Exploring Privacy Practices of Female mHealth Apps in a Post-Roe World
Authors
Title of the Paper
Exploring Privacy Practices of Women's mHealth Apps in the Post-Roe Era
Bibliographic Information
- Subject Areas: Digital Health Privacy, FemTech Technology and Societal Analysis
- Keywords: Digital Health, Mobile Health, FemTech, Women's Health, Privacy, Security
Research Background and Issues
-
Issues and Challenges:
- Women's mHealth apps (e.g., period tracking, pregnancy management) collect sensitive user data, raising increasing concerns about privacy.
- The U.S. Supreme Court's overturning of Roe v. Wade has sparked fears that women's health data might be used for surveillance and criminalization.
- Privacy practices of these mobile apps under this new legal framework have yet to be systematically reviewed.
-
Significance:
- Privacy protection is crucial for users, especially for apps involving women's health and reproductive data.
- The management of such data (e.g., collection, sharing, storage, and deletion) directly impacts women's safety in potentially criminalized environments.
-
Research Motivation and Related Work:
- Existing studies have not fully assessed the privacy practices of women's mHealth apps within the legal context following the overturning of Roe v. Wade.
- There is a need for comprehensive analysis of privacy policies, data collection mechanisms, and interface usability to evaluate these apps' privacy compliance.
Solution
-
Methods and Solutions:
- Select 20 popular women's mHealth apps for analysis of data safety sections, privacy policies, and interface usability related to privacy.
- Combine qualitative and quantitative analysis methods to uncover practices related to data management (collection, storage, sharing, deletion) and user privacy rights (e.g., data portability, consent withdrawal).
- Employ Cognitive Walkthrough and Heuristic Evaluation to constructively examine privacy issues in these apps' interface designs.
-
Innovations:
- The first study in the FemTech field to integrate data safety, privacy policy analysis, and user interface reviews.
- Provides a reusable code framework for categorizing themes in privacy policies, enabling automation and quantitative analysis.
-
Implementation Steps:
- App Selection:
- Collect women's health-related apps from the Google Play Store using keyword filtering and feature screening to identify target apps.
- Privacy Policy Analysis:
- Develop and iterate a thematic analysis code framework based on privacy laws (e.g., GDPR) and prior privacy issue experiences.
- Qualitatively code privacy policy content to identify patterns related to data management and privacy rights.
- Data Safety Sections and Interface Review:
- Analyze the usability and practicality of data privacy-related features through interface reviews.
- Evaluate user experience and usability using heuristic design principles.
- App Selection:
Research Findings
-
Specific Findings and Analysis:
- Conflicts Between Privacy Policies and Data Safety Information:
- Data safety sections often claim no data sharing, while most privacy policies imply sharing with third parties or legal disclosures.
- Some apps lack clear data encryption technologies or effective data deletion mechanisms.
- Complexity of Privacy Policies:
- Average length of 4,453 words, using technical jargon and ambiguous language, making it difficult for ordinary users to understand.
- Privacy policies often cover multiple services rather than specific apps, increasing comprehension challenges.
- Implicit Design Patterns Targeting Users:
- Includes default data tracking enabled and unmarked optional data fields.
- Pregnancy apps require input of pregnancy termination dates without transparent explanations.
- Conflicts Between Privacy Policies and Data Safety Information:
-
Advantages:
- Provides a comprehensive method for analyzing privacy statements and actual privacy practices.
- First to reveal inconsistencies between privacy policies, data safety mechanisms, and user interfaces in the FemTech field.
-
Experimental and Evaluation Results:
- Data Deletion and Portability:
- Some apps impose fees for users to port their health data; data exports are often incomplete.
- Language regarding data deletion is vague, lacking transparency.
- User Privacy Settings and Notification Controls:
- Only a few apps offer granular controls; most default to invasive privacy practices.
- Data Deletion and Portability:
-
Limitations and Future Directions:
- Currently limited to the Android operating system; expansion to the iOS ecosystem is needed.
- Privacy policy analysis has not fully quantified language complexity; longitudinal studies of policy changes are recommended.
- Future research should include in-depth interviews on user privacy perceptions and developer privacy obligations.
- Special attention is needed for pregnancy apps involving input of pregnancy termination data.
In summary, this paper reveals inconsistencies and design issues in privacy and data practices of women's mHealth apps, providing recommendations for improving privacy and security practices for technology developers and policymakers, while also pointing out directions for future research.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- What problems exist in the privacy policies and data management practices of women's mHealth apps after the overturning of Roe v. Wade in the United States?Category: Privacy Policy, Notice, and Terms ComprehensionSimilar questionsarrow_forward
- Are there conflicts between privacy policies and data protection statements in women's mHealth apps?Category: Privacy Policy, Notice, and Terms ComprehensionSimilar questionsarrow_forward
- What implicit patterns in the user interface design of women's mHealth apps may undermine users' privacy rights?Category: Privacy Policy, Notice, and Terms ComprehensionSimilar questionsarrow_forward
Practical Problems
1- Users of women's health apps worry that data privacy may be violated and even lead to legal risks.Category: Privacy Policy, Notice, and Terms ComprehensionSimilar questionsarrow_forward
- 67%
Caring for Intimate Data in Fertility Technologies
CHI '21· Reproductive & Women's Health +2
- 60%
SIGCHI Social Impact Award Talk – Making Privacy and Security More Usable
CHI '18· Privacy by Design & User Control +1
- 60%
You 'Might' Be Affected: An Empirical Analysis of Readability and Usability Issues in Data Breach Notifications
CHI '19· Privacy by Design & User Control +1
- 60%
Human-GDPR Interaction: Practical Experiences of Accessing Personal Data
CHI '22· Privacy by Design & User Control +1
- 60%
Obfuscation Remedies Harms Arising from Content Flagging of Photos
CHI '22· Privacy by Design & User Control +1
- 60%
Understanding Privacy Switching Behaviour on Twitter
CHI '22· Privacy by Design & User Control +1
- 60%
How Language Formality in Security and Privacy Interfaces Impacts Intended Compliance
CHI '23· Privacy by Design & User Control +1
- 60%
The Impact of Risk Appeal Approaches on Users’ Sharing Confidential Information
CHI '24· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)