- How women’s health apps are being used against them
In the age of digital health, women’s health apps have emerged as essential tools that help millions of women monitor and manage their wellbeing. From tracking menstrual cycles to monitoring fertility, these apps are designed to provide personalised health insights, improve quality of life, and empower women with knowledge about their bodies. But behind the user-friendly interfaces and helpful features, a disturbing question arises: Who owns the data we share with these apps? And more importantly, how can this data be misused?
As technology continues to infiltrate nearly every aspect of our lives, we are entering a new era where privacy is an illusion, especially for women. From social media platforms to health apps, data is being collected at an unprecedented rate. While some apps claim to protect user privacy, the reality is that personal data – particularly health data – often ends up in the hands of third parties, including corporations, advertisers, and even government agencies. The very same data that women entrust to health apps in hopes of better understanding their bodies can, in the wrong hands, be used against them.
The promise and peril of health apps
Women’s health apps, particularly those focused on reproductive health, are among the most popular health tools globally. Apps like Clue, Flo, and Ovia provide users with the ability to track menstrual cycles, ovulation periods, symptoms related to hormonal changes, and even mental health patterns. They have become go-to resources for millions of women who seek to understand their bodies better. The apps offer a degree of control and visibility, allowing women to plan pregnancies, monitor their health, and track irregularities that might signal health problems.
However, as these apps gain popularity, so does the amount of data they collect. Every time you input information about your cycle, symptoms, or mood swings, you’re creating a detailed record of your physical and emotional health. This data is incredibly valuable, not just for your personal wellbeing but also for companies interested in using this information to target you with ads, analyse trends, or build predictive models about women’s health.
The problem arises when these health apps sell or share this data with third parties without clear and informed consent. For instance, while some apps claim that they anonymise and aggregate user data, studies have shown that even de-identified data can sometimes be traced back to an individual with enough effort. In some cases, sensitive data, like information on sexual activity or the intention to get pregnant, can be linked to an individual’s identity.
A global issue with local consequences
While this is a global issue, the lack of awareness and regulatory frameworks in countries like Sri Lanka makes it particularly concerning. Sri Lanka, like many other nations, does not have comprehensive laws governing the protection of digital health data. With the rapid growth of smartphone usage and internet penetration, it is likely that Sri Lankan women are using health apps without fully understanding the potential risks involved.
Take, for example, the growing use of fertility tracking apps. In many countries, women use these apps as part of family planning. However, in places where reproductive rights are not fully protected, such as in Sri Lanka where abortion laws are restrictive and often stigmatised, this information could be used against a woman. Imagine a woman using an app to track her pregnancy intentions. If her data were to be sold to an insurance company, it could lead to higher premiums or even denial of services based on her reproductive health choices.
Moreover, in a country where digital literacy remains low, it is unlikely that many users are fully aware of the privacy policies of the apps they are using. Most privacy agreements are long, complex, and often written in legal jargon that is difficult to understand. This creates a situation where women are unknowingly agreeing to share sensitive data, which can then be exploited by corporate entities or governments with less than noble intentions.
The consequences of data breaches
Consider the case of the popular app Flo, which was involved in a controversy when it was revealed that the app shared users’ sensitive data, including their health data, with Facebook and other third parties. While Flo claimed that it had since updated its practices, the breach raised concerns about how widely sensitive data is shared and how little control users actually have over it.
In Sri Lanka, data breaches in the health sector could have dire consequences. Imagine a situation where a woman’s health app data – revealing her use of contraception, her sexual preferences, or even a history of miscarriage – gets leaked. The social stigma surrounding sexual and reproductive health choices is still pervasive in many parts of Sri Lanka. In a tightly-knit, conservative society, such breaches could lead to humiliation, discrimination, or even violence. Furthermore, women’s health data can be weaponised in ways that undermine women’s autonomy and privacy.
Additionally, apps like these are often used in contexts where women might be more vulnerable, such as during periods of domestic abuse or gender-based violence. If the abuser gains access to the woman’s health data – perhaps by tracking her menstrual cycle or her use of contraception – it could be used to exert further control over her body and choices.
The hidden truth behind data monetisation
Another growing issue in the world of health apps is how companies monetise women’s data. Many apps offer free services, but the catch is that users are often paying for the service in the form of their personal data. Health apps are increasingly monetising user data through partnerships with pharmaceutical companies, advertisers, or even research institutions. These companies then use the data to create highly targeted ads, conduct market research, or influence the development of new products.
While this might seem like a harmless trade – your health data in exchange for a free app – the consequences can be far-reaching. In some cases, women may unknowingly participate in research or be subjected to marketing practices that they never consented to. As apps collect more detailed information, including sensitive health data, it becomes increasingly clear that women are being commodified in the process.
For example, if a woman uses a health app to track her fertility or pregnancy, that data could be sold to insurance companies looking to tailor policies based on a woman’s reproductive health. A woman may then find herself paying higher premiums based on the fact that she is in her reproductive years, or even being discriminated against for the choices she makes about her body.
The need for stronger protections
The solution to these concerns lies in stronger data privacy laws and greater transparency from companies that provide health apps. Countries like those in the European Union have taken significant steps in this direction with their General Data Protection Regulation (GDPR), which provides individuals with greater control over their personal data and requires companies to be more transparent about how they collect, use, and store data.
Sri Lanka, however, lags behind in this regard. While the Personal Data Protection Act, which came into effect in 2023, is a step in the right direction, it still lacks comprehensive provisions on health data, particularly when it comes to apps. If Sri Lanka is to protect its citizens, especially women, from the misuse of their health data, it needs to establish clearer regulations and enforcement mechanisms for data protection in the digital health sector.
What women can do to protect themselves
Until laws and regulations catch up, women must take steps to protect their health data. Here are a few practical tips for staying safe:
- Read privacy policies: Before using a health app, read its privacy policy carefully. Pay attention to who the app shares your data with and whether you can opt-out of data sharing
- Use encrypted apps: Look for apps that prioritise encryption and data security. Some apps offer end-to-end encryption, which means that even the company running the app cannot access your data
- Be mindful of what you share: Only input the necessary information into health apps. Avoid oversharing sensitive details like your sexual activity or plans for pregnancy, especially if the app does not clearly explain how it will protect this data
- Opt for paid services: If possible, choose apps that charge a fee instead of offering free services. Many free apps monetise user data by selling it to third parties, while paid apps might offer better privacy protection
- Stay informed: Stay up to date with the latest news and research on digital privacy, especially regarding health apps. The more informed you are, the better equipped you’ll be to protect your data
Women’s health apps have the potential to be empowering tools that help women gain control over their health. However, as we continue to live in a digital age, it is crucial to remember that the data we share is incredibly valuable – and often vulnerable. While we cannot fully control the practices of corporations and app developers, we can take steps to protect our personal information and push for stronger laws to protect our digital rights. Only when we recognise the value of our data and demand better protections will we be able to fully harness the benefits of health apps without sacrificing our privacy and autonomy.
In the meantime, the most important tool we have as women is awareness – awareness of how our data is used, who owns it, and what we can do to protect it. Our health is personal, and it should remain that way.
(The writer is a feminist activist and advocate for gender equality, climate justice, and sexual and reproductive health rights [SRHR]. She is the founder of the Gender Justice Collective, which is dedicated to promoting women’s empowerment, digital safety, and youth-led initiatives)
…………………………..
The views and opinions expressed in this article are those of the author, and do not necessarily reflect those of this publication