Anticipatory Design

The Design Assumption That Breaks When the World Shifts

Joana CerejoAlso on Anticipatory Design Lab
ForesightAnticipatory DesignPrivacyAI

TL;DR

  • Period-tracking apps did not change after Dobbs, but the legal context did, turning ordinary data into potential criminal evidence.
  • The failure was one of scope: designers assumed the world their product operates in is fixed.
  • Foresight, not just forecasting, is how design safeguards users when context shifts overnight.

What period tracking apps taught us about anticipatory design and the architecture of trust

In June 2022, most period tracking apps were operating exactly as designed. They collected data — menstrual cycles, ovulation windows, sexual activity, pregnancy symptoms — with the same efficiency and the same privacy posture they had always had. The data hadn't changed. The users hadn't changed. The apps hadn't changed.

What changed was the legal context in which that data existed.

After Dobbs v. Jackson Women's Health Organization overturned Roe v. Wade on June 24, 2022, approximately fifteen USA states moved quickly toward severe restrictions or outright abortion bans. Several states, like Texas, Idaho, or Tennessee, have statutes that explicitly criminalize not just providers but, in specific circumstances, the pregnant person themselves. In those states, an app log of a missed period, a recorded pregnancy symptom, and a note about contraception, which are data collected by many health apps to help women track their cycle or better understand their body, became potential evidence in a criminal case. The same entry in a period tracking app meant something entirely different in Austin, Texas, than it does in Lisbon, Portugal.

This is not a story about abortion politics. It is a design story about what designers never assumed could happen. Just because things are a certain way today doesn't mean they will still be that way tomorrow. Context is not fixed. And all the period health tracking apps failed to account for the well-being of their most exposed users — women — and what it costs when nobody thinks to question it.

Context can change overnight. We keep over-relying on forecasting to shape the future, when design, today, desperately needs foresight to safeguard users for tomorrow.

The assumption designers didn't build for

There is a particular kind of design failure that is not a bug, not a poor user experience, and not even a bad business decision at the time of making. It is the failure of scope — the assumption, baked quietly into architecture, that the world in which the product operates is fixed.

Period tracking apps like Flo, Clue, Stardust, Natural Cycles, and Apple Health, were designed to be useful and, most importantly, safe. Safe meant keeping data away from insurers and employers, protecting it behind just a password. When the FTC went after Flo in 2021, it was for quietly passing user data to Facebook and Google for ad targeting. This was a breach that people understood, but they forgot that things could turn even worse fast. Nobody was designing for criminal prosecution.

No product team in 2016 was designing for the scenario where the data they stored could be used as criminal evidence in a case against their own users. Not because they didn't care. Because the legal context that would have made that scenario plausible didn't exist yet, and they failed to account for it.

Designers were not malicious. This is a reflection of the absence of foresight practices in today's design practice, which doesn't exercise them systematically. Designers and businesses treat the context in which their products operate as a given — stable, predictable, external to design. They scope their threat models to known adversaries and assume the regulatory environment is, at worst, slow-moving (which is not! And AI is adding a whole new layer to it).

The Dobbs case changed this overnight. AI is accelerating the same instability in ways we are only beginning to map.

What this mess revealed

Fortunately, the period tracking apps moved fast to protect their users after the ruling. Some did better than others. What those responses looked like says as much about the problem as the ruling itself.

Flo launched Anonymous Mode in July 2022 — a feature that lets users track their cycle without being identifiable. It should have been there from day one. It wasn't because nobody had asked what would happen if that data became a target.

Because it is headquartered in Berlin, Clue had something the other apps didn't: GDPR. European law gave its users a protection that American courts had less reach over. But Clue didn't design for this. It just happened to be in the right jurisdiction.

Stardust initially announced it would hand over user data if a court asked, which is what the law requires. That triggered immediate backlash. The announcement wasn't dishonest. It was a legal team doing legal work. The problem was that users had just understood, for the first time, what "lawful data requests" meant for the notes they had been keeping about their own bodies.

