Migrelle — Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains what personal data Migrelle ("Migrelle", "the app",
"we", "us") collects, why, how it is protected, and the rights you have over it.
Migrelle is a migraine and headache self-tracking app for iOS and Android. We built it
privacy-first and local-first: your health data lives on your device, and anything that
leaves your device for backup is end-to-end encrypted so that we cannot read it.
Quick summary (the plain-English version)
- Your migraine data stays on your device. An account is optional — you only need one
if you want encrypted backup and sync across devices.
- We can't read your health data. Before it ever leaves your phone, it is encrypted on your
device. Our servers store only an unreadable encrypted blob.
- The trade-off you must understand: because only you hold the key, **if you lose all your
devices and your recovery code, your encrypted backup cannot be recovered — not even by us.**
- No advertising. No third-party ad SDKs, no Google/Firebase Analytics, no selling or sharing
of your data with advertisers. We do not sell your data.
- Insights and your doctor report are calculated on your device, not on our servers.
- Product analytics are opt-in and off by default. If you turn them on, they run on a
self-hosted analytics tool (OpenPanel) on infrastructure we control in the EU — **no
third-party analytics company receives your usage — and carry no health content and no stable
identifier**. You can turn them off again any time in Settings.
- Crash diagnostics keep the app working. A self-hosted crash/error reporter runs by default to
catch bugs, carries no health content, and you can object to it (turn it off) in Settings.
The full detail is below. This summary is for convenience and is not a substitute for the rest
of the policy.
1. Who is responsible for your data (the controller)
The data controller for Migrelle is:
Limit Waste Sp. z o.o.
ul. Grzybowska 87, 00-844 Warszawa, Poland (EU)
KRS: 0000803658 · NIP: 5272905462 · REGON: 384349430
Contact: contact@migrelle.app
Data Protection Officer: not appointed — not mandatory for a controller of this size under GDPR Art. 37; re-assessed as the app grows.
If you have any question about this policy or your data, contact us at contact@migrelle.app.
2. The data we process, and why
2.1 Health data (special category data)
When you use Migrelle you can record information about your migraines and headaches, such as:
- migraine/headache attacks (timing, duration, severity, head region, aura, pain type, symptoms);
- suspected triggers and contextual notes (including weather context such as pressure, temperature,
humidity, where you choose to record it);
- medications and supplements you take, and how much relief you felt;
- self-report questionnaire answers and scores (for example MIDAS and HIT-6);
- reminders you set;
- optional photos or notes you attach to an entry.
This is health data, which is a special category of personal data under Article 9 GDPR.
Because of that, Migrelle is designed so that we do not have access to it in readable form:
- It is created and stored on your device, under your control — like notes you keep in a local
app. For this on-device processing, you are the one handling your own health data.
- If you turn on backup/sync, it is end-to-end encrypted on your device before it leaves (see
Section 4). Our servers hold only ciphertext we cannot read — we hold no key and cannot decrypt
it. We therefore do not process the readable content of your health data as a controller.
Because we do not read or use your health content, we do not ask you for, or rely on, a separate
Article 9 "explicit consent" to process it — that would misdescribe what actually happens. Instead
we give you this clear, up-front information (Article 13 transparency) so you understand exactly how
the app handles your data before you record anything. The limited, non-content metadata our
server does see when you sync is disclosed in Section 2.4, and the legal bases for the processing we
do carry out are in Section 3.
Where this data lives: primarily in a local database on your device. It is sent to our servers
only if you turn on backup/sync, and only in encrypted, unreadable form.
2.2 Account data
If you create an account (optional, only needed for backup/sync), we process:
- your email address, used to authenticate you and to secure and recover access to your account;
- (depending on the sign-in method you choose) a passkey/credential.
2.3 Subscription data
Migrelle is freemium. If you subscribe, your purchase is processed by Apple or Google
through their app stores — we never receive or store your card or payment details. Through our
subscription provider (RevenueCat) we receive your entitlement status (e.g. whether you have
an active trial or subscription, the product, and renewal/expiry dates) so the app can unlock
premium features. This is linked to a subscription identifier, not to your migraine data.
2.4 Sync metadata (please read — honest disclosure)
Even though the content of your health records is encrypted and unreadable to us, the act of
syncing exposes a small amount of metadata to our server for each encrypted record:
- the record type (for example "log entry", "medication", or "profile"),
- timestamps (when a record was created, updated, or deleted).
This means our server can see that an encrypted record of a certain type exists and when you
add, change or delete records — i.e. the cadence of your activity — but **not what the record
says.** We consider this a deliberate, disclosed trade-off of offering encrypted sync. We bind each
encrypted blob cryptographically to its record identity so a record cannot be silently swapped, and
we keep each app in a separate EU database to avoid combining signals across conditions. We do
not use this metadata to profile you or for advertising.
