Period Tracker Stardust Shares Users’ Reproductive Health Data Without Disclosure, Audit Finds

A Mozilla Foundation audit released in July 2026 found that Stardust, an astrology-themed period tracking app, transmits users’ reproductive health details — including birth control type, pregnancy status, moods, and symptoms — to a data firm not named in its privacy policy. The audit was produced in partnership with Harvard’s Berkman Klein Center and first reported by the BBC.

Mozilla researcher Shoshana Wodinsky found that Stardust pings third-party trackers from the moment the app opens, before a user enters any information. When a symptom is logged, the details are sent to analytics firm RudderStack alongside a persistent user ID, with no in-app option to disable the sharing. RudderStack is built to route data onward to additional destinations that Mozilla was unable to observe. Stardust also passes Facebook an ad identifier that links in-app behavior to existing user profiles on the platform. Stardust scored 2 out of 10 — the lowest of the six trackers audited. The company told TechCrunch it has never received a legal demand for user data.

By contrast, Euki, a nonprofit-run tracker, received a perfect 10. It requires no account, keeps health data entirely on the device, and offers a PIN, automatic deletion scheduling, and a decoy screen. Its only noted limitation is an in-app browser for educational content that loads standard web trackers, though it resets identifiers between visits.

The findings carry heightened significance given the legal landscape around reproductive health in the United States, where such data could potentially be sought by law enforcement in states with abortion restrictions. The audit suggests that many users of period tracking apps may be unaware of how broadly their most sensitive health information is being shared and with whom.

The Stardust disclosure is one of several privacy and security stories surfacing this week. Separately, a breach at AI music startup Suno exposed account data for hundreds of thousands of customers and revealed internal records suggesting the company scraped over 113,000 hours of YouTube Music audio to train its models. And the Department of Homeland Security’s data-sharing platform HSIN was found to have been breached after analysts twice dismissed signs of intrusion as false positives, a lapse that Senate Intelligence Committee vice chair Mark Warner called a risk to national security.

Source: WIRED

This article was generated by AI and cites original sources.
Scroll to Top