:

PERIOD TRACKER STARDUST SHARES HEALTH DATA WITH ANALYTICS FIRM

INDUSTRY DESK1 MIN READ
THU, JUL 16, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Mozilla research found that period tracker Stardust shares users' health data with an analytics company, revealing significant privacy gaps among menstrual health apps. The findings highlight inconsistent data protection practices across the category.

Mozilla's privacy testing identified stark differences in how period tracker apps handle sensitive user information. Stardust was found sharing health data with an analytics firm, raising concerns about user consent and data security. In contrast, another app tested by Mozilla maintained stronger privacy protections, described as "squeaky clean" in its data handling practices. The research underscores the need for greater transparency in period tracking applications, which collect intimate health information. Users often have limited visibility into where their data goes or how it's used. Period trackers have faced heightened scrutiny following the 2022 U.S. Supreme Court decision overturning federal abortion protections. Privacy advocates warned that menstrual data could potentially be accessed by law enforcement or used against individuals in states with abortion restrictions. The Mozilla findings suggest that privacy protections among period tracker apps remain inconsistent, leaving some users vulnerable to unexpected data sharing with third parties.

■ SOURCES

TechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A 68-year-old has been sentenced to over six years in prison in the U.K. for operating an illegal IPTV service that generated £980,812 ($1.3 million) over three years.

1H AGOIndustry Desk

A detailed analysis examines how the internet has shifted toward predatory practices, drawing significant engagement from tech community members on Hacker News with 227 points and 120 comments.

2H AGOIndustry Desk

A critical vulnerability in the popular GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary commands on hosting servers. The maximum-severity flaw requires immediate patching.

2H AGOSecurity Desk

Over 8,300 internet-facing Gitea instances remain unpatched against a critical vulnerability being actively exploited in remote code execution attacks, according to Shadowserver.

3H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.