Period app Stardust caught sharing private health data – Claril Noticias

The period-tracking app Stardust is sharing sensitive user health data with third-party analytics firm RudderStack, according to new research published by the Mozilla Foundation this week, contradicting the app’s strict privacy promises.

Despite plastering the slogan “Your data is private. Period” across its website, the application’s actual data-handling practices tell a vastly different story.

What Data is Stardust Sharing with Third Parties?

According to the Mozilla Foundation’s latest findings, which scrutinised the privacy frameworks of various period-tracking apps, Stardust transmits highly sensitive health information to RudderStack. This shared dataset includes users’ dates of birth, active methods of contraception, reproductive goals, and highly specific physiological symptoms. While Stardust links this information to a unique digital identifier rather than a legal name, the US Federal Trade Commission (FTC) has long warned that masking names with unique IDs does not guarantee anonymity, nor does it prevent the data from being traced back to individual users.

The Hidden Risks of Background Data Sharing

The investigation highlights the systemic security and privacy vulnerabilities inherent in using digital health tools that quietly offload user data to external companies. This data transfer typically occurs as background activity, completely hidden from the user’s view. While mobile applications frequently integrate third-party services for cloud storage, analytics, and payment processing, doing so with intimate health data introduces significant risks, including potential security breaches, accidental exposure, or forced disclosures to law enforcement agencies.

A History of Misleading Encryption Claims

Stardust first gained mainstream traction in 2022, experiencing a massive surge in downloads in the United States following the Supreme Court’s decision to overturn the constitutional right to abortion. At the time, the company heavily marketed itself as utilising end-to-end encryption, implying that not even Stardust employees could access user records. However, a technical analysis of the app’s network traffic conducted by TechCrunch exposed those security claims as entirely false.

For this latest study, Mozilla Foundation security researcher Shoshana Wodinsky utilised similar network traffic analysis techniques to evaluate how six different period trackers handle user data. The results showed that Stardust was the only application among those tested that actively transmitted sensitive health metrics to an external entity.

The Threat of Law Enforcement Subpoenas

Responding to the findings, a Stardust spokesperson told BBC News that RudderStack is “contractually prohibited from selling or using it for its own purposes.” Nevertheless, because both Stardust and RudderStack operate under US jurisdiction, both entities remain legally bound to comply with government and law enforcement demands for stored user data.

While Stardust founder Rachel Moranis did not comment on the initial findings, a company spokesperson later stated via email that the business “has never received any requests, demands, or legal process for user data from authorities or third parties.”

Are There Safer Period-Tracking Alternatives?

For users seeking a genuinely secure way to track their menstrual cycles, the Mozilla Foundation highlighted Euki as an exemplary alternative. Wodinsky’s testing found Euki to be exceptionally clean, as it does not share any data with third parties to run its core features, ensuring that all sensitive health records remain stored locally on the user’s physical device.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *