Featured Article

Period tracker Stardust surges following Roe reversal, but its privacy claims aren’t airtight

The app was found sharing users’ phone numbers with an analytics firm

Comment

Stardust icon on iOS
Image Credits: TechCrunch /

Period tracking app Stardust surged to the top of the U.S. Apple App Store in the wake of the Supreme Court’s decision to overturn Roe v. Wade after the app promised it will encrypt its users’ private data to keep it out of the hands of the government.

But TechCrunch found on Monday that the current version of the now-booming Stardust app is sharing the app users’ phone numbers with a third-party analytics company, which could be used to identify individual users of the app.

The decision to overturn Roe reversed 50 years of constitutional protections for abortion rights in the United States, allowing individual states to create laws to criminalize abortion. The decision has led to calls for users to delete their period-tracking apps from their phones, fearing the data collected by these apps could be used against them to prove an abortion was obtained illegally.

Others are abandoning their current period trackers and turning to apps like Stardust instead as a result of the company’s strong statement issued in light of the decision to overturn Roe. Stardust said it would implement end-to-end encryption so it would “not be able to hand over any of your period tracking data” to the government, helping to draw in hundreds of thousands of downloads over this weekend ahead of the release of the new, encryption-featured app version slated for release on Wednesday.

TechCrunch ran a network traffic analysis of Stardust’s iPhone app on Monday to understand what data was flowing in and out of the app. The network traffic showed that if a user logs into the app using their phone number (rather than through a login service provided by Apple or Google), Stardust will periodically share the user’s phone number with a third-party analytics service called Mixpanel.

Mixpanel is an analytics service that’s used widely by app developers to track their app’s usage and help identify errors or other ways to improve the app. It does this by tracking how someone uses the app and sending the data back to Mixpanel’s servers. Stardust also shared with Mixpanel details about the phone that the app was installed on, which iPhone model and software version and which cell carrier the phone was connected to.

During the network traffic analysis, TechCrunch saw no health data shared with Mixpanel. But sharing a phone number that’s tied to a specific user of a period-tracking app with a third party like Mixpanel could allow prosecutors to compel Mixpanel to turn over that data — even if Stardust claims that it can’t.

Stardust founder Rachel Moranis told TechCrunch, “The current (old) version of Stardust leverages several data collection mechanisms of Mixpanel that we have disabled/removed in the new version. In addition to not sending [personally identifiable information] to Mixpanel, we have also disabled IP tracking for our users to protect from that metadata being used to identify our users.”

In a tweet, Stardust said it was “working on” a way to allow users to sign in anonymously.

Stardust’s privacy policy, updated on June 26, indicates the app is not as protected as it claims. It notes the app collects a variety of data about users’ devices, activity and location, including through cookies and other tracking technologies. It also carves out some exceptions with regard to data sharing, noting how it may disclose de-personalized data with some providers, with user consent, or when required by law — if it must “comply with or respond to law enforcement or a legal process or a request for cooperation by a government or other entity, whether or not legally required.”

This also seems to contradict the part of the policy that insists that the company will never share users’ ages or “any data related to your health with any third parties.”

Since the overturning of Roe, tech companies are bracing for a new regime under which they could face legal orders compelling the turnover of pregnancy-related user data to state authorities and prosecutors. Some of the biggest tech companies still have not said how they would handle demands for data related to investigations relating to people seeking or providing abortions. That’s contributed to a rush to find apps and services that use end-to-end encryption, which prevents anyone — even the app maker — from accessing a user’s data.

Thanks to its announcement that it’s moving to encryption, Stardust’s app drew in 135,000 new installs on June 24, a 4,400% spike in the number of installs it saw on the previous day, about 3,000 installs, according to data from app intelligence firm Sensor Tower. On Saturday, June 25, the app saw another 200,000 installs and hit No. 1 on the U.S. App Store, up from its prior rank of No. 119. Combined, the two weekend days delivered 82% of Stardust’s more than 400,000 total lifetime installs.

TechCrunch asked the founders for more information about how the app is implementing end-to-end encryption. Stardust founder Moranis told TechCrunch that “all traffic to our servers is through standard SSL (hosted on AWS) and subsequent data storage on AWS RDS utilizing their built-in AES-256 encryption implementation.” Although this describes the use of encryption to protect data while in transit and while it’s stored on Amazon’s servers, it’s not clear if this implementation would be considered true end-to-end encryption.

