Zadushlivy Nina, Biviji Rizwana, Williams Karmen S
Department of Epidemiology and Biostatistics, Graduate School of Public Health and Health Policy, City University of New York, New York, NY, United States.
College of Health Solutions, Arizona State University, Phoenix, AZ, United States.
J Med Internet Res. 2025 Mar 5;27:e51517. doi: 10.2196/51517.
Mobile health apps often require the collection of identifiable information. Subsequently, this places users at significant risk of privacy breaches when the data are misused or not adequately stored and secured. These issues are especially concerning for users of reproductive health apps in the United States as protection of sensitive user information is affected by shifting governmental regulations such as the overruling of Roe v Wade and varying state-level abortion laws. Limited studies have analyzed the data privacy policies of these apps and considered the safety issues associated with a lack of user transparency and protection.
This study aimed to evaluate popular reproductive health apps, assess their individual privacy policies, analyze federal and state data privacy laws governing these apps in the United States and the European Union (EU), and recommend best practices for users and app developers to ensure user data safety.
In total, 4 popular reproductive health apps-Clue, Flo, Period Tracker by GP Apps, and Stardust-as identified from multiple web sources were selected through convenience sampling. This selection ensured equal representation of apps based in the United States and the EU, facilitating a comparative analysis of data safety practices under differing privacy laws. A qualitative content analysis of the apps and a review of the literature on data use policies, governmental data privacy regulations, and best practices for mobile app data privacy were conducted between January 2023 and July 2023. The apps were downloaded and systematically evaluated using the Transparency, Health Content, Excellent Technical Content, Security/Privacy, Usability, Subjective (THESIS) evaluation tool to assess their privacy and security practices.
The overall privacy and security scores for the EU-based apps, Clue and Flo, were both 3.5 of 5. In contrast, the US-based apps, Period Tracker by GP Apps and Stardust, received scores of 2 and 4.5, respectively. Major concerns regarding privacy and data security primarily involved the apps' use of IP address tracking and the involvement of third parties for advertising and marketing purposes, as well as the potential misuse of data.
Currently, user expectations for data privacy in reproductive health apps are not being met. Despite stricter privacy policies, particularly with state-specific adaptations, apps must be transparent about data storage and third-party sharing even if just for marketing or analytical purposes. Given the sensitivity of reproductive health data and recent state restrictions on abortion, apps should minimize data collection, exceed encryption and anonymization standards, and reduce IP address tracking to better protect users.
移动健康应用程序通常需要收集可识别信息。随后,当数据被滥用或没有得到充分存储和保护时,这会使用户面临严重的隐私泄露风险。对于美国生殖健康应用程序的用户来说,这些问题尤其令人担忧,因为敏感用户信息的保护受到政府法规变化的影响,例如罗诉韦德案的推翻以及各州不同的堕胎法律。有限的研究分析了这些应用程序的数据隐私政策,并考虑了与缺乏用户透明度和保护相关的安全问题。
本研究旨在评估流行的生殖健康应用程序,评估其各自的隐私政策,分析美国和欧盟(EU)管辖这些应用程序的联邦和州数据隐私法律,并为用户和应用程序开发者推荐最佳实践,以确保用户数据安全。
通过便利抽样从多个网络来源中选出总共4款流行的生殖健康应用程序——Clue、Flo、GP Apps的经期追踪器和Stardust。这种选择确保了美国和欧盟的应用程序有平等的代表性,便于对不同隐私法律下的数据安全实践进行比较分析。在2023年1月至2023年7月期间,对这些应用程序进行了定性内容分析,并回顾了关于数据使用政策、政府数据隐私法规以及移动应用程序数据隐私最佳实践的文献。下载这些应用程序,并使用透明度、健康内容、优秀技术内容、安全/隐私、可用性、主观性(THESIS)评估工具进行系统评估,以评估其隐私和安全实践。
欧盟的应用程序Clue和Flo的整体隐私和安全得分均为5分中的3.5分。相比之下,美国的应用程序GP Apps的经期追踪器和Stardust的得分分别为2分和4.5分。关于隐私和数据安全的主要担忧主要涉及应用程序对IP地址跟踪的使用、第三方参与广告和营销目的以及数据的潜在滥用。
目前,生殖健康应用程序中用户对数据隐私的期望未得到满足。尽管有更严格的隐私政策,特别是针对特定州的调整,但即使只是出于营销或分析目的,应用程序也必须在数据存储和第三方共享方面保持透明。鉴于生殖健康数据的敏感性以及近期各州对堕胎的限制,应用程序应尽量减少数据收集,超越加密和匿名化标准,并减少IP地址跟踪,以更好地保护用户。