Frasco v. Flo Health, Inc.
The period-tracking case that produced two results at once: a $59.5M settlement from Google, Flo, and Flurry — and, against the one defendant that refused to settle, the first major CIPA jury verdict in the statute's history, finding Meta liable for capturing women's reproductive-health data without consent. Here's how in-app data reached advertisers, both tracks of the outcome, and why every operator collecting sensitive data should read it.
What the case is about
Flo is one of the most popular period- and ovulation-tracking apps in the world — a place where users enter some of the most intimate information they'll ever type into a phone: menstrual cycles, sexual activity, attempts to conceive, pregnancy. The consolidated class action Frasco v. Flo Health, Inc., filed in the Northern District of California in 2021, alleged that Flo allowed Facebook (Meta), Google, and Flurry to eavesdrop on that confidential in-app health data — without users' consent — through the software development kits (SDKs) those companies supplied for analytics and advertising.[1]
The mechanism is the part every operator should understand, because it isn't unique to Flo. When an app integrates a third-party SDK, the SDK can receive the data the app passes to it. Here, the plaintiffs alleged that as users entered health information during onboarding and regular use, that information — menstruation and pregnancy details — was transmitted to Meta and the other SDK providers, who could then use it to strengthen their advertising businesses.[2] The theory: this was interception of confidential communications, actionable under California's Invasion of Privacy Act (CIPA).
What makes Frasco essential reading isn't only the sensitivity of the data. It's that the case split into two tracks with two very different lessons — a large settlement from the defendants who chose to resolve, and a historic trial loss for the one that didn't.
Track one — the $59.5M settlement
Three of the four defendants chose to settle rather than face a jury. Together, Google, Flo Health, and Flurry agreed to pay a combined $59.5 million, broken down as:
- Google — $48 million
- Flo Health — $8 million
- Flurry — $3.5 million
The settlement covers people in the United States who entered menstruation or pregnancy information into the Flo App between November 1, 2016 and February 28, 2019, with a California subclass receiving a double share.[3] Judge James Donato granted preliminary approval on April 22, 2026; the claims deadline is October 15, 2026, and the final approval hearing is set for October 29, 2026.[3] Notably, the timing of the settlements tells its own story: Google and Flurry settled before trial, and Flo Health settled during trial — leaving a single defendant to face the jury.[4]
Track two — Meta's landmark CIPA jury verdict
Meta was, in the court's words, "the last defendant standing." On August 1, 2025, after a two-week trial, a unanimous San Francisco jury found Meta liable under CIPA for obtaining the confidential menstruation and ovulation information that women communicated through the Flo App — without their consent.[5] The jury deliberated roughly three hours; at Meta's request each juror was polled, and the unanimous verdict was confirmed.[6]
Section 632 of the California Invasion of Privacy Act prohibits intentionally recording or eavesdropping on a confidential communication without the consent of all parties. The jury found that Meta's SDK functioned as an "electronic recording device" that captured users' confidential in-app health communications. CIPA carries statutory damages commonly cited at $5,000 per violation under Penal Code §637.2 — which, across a certified California class, is why Meta itself has described its exposure as reaching multiples of billions of dollars.
This is not a motion-to-dismiss ruling where a court merely found the allegations sufficient to proceed. It is a jury verdict on the merits — the first major one in CIPA's history — and legal commentators have called it "a viable blueprint for future privacy cases against Big Tech."[5] Meta tried to undo it: it moved to decertify the California class and to set aside the verdict. On September 17, 2025, the court denied those post-trial motions, leaving the liability finding intact; damages have not yet been set.[6] Meta has continued to pursue further challenges.
The unanimous verdict found Meta liable for using its SDK as an "electronic recording device" that captured confidential health communications without consent — the first time a jury applied CIPA to SDK-based tracking at scale.
— Summary of the Frasco v. Flo Health verdict and post-trial order[6]The reason this matters far beyond femtech is what the jury's reasoning did not depend on. The principles the jury applied — that an SDK can be an electronic recording device, what counts as consent, when intent may be implied — aren't limited to health data or health apps. They apply to any deployment of a third-party SDK or tracking tool that captures user communications in real time.[5] The health-data context made the case sympathetic to a jury; the legal machinery is general.
Where it stands (as of August 2026)
Two tracks, two statuses:
- The settlement ($59.5M from Google, Flo, and Flurry) has preliminary approval; the claims deadline is October 15, 2026 and the final approval hearing is October 29, 2026. Payments follow final approval and any appeals.[3]
- The Meta verdict stands after the court denied Meta's post-trial motions. The liability finding is in place; the court has not yet ruled on damages, and further appellate challenges are expected.[6]
Why Frasco is a landmark
Most of the 2026 CIPA wave is procedural — complaints filed, motions to dismiss won or lost. Frasco is different because it went the distance, and the two tracks together send a message no motion ruling can:
| What happened | Why it's significant |
|---|---|
| $59.5M settlement (Google, Flo, Flurry) | One of the largest data-privacy settlements tied to SDK/tracking data — and it priced in what three sophisticated defendants thought a jury would do. |
| First major CIPA jury verdict (Meta) | Proves the SDK/pixel-tracking theory doesn't collapse at trial. Motions to dismiss can be won or lost; this went to verdict and Meta lost. |
| Post-trial motions denied | The liability finding survived the defendant's best attempt to unwind it, hardening the precedent. |
| "Electronic recording device" reasoning | Applies to any third-party SDK or tracker capturing communications in real time — not just health apps. |
As Bloomberg Law put it, the verdict produced "a viable blueprint for future privacy cases against Big Tech" — decisions that "could be worth billions of dollars."[5] For any business that has quietly assumed CIPA claims get dismissed before trial, Frasco undermines the bet.
