started · updated
Icoso consulting releases privacy guide for cycle tracking apps
The Spanish provider icoso consulting S.L. has released a guide to help users evaluate the data privacy standards of menstrual cycle applications. The guide outlines six critical questions for assessing health data security:
1. Where are the servers located and does this apply to all data? 2. Which data is encrypted and does the provider hold the encryption keys? 3. Which third-party service providers receive data and in which countries is it processed? 4. Is there an independent tracker report available? 5. What is the app’s monetization model (subscriptions, advertising, or data sales)? 6. Can users export and delete their own data?
The guide notes that both local device storage and server-based synchronization can be privacy-friendly depending on encryption methods. Using its own app, Luna FemTech, as an example, icoso consulting states that synchronized entries are stored on servers within the European Union operated by Hetzner. Tracking and diary entries are encrypted on the device using AES-256 before synchronization.