Your health data is deeply personal. That’s why at Flo, protecting it isn’t just a feature - it’s our foundation.
Hundreds of millions of people worldwide trust Flo with their most intimate health information, and we don't take that lightly. That trust is built into how we design our products, how we make decisions, and how we hold ourselves accountable. You stay in control of your data and are always informed about how it’s used.
We built this Trust & Safety Centre so you can see exactly how. Our privacy practices, explained plainly. The team responsible for your data. The features and certifications that back up everything we say. From our award-winning Anonymous Mode, to our dual ISO certifications in privacy and security, every privacy decision we make is guided by one question: how do we deliver the highest level of data protection while keeping users fully in control and informed?
That question doesn't go away when it's inconvenient. It's how we've become the standard others are measured against in women's health technology. Explore the Trust and Safety Centre to learn what privacy leadership looks like across the femtech ecosystem and beyond.
How We Protect Your Data
At Flo, security isn't just a policy we point to – it's built into every decision we make.
Encryption at every layer
Encryption is a way of turning your data into unreadable code, like locking it in a digital safe. Only someone with the correct key can unlock it and read what’s inside. This ensures that even if someone were to intercept your data, they wouldn’t be able to understand it.
We use AES-256 encryption to protect your data when it's stored and TLS 1.3 encryption to secure it during transmission. These are the same standards used by banks and government agencies.
Access controls
Your data is protected by strict access controls. Only authorized Flo team members can access user data, and only when necessary to provide services or comply with legal obligations.
Continuous monitoring
Our security team provides 24/7 threat monitoring, using automated systems designed to identify and address potential risks before they impact your data. We also conduct regular security testing—including penetration tests, vulnerability assessments, and ongoing reviews by independent third-party security firms.
Independent verification
We don't just promise security—we prove it through regular third-party audits, penetration testing, our bug bounty programme, and internationally recognized certifications.
Our Certifications & Independent Audits
Flo is the first and only period tracking app with dual ISO 27001 and ISO 27701 certifications, setting the industry standard for security and privacy management.
Anonymous Mode: Industry-Leading Privacy
Anonymous Mode is our award-winning technology that allows you to use Flo without personal identifiers – such as your name, email, or IP address – linked to your health data. No one can identify you when you're in Anonymous Mode. Not even us.
How it works:
Anonymous Mode uses Oblivious HTTP (OHTTP) – a cutting-edge protocol that prevents anyone, including Flo, from linking your identity to your health data. We've also integrated post-quantum cryptography (PQC) to ensure your privacy is protected even as encryption-breaking technology advances. This isn't standard. We built it because the standard wasn't enough.
Industry Awards
Anonymous Mode has been recognized by some of the most respected names in technology and privacy:
- PICCASO Awards Europe: Most Innovative Data Privacy Project Finalist, 2024
- TIME: Best Inventions Finalist, 2023
- Fast Company: World Changing Ideas Finalist, 2023
- IAPP: Privacy Innovation Award Winner, 2022
Open source:
The code behind Anonymous Mode is publicly available, so everyone can see how it works and use it in their own technology.
We want to drive confidence in femtech for everyone. Our mission is for all women to feel safe and confident when tracking their health, whether or not they choose Flo. That’s why we open-sourced the code, giving other health technology companies the opportunity to leverage the investments we’ve made.
Without OHTTP (regular app mode)
Flo can view: Your IP address, device info,
and health data together
With OHTTP (Anonymous Mode)
The relay acts as a privacy barrier. Cloudflare can view who you are, but not your health data. Flo can view your health data, but does not know who it belongs to.
Our Privacy Team
Your data is protected by an award-winning team of privacy and security experts who have dedicated their careers to data protection.
Sue Khan - VP of Privacy & Data Protection Officer
CIPP/E. Winner of the PICCASO Awards Europe Outstanding DPO Award 2024. Sue leads Flo's privacy program and oversaw our achievement of ISO 27701 certification.
Laure Lydon - VP of Security
Women in Tech Security Award finalist. Laure leads Flo's security infrastructure and our ISO 27001 certification program, for which her team earned the PICCASO Privacy ISO 27001, Team of the Year 2025.
Tsimafei Savitski - Chief Legal & Compliance Officer
Leads Flo's legal and compliance programs, ensuring Flo’s practices meet regulatory requirements and industry standards.
Roman Bugaev - Chief Technology Officer
Leads Flo’s 200+ senior engineers in building secure, scalable technology, with responsible data management and robust privacy protections embedded directly into every product.
Privacy & Security Advisory Board
Launched in 2023, our Advisory Board includes independent external experts in privacy, security, women's health, and technology who share their expertise to help ensure Flo maintains best-in-class privacy and security practices.
Your Privacy Rights
Flo believes you should always be in control of what you share. So we apply GDPR rights to all our users, no matter where you live. Here's what that means for you:
Access your data
Request a copy of your data at any time.
Delete your data
You can delete your account and all associated data whenever you choose. Once deleted, it’s gone. We can’t recover it, and neither can anyone else.
Control data collection
Choose which data you share and easily manage your consent preferences within the app. You can change your mind at any time.
Export your data
Take your data with you. Export your information in a standard format to use with other apps or services.
Use Anonymous Mode
Track your health without your identity linked to your health data. Not even Flo can identify you.
Our Privacy Journey
Privacy excellence isn't built overnight. See how we've built our privacy program from 2016 to today.
2016-2019: Building the Foundation
From our earliest days as a new company, we prioritized privacy—creating our program, introducing our first privacy policy, and designing our product with GDPR compliance built in.
2019-2021: Learning & Improving
After receiving feedback about our use of the Facebook Analytics SDK in 2019, we immediately removed it. We then reached a settlement with the FTC to avoid the costs of litigation and conducted an independent privacy audit. We hired dedicated privacy leadership and overhauled our privacy framework.
2022-2023: Building a Foundation of Security & Privacy
In August 2022, we achieved ISO 27001 certification and engaged Guidepost Solutions to independently verify our practices. In January 2023, we launched our Privacy Advisory Board and introduced Anonymous Mode.
2023-2024: Setting the Gold Standard
In January 2024, we became the first period tracker to achieve ISO 27701 certification – making us the first and only female health app to have both ISO Security and ISO Privacy certifications!
2024-2025: Continuous Excellence
Maintaining our ISO certifications through regular audits, expanding Anonymous Mode capabilities, and continuing to set the standard for privacy in femtech.
Popular topics:
- Anonymous Mode technical deep dives
- ISO certification journey
- Understanding your privacy rights
- Privacy engineering insight
Legal Documents
Need to see the official legal language? Access our Privacy Policy, Terms of Use, Cookie Policy, and other legal documents.
All documents include plain-language summaries and links to relevant Privacy Portal sections that explain them in everyday terms.
What Privacy Features Does Flo Have?
Flo offers comprehensive privacy protections designed to give you maximum control over your information, including:
- Anonymous Mode - Track your period without any personal identifiers
- ISO 27001 & 27701 certifications - The only period tracker with dual certification
- GDPR rights for everyone - GDPR privacy rights to all our members, regardless of their location.
- Independent security audits - Regular third-party verification of our practices
- Privacy-first design - Privacy is built into every feature from the start
- Transparent, concise privacy information - Our in-app Privacy & Security page gives you the most important information you need, all in one place
- In-app privacy settings - Access, update, or delete your data anytime directly within the app.
Each of these features works together to ensure your health data stays private and under your control.
Take Control of Your Privacy Today
Enable Anonymous Mode
Track your cycle with maximum privacy protection.
Review Your Data
See exactly what information Flo has collected.
Have questions?
Get answers to common privacy questions.