Your Period App Told Facebook When You Had Sex — And Meta Got Caught Wiretapping

:mobile_phone: Your Period App Told Facebook When You Had Sex — And Meta Got Caught Wiretapping

That “safe” health app on your phone? It was literally sending Mark Zuckerberg your ovulation schedule. A jury just called it wiretapping.

13 million women. 3 years of secret data siphoning. 12 hidden tracking codes. One $59.5 million settlement — and Meta could owe up to $190 BILLION.

Flo Health, the world’s most popular period tracking app with 75 million users, was caught red-handed shipping your most intimate health details straight to Facebook’s ad machine. And I mean INTIMATE. We’re talking cycle dates, pregnancy plans, sexual activity, even masturbation habits. A jury just called it illegal wiretapping. You’re not ready for how bad this is.

eavesdropping


🧩 Dumb Mode Dictionary
Term What It Actually Means
SDK A chunk of code (made by Facebook/Google) that app makers drop into their app. It secretly phones home with your data
Wiretapping Listening in on someone’s private stuff without permission — like tapping a phone line, but digital
Custom App Events Secret labels Flo gave your data, like “R_SELECT_LAST_PERIOD_DATE” — so Facebook knew exactly what info you entered
Class Action When a bunch of people (here, 13 million women) sue together as one group
CIPA California Invasion of Privacy Act — the law Meta got found guilty of breaking
🔍 What Exactly Happened?

Okay so between November 2016 and February 2019, Flo embedded Facebook’s SDK deep inside their app. Every time you answered a health survey, tapped a date, or logged anything — that data got beamed straight to Meta.

We’re not talking vague analytics here. Meta set up 12 custom tracking codes inside Flo with names like:

  • R_SELECT_LAST_PERIOD_DATE
  • R_SELECT_CYCLE_LENGTH

Every single survey question you filled out? Meta got a copy. Automatically. For three years straight. And they used it to figure out who’d be a good target for baby product ads, fertility ads, and pregnancy-related marketing.

The kicker? Flo’s privacy policy said they were protecting your data the whole time. They revised that policy 13 times during the violation period. I mean. Thirteen rewrites to keep the lie going.

💰 The Money Trail
Who What They’re Paying Why
Google $48 million Also received the data via their own SDK
Flo Health $8 million Built the pipeline that leaked everything
Flurry (Yahoo) $3.5 million Third data partner that got a copy too
Meta REFUSED to settle Went to trial. Lost. Now facing appeal

Total settled so far: $59.5 million. Claim forms are expected in spring 2026.

But here’s where it gets truly wild: each CIPA violation carries a $5,000 penalty. With 38 million monthly active Flo users? Meta’s potential bill is somewhere around $190 billion. With a B. That’s more than Meta’s entire yearly revenue.

📊 Why Your Period Data Is Worth So Much

This isn’t random. Pregnancy data is worth up to 200 times more to advertisers than your age or location.

Think about it. If Facebook knows you’re trying to get pregnant, they can sell that signal to:

  • Baby product companies
  • Fertility clinics
  • Insurance companies
  • Maternity brands
  • Prenatal vitamin makers

One woman in the lawsuit, Autumn Meigs, was a teenager when this started. She testified she felt “a lot of anxiety” learning her most personal health data had been sold.

🗣️ How People Reacted
  • Jury foreman: Described the verdict as wanting to “send a message” about app privacy
  • Consumer Reports: Published a call to delete your Flo data immediately
  • Privacy advocates: Called this the first real case where Big Tech got held accountable for health data abuse
  • Meta: Still appealing. Still denying wrongdoing. Still Meta-ing.
  • Flo users online: Basically a collective “I KNEW something was off when I started getting baby ads before I told anyone I was trying”
⚠️ The Bigger Picture — It's Not Just Flo

Over one-third of American women use period tracking apps. And Flo isn’t the only one with sketchy data practices. After the Dobbs decision (which overturned abortion rights), privacy experts warned that period app data could be used against users in states where reproductive choices are criminalized.

This lawsuit proves that the threat isn’t theoretical. These apps ARE sharing your data. The only question is who’s buying it and what they’re doing with it.

Fun fact: Google and Flurry didn’t even fight the lawsuit. They just wrote the checks. Only Meta said “nah, we’ll take our chances” — and got hit with the wiretapping verdict.


Cool. Your Health App Was a Snitch This Whole Time. Now What the Hell Do We Do? ( ͡ಠ ʖ̯ ͡ಠ)

delete app

🔐 Build a 'Privacy Audit as a Service' for Health Apps

Most people have NO idea what their health apps are sending out. Build a simple tool or service that scans popular health/fitness apps and generates a “privacy report card” — showing what data goes where. Charge $5-15 per audit, or offer a subscription for ongoing monitoring.