Given its complexity and the stakes involved, implementing end-to-end encryption is often a time- and resource-intensive effort, where a single coding flaw could undermine the protections of the users’ data. It’s also not uncommon for companies that use end-to-end encryption to publish papers and technical notes explaining how their systems work – often even a point of pride for some companies – or even open-sourcing and publishing their code, as cryptographic proof that their systems are secure.

When asked if the company had conducted a third-party security audit of the app’s code, Moranis said that the company intends to “fully publish our implementation along with a third-party audit once it is complete,” but a timeline was not given. (TechCrunch will follow up when the results of the audit are available.)

After we heard from Stardust, the company quietly changed its privacy policy again to remove mentions of end-to-end encryption.

It’s hard to argue with people’s fears — the period tracking app industry was already found to have engaged in leaky data-sharing practices with third-party tracking and analytic firms, as well as tech giants like Facebook and Google. One app, Flo, had to settle last year with the U.S. Federal Trade Commission for violating its own privacy policy. Among other things, the app had falsely claimed it only shared “non-personally identifiable” information with third parties — which an investigation by the Wall St. Journal proved to be untrue.

Another app, Glow, had to settle with the state of California the year prior for exposing women’s medical information.

Consumer Reports said in May that many apps continue to use third-party trackers and don’t store consumers’ data locally on their devices where it can’t be shared or sold.

Plus, period tracking apps don’t have to comply with the federal privacy law known as the Health Insurance Portability and Accountability Act, or HIPAA.

With the threat of losing their entire user bases, however, many period trackers released statements to ensure customers their data is safe. Flo, which completed an independent privacy review in March, said that it will do “everything in its power” to protect users’ data and privacy. It also said it would launch a new “Anonymous Mode” feature that removes users’ personal identities from their Flo accounts.

Update, 6/30/22, 9:30 AM ET: Zack Whittaker followed up on Stardust’s update after the new app was released this week and found that the locally-generated encryption keys were being uploaded to Stardust’s own servers. This would allow the company the ability to decrypt user data. More here.

https://twitter.com/zackwhittaker/status/1542297308401995782

Supreme Court overturns Roe v. Wade: Should you delete your period-tracking app?

More TechCrunch

The FCC has proposed a $6 million fine for the scammer who used voice-cloning tech to impersonate President Biden in a series of illegal robocalls during a New Hampshire primary…

$6M fine for robocaller who used AI to clone Biden’s voice

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Is it…

Tesla lobbies for Elon and Kia taps into the GenAI hype

Crowdaa is an app that allows non-developers to easily create and release apps on the mobile store. 

App developer Crowdaa raises €1.2M and plans a US expansion

Back in 2019, Canva, the wildly successful design tool, introduced what the company was calling an enterprise product, but in reality it was more geared towards teams than fulfilling true…

Canva launches a proper enterprise product — and they mean it this time

TechCrunch Disrupt 2024 isn’t just an event for innovation; it’s a platform where your voice matters. With the Disrupt 2024 Audience Choice Program, you have the power to shape the…

2 days left to vote for Disrupt Audience Choice

The United States Department of Justice and 30 state attorneys general filed a lawsuit against Live Nation Entertainment, the parent company of Ticketmaster, for alleged monopolistic practices. Live Nation and…

Ticketmaster is at the heart of a US antitrust lawsuit against parent company Live Nation

The U.K. will shortly get its own rulebook for Big Tech, after peers in the House of Lords agreed Thursday afternoon to pass the Digital Markets, Competition and Consumer bill…

‘Pro-competition’ rules for Big Tech make it through UK’s pre-election wash-up

Spotify’s addition of its AI DJ feature, which introduces personalized song selections to users, was the company’s first step into an AI future. Now, Spotify is developing an alternative version…

Spotify experiments with an AI DJ that speaks Spanish

Call Arc can help answer immediate and small questions, according to the company. 