Apple Health held. On-device encryption was already the default — built years earlier as a matter of principle, not in anticipation of any specific legal threat. It still protected millions of users. Design by principle rather than by threat model: that is the closest any of these companies came to foresight.

Four companies. Four different responses. None of them had accounted for this plausible but unlikely future.

When law becomes architecture

Clue survived the Dobbs tsunami better than most. Not because of better features or tighter privacy settings, but because its European location put it under GDPR, and GDPR meant the data couldn't be compelled in ways American courts might demand.

We tend to think of privacy regulation as compliance overhead, a simple legal function, instead of a design function. GDPR requirements get mapped to consent flows, data export features, and deletion workflows. Privacy by design gets treated as a checklist. The work happens in a legal department, sometimes with design input, rarely with strategic architectural intent.

Dobbs changes that framing. Today, where a company is based directly impacts which law governs its data. This cannot be a compliance footnote anymore. It is part of what the product offers. In summer 2022, Clue's European headquarters protected its US users more reliably than any in-app setting, because it operated at the level of law, not UX. A user in Texas could trust Clue not because of a privacy policy, but because German law simply didn't allow what an American court might demand.

The EU AI Act extends this logic further. The Act prohibits AI systems that manipulate users through subliminal techniques, exploit psychological vulnerabilities, or enable real-time biometric surveillance for law enforcement in public spaces. These are prohibitions, hard stops encoded in the law. In a jurisdiction where they apply, they function as architectural guardrails. In a jurisdiction where they don't, the responsibility lands on the designer. And that responsibility demands more than forecasting — it demands designing with foresight: building systems that are not just efficient, but context-aware and resilient to change.

When law doesn't draw the line, the designer holds it — and that's a fragile place to stand.

This isn't only a period tracking app problem

Period tracking apps are the clearest case because the stakes became immediately apparent, and the public response was loud. But this isn't the only product category underlying this vulnerability that any product is exposed to, a stable context that can change at any moment.

Mental health apps face the same structural exposure. Apps that log mood states, therapy notes, crisis moments, and medication adherence have been entered into evidence in court cases over child custody. The user who logged "struggling today, having thoughts about not being here" was logging for personal well-being. The court reading that entry months later is doing something the design never accounted for.

Immigration-support apps that help people navigate visa processes, document their cases, and connect with legal aid were designed in policy environments that shifted considerably between 2016 and 2020 in the US, and keep shifting all over the world. Data about undocumented status, location patterns, family member location, and legal strategy are not abstractly sensitive. Under shifting enforcement, that data becomes a liability to the very people it was built to help.

Location apps designed to protect people from stalkers have themselves been subpoenaed — and the "trusted contacts" list becomes a log of a victim's movements.

Cryptocurrency tax trackers designed to help users stay compliant are now, in multiple jurisdictions, primary evidence in tax evasion investigations. The same logging behavior that was "responsible financial management" is "evidence of liability."

The pattern is consistent: a design that was appropriate for one contextual envelope becomes a liability when that envelope shifts. The shift is always external — not driven by the product, not controlled by the product team, and often outside the team's normal planning horizon.

What foresight would have asked in 2018

Nobody needed to predict Dobbs. They needed to ask a different question.

Most product teams plan for the future using forecasting, the method of analyzing historical data and past patterns to estimate what comes next. This is how Netflix recommends what you probably want to watch next, or how a business models next quarter's revenue. Forecasting is useful. But it only tells you what is probable, not preferable, based on what has already happened. It cannot see what has never happened before.

Foresight does something different. It asks what futures are possible and preferable, including ones that break from past trends. Not "what will probably happen?" but "what could happen — and are we built for it if it does?"

A team running even a basic foresight exercise in 2018 would have started by asking: what could change in the world that we are not planning for? The signals were there to find. Roe v. Wade had been under legal challenge for decades. Several states had already passed abortion restrictions that federal courts had blocked (temporarily). Digital health data had already appeared in criminal cases. The FTC was beginning to scrutinize how health apps shared user data with third parties. GDPR had just come into force in Europe, signaling that the legal landscape around personal data was shifting.

