Featured Article

Period tracker Stardust surges following Roe reversal, but its privacy claims aren’t airtight

The app was found sharing users’ phone numbers with an analytics firm

Comment

Stardust icon on iOS
Image Credits: TechCrunch /

Period tracking app Stardust surged to the top of the U.S. Apple App Store in the wake of the Supreme Court’s decision to overturn Roe v. Wade after the app promised it will encrypt its users’ private data to keep it out of the hands of the government.

But TechCrunch found on Monday that the current version of the now-booming Stardust app is sharing the app users’ phone numbers with a third-party analytics company, which could be used to identify individual users of the app.

The decision to overturn Roe reversed 50 years of constitutional protections for abortion rights in the United States, allowing individual states to create laws to criminalize abortion. The decision has led to calls for users to delete their period-tracking apps from their phones, fearing the data collected by these apps could be used against them to prove an abortion was obtained illegally.

Others are abandoning their current period trackers and turning to apps like Stardust instead as a result of the company’s strong statement issued in light of the decision to overturn Roe. Stardust said it would implement end-to-end encryption so it would “not be able to hand over any of your period tracking data” to the government, helping to draw in hundreds of thousands of downloads over this weekend ahead of the release of the new, encryption-featured app version slated for release on Wednesday.

TechCrunch ran a network traffic analysis of Stardust’s iPhone app on Monday to understand what data was flowing in and out of the app. The network traffic showed that if a user logs into the app using their phone number (rather than through a login service provided by Apple or Google), Stardust will periodically share the user’s phone number with a third-party analytics service called Mixpanel.

Mixpanel is an analytics service that’s used widely by app developers to track their app’s usage and help identify errors or other ways to improve the app. It does this by tracking how someone uses the app and sending the data back to Mixpanel’s servers. Stardust also shared with Mixpanel details about the phone that the app was installed on, which iPhone model and software version and which cell carrier the phone was connected to.

During the network traffic analysis, TechCrunch saw no health data shared with Mixpanel. But sharing a phone number that’s tied to a specific user of a period-tracking app with a third party like Mixpanel could allow prosecutors to compel Mixpanel to turn over that data — even if Stardust claims that it can’t.

Stardust founder Rachel Moranis told TechCrunch, “The current (old) version of Stardust leverages several data collection mechanisms of Mixpanel that we have disabled/removed in the new version. In addition to not sending [personally identifiable information] to Mixpanel, we have also disabled IP tracking for our users to protect from that metadata being used to identify our users.”

In a tweet, Stardust said it was “working on” a way to allow users to sign in anonymously.

Stardust’s privacy policy, updated on June 26, indicates the app is not as protected as it claims. It notes the app collects a variety of data about users’ devices, activity and location, including through cookies and other tracking technologies. It also carves out some exceptions with regard to data sharing, noting how it may disclose de-personalized data with some providers, with user consent, or when required by law — if it must “comply with or respond to law enforcement or a legal process or a request for cooperation by a government or other entity, whether or not legally required.”

This also seems to contradict the part of the policy that insists that the company will never share users’ ages or “any data related to your health with any third parties.”

Since the overturning of Roe, tech companies are bracing for a new regime under which they could face legal orders compelling the turnover of pregnancy-related user data to state authorities and prosecutors. Some of the biggest tech companies still have not said how they would handle demands for data related to investigations relating to people seeking or providing abortions. That’s contributed to a rush to find apps and services that use end-to-end encryption, which prevents anyone — even the app maker — from accessing a user’s data.

Thanks to its announcement that it’s moving to encryption, Stardust’s app drew in 135,000 new installs on June 24, a 4,400% spike in the number of installs it saw on the previous day, about 3,000 installs, according to data from app intelligence firm Sensor Tower. On Saturday, June 25, the app saw another 200,000 installs and hit No. 1 on the U.S. App Store, up from its prior rank of No. 119. Combined, the two weekend days delivered 82% of Stardust’s more than 400,000 total lifetime installs.

TechCrunch asked the founders for more information about how the app is implementing end-to-end encryption. Stardust founder Moranis told TechCrunch that “all traffic to our servers is through standard SSL (hosted on AWS) and subsequent data storage on AWS RDS utilizing their built-in AES-256 encryption implementation.” Although this describes the use of encryption to protect data while in transit and while it’s stored on Amazon’s servers, it’s not clear if this implementation would be considered true end-to-end encryption.