2.5 Product analytics (optional, opt-in, off by default)
To understand how the app is used and to improve it, we can collect first-party product
analytics — for example onboarding steps completed, screens viewed, paywall views, and subscription
events. This is off by default: the analytics tool is not started at all until you turn it
on, and we only ask you after you have been through onboarding. If you do opt in, these analytics:
- contain only product-usage mechanics — never your health content (no attack logs, symptom
values, scores, or notes are ever sent to analytics);
- do not use advertising identifiers (no IDFA/Ad ID) or third-party advertising/attribution SDKs;
- are not sent to Google Analytics, Firebase Analytics, or any third-party analytics company;
- use no stable identifier linking your usage to you or to your health status: the device
identifier and profile identifier the analytics library would otherwise generate are **cleared as
soon as it starts**, so events are not tied together into a per-user profile. The only device
information that travels with each request is a technical User-Agent header containing your
coarse device model and operating-system version (as any web request carries) — this is **not a
unique identifier and is not used to track you**.
You turn these analytics on (and off again) at any time in Settings → Privacy. Unlike a typical
hosted analytics service, we run our own self-hosted instance of OpenPanel on **infrastructure we
control within the EU (a data centre in Germany): your usage events are processed and stored on
our own servers in the EU and are not shared with any third-party analytics company**. Retention is
short and data is held in aggregate.
2.6 Crash and diagnostic data
To keep the app working and fix bugs, we run a **self-hosted crash/error reporter (GlitchTip, which
speaks the Sentry protocol) on infrastructure we control in the EU. This runs by default**
because a broken app can't be a safe health tool — our legal basis is legitimate interest
(Section 3), not consent — but you can object to it at any time in Settings → Privacy, which
stops it immediately. Crash/error reports carry only the error and its technical stack trace,
are scrubbed of personal and health data (navigation, logs and screenshots are stripped, and no
device/user identifiers are attached), and it is configured not to persist a device identifier.
We also offer an in-app feedback tool (Wiredash). It is not active unless you open it from
Settings → "Report a problem" — it is loaded only when you tap that row, so nothing is collected
or sent until you choose to write and submit feedback. Feedback is likewise scrubbed of health data
before it reaches us.
2.7 Anything sensitive we want to do later requires your explicit opt-in
Any feature that would need our servers to read your data (for example optional server-side AI
narration) is off unless you explicitly turn it on, and would run only on a minimized,
de-identified, temporary slice of data. We will never do this silently, and this policy will be
updated before any such feature ships.
3. Legal bases (GDPR)
| What we process | Legal basis |
|---|---|
| Providing the core app and storing/syncing your encrypted data (ciphertext + sync metadata) | Performance of a contract (Art. 6(1)(b)) — our Terms with you |
| The content of your health data (special category) | By design we do not process it in readable form as a controller: it stays on your device under your control, and any backup is end-to-end encrypted so we hold only ciphertext we cannot read. In our view we therefore do not process the readable content as a controller and do not rely on Art. 9(2)(a) explicit consent for content we cannot access; the instrument is transparency (Art. 13). If a supervisory authority considered Art. 9 engaged by our storage of your encrypted blobs, the encryption in Section 4 is the safeguard, and the point at which you affirmatively choose to send that encrypted data to us is your opt-in to backup — not a bundled onboarding consent |
| Managing your account and authentication | Performance of a contract (Art. 6(1)(b)) |
| Subscriptions and entitlements | Performance of a contract (Art. 6(1)(b)) |
| First-party product analytics | Your consent (Art. 6(1)(a)) — off by default, collected only if you opt in, withdrawable at any time in Settings |
| Crash / error diagnostics | Legitimate interests (Art. 6(1)(f)) in app stability and security, with no health content and no persistent identifier; you can object (Art. 21) at any time in Settings |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
We apply data minimization: we collect only what we need, and we keep health content
unreadable to us by design.
4. How your data is protected: end-to-end encryption (zero-knowledge)
This is the most important part of how Migrelle works, so we explain it plainly.
- Encryption happens on your device. Your migraine and health data is encrypted on your phone
using strong encryption (AES-GCM-256) before any of it is sent to our servers for backup.
- We store only ciphertext. Our servers (provided by Supabase, hosted in the EU) store
the encrypted blobs. We do not hold the key and cannot decrypt or read your health content.
This is what "zero-knowledge" means.
- Where the key lives. Your encryption key is stored in your device's secure hardware keychain
(Apple Secure Enclave / Android Keystore). It can sync to your other devices through the platform's
own end-to-end-encrypted keychain (e.g. iCloud Keychain or the Android equivalent).
- Your recovery code. When you create an account we give you a one-time recovery code that
wraps your key, as a backup way to regain access.
The trade-off you must understand (data-loss risk)
Because only you control the key, nobody else — including us — can reset it. If you **lose
access to all of your devices AND lose your recovery code, your encrypted backup cannot be
recovered.** We will not be able to restore it for you. This is the unavoidable cost of true
zero-knowledge encryption, and we want you to know it clearly:
**Save your recovery code somewhere safe. If you lose all your devices and your recovery code,
your backed-up data is permanently unrecoverable.**
Data that is only on your device (no account/backup) follows the same logic: if you lose or wipe the
device with no backup, that local data is gone.
