MigraSync is a migraine tracking app. It handles some of the most sensitive information there is — your health. This policy explains, in plain language, exactly what we collect, where it is stored, who can see it, and how you remove it.
1. Who we are
MigraSync ("MigraSync", "we", "us") is an independently developed mobile application for tracking migraine and headache attacks. For the purposes of data protection law, we are the data controller for the limited personal data processed through our backup service.
Contact: abhay050@gmail.com
2. What we collect
Health and tracking data you enter
This is the data you create by using the app:
- Attack records: start and end time, duration, pain intensity, pain location on the head map, and how the attack resolved.
- Symptoms and aura: nausea, photophobia, phonophobia, visual or sensory aura, and other symptoms you select.
- Triggers you record, and days you mark as good days.
- Medications: names, doses, schedules, when you took them, and how effective you rated them.
- Menstrual cycle entries, if you choose to track them.
- HIT-6 questionnaire responses and scores.
- Profile details you provide, such as your name, year of birth and diagnosis status, and an optional profile photo.
- App settings, reminders and notification preferences.
Weather and approximate location
If you enable weather tracking and grant location permission, the app uses your approximate location to look up local conditions — barometric pressure, temperature and humidity — and stores those readings with your entries. We use your location only to make that lookup; we do not build a location history, and we do not store precise coordinates on our servers. If you decline location access, the rest of the app works normally.
Account data (only if you sign up)
If you create an account for cloud backup, we store your email address and a salted, hashed password. We never store your password in a readable form.
Backup data (only if you enable it)
When cloud backup is on, a copy of your tracking data is stored on our server so it can be restored to a new device.
Purchase data
If you subscribe to Premium, payment is handled entirely by Google Play or the Apple App Store. We never see or store your card details. We receive only the subscription status needed to unlock Premium features.
What we do not collect
- No advertising identifiers, and no advertising SDKs of any kind.
- No third-party behavioural analytics or session-recording tools.
- No contacts, no photo library beyond a picture you deliberately select, no microphone, no continuous location.
3. Where your data is stored
| Data | On your device | On our server |
|---|---|---|
| Attacks, symptoms, triggers, good days | Always | Only with cloud backup on |
| Medications and doses | Always | Only with cloud backup on |
| Cycle log, aura log, HIT-6 scores | Always | Only with cloud backup on |
| Profile and settings | Always | Only with cloud backup on |
| Weather readings attached to entries | Always | Only with cloud backup on |
| Email address and password hash | — | Only if you create an account |
| Precise location | Not retained | Never |
| Payment card details | Never | Never |
Our backup service runs on Cloudflare infrastructure. Cloudflare acts as our hosting processor and does not use your data for its own purposes.
4. How we use your data
- To run the app. Showing your history, timers, charts and reminders.
- To generate insights. Correlations between your attacks and your weather, sleep, cycle, medication and trigger data. This analysis runs on your data only — it does not pool your records with other users' records.
- To produce reports. Building the PDF summaries you export for a clinician.
- To back up and restore. Only if you turn cloud backup on.
- To send notifications you asked for. Medication reminders, hydration reminders and risk alerts, all controllable in Settings.
- To support you. Answering emails you send us.
We do not use your health data for advertising, profiling for marketing, or training general-purpose machine learning models for third parties.
5. Legal basis for processing (UK/EU users)
- Consent — for processing health data, weather/location lookups, and notifications. You give it by choosing to enter data and enable those features, and you can withdraw it at any time by turning the feature off or deleting your data.
- Contract — for providing account, backup and subscription functionality you have signed up for.
- Legitimate interests — for keeping the service secure and preventing abuse.
6. Sharing and third parties
We do not sell, rent, or trade your personal data. We share it only in these narrow cases:
- Hosting provider. Cloudflare hosts our backup service and stores encrypted-in-transit data on our behalf.
- App stores. Google Play and Apple process subscription payments and tell us your entitlement status.
- Weather provider. An approximate location is sent to a weather data provider to retrieve conditions. No identifying information about you accompanies that request.
- You. When you export a report or share an entry, you decide who receives it. Anything you share outside the app is outside our control.
- Law. If we are legally compelled to disclose data, we will do so only to the extent required.
7. Device permissions we request
| Permission | Why | Optional? |
|---|---|---|
| Approximate location | Fetching local weather and barometric pressure for correlations | Yes |
| Notifications | Medication, hydration and risk reminders | Yes |
| Photo library | Setting a profile picture, only for the image you pick | Yes |
| Biometrics (Face ID / fingerprint) | Locking the app so others can't open your records | Yes |
Every one of these is optional. Declining any of them leaves core tracking fully functional.
8. How long we keep it
- On your device: until you delete the entry, clear the app's data, or uninstall the app.
- Cloud backup: until you disable backup or delete your account. Your backup is overwritten with each sync rather than accumulating versions.
- Account record: until you delete your account.
- After deletion: data is removed from live systems immediately and purged from routine infrastructure backups within 30 days.
9. Your rights
Depending on where you live, you have some or all of the following rights. We honour them for all users regardless of location:
- Access — see everything held about you.
- Portability — take it with you. Settings → Privacy → Export My Data produces a complete JSON archive.
- Rectification — edit or correct any entry directly in the app.
- Erasure — delete individual entries, or your entire account and all records.
- Withdraw consent — turn off backup, weather, notifications or biometrics at any time in Settings.
- Object / restrict — contact us and we will act on it.
- Complain — you may lodge a complaint with your local data protection authority.
We do not charge for exercising any of these rights, and we aim to respond to requests within 30 days.
10. Deleting your data
You can delete everything yourself, without contacting us: Settings → Privacy → Delete My Account & Records. This wipes local data and any cloud backup permanently.
Full step-by-step instructions, including what to do if you no longer have the app installed, are on the account deletion page.
11. Security
- All traffic between the app and our server uses HTTPS/TLS.
- Passwords are stored only as salted hashes; we cannot read them.
- Backup access is authenticated per account — one account cannot read another's data.
- You can require Face ID or a fingerprint to open the app, so your records are protected even if someone else picks up your phone.
- Data kept only on your device is protected by your device's own encryption and lock screen.
No system is perfectly secure. If a breach ever affects your data, we will notify you and the relevant authority without undue delay.
12. Children
MigraSync is not directed at children under 13 (or under 16 where local law sets that threshold), and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
13. International transfers
Our backup service runs on globally distributed infrastructure, so data may be processed outside your country. Where required, transfers are covered by appropriate safeguards such as Standard Contractual Clauses. If you never enable cloud backup, your data never leaves your device and no transfer occurs.
14. Changes to this policy
If we change this policy we will update the date at the top of this page. For material changes affecting how your health data is handled, we will also notify you in the app before the change takes effect.
15. Contact
Questions, requests, or complaints about privacy: abhay050@gmail.com. We read every message.