Judge Donato, of the Northern District of California, granted partial class certification in a high-profile privacy lawsuit involving a popular women’s health tracking app. The case centers on allegations that the app, between 2016 and 2019, transmitted sensitive user health data to major technology companies without proper user consent, in violation of privacy laws and the app’s own representations. The court’s decision allows certain claims to proceed on a classwide basis, while denying certification for others.
Key Allegations and Background
The plaintiffs, representing millions of users nationwide, allege that the health app collected and shared highly personal information—such as menstruation, ovulation, and pregnancy data—with third parties, specifically Google and Meta (formerly Facebook), via embedded software development kits (SDKs). Plaintiffs claim these actions were contrary to the app’s privacy policies, which assured users that such data would remain confidential and not be shared except as necessary for the app to function or with express consent.
Evidence presented showed that the app’s onboarding process required users to input sensitive reproductive health information, which was then transmitted to Google and Meta. The data included unique identifiers capable of linking the information to individual users, enabling tracking across devices and over time. Plaintiffs also alleged that the data was commercially exploited for advertising and machine learning purposes.
Class Certification Analysis
The court’s analysis focused on whether the requirements for class certification under Federal Rule of Civil Procedure 23 were met. The court found:
- Numerosity, Typicality, and Adequacy: The proposed classes include millions of users, making individual litigation impractical. The named plaintiffs’ claims were found to be typical of the class, and class counsel was deemed adequate.
- Commonality and Predominance: The court determined that key questions—such as whether the app’s privacy representations were uniform, whether sensitive data was transmitted, and whether users’ privacy was violated—could be answered with common evidence applicable to all class members.
Defenses Raised by Defendants
Defendants argued that class certification should be denied based on several grounds:
- Implied Consent: Defendants claimed users consented to data sharing by continuing to use the app after being exposed to certain disclosures. The court rejected this, finding no evidence that users were adequately notified of the specific conduct at issue.
- Contractual Limitations and Waivers: Defendants pointed to a one-year contractual limitations period and a class action waiver in the app’s terms of service. The court found the waiver unconscionable (both procedurally and substantively under CA law) and unenforceable, and held that the limitations defense did not defeat predominance due to the uniformity of the app’s representations.
- Standing: The court rejected arguments that users lacked standing if only anonymized data was shared, holding that the loss of control over private information constitutes a concrete injury.
Claims Certified for Class Treatment
The court certified the following claims for classwide adjudication:
- Nationwide Class: Claims against the app developer for (1) violation of the California Confidentiality of Medical Information Act (CMIA), (2) breach of contract, and (3) common law intrusion upon seclusion.
- California Subclass: Claims against the app developer for invasion of privacy under the California Constitution, and against Google and Meta for violation of the California Invasion of Privacy Act (CIPA) Section 632.
Claims Not Certified
The court denied certification for:
- Comprehensive Data Access and Fraud Act (CDAFA): Plaintiffs failed to provide classwide evidence of “damage or loss” as required by the statute.
- CIPA Section 631: Plaintiffs did not demonstrate a classwide method for establishing the geographic requirements of the statute.
- Injunctive Relief Classes: The request for certification of injunctive relief classes was denied due to insufficient focus on non-monetary remedies.
ERICA FRASCO, et al., Plaintiffs, v. FLO HEALTH, INC., et al., Defendants. Additional Party Names: Autumn Meigs, Facebook, Inc., Google LLC, Jennifer Chen, Justine Pietrzyk, Leah Ridgway, Madeline Kiss, Meta Platforms, Inc., Sarah Wellman, Tesha Gamino, No. 21-CV-00757-JD, 2025 WL 1433825, at *19 (N.D. Cal. May 19, 2025).
