Pregnancy app privacy: where your data actually goes, myCocoon
myCocoon Get myCocoon
Editorial illustration of an iPhone with three sage data ribbons of sleep, heart rate, and steps flowing across a cream background.

Compared

Pregnancy app privacy: where your data actually goes

23 June 2026 · 15 min read

Are pregnancy apps safe, and where does your data go?

Most pregnancy apps are safe in the ordinary sense and careless in the sense that matters. The dominant trackers keep what you log on their own servers, carry advertising identifiers, and reserve the right to share or sell it. One has a federal privacy order on its record. Another lost a jury trial over the data it leaked. The most private option keeps your health data on your phone. This piece maps where each app’s data actually goes, with the primary source in the same paragraph as the claim.

We looked at six apps in detail: Flo, Ovia, What to Expect, BabyCenter, Glow, and myCocoon. The pattern across the first five is consistent enough to be a category trait. The exception, myCocoon, is built the other way around: every Apple Health reading lives in a local-only store that never syncs to iCloud or to a company server, the app watches each Health signal it reads, sleep, resting heart rate and steps, against your own rolling baseline on the device, and Cloud AI is off until you choose to turn it on. It is also iPhone-only, iOS 26 and up, with no Android version and a smaller content library than Flo or What to Expect. That contrast is what makes the comparison worth running.

Last reviewed: 23 June 2026.

What we looked at, and what we left out

Comparing privacy badly is easy. You skim one App Store label, panic, and delete everything. A useful comparison names the axes before the verdict, so you can follow the reasoning rather than just accept the conclusion. We scored four things for each app.

  • Where the data lives. Company servers, or your device.
  • Ad-tracking SDKs. Whether the app carries advertising identifiers and trackers, read from its App Store privacy label.
  • Sells or shares data. What the privacy policy actually permits, not what the marketing says.
  • Regulatory record. Any documented government order, settlement, jury verdict, or independent audit warning.

What we left out: feature depth, community, content libraries, and price. Those matter when you choose an app, and the roundup on the best pregnancy apps for 2026 weighs them. This piece is only about where the data goes. One more note up front. myCocoon is the app this blog belongs to, and its privacy claims here are self-asserted, not yet checked by an independent auditor. We flag that again where it matters.

Where each pregnancy app’s data actually goes

AppWhere the data livesAd-tracking SDKsSells or shares dataRegulatory record
FloCompany servers, post-FTC consent flowYes: identifiers, location, usageShared health data with Facebook, Google, others, 2016 to 2019 (FTC complaint, 2021)2021 FTC order; Aug 2025 Meta jury verdict
Ovia (Labcorp)Company serversYes: data linked to you, incl. sensitivePolicy permits selling de-identified data; employer reporting (Washington Post, 2019)Mozilla warning
What to Expect (Ziff Davis)Company serversYes: contacts, identifiers, usage, sensitivePolicy permits selling online data to advertisers (Mozilla)Mozilla warning
BabyCenter (Ziff Davis)Company serversYes: identifiers, usage, sensitivePolicy permits selling online data to advertisers (Mozilla)Mozilla warning
GlowCompany servers, plus Apple Health syncYes: cross-app tracking, sensitive, locationSensitive data shared for advertising (Mozilla)$250k California settlement, 2020; Mozilla warning
myCocoonHealth data on device; entries to your iCloudNoneNo (self-asserted, not yet audited)None; claims not independently audited

The two middle columns are read from each app’s App Store privacy label and the audits Mozilla published when it flagged all ten pregnancy trackers it reviewed, 18 of 25 products overall, on 17 August 2022. The per-app sections below carry the full citation for every claim.

App by app: who keeps what, and who shares it

Flo is the market leader and the cautionary tale. From 2016 to 2019 it passed health information, including the fact that a user was pregnant, to Facebook, Google, and analytics firms through named app events, despite a policy that promised the opposite. (FTC complaint, 2021) The 2021 settlement with the Federal Trade Commission required Flo to obtain affirmative consent before sharing health data, to notify affected users, to instruct any third party that received the data to destroy it, and to submit to an independent privacy review. (FTC, final order, 2021) The story did not end there. On 1 August 2025 a California jury found that Meta violated the state’s Invasion of Privacy Act by collecting Flo users’ reproductive data through its SDK. (CNBC, 2025) Damages have not been set, and the judge later signaled Meta could owe as much as roughly 8 billion dollars. (Courthouse News, 2025) Flo today runs under that federal order, which is a real, enforceable constraint. For the longer head-to-head, see myCocoon vs Flo.

