Rachel Moranis did not respond to requests for comment.

    A Pattern the Regulators Are Already Moving to Address

    The Stardust period tracker data disclosure lands in a regulatory environment that is growing less tolerant of health-app privacy gaps. The FTC has finalised changes to its Health Breach Notification Rule requiring vendors of digital health records, including health apps that fall outside the scope of HIPAA, to notify individuals, the commission, and in some cases the media whenever unsecured personally identifiable health data is compromised, according to Fierce Healthcare.

    The rule has teeth. Earlier, the FTC reached a settlement with the developer of fertility app Premom over allegations it shared users’ sensitive health data with AppsFlyer and Google without adequate disclosure, and failed to notify consumers, in violation of the Health Breach Notification Rule. The FTC’s health privacy guidance makes clear that the commission views both its own Act and the Health Breach Notification Rule as tools for policing how health apps handle personal data.

    The broader problem is structural. Sharing data with third parties for analytics, storage, or payment processing is routine practice across the app ecosystem. That normalisation is precisely what makes it consequential: users rarely see it happening, and the risks accumulate quietly. A data breach at an analytics firm, a law-enforcement subpoena served to a US company, or a future change of ownership at the analytics provider can all turn a routine data-sharing arrangement into a serious exposure.

    Stardust’s current predicament is compounded by its history. In 2022, the app surged in downloads after the US Supreme Court overturned the constitutional right to seek an abortion. The company claimed at the time that end-to-end encryption meant even Stardust itself could not access user data. TechCrunch analysed the app’s network traffic and found that claim to be false. Wodinsky used the same network-traffic technique for the current Mozilla research, underscoring that the methodology for auditing these apps is well established, even if the apps themselves do not always act as though they might be audited.

    The broader scrutiny of health-app data handling has renewed pressure on the sector to demonstrate, not merely assert, that privacy commitments are technically enforced. Contractual language binding a data recipient is a paper control. Network traffic does not lie.

    The more consequential question for Stardust now is whether the FTC’s evolving enforcement posture, combined with the Premom precedent, turns this disclosure from a reputational problem into a regulatory one. That answer will depend on whether the commission concludes Stardust’s users were adequately informed about where their health data was going.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Funke Adeyemi

    Funke Adeyemi spent a decade in corporate banking and fintech before moving to business journalism. She started in trade finance at a major UK bank, moved to a payments company scaling into African markets, and spent her last role leading partnerships at a cross-border remittance platform. She writes about business strategy, fintech, digital banking, and the corporate news that moves markets. She is interested in how companies actually make money rather than how they describe making money in investor presentations. Funke lives in South London. She reads earnings calls the way other people listen to podcasts, and finds them about as reliable.

    Related Posts

    Lurie Pushes Waymo Robotaxi Regulations After July 4 Gridlock

    21/07/2026

    Google Vids Personal Avatar Feature Turns Selfies Into AI Presenters

    20/07/2026

    Aina Secures $5.5M to Build an AI Interface That Acts, Not Just Listens

    19/07/2026
    Leave A Reply Cancel Reply

    Fortune Herald Logo

    Connect with us

    FortuneHerald Logo

    Home   About Us   Contact Us   Submit Your Story   Terms of Use   Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.