Most people reading this share more about themselves with their smartphones than they would with their best friend or spouse. We entrust not just our devices with the details of our lives, but apps on those devices. We hand over tons of personal information into the hands of faceless strangers, believing that the boundaries of privacy will be respected. But, as recent lawsuits against health data app companies show, this trust can be shattered in an instant.
Most recently, a popular phone app designed to help women track their menstrual cycles and reproductive health was found to be quietly transmitting deeply personal data. Let’s look at how a company called Flo ended up in a legal code red.
Millions of Females Go with the Flo
Flo Health is a digital health company focused on women's reproductive health and wellness. Their flagship period-tracking app, the Flo Period & Ovulation Tracker, or simply “Flo”, allows users to log menstrual cycles, symptoms, and other health-related data to monitor patterns and predict future periods. The app launched with a focus on providing menstruation-related features such as cycle predictions, ovulation tracking, and symptom logging. It has since expanded to offer features for pregnancy tracking, birth control, general wellness (such as a “lifestyle tracker”), and educational content about reproductive health.
Flo Health's app is one of the most downloaded health apps in the Apple App Store, with over 165 million installations and 38 million monthly active users. Like other period-tracking applications in the market, Flo uses algorithms to analyze user-inputted data to provide personalized insights and predictions about menstrual cycles. The app uses artificial intelligence to offer advice and assistance related to women's health. This allows users to track their menstrual cycles, receive health and wellness suggestions, and connect with a community of users.
But beneath Flo’s user-friendly interface lies a complex data-sharing network that raises serious privacy concerns.
Hidden Risks of Sharing Data
Software Development Kits (SDKs) are sets of code that enable app developers to integrate specific functions into their applications without having to build them from scratch. Flo’s period tracking app uses SDKs to transmit user data to third-party companies, such as Google, Meta (owner of Facebook, WhatsApp, and Instagram), and Flurry Inc. (a mobile analytics, monetization, and advertising company).
SDKs are pre-packaged tools that allow developers to streamline app development, saving time and effort. They provide pre-built functions for tasks like analytics, advertising, social media sharing, and user authentication. By integrating SDKs, developers can focus on creating a seamless user experience, rather than building complex features from the ground up.
However, this convenience comes with a significant trade-off: the potential for sensitive user data to be shared with third parties without consent. In Flo's case, the app's use of SDKs enabled it to share user data with advertising partners and technology giants — often without explicit consent or limitations on usage. And despite assuring users that their health information would remain private, the company was found to be sharing sensitive data with third parties.
In 2019, the Wall Street Journal revealed that the company had spent years disclosing this intimate health data to dozens of third parties, who were free to use it for their own purposes. This prompted the Federal Trade Commission (FTC) to launch its own investigation into Flo Health's data privacy practices.
Government and Private Lawsuits
In 2020, the FTC filed a complaint against Flo Health, alleging that the company made deceptive statements to users about its data sharing practices. That case wasn’t long-lived, though. By January of 2021, Flo settled with the FTC. The agreement required the company to implement some major changes: get an independent review of its privacy practices, obtain user consent before sharing data, and notify third parties that had received users' data to destroy that information.
But this was far from the end of the matter. The FTC’s settlement resulted in mainly efforts to prevent future deceptive practices. While the FTC’s complaint also sought monetary relief and restitution to affected users, the settlement did not make Flo pay up to users. Probably after getting wind of the FTC’s case, those users wanted their own justice. The same year that Flo had settled with the federal government, users of the company’s app filed a lawsuit against Flo Health, along with Google and Meta. The case was a class action complaint, headed by the titular plaintiff, Erica Frasco.
Both the federal agency’s and Frasco’s complaints shared similar allegations and were based on the same set of acts by Flo, but there were some key differences. The FTC complaint focused on Flo Health's deceptive practices — specifically making false or misleading statements about its data sharing practices and failing to obtain users' consent. It highlighted that Flo Health shared users' health information with third-party companies without adequate disclosure or consent.
The class action complaint, on the other hand, focused on Flo Health's invasion of users' privacy. It was based on violations of California state laws (like the California Confidentiality of Medical Information Act). The complaint defined a broader class of plaintiffs, including all people in the United States who used the Flo App between June 2016 and the present. Perhaps most importantly, the complaint sought damages — money to the affected users to make things right.
These lawsuits were hardly the first of their kind. Right before Flo Health was sued, California Attorney General Xavier Becerra had just finished settling a similar lawsuit against a similar app, Glow, that tracks fertility. An investigation revealed that Glow's app failed to adequately safeguard health information, allowed access to user data without consent, and had security issues with its password change function. The allegations against Flo, though, were more serious.
Settlements Don’t Settle the Matter
This past March, Flurry agreed to pay $3.5 million to settle its part of the Frasco suit. The deal was made due to Flurry’s limited financial resources as a dissolved entity. And just last week, Google filed its own notice of settlement, effectively evading a pending jury trial. Although Google's settlement terms are not publicly disclosed, the company will likely exit the lawsuit, leaving Flo Health and Meta Platforms Inc. to face trial later this month.
Google’s settlement and the exit from the lawsuit leave several key questions unanswered. Since the court hasn’t resolved anything yet, we still don’t know what is considered "private" health data, nor whether California's Invasion of Privacy Act applies to digital surveillance tools.
Suzanne Bernstein of the Electronic Privacy Information Center noted: “There’s a long way to go for privacy protections in the US. This lawsuit that’s been ongoing shows that there can and should be standing in courts for these kind of privacy violations.”
The case against Meta Platforms Inc. will proceed to trial. Plaintiffs allege that the company illegally intercepted health data, including communications with users, from Flo Health through Facebook code integrated into the app. A ruling against Meta could have significant implications for the many other companies that provide third-party collection tools.
Related Resources:
- Guide to U.S. Data Privacy Laws (FindLaw's Learn About the Law)
- Google Settles Lawsuit by Purging Billions of Personal Records (FindLaw's Law and Daily Life)
- Mobile Security: Protecting Your Mobile Devices and Privacy (FindLaw's Learn About the Law)