I’ve worked in and with Big Data since 2001. Give me your ZIP code, household makeup, and life stage, and I can usually predict the next car you’ll buy and what’s in your pantry. So why write about data privacy? Because I’m both a lover of data and an advocate for smart boundaries. This is about finding a rhythm that works for you, not perfection or paranoia.
Today, we’re staying focused on one decision you and I have made at least once: should I download this health app (say, a period tracker) and accept its terms and conditions?
A quick primer: HIPAA privacy vs. consumer health apps
HIPAA covers your doctor, hospital, and you. Most consumer health apps are not covered. When your medical information flows into an app that isn’t a HIPAA “covered entity” or its business associate, HIPAA protections typically don’t apply to that copy of your data. In short: your medical records are protected; your app data usually isn’t.
That doesn’t mean no rules—state laws and company promises still matter. But it does mean read the fine print on any app that touches your health life.
Where I look before downloading any health app
I check three places:
The App Store’s privacy label (especially “Data Linked to You” and “Data Used to Track You”). These labels are developer‑provided, and Apple requires them for new apps and updates. Developers are responsible for keeping them accurate and up to date.
The app’s privacy policy.
The app’s terms and conditions.
Think of this as the nutrition label, the recipe, and the house rules, respectively.
The Business of Adulting is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.
How to read the App Store labels
On each app page, you’ll see categories of data the app may collect and whether that data is linked to you or used to track you. Here’s what those mean in plain English:
“Data Linked to You”
This is data tied to your identity (your account, device, or details like your phone number). Apple lists the following data types: you won’t see every subtype on every app, but these are the buckets:
Contact Info — name, email, phone, physical address, or other ways to reach you.
Health & Fitness — health/medical data (e.g., from HealthKit) and fitness/activity data.
Financial Info — payment details, credit info, salary, or other financial data.
Location — precise (GPS‑level) or coarse (rough area).
Sensitive Info — things like racial/ethnic data, sexual orientation, pregnancy/childbirth info, disability, religious or philosophical beliefs, trade union membership, political opinions, genetic or biometric data.
Contacts — your address book or social graph.
User Content — emails or messages, photos/videos, audio, gameplay content, customer support chats, and other content you create.
Browsing History — content you viewed outside the app (e.g., websites).
Search History — searches performed in the app.
Identifiers — User ID (screen name, account ID) and Device ID (like an advertising ID).
Purchases — purchase history or tendencies.
Usage Data — product interactions (taps, clicks, views), advertising data, other usage metrics.
Diagnostics — crash logs, performance data, other technical diagnostics.
Surroundings — environment scanning (e.g., scene detection in AR experiences).
Body — hand structure/movements or head movement (relevant for some AR/VR features).
Other Data Types — anything not covered above.
“Data Used to Track You”
If the app links data from this app with data collected by other companies (apps, websites, or offline sources) for targeted ads or ad measurement—or shares data with a data broker—that’s “tracking.” Examples: sharing device location with a broker, or sending an email list/IDs to an ad network for retargeting. This is the part that fuels those eerily on‑point ads where you think, “I was just at dinner last night talking about needing mittens and now all I see are ads for mittens!”
Pro tip: On an iPhone, you can choose Ask App Not to Track and still use the app’s full capabilities; you’ll also find a Tracking setting to review permissions app by app. I select this for every single app on my phone.
A period‑tracker example: what I’d weigh
Let’s say I’m perimenopausal and want a period tracker that logs my cycles and symptoms.
Privacy label check:
If I see Identifiers (User ID, Device ID) + Contact Info + Health & Fitness all linked to me, that’s a lot of connection points between me and my health data.
If I see Data Used to Track You, I assume advertising networks or data brokers could use my info to target or retarget me across apps. That’s a personal hard stop for many people, myself included.
Privacy policy scan:
Look for phrases like “share,” “sell,” “advertising partners,” “analytics providers,” “data brokers,” “affiliates,” and “service providers.”
See if they promise no selling of personal data (not just “we don’t sell for money”), whether they honor deletion requests, and whether health data gets extra protection.
Terms and conditions scan:
Look for broad licenses to use your content, limits on deletion/portability, and whether arbitration or class‑action waivers make it harder to resolve a dispute. This last one has especially come under fire in a way you won’t believe.
Remember: most health apps are not HIPAA‑covered. Their promises live in the privacy policy and terms and conditions, not in HIPAA privacy rules.
Pro Tip: Let an AI speed‑read the fine print
When I’m on the fence, I paste the privacy policy and terms and conditions into an AI assistant and use this exact prompt:
“Please read these and tell me if my identity or data is at risk of being sold or shared if I consent to these terms.”
You’ll still want to skim it yourself, but this gives you a fast first pass and plain‑English flags you can double‑check.
If you decide to use the app anyway (no shame, real life!)
Here’s how to lower your data exhaust:
Use “Sign in with Apple” (and Hide My Email) when available.
Tap “Ask App Not to Track.” Then review Settings → Privacy & Security → Tracking to confirm.
Turn off in‑app analytics/ads toggles you don’t need.
Limit permissions (location, contacts, photos) to “While Using the App” or “None,” unless essential.
Re‑check the label after updates. Developers must keep disclosures current, but practices change.
So, what am I currently doing to track my health data?
Personally, I skip period‑tracking apps. I keep a private, coded system in my calendar: a simple placeholder for start/stop days and a code for symptoms (e.g., a playful phrase that means “hot flashes” to me). I’m not sharing my exact codes here because tools like Google Calendar are still products with their own data practices, and the whole point is to keep your system yours. The goal isn’t secrecy for secrecy’s sake. Moreover, it’s choosing a system that doesn’t hand over more than you’re comfortable with.
Key Takeaways
HIPAA privacy protects your medical records with covered providers, not with typical consumer health apps made by private or publicly owned companies.
The App Store’s Data Linked to You and Data Used to Track You sections are your fastest gut‑check. If tracking or lots of identifiers are listed, be cautious.
Your best defense: read (or AI‑assist) the privacy policy and terms and conditions, decide your comfort level, and pick a rhythm (app or no app) that respects your boundaries.
If you’d rather not feed data brokers, a simple coded calendar can work brilliantly.
We deserve tools that serve us, not the other way around.
Cheers to using our resources wisely,
Andrea
Thanks for reading The Business of Adulting! This post is public, so feel free to share it.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.