The team behind menstrual health and period tracking app Clue has said it will not disclose users’ data to American authorities, following Donald Trump’s reelection.
The message comes in response to concerns that during Trump’s second presidency, abortion bans that followed the overturn of Roe v. Wade in 2022 will worsen and states will attempt to increase menstrual surveillance in order to further restrict access to terminations.
Cool but the proper solution is that they shouldn’t have access to this data at all. It should be either stored locally, or encrypted on their servers. Companies not being able to access their consumer data should be the default.
My wife uses a spreadsheet and connected it to her calendar. Seems pretty accurate.
It is a modified version of this:
That will last only until a judge signs a warrant.
Or until the American people get bored with talking about it, like with everything else, then stop caring and just let whatever happen.
Or until Trump decides to have an army of hackers like Putin.
We already do. We wage cyber warfare with other countries the same.
Were people unclear on this? They think that the US is just letting cyber warfare happen without participating…?
Don’t fall for it. Read their privacy policy.
They keep your data in the cloud and share it with third parties, including advertisers.
Pen and paper doesn’t snitch.
not defending the bogus use of the cloud to host sensitive data, nor do i unquestioningly believe this? but correcting the record since you did 80% of the work in finding the link:
Be assured that the sensitive health data you track in the Clue app is never shared with or sold to advertisers, or any partners whose services we may recommend in Clue.
If you actually read what you sent it seems like the only data that is shared to advertisers is standard marketing stuff like IP, device ID, age group, and location. Still bad and I stand with others recommending locally hosted FOSS alternatives.
There are also foss alternatives. Install fdroid and get drip.
Drip is a horrible name for a period tracking app lol
I mean at that point just call it Bleed lol
GUSH
What an insightful comment, the_crotch
It actually inspired me to start writing my own competing period tracking app, Margaret Plug That Up Already You’re Ruining The Carpet
I like you
That was my first thought. Why?
You guys are talking about it arent ya?
And look how fast you memorized the name.
Research conducted by the Mozilla Foundation indicates that the app referred to in the article, Clue, gathers extensive information and shares certain data with third parties for advertising, marketing, and research reasons.
Here are some menstruation tracking apps that are open-source and prioritize user privacy by keeping your data stored locally on your device:
So the government just needs to acquire this data from one of those third parties if it wants it.
so what they’re really saying is they won’t give it away for free
They do claim to not share any medical data with third parties though. See other comments for source.
I wouldn’t trust them either way…
You don’t know how fascism works, do you?
Drip doesn’t save anything to the cloud, it’s all local to your device. I can’t speak to the others.
Which does mean one has to backup and manually move your tracking history to a new device. Guess who forgot to do that 😂
Good idea is to use something like Syncthing to copy data between your phone and another device like a laptop or another phone. This depends on the app, for Drip you have to manually export the data yourself on a regular basis.
Another useful idea is if you have an old phone lying around get it connected via Syncthing and back up everything to it. If your current phone dies or is lost you can switch back immediately, a hot backup. If you have root on your device you can use NeoBackup to schedule backups of the data into a folder Syncthing can access and send to backup locations, say a home computer or spare device.
God I wish I could learn more about this shit.
For all of the Linux and FOSS nerds on Lemmy, I don’t think I’ve seen one make a guide on how to have good digital stewardship of oneself. Syncthing sounds freaking awesome. Still feel like there’s a barrier to entry for me though
What OS do you use? Windows, Mac, Linux? And same for your phone? Android? If so, you should be able to get it set up on your desktop and phone.
First, get it installed on your desktop. For windows and mac go to the Syncthing download page and grab the installer. On Linux you will find install instructing below, but basically use your package manager to install syncthing.
Once it is installed you can start it up and it will open a GUI, most likely through your web browser (probably 127.0.0.1:8384 or similar). From here you will have your Syncthing interface for your computer set up, so on to the phone.
On your phone install syncthing from whichever store you use, fdroid is my favourite. Once installed open it and you should have an option to add another device. You can use this to scan the QR code on your computer Syncthing interface.
Currently on Windows 11 (yuck) and have a Galaxy S23.
Next devices I’m looking at are a Framework laptop and Fairphone.
The QR code sounds super easy which is a good sign. I guess most of my complaints rest with what a full FOSS and pro-privacy cyber-system would look like overall. I come from a Windows world so I have those household names stuck in my head, like Word, Outlook, etc. I guess I’m really looking for a guide that has a 1:1 for the entire OS from Windows to Linux, and maybe more if it improves people’s lives. Thinking Jellyfin and Bitwarden and all those purpose-driven applications.
