MigraineNest / Legal

Privacy Policy

Last updated: September 29, 2026

Migraine records can be sensitive. This policy separates information submitted through the website from information kept by the iOS app. Using the app to create a record does not, by itself, send that record to Julian Ma.

MigraineNest is operated by Julian Ma, an individual. Privacy requests: julianma.builds@gmail.com.

1. Scope and purpose

This policy describes the MigraineNest website, its early-access and feedback forms, and the iOS app when available. We use information to run those experiences, respond to messages, understand website usage, provide requested app features, and manage purchases. The website does not need access to your in-app migraine records to place you on the waitlist.

2. Website forms and messages

If you join the early-access list, we receive the email address you submit. If you use the feedback form or email us, we receive the contact details and message content you choose to provide. Feedback may contain health information if you put it there; please avoid including medical details you do not want to share through a website form.

Website forms are processed and stored through Netlify Forms. We use waitlist information to contact you about MigraineNest and feedback to read and, where appropriate, respond to your message. The feedback link inside the iOS app opens a separate Tally form; information you submit there is handled through Tally. We do not use form contents as app health records. You can ask us to remove a submission using the contact address above.

3. Website analytics

The waitlist page uses PostHog to count selected interactions, such as page visits, sections viewed, demo controls, and form success or failure. Its current configuration is cookieless, disables session recordings, automatic capture and person profiles, and respects Do Not Track. Events may include the page path, referring domain, campaign tags, and broad device class. We do not intentionally send form answers or app health-record content in analytics events.

Hosting and analytics providers may receive technical connection information such as an IP address as part of delivering the page or an event, even when analytics cookies are not used. The Terms and Privacy pages do not load the website analytics script.

The iOS app has a separate, optional usage-analytics setting. It is off unless you agree. In a build configured to upload analytics, selected events are sent to PostHog and may include the screen or action, event time, a pseudonymous app-install identifier and session identifier, broad device and locale information, subscription state, and whether a migraine is being tracked. Using a migraine feature can itself reveal health-related activity even when the event contains no record content. The current event contract is designed not to send note text, symptom or medicine details, voice audio, or report contents. You can withdraw consent in Settings > Privacy, which stops future app-analytics collection and clears unsent local events. To ask about data already sent, contact us; identifying a pseudonymous event and fulfilling a deletion request may depend on information available to us and the provider.

4. Information in the iOS app

Records may include attack dates, symptoms, aura, pain location and intensity, medicines, factors, notes, and related summaries. The current app implementation stores records and generated summary data in the app's device storage. Quick Note speech input creates editable text; it does not by itself add a saved audio recording to the record. Separately, if you choose to save a Voice Note, its audio file is stored in the app's device storage. PDFs generated for sharing may be placed temporarily on the device; copies you save or send elsewhere are controlled by the destination you choose.

MigraineNest does not currently operate its own cloud sync for these health records. This is not a promise that data can never leave the device: Apple device or iCloud backups may include app data according to your device settings, and you can choose to export or share it. Deleting one record does not necessarily remove previous exports, temporary files, older report snapshots, backups, or recipient copies.

5. Voice input and AI-assisted features

Quick Note can turn speech into text using Apple's Speech framework. The app does not require on-device-only speech recognition, so audio may be processed by Apple rather than solely on your device. If you deny speech permission, transcription does not proceed. This speech-recognition step is separate from saving a Voice Note or extracting record events from text. Apple's handling is described in Apple's privacy information.

Quick Note event extraction starts with local parsing rules and, on supported devices, can use Apple's Foundation Models integration to suggest structured entries for your review. The current app does not configure a separate developer-operated remote language-model endpoint for Quick Note. We do not use your health records for our own model training. If a future version adds remote AI processing, this policy and any required in-app notice will be updated before that processing is introduced.

6. Purchases, videos, and other providers

Apple processes App Store purchases and payment-card details. The app reads verified StoreKit subscription status, product ID and relevant transaction dates to grant Plus access; it does not operate a purchase-verification server in the current implementation. Restoring a purchase checks entitlement, not health records.

If you choose to connect Apple Health, the app requests permission to read sleep information for optional context. If you enable location for current weather context, the app sends latitude and longitude rounded to two decimal places to Open-Meteo to obtain weather and pressure information. Open-Meteo may also receive ordinary connection information, including your IP address. The weather request does not include your migraine entries. See Open-Meteo's Terms & Privacy.

When you open an embedded Relief video, the app loads YouTube services; opening it in YouTube connects to YouTube directly. YouTube may receive ordinary connection and browser information. The current video links do not append your migraine entries to the URL. See Google's Privacy Policy for its practices.

Website hosting and forms use Netlify; the in-app feedback form uses Tally; website analytics and optional, consented app analytics use PostHog. Their processing may occur outside your country of residence. We may also disclose information when required by law or to protect the service and its users. We do not sell personal information or use health-record content for targeted advertising.

7. Storage, deletion, and security

Website submissions are kept while needed to manage the waitlist, respond to feedback, or meet applicable obligations, then removed. You can request deletion of a website submission by email. On-device records remain until you delete them in the app or remove app data. App exports, device backups, and copies sent to others have separate retention controlled by the relevant service or recipient.

We use the protection available in the app and our service providers, but no storage or transfer method can be guaranteed completely secure. We cannot retrieve or delete data that has never been sent to us, such as a local record or a copy held by a recipient.

8. Your choices and rights

You may choose not to submit a website or in-app feedback form, not to use speech input or save a Voice Note, not to connect Apple Health or allow location, not to open an external video, and not to export a report. You can withdraw optional app-analytics consent in Settings > Privacy. You can view, edit, and delete individual app records without Plus. Device settings control some permissions and backup behavior.

Depending on your location, you may have rights to request access, correction, or deletion of information we hold about you. Email us with enough information to identify the relevant website submission; we may need to verify your request. We cannot provide access to app records that remain only on your device. The service is not directed to children; if you believe a child has sent us information, please contact us.

9. Updates and contact

We will update this page when our practices materially change and revise the date above. If a change requires additional notice or consent under applicable law, we will provide it.

For privacy questions or requests, email julianma.builds@gmail.com.