{
  "slug": "flo",
  "category": "period-trackers",
  "name": "Flo",
  "description": "Period, ovulation and pregnancy tracking app with cycle predictions, symptom logging and health content, funded by Flo Premium subscriptions. An Anonymous Mode removes name and email from the account.",
  "website": "https://flo.health",
  "license": null,
  "platforms": [
    "android",
    "ios"
  ],
  "jurisdiction": {
    "code": "GB",
    "name": "United Kingdom",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": true,
    "cloud_act": "agreement"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "F",
  "score": 20,
  "coverage": 100,
  "summary": "Flo scores 20 out of 100 (grade F) on the period trackers criteria. It partly meets no ads or data sales, independent audit and no account needed. It does not meet open source, no trackers or telemetry and data stays on device. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
  "url": "https://privacyratings.com/period-trackers/flo/",
  "markdown": "https://privacyratings.com/period-trackers/flo/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.iggymedia.periodtracker/latest/",
      "note": "The Exodus report finds AppsFlyer, Google Firebase Analytics and Sentry in the Android app."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://flo.health/privacy-policy",
      "note": "Funded by subscriptions with no in-app ads or data sales, but with consent device identifiers are shared with AppsFlyer and ad partners such as Meta and Google Ads to target Flo's own ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://flo.health/privacy-portal/certification",
      "note": "Flo holds ISO 27001 and ISO 27701 certifications and cites a third-party privacy audit, but no full audit report is public."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "local_storage": {
      "title": "Data stays on device",
      "weight": 3,
      "answer": "no",
      "evidence": "https://flo.health/privacy-portal",
      "note": "Cycle data is stored on Flo's servers, encrypted at rest but not end-to-end encrypted."
    },
    "no_account_needed": {
      "title": "No account needed",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://flo.health/product-tour/anonymous-mode",
      "note": "An account is created on Flo's servers, but Anonymous Mode lets it be used without a name, email or other identifiers."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google Tag Manager",
        "host": "inline code",
        "effect": "no"
      },
      {
        "name": "Trustpilot",
        "host": "widget.trustpilot.com",
        "effect": "none"
      }
    ],
    "tested_at": "2026-10-01T06:59:50.340Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}