Hidden in Plain Sight: a Structured Analysis of Privacy Policies in the Context of Body-worn 'FemTech' Technologies

Privacy by Design & User ControlPrivacy Perception & Decision-MakingPrivacy Policy MakersHCI ResearchersStatisticians & Data Scientists

Research Background and Issues

  • Issues and Challenges: With growing interest in women's reproductive health within the field of human-computer interaction, there has been an increasing number of technologies focused on women's health, specifically "FemTech" devices. These technologies offer better management and understanding of women's intimate health. However, due to the highly sensitive nature of the data collected by these devices, which often involves politicized topics (e.g., reproductive health and abortion rights), privacy breaches could lead to psychological distress, discrimination, and gender inequality. These potential issues highlight the need to ensure users are fully informed about how their data is collected, used, stored, and shared.

  • Importance: Women's health data, including menstrual cycles, pregnancy status, and contraceptive information, is often more sensitive than financial data. If such health data is misused or shared with third parties, users may face serious threats to their personal privacy and safety, such as workplace discrimination or political consequences (e.g., lawsuits related to abortion). Additionally, breaches of this data could lead to mistrust in technology, ultimately impacting the sustainable development of the FemTech industry.

  • Research Motivation and Existing Studies: While existing studies have addressed privacy and security issues in FemTech technologies, they primarily analyze specific policy texts or focus on privacy practices in mobile applications, rarely examining the complete privacy policy texts of wearable devices. This indicates the need for a systematic analysis of FemTech privacy policies to assess their transparency and provide recommendations for improving user informed consent and data rights.


Solutions

  • Research Methods:
    The authors conducted a structured content analysis of privacy policies from 18 existing FemTech devices. Using an empirical privacy taxonomy, the study comprehensively evaluated privacy policies across multiple dimensions, including data storage, data usage, and data sharing. The case studies covered various device types (e.g., smartwatches, wristbands, patches) and analyzed key issues related to user privacy.

  • Innovations:

    1. Comprehensive Analysis: Unlike previous studies that only mention certain parts of privacy clauses, this study examines the complete privacy policy texts, offering a more thorough understanding of actual privacy practices.
    2. Six Key Challenges Identified: The study distilled six critical issues from the wording, content presentation, and implementation of privacy policies, which impact policy transparency and user comprehension.
    3. Specific Recommendations: The study provided nine actionable suggestions to improve the transparency and comprehensibility of privacy policies, illustrated with examples of "best practices" and "anti-patterns."
  • Implementation Steps:

    1. Collect and filter 18 valid privacy policy texts, covering various types of FemTech devices.
    2. Use an empirical taxonomy to code and analyze multiple aspects, such as data usage, storage locations, and third-party data sharing.
    3. Combine closed and open coding methods to iteratively refine the coding schema and summarize six key categorical issues.
    4. Based on the analysis results, propose specific, actionable recommendations for designing more transparent and comprehensible privacy policies.

Research Outcomes

  • Specific Findings:

    1. Provided a detailed list identifying the types of data collected by FemTech devices (e.g., reproductive health, device information, interaction data) and their sharing practices.
    2. Identified six key issues, including unclear data usage, unspecified server locations, ambiguous policy wording, mixed handling of data types, inconsistent data rights management, and inadequate mechanisms for notifying users of policy updates.
    3. Summarized the extent to which each privacy policy supports user rights (e.g., data access, modification, deletion) and found that only a minority of devices offer comprehensive data rights functionality.
  • Advantages:

    1. Thoroughness: Comprehensive coverage of all aspects of FemTech privacy policies, beyond privacy clauses or specific device features.
    2. In-depth Analysis: Revealed subtle differences in policies through taxonomy and detailed coding, such as issues with regional legal applicability and insufficient recognition of data sensitivity.
    3. Practicality: Provided nine specific recommendations to guide device manufacturers and policymakers in enhancing policy transparency and improving user privacy experiences.
  • Experimental or Evaluation Results:
    The analysis uncovered specific issues in many policies, such as the use of vague terms (e.g., "may," "for example") or unclear descriptions of server locations and legal applicability for cross-border data. Additionally, mechanisms for notifying users of policy updates remain inadequate, with most devices relying on users to check updates themselves.

  • Limitations and Future Directions:

    1. The study did not address actual user perceptions or interactive experiences with policies, focusing solely on policy text analysis.
    2. The specific impact of regional laws or cultural contexts on policy interpretation was not explored in depth.
    3. Future research could delve into linguistic or design approaches to optimize the readability and acceptance of privacy policies, or validate the effectiveness of specific recommendations through user experiments.

Through this study, the authors not only highlighted transparency issues in current FemTech privacy policies but also provided clear directions for promoting greater social responsibility and policy improvements in managing women's health data.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/188260/2025

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3713702
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making
work
Professions
Privacy Policy Makers, HCI Researchers, Statisticians & Data Scientists
article
Content Status
Full text indexed
hub
Related Papers
10 related papers