Researchers allege fertility app Premom was sharing data with three Chinese companies without user consent; Google briefly removed the app from Play Store
most had no idea the app could even do this. https://www.washingtonpost.com/ ... Wolfie Christl / @wolfiechristl : Fertility app Premom found to share personal data with Google, AppsFlyer and Chinese advertising/data companies Juguang, UMSNS and Umeng (Alibaba), including geolocation, wifi/bluetooth data, and all kinds of persistent identifiers: https://digitalwatchdog.org/ ... https://digitalwatchdog.org/ ... https://twitter.com/... Thanks: @tonyajoriley
Context & Ripple Effects
This report is the opening move in a three-year arc: researchers documented Premom shipping geolocation, wifi/bluetooth data, and persistent identifiers to Google, AppsFlyer, Juguang, UMSNS, and Umeng (Alibaba) without consent, prompting a brief removal from the Play Store. The findings anticipated the eventual reckoning — in 2023 the company reached an $200K settlement with the FTC and state attorneys general over allegedly sharing sensitive user information with third parties.
The story also slots into a longer pattern of analytics SDKs quietly exporting intimate data: years earlier, apps were caught sending heart rates and pregnancy intent to Facebook via its analytics SDK, and later studies found most popular children's apps feeding location data to the ad industry — making Premom a health-data instance of a structural SDK governance problem.
First-order effects
- Premom users learned their reproductive-app activity, location, and device identifiers had flowed to advertising and data firms including Alibaba-linked Umeng, with no consent mechanism disclosed to them.
- Google's brief Play Store removal put direct revenue and distribution pressure on Premom's developer, showing store policy enforcement can act faster than any regulator.
Second-order effects
- Health and fertility app developers face forced audits of their third-party SDK chains, since the same analytics kits implicated here are embedded across the category.
- Ad intermediaries such as AppsFlyer come under pressure to vet what categories of app data they accept, as being named in a sensitive-data scandal is now a commercial risk for attribution vendors.
Third-order effects
- If the pattern holds, reproductive and health data becomes a distinct regulatory category — the FTC and state AGs' later action against Premom signals enforcement aimed at sensitive-data flows rather than generic privacy violations.
- App stores consolidate into de facto first-line privacy enforcers, with removal decisions shaping developer behavior ahead of formal rulemaking.
The trend: Sensitive-category apps are being pushed by researchers, platforms, and eventually regulators toward consent-based data flows, with analytics SDKs as the choke point.