Does Flo train on your data?
Flo said in 2021 that it trains models on "Flo's large user population". Its FAQ now asks whether your data trains Flo's AI and answers only for third parties. Flo is being written to.
This clause is real, but it doesn't resolve the training question - see the finding below.
""The data science department specifically relies on Amazon SageMaker for ML, leveraging powerful GPU-based machines offered by AWS to train models on Flo's large user population," says Bugaev."
- 23 Sept 2026
- 5 Oct 2026
- All accounts (free and Premium)
- global
- Fetched from the company
- 30E69F70…ECD7
Why this is still UNCLEAR: This is menstrual and reproductive health data, about as sensitive as consumer data gets, and the policy is specific about where it goes. A named sub-processor, Tecton, Inc., described as a "Machine Learning Development Platform", receives "Personal data relating to cycle dates, goals, symptoms" for cycle predictions, retention forecasting and content. The word "train" isn't in the policy's 46,000 characters. The Privacy Portal FAQ asks the question in its own heading, whether your personal data is used to train Flo's AI, and answers about third parties: "Your personal data is not used to train third party AI models." Of Flo's own cycle-prediction models it says nothing. One Flo document does. A newsroom post from March 2021, republished from the AWS Startup Blog, quotes Flo's CTO on training models "on Flo's large user population" from the period dates, symptoms and metadata people log. Those are the company's own words, five years old, and no later document repeats or withdraws them. No opt-out is stated anywhere. As with Replit, the entry stays UNCLEAR while Flo is asked whether the 2021 statement still describes the app.
What each plan can refuse
The same questions, asked of every plan we could identify. Every cell comes from a quoted clause or a documented search - see the evidence above.
- Not established
- Not stated
- —
- —
- Not established
How to opt out of Flo AI training
Plan by plan, from what Flo's own policy says about refusing. Where it publishes the steps, they're listed here with the limits they carry. Where there's nothing to switch off, or nothing graded, this says so instead of inventing a menu path.
All accounts (free and Premium)
Not graded, so no route is pointed at. This is menstrual and reproductive health data, about as sensitive as consumer data gets, and the policy is specific about where it goes. A named sub-processor, Tecton, Inc., described as a "Machine Learning Development Platform", receives "Personal data relating to cycle dates, goals, symptoms" for cycle predictions, retention forecasting and content. The word "train" isn't in the policy's 46,000 characters. The Privacy Portal FAQ asks the question in its own heading, whether your personal data is used to train Flo's AI, and answers about third parties: "Your personal data is not used to train third party AI models." Of Flo's own cycle-prediction models it says nothing. One Flo document does. A newsroom post from March 2021, republished from the AWS Startup Blog, quotes Flo's CTO on training models "on Flo's large user population" from the period dates, symptoms and metadata people log. Those are the company's own words, five years old, and no later document repeats or withdraws them. No opt-out is stated anywhere. As with Replit, the entry stays UNCLEAR while Flo is asked whether the 2021 statement still describes the app.
What this policy has done since we started watching
1 change detected since 30 Aug 2026. Each one is a diff between two archived copies, and each links to the passage that moved.
Vendor response
We wrote to Flo on 2 Oct 2026, quoting the clauses above and inviting a correction. Nothing has come back. That's published because a company declining to comment on its own policy is something a reader should know, and because the invitation should be on the record whether or not it's taken up. Any reply goes here, word for word.
Report a wrong clause