Period-tracking apps look simple on the surface: log symptoms, get a predicted date. Underneath, many now run AI models that infer ovulation windows, fertility status and symptom patterns from accumulated user data — and researchers are increasingly asking who is accountable when those predictions go wrong, or when the data behind them travels somewhere the user never expected. Vrije Universiteit Amsterdam is hosting an event on October 29, 2026, titled “Your Cycle, Your Data,” built around research describing an estimated 50 million women worldwide who rely on these apps.
Why regulators classify these apps as AI systems
The OECD’s AI Incidents Monitor has logged period-tracking apps as AI systems in their own right, on the reasoning that they process and infer from user data to generate personalized predictions rather than simply recording dates a user enters. That classification matters because it opens the door to AI-specific regulatory scrutiny, rather than treating these apps as simple calendars exempt from algorithmic accountability frameworks.
The documented harms behind the research
The OECD’s entry lists concrete categories of harm tied to these apps: potential discrimination in insurance and employment based on inferred reproductive health status, and safety risks arising from data misuse, including the use of app data in government surveillance efforts targeting abortion providers in jurisdictions with restrictive abortion laws. A 2026 buyer’s guide citing Mozilla’s privacy testing found that some period-tracking apps still fold reproductive health details into advertising profiles, while presenting themselves publicly as privacy-focused despite offering only standard data protections.
Why reproductive data draws special scrutiny
Unlike a sleep-tracking app, period-tracking data sits at the intersection of health privacy and reproductive rights, particularly in the United States following the end of federal abortion protections. Data showing a missed or late period, or sudden changes in tracked cycle patterns, could theoretically be used as evidence in jurisdictions criminalizing abortion — a risk advocacy groups have warned about for years, and one the OECD’s incident entry now documents as a realized rather than hypothetical concern.
The privacy-first counter-movement
Partly in response to these concerns, a wave of newer apps has marketed itself explicitly on privacy guarantees. Menotracker, which launched in February 2026 as a menopause-focused tracker, positions on-device, non-stored data handling as its core feature, using pseudonymous identities and encrypted data distribution developed with a dedicated privacy technology partner. Other period and cycle trackers advertise similar no-account, no-cloud-storage designs, explicitly marketing that user data never leaves the device. These remain developer claims rather than independently audited guarantees, and privacy researchers recommend verifying them against the actual privacy policy rather than app-store marketing copy.
What app makers say in their defense
Mainstream period-tracking companies generally argue that AI-driven predictions genuinely improve the product — more accurate fertility windows, earlier detection of irregular cycles that might signal underlying conditions like polycystic ovary syndrome — and that data sharing, where it occurs, is typically limited to de-identified, aggregated information used for product improvement or research rather than sold to identify individual users. Privacy advocates counter that de-identified reproductive health data has repeatedly been shown, in other contexts, to be re-identifiable when combined with other datasets.
What’s next
The VU Amsterdam event later this month is expected to probe exactly this tension: where responsibility lies when an AI-driven prediction fails, and how transparent companies are obligated to be about what their models infer beyond what users explicitly log. With roughly 50 million women relying on these apps globally, the outcome of that accountability debate — in Europe and beyond — could reshape how an entire category of consumer health AI is required to handle some of the most sensitive data people generate about their own bodies. Researchers involved in organizing the event say they hope to produce concrete policy recommendations rather than another round of general warnings, specifically targeting the gap between what period-tracking apps claim in their marketing and what their underlying AI systems are actually doing with the predictions they generate. Several European lawmakers are expected to attend, raising the possibility that findings from the event feed directly into ongoing discussions over how the EU’s existing digital and health-data rules should be applied to this specific category of consumer AI, rather than being left to each individual app maker’s own privacy policy to decide.
Photo: VinzentWeinbeer / PIXABAY via Pixabay