Apparently, none of those signals were enough to predict Dobbs. But together they pointed toward a plausible scenario: a legal context in which intimate health data could become evidence against the very users who created it. Foresight would have surfaced that question. Backcasting is how you answer it.

Backcasting means starting from a future scenario and asking what an earlier team should have built to protect their users if that future arrived. The scenario here is 2022: a user's period log is evidence in a criminal case. Working backward to 2018, the answers are concrete — and every one of them was achievable at the time. Data is collected only when necessary, and retained only as long as it serves the user. Health data that works without an identity attached. On-device storage is the default. Deletion that actually deletes, not a soft archive, a real wipe. Transparency about where data lives and whose law governs it.

None of this was unavailable in 2018. It wasn't built because the question wasn't asked.

I call this the context assumption — the quiet default that the world a product operates in today is the world it will operate in indefinitely. It is one of the most expensive assumptions in design, and the hardest to see, because it is invisible while the world is stable.

Three pillars under pressure

In my book, The Anticipatory Design Playbook, I frame the design challenge of AI systems around three missing human elements: user intent, foresight, and user agency. Dobbs stress-tests all three in ways that generalize beyond health apps, exposing not just the failures but the assumptions each pillar had been resting on, unexamined.

The three missing human elements in AI systems — Intent, Foresight, and Agency — each marked with the anticipatory-design triangle.

User intent is the primary goal a user is trying to achieve — distinct from stated preferences, past behavior, or what the UI makes easy to click. A period tracking app was designed around a clear intent: understanding women's bodies, tracking health, planning ahead. The data it collected existed in service of that intent. When the context shifted, the same data was turned against it. The design had been built to serve user intent faithfully, but only inside the world it was designed for. Intent is not just what users want right now. It is what a design commits to protecting across conditions it doesn't fully control.

Foresight is the practice of asking what futures are possible, not just probable, and designing so the product holds up in them. The period tracking apps had no foresight gap in the technical sense: the code worked, the data stored cleanly, the logic ran correctly. The gap was in design practice. No product team had asked, systematically, in what future this data would stop serving users and start working against them. That question — not a prediction, just a question — leads directly to data minimization, on-device storage, real deletion. The absence of foresight didn't show up as a bug. It showed up as a blind spot the ruling walked right through.

User agency is trust through control — not a settings screen, not a consent flow, but architecture that holds when the context shifts. In this case, it would have meant genuine control over what data exists at all. The apps had built the form of agency: privacy policies, toggles, delete buttons. The substance would have been an architecture that didn't accumulate what a court could later compel. The difference is invisible when the context is stable. Dobbs made it visible, permanently.

What design owes its users

The boundary between what is useful and what is dangerous is not a fixed line. It is a function of context — legal context, political context, social context — that designers do not control and cannot always predict.

This is not an argument for building nothing. It is not a case for designing only under the most restrictive possible threat model, which produces products that are technically safe and practically useless. It is an argument for foresight as a design practice, not a one-time risk assessment filed at product launch. It is an argument for jurisdiction as a design material, not a checkbox owned by legal. It is an argument for building user agency that is real — architecture that holds when the world shifts, rather than a UX layer over a data structure that was never built for user control.

In design, we talk about the creepy line — the threshold where helpful becomes invasive. We treat it as something we calibrate: get the personalization right, choose the right moment, explain the logic, and the product stays on the right side. What Dobbs made visible is that the line isn't ours to calibrate. Context moves it. The same app, the same data, the same user — in a different legal reality, the line had already shifted, and no one had designed for that.

Foresight is the practice of designing for a world where that line has already moved. Not predicting where it will go. Building so that when it does, users still have real control over what exists.

Clue and Apple — the apps that held in 2022 — weren't the ones that predicted Dobbs. They were the ones that had already stopped accumulating data they didn't need — not because the threat was visible, but because a principle had been applied before the threat arrived. That is the design we owe our users.

Share
Try it in the toolkit

Anticipatory Design Framework

Design the need before users ask: the Anticipate → Imagine → Shape method, made repeatable.