Why this case matters for website and app operators
The uncomfortable core of Frasco is that the conduct wasn't exotic. Flo did what countless apps and sites do: it integrated third-party SDKs and tags for analytics and advertising, and data flowed to those third parties. The difference was the sensitivity of the data and the fact that it went to trial — but the mechanism (a third-party tool receiving data the product handled) is everywhere.
Two lessons generalize directly:
- An SDK or tag that receives user data can be an "electronic recording device." If a third party is capturing communications in real time without consent, the label on the tool doesn't save you — the Flo jury looked through it.
- Consent has to be real, before the capture. The verdict turned on the absence of consent. A tool that fires and transmits before the user has genuinely agreed is the exact fact pattern that lost.
And the exposure scales frighteningly: at $5,000 per violation across a class, "multiples of billions" is not hyperbole — it's Meta's own characterization of what a certified class plus statutory damages can produce.[5]
What this means for your site
The durable lesson from Frasco is that the safe posture doesn't depend on winning a motion — it depends on not capturing communications without consent in the first place. If your site or app hands data to third-party SDKs, pixels, or tags before a user genuinely consents, you have the fact pattern the Flo jury punished, regardless of how sensitive the data is.
The protective steps are the same whether you run a health app or an e-commerce store:
- Don't let third-party trackers capture or transmit before consent. Block non-essential SDKs, pixels, and tags until the user genuinely opts in — that removes the "without consent" element the verdict rested on.
- Be especially careful with sensitive data. Health, financial, and other sensitive inputs draw both plaintiffs and juries; keep third-party tools away from those data paths entirely.
- Make consent real and provable. A genuine, affirmative choice — logged as evidence — is what stands between you and a "no consent" finding.
That's precisely what ConsentPixel is built to do — block third-party trackers at the browser level until a visitor genuinely consents, and log each decision as tamper-evident evidence — so a tracker can't quietly capture a communication before the user has agreed. To be clear about our lane: this is the website/consent layer, not app-SDK instrumentation or legal advice; for app SDKs and your specific exposure, work with your engineering team and qualified counsel.
And because the whole problem starts with a third-party tool receiving data before consent, the cheapest first step is to see what's actually firing on your site, and when.
Is a third-party tracker capturing data before consent on your site?
Scan free in about 10 seconds to see every third-party tracker firing on your site — including the ones transmitting before a visitor consents, the exact element the Flo verdict turned on.
Scan your site free →No account needed · then start a 14-day free trial, no credit card, from $8.99/mo
Frequently asked questions
What was Frasco v. Flo Health about?
How much was the Flo settlement, and who paid?
What did the jury decide about Meta?
Why does the Meta verdict matter beyond health apps?
What should my business take away from Frasco?
Sources
- Labaton Keller Sucharow — "Frasco v. Flo Health Inc." (co-lead counsel case page). Confirms the SDK eavesdropping theory, class certification, the Aug 1, 2025 Meta verdict, and the $59.5M settlement total.
- HIPAA Journal — "Flo Health, Google, Flurry to Pay $59.5M to Settle Privacy Lawsuit". Settlement structure, class definition, and the claims the suit alleged.
- Claim Depot / Period Tracker Data Privacy Litigation — settlement details. The Google $48M / Flo $8M / Flurry $3.5M breakdown, class period, claims deadline (Oct 15, 2026), and final approval hearing (Oct 29, 2026).
- Lawdragon — "Big Tech on Trial: Jury Finds Meta Liable for Misusing Women's Health Data". Trial narrative: Google/Flurry settled before trial, Flo settled mid-trial, Meta went to verdict.
- Bloomberg Law — "Meta's Health Privacy Trial Loss Spotlights Power of Wiretapping". The first-of-its-kind verdict, the "blueprint for future privacy cases," and the billions-of-dollars exposure.
- CIPAWorld — "Verdict Intact: Meta's Post-Trial Attempts to Avoid Liability… Fall Flat". The §632 finding, denial of post-trial motions (2025 WL 2680068), and that damages remain to be set.
Sources accessed and summarised August 2026. The settlement is subject to final court approval; the Meta verdict is subject to ongoing challenges. Status is current as of the publication date and may change as the litigation proceeds.
Disclaimer: This page is for general informational purposes only and is not legal advice. It describes a settlement (resolved without admissions by the settling defendants) and a jury verdict that the affected defendant is challenging; nothing here should be read as a comprehensive account of the litigation. Case details are drawn from the settlement notices and legal reporting listed above; the court's post-trial order is reported at 2025 WL 2680068 (N.D. Cal. Sept. 17, 2025). The $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2. Status is stated as of August 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel; it addresses the website consent layer, not app-SDK instrumentation. For advice on your specific situation, consult a qualified privacy attorney.