Given its complexity and the stakes involved, implementing end-to-end encryption is often a time- and resource-intensive effort, where a single coding flaw could undermine the protections of the users’ data. It’s also not uncommon for companies that use end-to-end encryption to publish papers and technical notes explaining how their systems work – often even a point of pride for some companies – or even open-sourcing and publishing their code, as cryptographic proof that their systems are secure.

When asked if the company had conducted a third-party security audit of the app’s code, Moranis said that the company intends to “fully publish our implementation along with a third-party audit once it is complete,” but a timeline was not given. (TechCrunch will follow up when the results of the audit are available.)

After we heard from Stardust, the company quietly changed its privacy policy again to remove mentions of end-to-end encryption.

It’s hard to argue with people’s fears — the period tracking app industry was already found to have engaged in leaky data-sharing practices with third-party tracking and analytic firms, as well as tech giants like Facebook and Google. One app, Flo, had to settle last year with the U.S. Federal Trade Commission for violating its own privacy policy. Among other things, the app had falsely claimed it only shared “non-personally identifiable” information with third parties — which an investigation by the Wall St. Journal proved to be untrue.

Another app, Glow, had to settle with the state of California the year prior for exposing women’s medical information.

Consumer Reports said in May that many apps continue to use third-party trackers and don’t store consumers’ data locally on their devices where it can’t be shared or sold.

Plus, period tracking apps don’t have to comply with the federal privacy law known as the Health Insurance Portability and Accountability Act, or HIPAA.

With the threat of losing their entire user bases, however, many period trackers released statements to ensure customers their data is safe. Flo, which completed an independent privacy review in March, said that it will do “everything in its power” to protect users’ data and privacy. It also said it would launch a new “Anonymous Mode” feature that removes users’ personal identities from their Flo accounts.

Update, 6/30/22, 9:30 AM ET: Zack Whittaker followed up on Stardust’s update after the new app was released this week and found that the locally-generated encryption keys were being uploaded to Stardust’s own servers. This would allow the company the ability to decrypt user data. More here.

https://twitter.com/zackwhittaker/status/1542297308401995782

Supreme Court overturns Roe v. Wade: Should you delete your period-tracking app?

More TechCrunch

Google has joined investors backing Namma Yatri, an open-source ride-sharing app in India that is eroding market share from Uber and Ola with its no-commission model. The Android developer, which…

Google backs Indian open-source Uber rival

These messaging features, announced at WWDC 2024, will have a significant impact on how people communicate every day.

At last, Apple’s Messages app will support RCS and scheduling texts

iOS 18 will be available in the fall as a free software update.

Here are all the devices compatible with iOS 18

The tests indicate there are loopholes in TikTok’s ability to apply its parental controls and policies effectively in a situation where the teen user originally lied about their age, as…

TikTok glitch allows Shop to appear to users under 18, despite adults-only policy

Lhoopa has raised $80 million to address the lack of affordable housing in Southeast Asian markets, starting with the Philippines.

Lhoopa raises $80M to spur more affordable housing in the Philippines

Former President Donald Trump picked Ohio Senator J.D. Vance as his running mate on Monday, as he runs to reclaim the office he lost to President Joe Biden in 2020.…

Trump’s VP candidate JD Vance has long ties to Silicon Valley, and was a VC himself

Hello and welcome back to TechCrunch Space. Is it just me, or is the news cycle only accelerating this summer?!

TechCrunch Space: Space cowboys

Apple Intelligence features are not available in the developer beta, which is out now.

Without Apple Intelligence, iOS 18 beta feels like a TV show that’s waiting for the finale

Apple released the public betas for its next generation of software on the iPhone, Mac, iPad and Apple Watch on Monday. You can now test out iOS 18 and many…

Apple’s public betas for iOS 18 are here to test out

One major dissenter threatens to upend Fisker’s apparent best chance at offloading its unsold EVs, a deal that would keep the startup’s bankruptcy proceeding alive and pave the way for…

Fisker has one major objector to its Ocean SUV fire sale

Payments giant Stripe has delayed going public for so long that its major investor Sequoia Capital is getting creative to offer returns to its limited partners. The venture firm emailed…

Major Stripe investor Sequoia confirms $70B valuation, offers its investors a payday

Alphabet, Google’s parent company, is in advanced talks to acquire Wiz for $23 billion, a person close to the company told TechCrunch. The deal discussions were previously reported by The…

Google’s Kurian approached Wiz, $23B deal could take a week to land, source says

Name That Bird determines individual members of a species by identifying distinguishing characteristics that most humans would be hard-pressed to spot.