:brain: Example: A freelance developer in Lisbon built a browser extension that flags apps with known data-sharing SDKs. Listed it on Product Hunt, got 800 upvotes in a day, then licensed it to a European health data compliance startup for €4K/month.

:chart_increasing: Timeline: MVP in a weekend using public SDK databases. First paying users within 2 weeks if you market it on privacy-focused subreddits like r/privacy and r/degoogle.

💰 Become a Flo Lawsuit Claim Filer — For Other People

The $59.5M settlement means millions of women qualify for payouts — no proof required. But most people won’t bother filling out the forms. Set up a simple landing page that walks people through the claim process, collects an email list, and monetize through affiliate links to privacy-first period tracking alternatives like Drip or Euki.

:brain: Example: A TikTok creator in Atlanta made a 45-second video explaining the Equifax settlement claim process, got 2.3M views, and drove 40K signups to her email list. She then sold a $12 “digital privacy toolkit” to 3,100 of them. That’s $37K from one lawsuit explainer.

:chart_increasing: Timeline: Set up a Carrd or Notion page today. Post the explainer video this week. Claim forms open spring 2026 — so you’re early.

📱 Sell Pre-Configured 'Clean Phones' to Privacy-Conscious Women

Take budget Android phones, strip out all the tracking garbage, pre-install privacy-first alternatives for period tracking, messaging, and browsing. Sell them on Etsy or through Instagram reels targeting the “detox your phone” audience. The Flo lawsuit just created a massive wave of women who now actively distrust their apps.

:brain: Example: A guy in Warsaw buys Xiaomi phones for €80, installs GrapheneOS or CalyxOS, pre-loads Signal + Drip + Brave, and sells them as “Privacy Phones” on a Shopify store for €249. Moves 15-20 units/month through Telegram privacy groups. That’s €2,500+/month profit from phones nobody else thought to de-Google.

:chart_increasing: Timeline: First unit ready in a day. Shopify store up in a weekend. First sales within a week if you post in privacy forums and women’s health communities.

📝 Write 'Terms of Service Translations' for Health Apps

Nobody reads privacy policies. But after lawsuits like this, people WANT to know — they just can’t understand legalese. Create bite-sized, plain-English breakdowns of popular health app privacy policies. Monetize through a Substack newsletter, a micro-SaaS tool, or by selling “translated” reports to companies who want to prove they’re transparent.

:brain: Example: A law student in Nairobi started a Substack called “TOS;DR for Health Apps” — plain-language breakdowns of what health apps actually do with your data. Hit 6,000 subscribers in 3 months. Now charges health startups $500 to write their “plain English privacy page” as a trust signal.

:chart_increasing: Timeline: First post takes an afternoon. Consistency over 4-6 weeks builds the audience. Revenue starts when you have 1,000+ subscribers or your first B2B client.

🛡️ Start a 'Data Deletion Concierge' Service

Most people don’t know they can request their data be deleted from apps and ad networks. Offer a done-for-you service: for $25-50, you send GDPR/CCPA deletion requests to every company that has someone’s health data. Target the post-Flo-lawsuit crowd who just found out Facebook has their cycle data.

:brain: Example: Two college students in Berlin built a simple form that auto-generates deletion request emails for 200+ companies. They charge €29/year for the “auto-send” premium tier. Got featured on a German tech podcast, hit 4,000 paying users in 6 months. That’s €116K/year from helping people press “delete.”

:chart_increasing: Timeline: Build a basic form with templates in a weekend. Charge immediately. The demand is RIGHT NOW while the lawsuit is in the news.

🛠️ Follow-Up Actions
Want to… Do this
:magnifying_glass_tilted_left: Check if you qualify for the $59.5M payout Visit OpenClassActions — used Flo between Nov 2016-Feb 2019? You’re probably in
:mobile_phone: Switch to a privacy-first period tracker Try Drip (open source) or Euki (designed for data safety)
:broom: Delete your Flo data right now Open Flo → Settings → Account → Delete Account (and send a CCPA deletion request separately)
:locked_with_key: Check what SDKs your apps are hiding Use Exodus Privacy — free tool that scans Android apps for hidden trackers
:open_book: Read the full investigation The Bureau of Investigative Journalism deep-dive

:high_voltage: Quick Hits

Want to… Do this
:magnifying_glass_tilted_left: See if Flo snitched on you Check if you used the app between 2016-2019 → file a claim
:mobile_phone: Scan your apps for hidden trackers Install Exodus Privacy on Android — it’s free and instant
:shield: Switch to an app that doesn’t spy Drip is open-source and stores everything locally
:money_bag: Check if you’re owed money from other lawsuits Browse TopClassActions.com for active settlements you might qualify for

Your phone knows more about your body than your doctor does. The difference is your doctor has to keep it secret.

3 Likes