At this point I don’t know what I don’t know, and I just wish that some of the awesome devs on Lemmy would post a guide to all of this, soup to nuts style. Maybe one day
I think piecemeal is a good way to go. Switch from MS Office to LibreOffice, from iOS to android, from Photoshop to Krita, then go to dual booting Linux (probably Mint or similar) with Windows, learn more using both, find what things you reboot to Windows for, find solutions for those using Wine and alternative software, get used to solving problems in Linux land and learn the tools. Once you are comfortable with a mix of both get rid of what you can, use Windows less and less, try CalyxOS or Graphene for your phone if possible, keep making steps. Each step makes progress, and imperfect solutions are a better starting point for finding better solutions.
That said, for the earliest steps a virtual machine is an amazing tool, as is an old laptop. You can learn to solve problems on virtual or real hardware without making your life harder then inch closer to freedom. I’ve been using Linux since 2006 and honestly it has been a constant learning process. The first year was mostly VM learning, then an accidental install on my external HDD taught me about hubris and data protection. Since then I have kept moving towards more open hardware and software one step at a time. Getting started is the key, nothing teaches as well as trying.
It would be nice if it did have some automatic backup solution. Backup options could be something like Nextcloud, or some local server. Maybe even android backup but the data has to be encrypted with a password and be an opt in feature.
The only way to protect data is to not gather it.
Having your own data can be incredibly useful and valuable, the trick is protecting that data so that nefarious actors can’t use it.
Sure, but tracking period data can be very helpful for people. For a threat model of abortion criminalisation (or maybe trans healthcare criminalisation with treatments stopping periods, or really any kind of restrictions on medical autonomy), encryption at rest of locally stored period data is perfectly sufficient. They are not going to send military intelligence agencies after a random person having an abortion. It is actually a relatively low threat model, like equivalent to buying drugs online or something like that.
I mostly mean having data stored in a centralized database owned by a corporation. Since even if it’s encrypted you’re just one warrant away from the data being handed over.
If only the user has the key then there’s no real concern with the data being handed over
False
I hadn’t seen this comment, thanks for making it.
Why the hell period data needs to be stored on the cloud?
How much could it weight? A few Kb? Local storage!
I would never trust such data leaving my device when is no need for it whatsoever.
Aren’t there any open source period tracking apps? I’ll do one, it can’t be that hard. An sqlite database patched to a frontend calendar and some basic predictions based on normal scenarios.
Aren’t there any open source period tracking apps?
Many. On F-Droid.
drip. menstrual cycle and fertility tracking (Open-source, non-commercial and leaves your data on your phone.) https://f-droid.org/packages/com.drip/
Drip is a pretty wild name to call your menstrual tracking app.
Everyone says that. Idk what the big deal is
First I thought “WTF is period data a thing that should concern the government”, but then I noticed we are talking about the future Handmaids Tale country here.
Newsweek has really trash headlines. No one’s asking, yet, so that’s a terrible headline.
(Yes I voted Kamala, and yes I did it for medical autonomy reasons as well as orange potato reasons, Vance reasons, heritage foundation reasons, and Project 2025.)
It’s still a trash headline and pretty standard fare for Newsweek. Why is it trash? Because it’s classic The Boy Who Cried Wolf. When I read this headline, I need it to be real.
Still not worth the risk to download it. Get a paper journal, they make ones that guide you through tracking all the necessary data.
Paper without some sort of code to hide what’s happening isn’t much better, considering if something ever happens you could get searched.
Sure I guess but you can also just leave it at home.
They say that, but when Ken Paxton subpoenas them they will say they have no choice. It would be better to use an app that doesn’t store this data server side at all.
FOSS Period Tracking Apps Exist: (there may be others, as well)
https://fossdroid.com/a/bluemoon.html
https://fossdroid.com/a/mensinator.html
https://github.com/TotallyMonica/foss-period-tracker
Also paper and pencil.
Also the oldest known “writing” is a stick with 28 notches on it.
source on the 28 notch stick?
