· 8 min read
Consent-first sharing in health apps
What a 171-response survey taught us about who people would let see their cycle data, and why sharing should be off by default and scoped.
Sharing in a health app should be off by default, granted one item at a time, and revocable silently, because for most people sharing is conditional on control. In a 171-response survey for Myra, a women's-health and period-tracker concept I led in Nepal, only about half of women said yes outright to a partner or family member following their cycle; another third said maybe, if I could control what they see. That result turned a "share with partner" feature into a consent system, and it's the clearest piece of research behind my work on consent UX and health app privacy.
Two things up front. Myra is a paused concept, not a released app, so nothing here was used or tested. And the survey is a small, skewed sample, so every number below comes with its limits beside it. The full study is on my research page, and the design is in the Myra case study.
What did the survey ask, and who answered?
We fielded an online survey on a Tally form in April–May 2025. The team wrote the questionnaire. It branched on gender: women answered about tracking and sharing, men answered about following.
| Responses | n = 171: women's branch 106 (105 women, 1 non-binary respondent), men's branch 65 |
| Recruitment | Our own networks: friends, colleagues, email, Instagram, LinkedIn, student organisations |
| Who | Student-heavy; 87% aged 18–24, no one over 34; only 3.5% preferred Nepali alone |
| Analysis | Descriptive counts and shares, one crosstab; only aggregates are published |
Alongside the survey we held informal interviews and conversations. I didn't keep notes, so nothing here relies on them.
Would women share their cycle data with a partner or family?
The headline result, from the women's branch (n = 106):
| Comfortable if a partner or family member could follow your cycle? | n | % |
|---|---|---|
| Yes, definitely | 52 | 49 |
| Maybe, if I could control what they see | 34 | 32 |
| No, not comfortable | 11 | 10 |
| Not sure | 9 | 9 |
Then the detail that changed the design: 37% of women also ticked "I prefer to manage it alone", including 10 of the 52 who said "yes, definitely". For these respondents, wanting support and wanting privacy weren't opposites. Control was the swing vote.
What does the other person actually want to see?
The men's branch (n = 65, same sample limits) gave the other half of the answer. 86% rated knowing her physical symptoms, and knowing when she needs rest, at 4–5 in importance. But only 11% wanted "symptom updates". They asked for interpreted outputs instead: a daily summary (63%) and emotional-support tips (51%). And 52% said reminders to be emotionally available should come only if she chooses to share that info.
So the people receiving the data wanted to understand, not to watch. That's convenient, because it's also the safer design.
Why sharing should be off by default and scoped
Put the two branches together and the requirements write themselves:
- Off by default. Every grant starts off. A third of women would share only with control; the default has to respect the most cautious answer, not the most enthusiastic one.
- Scoped per item. She grants one thing at a time: a needs-rest signal, period dates, a mood summary. Not "share my data".
- Interpretations, not logs. The companion sees "She may need more rest this week" and one suggested action, never her calendar, symptoms or notes.
- Several people, separate grants. Men in the sample would use the feature for a mother (58%) or sister (54%) almost as often as a girlfriend (66%). A companion is a relationship, and there can be more than one.
- Silent revocation. She can stop in two taps. The other side sees a neutral "Sharing paused", never a reason.
The proposed defaults, as a table:
| Data | Default | Can she grant it? |
|---|---|---|
| Needs-rest signal (derived) | Off | Yes, recommended first |
| Period dates and current phase | Off | Yes |
| Mood summary (weekly, derived) | Off | Yes |
| Raw symptom logs | Off | One symptom at a time, with a warning |
| Fertility window | Off | Yes, with a second confirmation |
| Private notes | Never | No |
The survey justifies the direction of these defaults. It doesn't validate their details.
This also lines up with a principle that exists in law elsewhere. The EU's GDPR asks that, by default, personal data is not made accessible to an indefinite number of people without the person's own intervention. Nepal isn't bound by the GDPR, and Myra wasn't designed to comply with it, but "nothing is shared until she acts" is the same idea.
How does a consent-first sharing flow work?
The flow I designed has six states: no companion, code issued, pending her confirmation, linked with grants, the companion's view, and revoked.
- Inviting isn't sharing. She gets a short, single-use code. The invite screen says nothing is shared yet.
- Entering a code isn't enough. She sees who entered it and confirms. A code shared under pressure opens nothing by itself.
- Reducing access is always silent. Removing one grant, stopping entirely or turning on anonymous mode all show the companion the same neutral state. They never learn what was removed or why.
The silent-revocation rule matters most. In a relationship or a household, "she turned off sharing your access to her mood" is information. A neutral state is the only one that doesn't create a conversation she didn't choose.
A consent UX checklist for health and femtech apps
- Every sharing grant starts off.
- Grants are per item, not all-or-nothing.
- Share derived signals before raw data; some data (private notes) can never be shared.
- Each companion has separate grants.
- Linking needs the data owner's confirmation, not just a code.
- Stopping takes two taps, works at once, and gives no reason on the other side.
- Lock-screen notifications are generic by default.
- A life-stage change (such as pregnancy) asks again before anything new is shared.
- Every companion screen says who controls it: "She controls what you see".
What this research can't tell you
The survey can't say what a mother in a joint family in a rural district would want, and it can't say whether anyone would actually link a sister's phone. The questions also introduced Companion Mode by name and described it respectfully, which may have raised acceptance. I was the founder analysing demand for my own product, so I've tried to publish the numbers that cut against us too: 37% would rather manage alone, and 10% weren't comfortable at all.
The next steps I'd take are a proper interview study with women across age, language and household type, with recorded notes, and a consent-flow usability test where the measure is simple: can a participant correctly explain what a companion will see?
Where Myra stands
The pitch won recognition: 2nd Runner-Up at the Hult Prize at Kathmandu University in 2025, then selection for the first Hult Prize national competition in Nepal, and first prize at Project YuwaXcel in 2026. Then we paused, because we'd lost direction and all of us were working full-time jobs. Measured outcome: none. No app was released, and the consent model was never tested with a single linked pair.
What I kept is the lesson: a share button is a consent system. For more on how I label what was and wasn't measured, see writing honest case studies.
References
- Article 25 GDPR, Data protection by design and by default, Regulation (EU) 2016/679.
- Hult Prize at Kathmandu University, result announcement (Instagram).
questions people ask
Frequently asked questions
Should sharing in a period tracker or health app be on by default?
No. Every sharing grant should start off and be turned on one item at a time by the person whose data it is. In the Myra survey (n = 106 women, a convenience sample), 32% would share only if they could control what the other person sees.
What should a partner or family member see in a cycle-tracking app?
Interpretations, not raw logs: for example, 'she may need more rest this week' and one suggested action. In the Myra survey's men's branch (n = 65, convenience sample), 63% wanted a daily summary and only 11% wanted symptom updates.
How should revoking access work in a health app?
Stopping should take a couple of taps, take effect at once, and be silent on the other side: the companion sees a neutral 'Sharing paused', never a reason or a list of what was removed.
Is Myra a released app?
No. Myra is a paused concept. The consent model was designed from survey aggregates and was never built or tested with users.