Ovia, owned by Labcorp, is the clinical-depth option and the one with an employer twist. Its privacy policy permits selling de-identified, aggregated data, and Ovia has long marketed exactly that to the employers and health plans that distribute it. A 2019 Washington Post investigation described employers receiving aggregated reports on their workforce: average trimester, share of high-risk pregnancies, return-to-work timing, and the questions women were asking. (Washington Post, 2019) De-identification is reassuring in theory and reversible in small pools, where one pregnant employee can be the only data point. Mozilla’s Privacy Not Included flagged the app while crediting it for clearer handling of law-enforcement requests than most. (Mozilla, Ovia review)

What to Expect is free, ad-supported, and the bluntest about it. Its App Store privacy label lists data used to track you, including contacts, identifiers, usage, and sensitive information. Mozilla quotes the policy directly: the app may sell or transfer your online data to certain third parties such as advertisers, buys additional data from brokers, and discloses information to authorities on request. (Mozilla, What to Expect review) The content is reviewed and trustworthy. The data policy is what you pay for a free app.

BabyCenter, owned by the same parent as What to Expect, runs the same model. Mozilla’s audit found a policy that permits selling or transferring online data to advertisers, the purchase of broker data, precise-location tracking, and disclosure to authorities on request. (Mozilla, BabyCenter review) Like its sibling, it pairs decades of trusted editorial with a data policy written for an advertising business.

Glow is the only one of the six with a documented financial penalty. In 2020 it paid 250,000 dollars to settle with California over security failures, first surfaced by Consumer Reports researchers who showed that one account could reach another user’s reproductive-health data. (Consumer Reports) Its current App Store profile shows cross-app tracking and the use of sensitive, location, and identifier data for third-party advertising and personalization, and Mozilla carries a Privacy Not Included warning. (Mozilla, Glow review) Glow also advertises AI insights without naming the model or where it runs.

myCocoon is the app built around the opposite default. It keeps two separate stores. One holds what you enter yourself, your due date, kicks, appointments, and journal entries, and syncs through your own iCloud account so a new phone picks up where you left off. The other, where every Apple Health signal goes, lives on your phone only, with no connection to iCloud and no connection to a myCocoon server. There are no ads and no ad-tracking identifiers, because there is no ad business to feed. With Cloud AI off, the everyday AI runs on Apple’s on-device Foundation Models, and the app watches a few Health signals, sleep, resting heart rate and steps, each one against your own rolling baseline, raising a quiet nudge when any single signal drifts: a run of short nights, an elevated resting heart rate, an unusually high-activity day. Mood is watched separately, for a sustained downward run rather than a one-off low day. The day’s readings are gathered into a daily digest on the phone. Reading them jointly, as one correlated picture, is on the roadmap, not shipped. What most trackers do not attempt at all is this kind of per-signal, baseline-aware nudging from passive Health data. Cloud AI is off until you switch it on. Turn it on and your question goes to Google’s Gemini with a structured briefing: your week and trimester, your first name and baby’s name if you have set them, profile basics, recent symptom names and counts, your mood and sleep trends, and a daily read of your sleep hours, resting heart rate and steps. What is never sent, in either mode, is your journal text, your photos, your voice recordings as audio, and your full Health history. The honest line is not that nothing leaves. It is that a defined summary leaves, and only after you ask. One caveat, repeated: these are design claims this blog is making about its own app, and no independent auditor has yet verified them. The architecture is described in how a pregnancy app reads what is already on your phone.

Why your health data is not supposed to sync to iCloud

Apple’s HealthKit guidelines contain one rule that shapes this entire category: apps must not store users’ health data in iCloud. (Apple, Health privacy white paper, 2023) That is why most pregnancy apps either read very little from your Health app, or read a number, show it, and forget it. The rule is usually treated as a constraint to work around. Treated as a design requirement, it produces a different architecture.

Most apps in this category have not tried it, but privacy, artificial intelligence, and Apple Health can coexist if you split your storage. Health-derived data, the heart rate and sleep and weight your iPhone already holds, goes in a local-only store that never syncs. Everything you type yourself goes in a separate store that can sync to your own iCloud. The first store is the one Apple’s rule protects. The second is yours to back up. An app designed this way can read several Health channels on the device, watching each one against its own rolling baseline, and keep the raw Health store off iCloud and off its own servers entirely. The only health data that ever leaves, and only if you switch on Cloud AI, is a daily summary of those signals: your sleep hours, resting heart rate and steps. For which apps touch Apple Health at all, see which pregnancy apps work with Apple Health.

The catch is that you have to build this on day one. An app that has kept everything on its servers for years cannot retrofit the local-only store without rebuilding how its data syncs from the ground up. That is the real reason “privacy” and “AI” and “Apple Health” rarely appear together in this category. The three do not conflict. Retrofitting an app built around server sync is expensive.

Should you delete your pregnancy app after Dobbs?

Probably not, and not for the reason the headlines suggest. After the Dobbs decision, the Electronic Frontier Foundation examined the “delete your period app” advice and concluded it was not necessarily the right move. (EFF, 2022) The dragnet mining of cycle entries to identify pregnancies is a possible future risk, not the way cases are built today.

