READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Period-Tracking App Stardust Shared Health Data With Third Party, Mozilla Research Finds

Period-Tracking App Stardust Shared Health Data With Third Party, Mozilla Research Finds
Mozilla researcher Shoshana Wodinsky found Stardust, an app that claims 'your data is private, period,' shared users' birthdate, birth control type, and symptom data with analytics firm RudderStack. Stardust says the data isn't sold and can't be used by RudderStack for its own purposes, but the app's own privacy marketing looks like a stretch given the facts.

An app that literally puts "your data is private" in its own slogan got caught sharing sensitive health data with an outside company. That's the finding from Mozilla's latest privacy audit of period-tracking apps, reported by TechCrunch.

Mozilla security researcher Shoshana Wodinsky tested six period-tracking apps by analyzing their network traffic, the digital breadcrumbs that show what data actually leaves a user's phone and where it goes. Stardust was the only one of the six caught sharing sensitive health data with a third party: analytics company RudderStack.

That data included the user's birthdate, birth control type, reproductive goals, and specific symptoms. Stardust tied this information to a unique identifier instead of the user's actual name.

The Federal Trade Commission has warned for years that swapping a name for a unique ID doesn't actually anonymize data. Identifiers can still be linked back to a real person through other data points, device fingerprints, or cross-referencing. Privacy-by-euphemism doesn't hold up.

This isn't Stardust's first rodeo

TechCrunch first covered Stardust back in 2022, when downloads spiked after the Supreme Court overturned Roe v. Wade and the constitutional right to seek an abortion. At the time, Stardust claimed its data was end-to-end encrypted, meaning not even the company itself could access user data.

TechCrunch tested that claim in 2022 by analyzing the app's network traffic and found it was false. So this isn't a company with a clean track record suddenly slipping up. It's a repeat pattern of privacy claims that don't match what the code actually does.

What Stardust says in its defense

A Stardust spokesperson told TechCrunch that RudderStack is contractually prohibited from selling the data or using it for its own purposes. Sharing data with a vendor under contract restrictions is different from selling it outright on the open market.

If that contract is real and enforced, it does meaningfully limit what RudderStack can do with the information. That's the strongest defense a reasonable person could make on Stardust's behalf, and it deserves to be taken at face value absent evidence otherwise.

But a contract doesn't erase the exposure. Both Stardust and RudderStack are U.S.-based companies, which means both can be legally compelled to hand over user health data if law enforcement comes calling with a subpoena or warrant. No hacking required, no contract violation required. Just a legal process that either company would likely have to comply with.

Stardust founder Rachel Moranis did not respond to TechCrunch's request for comment, including a direct question about whether the company has ever received a law enforcement demand for user data. A spokesperson acknowledged receiving the email but never actually answered.

In an environment where several states have restricted or banned abortion since 2022, whether an app has handed over reproductive health data to law enforcement is not a hypothetical question. It's a question at the core of why users choose an encrypted, private app in the first place.

The one app Mozilla actually likes

Of the six apps Wodinsky tested, only one got a clean bill of health: Euki. Mozilla found Euki wasn't sharing data with third parties for its core features, and users' health data never left their own device.

This is the actual gold standard for a privacy app, not marketing copy on a landing page. If your data never leaves the phone, there's no server to subpoena and no vendor contract to worry about.

Why this matters beyond one app

Sharing data with third parties for analytics, storage, or payments is standard practice across the app industry. Mozilla's report notes this happens as background activity, invisible to the user scrolling through symptoms and cycle dates.

The risk isn't theoretical. Every additional company touching sensitive health data is another potential point of failure, another target for a data breach, and another entity that can be legally compelled to disclose records.

Consumers relying on marketing claims like "your data is private" have no way to verify that promise without independent researchers like Wodinsky actually testing the app's network traffic. That's not a regulatory system working. Privacy policy enforcement is being outsourced to nonprofit researchers because no one else is checking.

Whether the FTC or state attorneys general take any action against Stardust over the gap between its privacy claims and its actual data-sharing practices remains an open question. No investigation or enforcement action has been announced as of this writing.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchPeriod tracker Stardust shares users’ health data with analytics firm, says Mozilla research