Bird Buddy’s new AI feature lets people name and identify individual birds

YouTube Music is introducing two new ways to boost song discovery on its platform. YouTube announced on Monday that it’s experimenting with an AI-generated conversational radio feature, and rolling out…

YouTube Music is testing an AI-generated radio feature and adding a song recognition tool

Tesla had internally planned to build the dedicated robotaxi and the $25,000 car, often referred to as the Model 2, on the same platform.

Elon Musk confirms Tesla ‘robotaxi’ event delayed due to design change

What this means for the space industry is that theory has become reality: The possibility of designing a habitation within a lunar tunnel is a reasonable proposition.

Moon cave! Discovery could redirect lunar colony and startup plays

Get ready for a prime week of savings at TechCrunch Disrupt 2024 with the launch of Disrupt Deal Days! From now to July 19 at 11:59 p.m. PT, we’re going…

Disrupt Deal Days are here: Prime savings for TechCrunch Disrupt 2024!

Deezer is the latest music streaming app to introduce an AI playlist feature. The company announced on Monday that a select number of paid users will be able to create…

Deezer chases Spotify and Amazon Music with its own AI playlist generator

Real-time payments are becoming commonplace for individuals and businesses, but not yet for cross-border transactions. That’s what Caliza is hoping to change, starting with Latin America. Founded in 2021 by…

Caliza lands $8.5 million to bring real-time money transfers to Latin America using USDC

Adaptive is a platform that provides tools designed to simplify payments and accounting for general construction contractors.

Adaptive builds automation tools to speed up construction payments

When VanMoof declared bankruptcy last year, it left around 5,000 customers who had preordered e-bikes in the lurch. Now VanMoof is up and running under new management, and the company’s…

How VanMoof’s new owners plan to win over its old customers

Mitti Labs aims to transform rice farming in India and other South Asian markets by reducing methane emissions by 50% and water consumption by 30%.

Mitti Labs aims to make rice farming less harmful to the climate, starting in India

This is a guide on how to check whether someone compromised your online accounts.

How to tell if your online accounts have been hacked

There is a general consensus today that generative AI is going to transform business in a profound way, and companies and individuals who don’t get on board will be quickly…

The AI financial results paradox

Google’s parent company Alphabet might be on the verge of making its biggest acquisition ever. The Wall Street Journal reports that Alphabet is in advanced talks to acquire Wiz for…

Google reportedly in talks to acquire cloud security company Wiz for $23B

Featured Article

Hank Green reckons with the power — and the powerlessness — of the creator

Hank Green has had a while to think about how social media has changed us. He started making YouTube videos in 2007 with his brother, novelist John Green, at a time when the first iPhone was in development, Myspace was still relevant and Instagram didn’t exist. Seventeen years later, posting…

Hank Green reckons with the power — and the powerlessness — of the creator

Here is a timeline of Synapse’s troubles and the ongoing impact it is having on banking consumers. 

Synapse’s collapse has frozen nearly $160M from fintech users — here’s how it happened

Featured Article

Helixx wants to bring fast-food economics and Netflix pricing to EVs

When Helixx co-founder and CEO Steve Pegg looks at Daisy — the startup’s 3D-printed prototype delivery van — he sees a second chance. And he’s pulling inspiration from McDonald’s to get there.  The prototype, which made its global debut this week at the Goodwood Festival of Speed, is an interesting proof…

Helixx wants to bring fast-food economics and Netflix pricing to EVs

Featured Article

India clings to cheap feature phones as brands struggle to tap new smartphone buyers

India is struggling to get new smartphone buyers, as millions of Indians don’t go for an upgrade and continue to be on feature phones.

India clings to cheap feature phones as brands struggle to tap new smartphone buyers

Roboticists at The Faboratory at Yale University have developed a way for soft robots to replicate some of the more unsettling things that animals and insects can accomplish — say,…

Meet the soft robots that can amputate limbs and fuse with other robots