Other safeguards: reminders are delivered as local notifications and **push notifications never
contain health content**; access to our infrastructure is restricted and logged; we keep each app in
a separate EU project.
No method of storage or transmission is 100% secure, but zero-knowledge encryption means that even a
breach of our servers would expose only unreadable ciphertext, not your health content.
5. Who we share data with (processors and recipients)
We do not sell your personal data, and we do not share it with advertisers. We use a small
number of service providers ("processors") who act on our instructions:
| Provider | Purpose | What they can access |
|---|---|---|
| Supabase (EU region) | Account authentication and encrypted backup/sync storage | Your email (auth) and encrypted, unreadable health blobs + the sync metadata in Section 2.4 |
| RevenueCat | Subscription/entitlement management | Subscription/entitlement status tied to a subscription identifier — no health data |
| Apple App Store / Google Play | Processing your subscription payment | Your payment details (handled entirely by them; we never see your card data) |
| Our own self-hosted analytics (OpenPanel) — hosted in the EU (Germany) on infrastructure we control | First-party product analytics (opt-in, off by default) | First-party usage events on infrastructure we control — no health content, no ad identifiers, no third-party analytics company involved |
| Our own self-hosted crash reporter (GlitchTip) — EU infrastructure we control | Crash / error diagnostics (on by default, legitimate interest; you can object) | Scrubbed error + stack trace — no health content, no persistent device identifier |
| Wiredash | In-app feedback (loaded only when you open it) | Feedback you choose to send, technical metadata — no health content |
We may also disclose data if legally required (e.g. a valid court order) — but for your health
content this would only ever be unreadable ciphertext, because we do not hold your key.
Apple and Google process your purchases under their own privacy policies; please review them.
6. International data transfers
Your account data and encrypted backups are hosted in the European Union (Supabase EU region),
and our self-hosted product analytics (OpenPanel) run on EU infrastructure — so your usage
analytics stay in the EU and are not sent to a third-party analytics company abroad. We design
Migrelle so that no health data is transferred or stored outside the EU/EEA.
Some providers (for example app-store billing, or a non-EU crash tool if we use one)
may process limited data outside the EEA. Where that happens, the transfer is protected by an
appropriate safeguard such as the EU Standard Contractual Clauses or an adequacy mechanism (e.g. the
EU–US Data Privacy Framework). If our processor list changes in a way that affects transfers, we will
update this policy. (Confirm the final processor list with your lawyer.)
7. How long we keep your data
- On-device data: kept until you delete it or uninstall the app.
- Encrypted backups: kept while your account is active, so you can restore and sync. Deleted
records are removed from the backup as part of sync; deleting your account removes your backups.
- Account/email: kept while your account exists.
- Subscription records: kept as required for billing, tax and accounting obligations.
- Anonymous analytics: kept only for a short period in aggregate form.
When you delete your account, we delete your account data and encrypted backups from our active
systems within a reasonable period, except where we must keep limited records to meet a legal
obligation (e.g. proof of a transaction).
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase your data ("right to be forgotten");
- Port your data — receive it in a structured, machine-readable format;
- Restrict or object to certain processing;
- Withdraw consent at any time (this doesn't affect processing done before withdrawal).
How to exercise them:
- Export your data and delete your account/data directly in the app:
Settings → Privacy → Export data and Settings → Account → Delete account. In-app deletion
removes your encrypted backups from our servers.
- Control telemetry in Settings → Privacy: turn product analytics on or off (it is off
until you opt in), and object to crash diagnostics (turn it off). Your health data itself
lives on your device — you can delete it (and any encrypted backup) at any time via the deletion
options above; there is no separate server-side health-data processing to "withdraw".
- For anything else, email contact@migrelle.app and we will respond within the time the law requires
(normally one month).
Note: because of zero-knowledge encryption, an "access/export" request is fulfilled **on your
device**, where your data is readable. We cannot export your health content from our servers because
we cannot decrypt it.
You also have the right to lodge a complaint with a supervisory authority. In Poland this is the
President of the Personal Data Protection Office (UODO), or the authority in your EU country of
residence.
9. Children
Migrelle is not intended for children. You must be at least 16 years old to use the app and
to create an account, consistent with Poland's GDPR Art. 8 digital-consent age. We do not knowingly
collect data from anyone under that age; if we learn that we have, we will delete it.
10. Changes to this policy
We may update this policy as the app evolves or the law changes. We will update the "Last updated"
date and, for material changes (especially anything affecting your health data or a new processing
purpose), we will notify you in the app and, where required, ask for renewed consent before the change
takes effect.
11. Contact
Questions, requests, or complaints:
Limit Waste Sp. z o.o. — contact@migrelle.app — ul. Grzybowska 87, 00-844 Warszawa, Poland (EU)