What is the FTC?
The FTC is the Federal Trade Commission. It’s an important government agency in the US that oversees businesses to protect consumers and encourage fair competition.
What is the Flo FTC settlement, and why did Flo settle with the FTC?
Allegations of events regarding user data between 2016 and 2019 led to an FTC investigation. It was alleged that Flo shared health information with third-party advertising companies without permission.
This was not the case. Like many companies, Flo shared limited data with selected third-party companies to internally measure the performance of our app. None of this data contained our members’ names, addresses, or birth dates. Nor did we share health information with the social media, advertising, or marketing departments of these third parties.
Flo chose to stop sharing any information with these third parties in January 2021. At the same time, we agreed to settle the matter with the FTC. As a growing company, we made this decision to avoid the time and cost associated with litigation. It enabled us to instead focus our efforts on rolling out best-in-class security and privacy protections. Since then, Flo has become the only women’s health app to be awarded dual International Organization for Standardization (ISO) certifications in privacy and security — widely recognized as the gold standard in the industry.
We would like to make clear that this settlement was in no way an admission of wrongdoing. Flo continues to stand by its position. We have never, and will never, sell your data — nor will we share your health information with third parties for marketing purposes.
What did Flo have to do as part of the settlement?
As mutually agreed with the FTC, Flo’s privacy policies and practices were successfully audited in March 2022. The auditors found:
- Flo does not have any gaps or weaknesses in its privacy practices.
- Flo’s practices are in line with its public privacy policy. You can read our Privacy Policy here.
In particular, the auditors’ report highlighted:
- “Data privacy and security are heavily emphasized at Flo as being at the core of their operations.”
- “Flo was able to demonstrate a commitment to the privacy and security of its users’ data. [It] has devoted appropriate resources and personnel to ensuring it maintains these commitments.” You can find out more about our privacy and security team here.
Your privacy and security will always be Flo’s number one priority — it sits at the heart of everything we do. We’re proud to have:
- Dual ISO certifications — globally recognized as the gold standards for data privacy and information security. Flo is the only women’s health app to hold both.
- Robust policies and procedures in place to keep your data safe. These are regularly reviewed internally and by independent, external auditors.
- A dedicated in-house privacy, security, and trust team, along with a privacy and security advisory board, that are both made up of experienced industry leaders who help to advise Flo on data protection.
Flo is also a registered data controller in the UK and complies with the UK General Data Protection Regulation (GDPR) — a very high standard in data protection.
Can I trust Flo with my data?
Yes, you can. We have never — and will never — sell your data. Our only source of revenue is the money you pay for your subscription. Learn more about how we keep your data safe here. You can also find answers to commonly asked Flo data protection questions here.