Privacy Policy
Last updated 3 September 2026
The short version
Signing in with Apple is required to use mygraine — there's no way to use the app without an account. Your migraine diary — symptoms, medications, notes, everything you write or say — stays on your iPhone; it is never uploaded anywhere. Separately, an anonymized slice of every attack you log — stage, severity, symptom codes, trigger categories, and date — is always stored on our server, along with which known migraine contributors were active on any day you've confirmed either had an attack or was migraine-free (weather, sleep, hormonal window, and similar). It's kept in tables with no user or device identifier attached to them at all, so none of it can be traced back to you, even by us, and may be used in the future for aggregate trend research across all users.
What stays on your device
Everything below is read and processed on your iPhone, not sent to our servers:
- Every diary entry you log — stage, severity, symptoms, triggers, medications, and any notes.
- Voice recordings and transcripts from voice logging — speech recognition runs on-device.
- Apple Health data mygraine reads (sleep, activity, meal timing) to calculate your Threshold Load.
- On iPhone 15 Pro or newer with Apple Intelligence turned on, the personalized Patterns digest and note summaries — generated on-device using Apple’s Foundation Models framework, with no network access, never sent to Apple or to us.
What we store, and why
Your account. mygraine requires signing in with Apple before you can use the app — there's no guest mode and no way around it. When you sign in, we store your Apple-provided name (if you share it) and email address, so we can identify your account, check it against our free-access allowlist, and let sync and support work.
An anonymous attack log. Every time you log or update an attack, five fields are always synced to our server: the date, stage, severity, symptom codes, and trigger categories. This table has no column of any kind for a user ID, device ID, or anything else that could link a row back to an account — structurally, not just by policy — and we may use this anonymized data in the future for aggregate trend analysis across all users.
Anonymous daily contributors. For any day you've explicitly confirmed either had an attack or was migraine-free (tapping the app's “No migraine today”/“Mark migraine-free” action), we also store which known migraine contributors were present that day (e.g. a pressure drop, poor sleep, a skipped meal) and that day's computed Threshold Load — never a day you haven't confirmed either way. Same structural guarantee as the attack log above: no user or device column of any kind.
Your attack count. Separately, we keep a running count of attacks tied to your account (not their content) — this powers our own product usage insight and nothing else.
A notification log. When the app sends you a local alert (a threshold crossing, a weather warning, and similar), we record which type it was and when, tied to your account — this is so we can help if you report not receiving one you expected. Never the alert's text itself.
Feedback you send us. If you submit feedback in the app, we store the message, an optional category, and your app version, tied to your account so we can follow up if needed.
Subscription status. Purchases are handled entirely by Apple through the App Store. We never see your payment details — only whether your subscription is active, from Apple and our payments provider (RevenueCat).
What we don't do
- No advertising, and no advertising identifiers.
- No third-party analytics or tracking SDKs of any kind.
- No selling or sharing your data with anyone, for any reason.
Who can see what
mygraine is built and operated by an individual developer (Gareth Lowrie), not a company with a support team. Account records and the anonymous attack log are stored with Supabase, our database provider. No one — including us — can view your diary content, since it never reaches our servers in the first place.
Your choices
- Turn off Apple Health access at any time in Settings on your iPhone.
- Delete individual diary entries, or the app itself, to remove everything stored locally.
- Contact us (see below) to have your account and its associated data — email, attack count, and feedback — deleted from our servers.
Children
mygraine is not directed at children and is not intended for use by anyone under 16.
Changes to this policy
If this policy changes in a way that affects how your data is handled, we'll update this page and change the date above.
Contact
Questions about this policy or your data — including deletion requests — can be sent via our support page.