Fertility tracking app Premom settles with the FTC and state AGs for $200K over allegedly sharing sensitive user information with third parties without consent
The app allegedly shared sensitive user information with China-based companies known for privacy problems
Context & Ripple Effects
Premom's settlement closes out a three-year arc: researchers alleged back in 2020 that the fertility app was sharing data with three Chinese companies without user consent, a claim serious enough that Google briefly pulled it from the Play Store. The $200K payout with the FTC and state attorneys general turns that allegation into an enforcement record.
The timing matters because period trackers have been under intensifying scrutiny since Roe was overturned, when advocates warned that cycle data shared with partners or affiliates could become evidence of a crime — and because Privacy International had already caught apps like MIA Fem and Maya piping monthly timings and symptoms to Facebook as far back as 2019.
First-order effects
- Premom pays $200K to the FTC and state AGs and now operates under a settled consent-violation record tied to disclosures about China-based recipients of its users' sensitive data.
- The FTC adds another enforcement precedent in health-adjacent consumer apps, extending a line that already includes banning stalkerware operator Support King from the surveillance business.
Second-order effects
- Every period tracker with third-party SDK relationships — Stardust was documented sharing phone numbers with analytics firm Mixpanel just after Roe fell — now faces the same researcher-plus-regulator playbook Premom went through, making data-flow audits a pre-compliance cost of the category.
- App stores and state AGs gain a template for acting on independent privacy research rather than waiting for breaches, raising the bar for what 'consent' must look like in sensitive-health onboarding flows.
Third-order effects
- If enforcement keeps pairing privacy researchers' findings with FTC action, fertility and period-tracking apps get pushed toward consent architectures where sensitive data never leaves the device or is contractually firewalled from advertisers and analytics intermediaries.
- Post-Roe, reproductive data becomes treated as legally sensitive by default, shifting the category's structure toward local-first designs and away from the ad-tech plumbing Privacy International exposed across MIA Fem and Maya.
The trend: Consumer health apps are being forced from opaque third-party data sharing toward enforceable consent, as regulators convert privacy researchers' findings into settlements and bans.