can period-tracker data be subpoenaed?
short answer: data that sits on a company’s server can be demanded from that company. data that only exists on your own computer has no company to ask. the longer answer has caveats worth knowing.
what actually happened
period-app privacy stopped being hypothetical years ago. the FTC settled with Flo in 2021 over health data shared with analytics companies after the app promised it wouldn’t. in 2025, the Frasco v. Flo case ended with Flo, Google, and Flurry settling — proposed settlements totaling roughly $59.5 million — while a jury found the remaining defendant, Meta, liable under the California Invasion of Privacy Act for collecting period- and ovulation-tracker data through its advertising software. none of that required a subpoena; the data was simply flowing to third parties as a matter of business. a proposed settlement still needs court approval and a verdict can be appealed, so treat those as the record as of the date at the foot of this page.
the structural point
a subpoena is a demand served on whoever HOLDS the data. cloud apps hold your data, so they can be asked — and their privacy policies decide how hard they resist. an offline app holds nothing, so there is nothing to serve. this isn’t a heroic promise; it’s just architecture. offline by design means the question never reaches a server, because there isn’t one.
the honest caveats
where LunaLog stands
LunaLog keeps your cycle in a local file on your computer. no account, no server, no analytics. there is no Cosmicore database of users’ cycles — not by policy, by architecture. buy it once and own it.
see LunaLog → a period tracker for your PC →
last updated September 2026.