It was some time ago that I read of that, so the details are fuzzy. And here’s what I found:
https://nypost.com/2019/07/25/10000-year-old-engraved-stone-could-be-worlds-oldest-lunar-calendar/
“A 10,000-year-old engraved stone could be a lunar calendar. The rare pebble — found high up in the mountains near Rome, Italy, the hammer-stone was found on top of Monte Alta in the Alban Hills. It’s believed that our early ancestors would’ve used the stone to keep track of the moon’s cycles. Notches were engraved “as if they were being used to count, calculate or store the record of some kind of information. And these notches — which total either 27 or 28 — suggest the stone’s engraver used the pebble to track lunar cycles.” ref
It could also have been The Ishango Bone (https://www.thedailybeast.com/the-ishango-bone-the-worlds-oldest-period-tracker/)
How does an app being FOSS defend them from warrants?
Edit. Thank you guys for the details. I learneded something new today, much appreciated.
FOSS implies it’s your hardware, therefore a subpoena would extract no information because there is no information outside of the users device.
Interesting, thank you. I guess I don’t know enough about FOSS then.
“Free and open source software.” It’s an ethos that says that code should be free and open for people to use and improve as they see fit. The core of it is that if you modify any software that is FOSS, your software must also be FOSS. So overtime the software and what its used for improve, change, widen. Lucky for us, the movement has been ongoing for 50+ years, so it’s a mature ethos whose benefits are everywhere. Most of the internet runs on FOSS. Lemmy itself is FOSS.
It doesn’t necessarily mean an app is more private, but it does mean you can generally self host, as the commentor said. There isn’t a profit motive with most FOSS, at least not at its core, so there is little desire to data harvest generally. There is also a heavy overlap between FOSS advocates and privacy advocates, so they tend to be more privacy conscious via local data storage or encryption.
Just to key in on the overlap between FOSS and privacy, because the source code for the software is open, it means that anyone can take a peek at how everything is running under the hood (among other things). It becomes possible to verify that software is storing data locally and properly encrypting when applicable (as opposed to blindly trusting the software’s author and or lawyers).
It may also be a fun fact that best practice in encryption is to open source your algorithms. The helps safeguard against backdoors and mistakes/ errors that could compromise the security of the algorithm. Much for similar reasons as above, as it allows the security community to check your math (in a field where it is incredibly easy to get your math wrong).
Ok yeah, I understood everything in your first paragraph. The privacy part was what I was really asking about. So if you’re not self hosting you’re still at the whim of the person/company/whatever that is.
You could also argue that if even if you’re not self-hosting (i.e. renting server hardware from a 3rd party), your data is still in a siloed environment. While it may be accessible by law enforcement if you are targeted specifically, it’s unlikely to be dragnetted like the data collected from popular apps.
Something being FOSS doesn’t necessarily mean it’s safe / ethical, but a LOT of FOSS apps are designed with those principles in mind.
However, being FOSS means that if an app claims that it is safe / ethical (ex. In this case, not storing data anywhere but on your device), you or an experienced peer can check the code to verify that fact.
It doesn’t, but with these apps, you can see what information they send back to their servers (if any). If there is no info getting sent back to any servers, then there’s nothing a subpoena can do since there’s no info to subpoena. You can’t obtain info that just isn’t there.
That makes sense. Thank you!
Simple. Most FOSS are built for privacy and thus do not harvest data to send to some server somewhere in the world for whatever obscure reason. The data is locally stored on your device and stays and dies there.
No callback, no selling nor surrending data.
Personally speaking, I’d quicker have all data banks destroyed than surrendered to whatever purposes, if I ever decided to build an aplication that somehow compiled data.
deleted by creator
Why do they need to save the tracked period data to a server farm? Why can’t it just be saved on the phone, huh?
Probably because they want to be able to maintain users during device switches. Given much of the world is on an annual or bi-annual cycle it’d suck to lose your users each time.
They could just do the password manager approach where the data is encrypted on your phone but stored in the cloud. App retains users, sensitive data remains private.
I wonder how many average users would be bothered to export their period database and transfer to a new phone every time they get a new phone. I do that when I get a new phone (not often, I use my phones till they break/are literally unusable and unfixable), but I’ve had real trouble getting other people to do these kinds of things.
Yeah they may not cooperate with authorities, but I’m sure they’d be happy to sell it to contractors working on behalf of the government to the same ends. They already sell the info as it is.
For now
Drip is also available on F-droid.
Haha that is some app name!
It’s the app the comment above me was recommending. I just wanted to make that clear and show that it was available outside the app stores as well.