Exploring Privacy Practices of Female mHealth Apps in a Post-Roe World

Reproductive & Women's HealthPrivacy by Design & User ControlPrivacy Perception & Decision-MakingElderly Care WorkersPrivacy Policy Makers

Title of the Paper

Exploring Privacy Practices of Women's mHealth Apps in the Post-Roe Era

Bibliographic Information

  • Subject Areas: Digital Health Privacy, FemTech Technology and Societal Analysis
  • Keywords: Digital Health, Mobile Health, FemTech, Women's Health, Privacy, Security

Research Background and Issues

  • Issues and Challenges:

    • Women's mHealth apps (e.g., period tracking, pregnancy management) collect sensitive user data, raising increasing concerns about privacy.
    • The U.S. Supreme Court's overturning of Roe v. Wade has sparked fears that women's health data might be used for surveillance and criminalization.
    • Privacy practices of these mobile apps under this new legal framework have yet to be systematically reviewed.
  • Significance:

    • Privacy protection is crucial for users, especially for apps involving women's health and reproductive data.
    • The management of such data (e.g., collection, sharing, storage, and deletion) directly impacts women's safety in potentially criminalized environments.
  • Research Motivation and Related Work:

    • Existing studies have not fully assessed the privacy practices of women's mHealth apps within the legal context following the overturning of Roe v. Wade.
    • There is a need for comprehensive analysis of privacy policies, data collection mechanisms, and interface usability to evaluate these apps' privacy compliance.

Solution

  • Methods and Solutions:

    • Select 20 popular women's mHealth apps for analysis of data safety sections, privacy policies, and interface usability related to privacy.
    • Combine qualitative and quantitative analysis methods to uncover practices related to data management (collection, storage, sharing, deletion) and user privacy rights (e.g., data portability, consent withdrawal).
    • Employ Cognitive Walkthrough and Heuristic Evaluation to constructively examine privacy issues in these apps' interface designs.
  • Innovations:

    • The first study in the FemTech field to integrate data safety, privacy policy analysis, and user interface reviews.
    • Provides a reusable code framework for categorizing themes in privacy policies, enabling automation and quantitative analysis.
  • Implementation Steps:

    • App Selection:
      • Collect women's health-related apps from the Google Play Store using keyword filtering and feature screening to identify target apps.
    • Privacy Policy Analysis:
      • Develop and iterate a thematic analysis code framework based on privacy laws (e.g., GDPR) and prior privacy issue experiences.
      • Qualitatively code privacy policy content to identify patterns related to data management and privacy rights.
    • Data Safety Sections and Interface Review:
      • Analyze the usability and practicality of data privacy-related features through interface reviews.
      • Evaluate user experience and usability using heuristic design principles.

Research Findings

  • Specific Findings and Analysis:

    1. Conflicts Between Privacy Policies and Data Safety Information:
      • Data safety sections often claim no data sharing, while most privacy policies imply sharing with third parties or legal disclosures.
      • Some apps lack clear data encryption technologies or effective data deletion mechanisms.
    2. Complexity of Privacy Policies:
      • Average length of 4,453 words, using technical jargon and ambiguous language, making it difficult for ordinary users to understand.
      • Privacy policies often cover multiple services rather than specific apps, increasing comprehension challenges.
    3. Implicit Design Patterns Targeting Users:
      • Includes default data tracking enabled and unmarked optional data fields.
      • Pregnancy apps require input of pregnancy termination dates without transparent explanations.
  • Advantages:

    • Provides a comprehensive method for analyzing privacy statements and actual privacy practices.
    • First to reveal inconsistencies between privacy policies, data safety mechanisms, and user interfaces in the FemTech field.
  • Experimental and Evaluation Results:

    • Data Deletion and Portability:
      • Some apps impose fees for users to port their health data; data exports are often incomplete.
      • Language regarding data deletion is vague, lacking transparency.
    • User Privacy Settings and Notification Controls:
      • Only a few apps offer granular controls; most default to invasive privacy practices.
  • Limitations and Future Directions:

    • Currently limited to the Android operating system; expansion to the iOS ecosystem is needed.
    • Privacy policy analysis has not fully quantified language complexity; longitudinal studies of policy changes are recommended.
    • Future research should include in-depth interviews on user privacy perceptions and developer privacy obligations.
    • Special attention is needed for pregnancy apps involving input of pregnancy termination data.

In summary, this paper reveals inconsistencies and design issues in privacy and data practices of women's mHealth apps, providing recommendations for improving privacy and security practices for technology developers and policymakers, while also pointing out directions for future research.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/147278/2024

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3613904.3642521
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2024
emoji_events
Award
No award tagged
group
Authors
5 authors
sell
Subtopics
Reproductive & Women's Health, Privacy by Design & User Control, Privacy Perception & Decision-Making
work
Professions
Elderly Care Workers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
8 related papers