Millions of people have trusted Flo with some of the most intimate details of their lives. For many, the period and fertility tracking app became a place to record periods, pregnancies, fertility journeys, symptoms and other deeply personal information about their reproductive health.
But Flo is now at the centre of allegations that some of this information was shared with third-party technology companies without users’ knowledge or consent.
So, what exactly is Flo accused of doing – and what could it mean for people who used the app in the UK?
What are the allegations against Flo?
Legal action alleges that between 30 June 2016 and 23 February 2019, sensitive information entered into the Flo app was disclosed to third-party technology companies without users being properly informed or giving valid consent.
The companies named in the legal action include Google, Meta and Flurry, an analytics platform used by app developers.
According to the claims, information was transmitted through software built into the Flo app. This type of software is commonly used by app developers for things such as analytics and understanding how people use their services.
The issue at the heart of the Flo case is not simply that third-party technology was being used. It is whether users understood what information was being transmitted, who was receiving it and whether they had given valid consent.
Was Flo hacked?
No. The allegations against Flo are different from the kind of data breach most people associate with hackers or cybercriminals.
There is no suggestion that criminals broke into Flo’s systems and stole users’ information.
Instead, the legal action focuses on whether Flo itself disclosed information through technology integrated into its app without users being properly informed.
That distinction matters, but it doesn’t necessarily make the privacy concerns any less significant.
If you’ve recorded details about a pregnancy, fertility problems, a miscarriage or your sexual health in an app you believed was private, discovering that information may have gone somewhere you didn’t expect could feel like a serious violation of your privacy.
What happened in the US?
Concerns about Flo’s data practices first attracted widespread attention in 2019. In 2021, Flo reached a settlement with the US Federal Trade Commission following allegations about the way it had shared sensitive health information. As part of the settlement, Flo agreed to measures including obtaining users’ consent before sharing certain health information and undergoing independent privacy reviews.
Further legal action followed. In July 2026, Flo Health, Google and Flurry agreed to a proposed $59.5 million settlement to resolve certain claims brought in the United States. The companies have not admitted wrongdoing. The US settlement does not apply to UK Flo users.
What does this mean for UK users?
That’s an important question.
In the UK, health information is generally treated as special category data under data protection law and receives additional protection because of its sensitive nature. If personal health information was shared without users being properly informed or without a valid legal basis, it could lead to a claim under UK data protection law.
The allegations relate to people who used Flo between 30 June 2016 and 23 February 2019.
If you used the app during this period, it’s worth staying informed about developments and understanding the allegations at the centre of the case.
Join the Claim connects consumers with SRA-regulated lawyers. Visit the claim page to check your eligibility if a claim is open with one of our trusted legal partners. If a group action has not yet been launched, you can register your interest and we’ll keep you informed if a partner firm decides to take a claim forward.