The real vector is more mundane and more human. People are reported by someone they know: a hospital worker, a partner, a family member. The evidence that follows is usually texts, emails, and browser search history, not the symptom log inside a tracker. (EFF, 2022) Data brokers and the location trail your phone leaves are a larger exposure than your kick counter.

That does not make pregnancy-app data harmless. Deleting an app does not delete what already sits on the company’s servers, and some policies have permitted handing data to police on request. Congress has written to period-app makers about the misuse of sensitive data. (EFF, 2022) The proportionate response is not panic. It is choosing an app that does not pool sensitive data on a server in the first place, and being as careful with your searches and your messages as you are with your tracker.

Common questions

Are pregnancy apps safe to use? Most are safe from malware and follow the app-store rules, but the popular trackers treat your data as a revenue source. They store what you log on company servers, carry advertising identifiers, and reserve the right to share or sell it. Flo carries a 2021 FTC order and a 2025 jury verdict against Meta over its data. Safety here is less about hacking and more about where your information is allowed to travel.

What is the most private pregnancy app? The most private design keeps health data on your device rather than on a company server. Among the apps reviewed here, myCocoon is built that way: health-derived data stays in a local-only store, your own entries sync only to your iCloud, and there are no ads or ad-trackers. That claim is self-asserted and not yet independently audited. Every other app reviewed here stores your data on its own servers and carries tracking identifiers.

Is Flo safe after the FTC settlement and the Meta verdict? Flo operates under a 2021 FTC order requiring affirmative consent before sharing health data, user notification, third-party data destruction, and independent privacy review. In August 2025 a California jury separately found Meta liable for collecting Flo users’ reproductive data through its SDK. The order is an enforceable constraint, and Flo has added privacy features since. Whether that is enough trust for you is a personal call.

Can my pregnancy app data be used against me? It is possible but not the most likely vector. The EFF notes that cases are usually built from texts, emails, and search history, plus reports from people who know you, rather than from cycle or symptom logs. The larger exposures are data brokers and your phone’s location trail. Deleting an app does not remove data already on a company’s servers, so the better protection is choosing an app that never pools it there.

Do pregnancy apps share data with employers? Some do, in aggregated form. Ovia is distributed through employers and health plans, and its policy permits selling de-identified, aggregated data; a 2019 Washington Post investigation described employers receiving workforce-level pregnancy reports. De-identification can be reversed in small groups, where one pregnant employee may be the only data point. Apps that keep health data on your device do not have this channel to begin with.

Does my health data on my iPhone end up in iCloud? Apple’s HealthKit rules say apps must not store your health data in iCloud, so a well-built app keeps Apple Health readings in a local-only store that does not sync. Your own typed entries, like appointments or journal notes, can sync to your personal iCloud if the app offers backup. The two are separate by design. If an app syncs raw health values to its own servers, that is a deliberate choice, not an Apple default.

Is there a private pregnancy app that keeps health data on your phone? Yes. Among the apps reviewed here, myCocoon is built around it. Every Apple Health reading lives in a local-only store on your iPhone that never syncs to iCloud or to a company server. With Cloud AI off, the everyday AI runs on the device with Apple’s Foundation Models, so the core works with no cloud at all. It watches a few Apple Health signals, sleep, resting heart rate and steps, each one against your own rolling baseline, and raises a quiet nudge when any single signal drifts, a run of short nights, an elevated resting heart rate, an unusually high-activity day. Mood is watched separately, for a sustained downward run rather than a one-off low day. Reading these jointly, as one correlated picture, is on the roadmap, not shipped. There are no ads and no data sale. Cloud AI is off until you turn it on. Turn it on and your question goes to Google’s Gemini with a structured briefing: your week and trimester, your first name and baby’s name if you have set them, profile basics, recent symptom names and counts, your mood and sleep trends, and a daily read of your sleep hours, resting heart rate and steps. What is never sent, in either mode, is your journal text, your photos, your voice recordings as audio, and your full Health history. The honest limits: it is iPhone-only on iOS 26 or later, with no Android version, no peer community, and a smaller content library than Flo or What to Expect. The claim is self-asserted, not yet independently audited.

Bottom line

Five of the six store your data on their servers, carry ad-tracking identifiers, and reserve the right to share or sell it. One of those has a federal order and a jury verdict on its record, another a state penalty, and a third an employer-reporting business. None of that makes them malware. It makes them ad-supported software in a category where the data is unusually intimate.

The most private posture is the one that never collects the sensitive data centrally: health readings kept on your device, your own entries synced only to your iCloud, no ads, no trackers. myCocoon is built that way, and that claim is still waiting on an independent audit to confirm it. You can read exactly what it does and does not send, line by line, on its privacy page and decide for yourself. If privacy is your deciding factor and you are on an iPhone running iOS 26 or later, myCocoon is on the App Store today. If an Android version, a peer community, or a larger content library matters more, the 2026 roundup is the honest starting point. Either way, choose with the data map in front of you.

§