Arc Search’s new Call Arc feature lets you ask questions by ‘making a phone call’

After multiple delays, Apple and the Paris area transportation authority rolled out support for Paris transit passes in Apple Wallet. It means that people can now use their iPhone or…

Paris transit passes now available in iPhone’s Wallet app

Redwood Materials, the battery recycling startup founded by former Tesla co-founder JB Straubel, will be recycling production scrap for batteries going into General Motors electric vehicles.  The company announced Thursday…

Redwood Materials is partnering with Ultium Cells to recycle GM’s EV battery scrap

A new startup called Auggie is aiming to give parents a single platform where they can shop for products and connect with each other. The company’s new app, which launched…

Auggie’s new app helps parents find community and shop

Andrej Safundzic, Alan Flores Lopez and Leo Mehr met in a class at Stanford focusing on ethics, public policy and technological change. Safundzic — speaking to TechCrunch — says that…

Lumos helps companies manage their employees’ identities — and access

Remark trains AI models on human product experts to create personas that can answer questions with the same style of their human counterparts.

Remark puts thousands of human product experts into AI form

ZeroPoint claims to have solved compression problems with hyper-fast, low-level memory compression that requires no real changes to the rest of the computing system.

ZeroPoint’s nanosecond-scale memory compression could tame power-hungry AI infrastructure

In 2021, Roi Ravhon, Asaf Liveanu and Yizhar Gilboa came together to found Finout, an enterprise-focused toolset to help manage and optimize cloud costs. (We covered the company’s launch out…

Finout lands cash to grow its cloud spend management platform

On the heels of raising $102 million earlier this year, Bugcrowd is making good on its promise to use some of that funding to make acquisitions to strengthen its security…

Bugcrowd, the crowdsourced white-hat hacker platform, acquires Informer to ramp up its security chops

Google is preparing to build what will be the first subsea fiber-optic cable connecting the continents of Africa and Australia. The news comes as the major cloud hyperscalers battle it…

Google to build first subsea fiber-optic cable connecting Africa with Australia

The Kia EV3 — the new all-electric compact SUV revealed Thursday — illustrates a growing appetite among global automakers to bring generative AI into their vehicles.  The automaker said the…

The new Kia EV3 will have an AI assistant with ChatGPT DNA

Bing, Microsoft’s search engine, was working improperly for several hours on Thursday in Europe. At first, we noticed it wasn’t possible to perform a web search at all. Now it…

Bing’s API was down, taking Microsoft Copilot, DuckDuckGo and ChatGPT’s web search feature down too

If you thought autonomous driving was just for cars, think again. The “autonomous navigation” market — where ships steer themselves guided by AI, resulting in fuel and time savings —…

Autonomous shipping startup Orca AI tops up with $23M led by OCV Partners and MizMaa Ventures

The best known mycoprotein is probably Quorn, a meat substitute that’s fast approaching its 40th birthday. But Finnish biotech startup Enifer is cooking up something even older: Its proprietary single-cell…

Meet the Finnish biotech startup bringing a long-lost mycoprotein to your plate

Silo, a Bay Area food supply chain startup, has hit a rough patch. TechCrunch has learned that the company on Tuesday laid off roughly 30% of its staff, or north…

Food supply chain software maker Silo lays off ~30% of staff amid M&A discussions

Featured Article

Meta’s new AI council is composed entirely of white men

Meanwhile, women and people of color are disproportionately impacted by irresponsible AI.

21 hours ago
Meta’s new AI council is composed entirely of white men

If you’ve ever wanted to apply to Y Combinator, here’s some inside scoop on how the iconic accelerator goes about choosing companies.

Garry Tan has revealed his ‘secret sauce’ for getting into Y Combinator

Indian ride-hailing startup BluSmart has started operating in Dubai, TechCrunch has exclusively learned and confirmed with its executive. The move to Dubai, which has been rumored for months, could help…

India’s BluSmart is testing its ride-hailing service in Dubai

Under the envisioned framework, both candidate and issue ads would be required to include an on-air and filed disclosure that AI-generated content was used.

FCC proposes all AI-generated content in political ads must be disclosed

Want to make a founder’s day, week, month, and possibly career? Refer them to Startup Battlefield 200 at Disrupt 2024! Applications close June 10 at 11:59 p.m. PT. TechCrunch’s Startup…

Refer a founder to Startup Battlefield 200 at Disrupt 2024

Social networking startup and X competitor Bluesky is officially launching DMs (direct messages), the company announced on Wednesday. Later, Bluesky plans to “fully support end-to-end encrypted messaging down the line,”…

Bluesky now has DMs