Migrania Join the Beta

Privacy Policy

Version 1.0 – last updated July 2026

This privacy policy explains how personal data is processed when you use the “Migrania” app (the “App”) and this website. We provide this information pursuant to Art. 13 of the General Data Protection Regulation (GDPR).

1. Controller

Christopher Brock
Vennhauser Allee 196 C
40627 Düsseldorf
Germany

Email: contact@migrania.app (full details in the legal notice).

A data protection officer is not appointed, as we are not required to appoint one at this scale. For any privacy questions, please use the contact email above.

2. Your data stays yours

Your tracking data never reaches us. The migraine attacks, medication intakes, symptoms, free-text notes, and PDF report contents you record are stored on your device. Migrania never transmits them to the developer; we have no access to them.

You can optionally turn on iCloud sync, which is off by default — you decide whether to enable it. When you do, your entries are additionally stored in your own private iCloud database and are end-to-end encrypted: the health content is encrypted with keys held in your iCloud Keychain, so neither Apple nor we can read it. There is no account with us. You can also still move your data yourself by exporting an encrypted backup file or by creating a PDF report — both remain entirely under your control.

Recovery caveat: because the synced data is end-to-end encrypted, if you lose access to your Apple ID or iCloud Keychain we cannot recover it for you. Keep an exported backup file so you always have a copy under your own control.

3. Categories of personal data

We process — or, in the case of your health data, enable you to store — the following categories:

  • Health and tracking data: migraine attacks, medication intakes, symptoms, free-text notes, and the contents of PDF reports. This data is stored on your device and, only if you enable the optional iCloud sync, additionally in your own private, end-to-end-encrypted iCloud database (see section 2). It is never transmitted to us. You can export it yourself as an encrypted backup file or as a PDF report.
  • Product analytics (optional): if you opt in, anonymous usage analytics are collected via PostHog (EU endpoint). Analytics are off by default, contain no free-text and no direct identifiers, exclude all health content, and are limited to a fixed allowlist of events.
  • Crash reporting (optional): if you opt in, technical crash data is collected via Sentry (EU/Germany region). Crash reporting is off by default and limited to technical diagnostic data.
  • Website: if web analytics are used, they are cookieless and self-hosted (page URL, referrer, browser type). No cookies and no persistent identifiers are set.

4. Purposes and legal bases

  • Health and tracking data (purpose: letting you record and review your own wellness data on your device): your explicit consent under Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR. As this is special-category data (Art. 9 GDPR), it is processed only on the basis of your explicit consent given in the App. Enabling the optional iCloud sync rests on the same basis: your separate explicit consent under Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR, given when you turn sync on and revocable at any time by turning it off.
  • Product analytics and crash reporting (purpose: improving stability and the product): your consent under Art. 6(1)(a) GDPR, which you give by opting in and can withdraw at any time.

5. Recipients and processors

Unless you enable the optional iCloud sync, your health and tracking data is not shared with any processor — it never leaves your device except through a backup file or PDF that you create and control yourself. The processors we may engage each act under a data processing agreement (DPA / AVV):

  • Apple (iCloud, only if you enable sync): if you turn on iCloud sync, Apple stores your data in your own private iCloud database. Because the health content is end-to-end encrypted with keys from your iCloud Keychain, Apple cannot read it. This runs on your own Apple ID with no account with us, and is covered by Apple's data processing terms under the Apple Developer Program; we do not engage a separate sync provider.
  • PostHog (EU): optional, opt-in product analytics, processed on EU infrastructure.
  • Sentry (EU/Germany): optional, opt-in technical crash data.

6. Third-country transfers

Processing by our analytics and crash-reporting processors takes place within the EU/EEA. If you enable the optional iCloud sync, Apple may process and store your data on infrastructure that includes the United States. Apple Inc. is certified under the EU-US Data Privacy Framework, which the European Commission recognises as ensuring an adequate level of protection (Art. 45 GDPR); this is the transfer basis. Because your data is end-to-end encrypted, its content remains inaccessible to Apple wherever it is stored. Any backup files or PDF exports you create are stored wherever you choose, which is under your sole control.

7. Retention

Your health and tracking data is kept until you delete it; you remain in control of it at all times and can delete all data within the App. If you enabled iCloud sync, deleting your data in the App also removes the synced copy from your private iCloud database. Optional analytics and crash data are retained only for as long as necessary for the stated purpose and are deleted according to the respective provider’s retention windows. Cookieless website logs are kept only briefly for operational and security purposes.

8. Is providing data mandatory?

You are not legally or contractually obliged to provide data. The App is fully usable for tracking without enabling analytics or crash reporting, which are optional and off by default. Not enabling them has no negative consequences for your use of the App.

9. No automated decision-making

There is no automated decision-making or profiling within the meaning of Art. 22 GDPR. Migrania does not predict migraine attacks and does not infer causal triggers; it only displays the data you have entered yourself.

10. Your rights

Under the GDPR you have the right to:

  • access your personal data (Art. 15);
  • rectification of inaccurate data (Art. 16);
  • erasure (Art. 17);
  • restriction of processing (Art. 18);
  • data portability (Art. 20) — you can export all your data yourself as a backup file at any time;
  • object to processing (Art. 21);
  • withdraw your consent at any time (Art. 7(3)), without affecting the lawfulness of processing before withdrawal. Withdrawal is possible at any time in the App’s settings.

Because you hold your health data yourself — on your device and, if you enable it, in your own end-to-end-encrypted iCloud — you can exercise most of these rights directly in the App (e.g. by editing, exporting, or deleting your entries; a deletion also purges any synced iCloud copy).

11. Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority. The authority competent for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
ldi.nrw.de

12. Changes to this policy

We may amend this privacy policy, for example following changes to the App, to processors, or to the legal framework. The current version is always available on this page.

The German version of this privacy policy is the legally authoritative one.

Legal

  • Legal notice
  • Terms & Conditions
  • Privacy Policy

Language

  • English
  • Deutsch

© 2026 Christopher Brock. All rights reserved.