The digitalisation of the reproductive body has engaged myriads of cutting-edge technologies to support people in understanding and managing their intimate health. Generally understood as female technologies (FemTech), these products and systems collect a wide range of intimate data, predominantly related to sexual and reproductive health. This sensitive data is then processed, transferred, saved, and shared with other parties. The data-hungry nature of this industry and the lack of proper safeguarding mechanisms, standards, and regulations for this vulnerable data can lead to complex harms or diminished user agency. In this paper, we adopted mixed methods, including an online survey and a Story Completion Method (SCM), to explore user understanding of the security and privacy (SP) of these technologies. We conducted online user studies in two countries: the UK and Iran, in English and Farsi (Persian), respectively. We recruited 102 UK and 130 Iranian participants for our surveys, and 17 UK and 34 Iranian participants for our SCM studies. Our findings show that while users can speculate on the range of harms and risks associated with these technologies, they are not necessarily presented and equipped with the technical skills to protect themselves. We identified a larger gap in the Iranian group compared to the UK group, which can be attributed to factors such as differences in data protection regulations between the two countries. This comparative study highlights how disparate data protection frameworks and unique cultural contexts can shape user vulnerability to FemTech risks. We discuss how participatory threat modelling and Security and Privacy by Design are critical to protecting users in these sensitive systems.
Mehrnezhad et al. (2026) studied this question.