Medical disclaimer: MigraineMe is not a medical device. It does not diagnose, treat, cure, or prevent any medical condition. The insights and recommendations provided are for informational purposes only and should not be considered medical advice. Always consult a qualified healthcare professional for medical decisions.

Contents

  1. Information We Collect
  2. How We Use Your Data
  3. Authentication Providers
  4. Data Storage and Security
  5. Third-Party Services
  6. Permissions
  7. Data Retention
  8. User Rights and Data Deletion
  9. International Data Transfers
  10. Children's Privacy
  11. Changes to This Policy
  12. Contact

1. Information We Collect

1.1 Account Information

When you create an account or sign in, we may collect:

We do not collect or store passwords from third-party login providers.

1.2 Health and Activity Data (User-Entered)

You may choose to enter:

  • Migraine episodes (type, severity, duration, pain locations)
  • Triggers (environmental, dietary, behavioural, hormonal)
  • Prodromes and warning symptoms
  • Medications and dosages
  • Relief methods and their effectiveness
  • Menstruation cycle data
  • Activities and missed activities
  • Notes and timestamps

This data is stored only for your personal use within the app and to generate personalised insights.

1.3 Connected Health Services (Optional)

If you choose to connect supported services, we may collect health-related data such as:

WHOOP

  • Sleep duration, stages, and quality scores
  • Recovery scores
  • Heart rate variability (HRV) and resting heart rate
  • Blood oxygen (SpO2) and skin temperature
  • Activity and workout summaries

Garmin

  • Steps and activity data
  • Sleep data and heart rate
  • Activity summaries

Google Health Connect

  • Sleep data, heart rate and HRV
  • Blood pressure
  • Activity and exercise data
  • Nutrition records

This data is only collected if you explicitly enable the integration and grant the required permissions. You can disconnect any integration at any time.

1.4 Automatically Collected Device Data (Optional)

If you grant permission, MigraineMe may collect the following device-based metrics:

Each of these requires explicit user permission and can be individually disabled at any time in the app's Data Settings.

1.5 Location Data (Optional)

If enabled, MigraineMe collects approximate daily location data to retrieve local weather conditions and associate environmental factors with migraine patterns. Location collection is optional, requires explicit permission, can be disabled at any time, is stored at daily resolution (not continuous tracking), and is used solely to fetch weather data for your area.

1.6 Nutrition Data (Optional)

If you log food or connect a nutrition source, we may process food names, meal types, macro and micronutrient values, and migraine-relevant exposure flags (tyramine, alcohol, gluten, caffeine). Nutrition data is used to identify dietary trigger patterns.

2. How We Use Your Data

Your data is used to authenticate your account, store and display your migraine and health history, calculate personalised risk scores and trigger analysis, generate AI-powered daily insights (premium), synchronise enabled third-party health data, and improve app functionality and reliability.

2.1 AI-Powered Features

MigraineMe uses artificial intelligence to generate personalised daily insights for premium users. This involves aggregating and summarising your health data, then sending this summarised data to OpenAI's API (GPT-4o-mini) to generate actionable advice.

Important: Only aggregated summaries are sent to the AI service — not raw personal identifiers. The data sent does not include your name, email, or account information. OpenAI's API data usage policy states that API inputs are not used to train their models.

2.2 What We Do Not Do

3. Authentication Providers

MigraineMe supports login via email and password, Google Sign-In, Facebook Login, and Apple Sign-In. When using a third-party provider, authentication is handled securely by the provider and Supabase. MigraineMe receives a session token and basic profile identifier only — we never receive access to your provider password.

4. Data Storage & Security

All data is stored securely using Supabase, a managed backend platform built on PostgreSQL, hosted in the European Union. Security measures include:

5. Third-Party Services

ServicePurposeData Shared
SupabaseBackend, database, authenticationAll app data (encrypted)
RevenueCatSubscription managementUser ID, purchase status
OpenAIAI daily insights (premium)Aggregated health summaries (no personal identifiers)
Google / Facebook / AppleAuthentication (optional)Session token only
WHOOP / GarminHealth metrics (optional)Health data via authorised API
Open-MeteoWeather dataApproximate location coordinates

Each third-party service is governed by its own privacy policy. MigraineMe only accesses the minimum data required for functionality.

6. Permissions

PermissionPurposeRequired?
InternetCore app functionalityYes
Location (approximate)Weather data for trigger correlationOptional
MicrophoneAmbient noise level samplingOptional
Health ConnectSleep, heart rate, activity dataOptional
NotificationsReminders and check-in promptsOptional
Usage StatsScreen time trackingOptional

All optional permissions can be granted or revoked at any time through your device settings or the app's Data Settings screen.

7. Data Retention

Your data is retained as long as your account remains active, or until you request deletion. If you disconnect a third-party service, no new data will be collected from that provider. Previously collected data remains unless you delete it.

8. User Rights & Data Deletion

You have full control over your data.

8.1 In-App Controls

8.2 Full Account Deletion

To request complete deletion of your account and all associated data, visit our account deletion page or email us directly:

📧 help@migraineme.app — Subject: "MigraineMe Data Deletion Request"
Include the email address used to sign in. Your request will be processed within 30 days.

8.3 Data Export

You may request a copy of all your stored data by contacting us at the email address above.

9. International Data Transfers

Your data is stored on servers within the European Union. If you access MigraineMe from outside the EU, your data will be transferred to and processed in the EU. For the AI insights feature, aggregated (non-identifying) health summaries may be processed by OpenAI's servers in the United States.

10. Children's Privacy

MigraineMe is not intended for use by children under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Last updated" date at the top of this page. If we make material changes, we will notify you through the app.

12. Contact

If you have questions or concerns about this Privacy Policy or your data: