Privacy Policy

Last updated: May 25, 2026

MigraCue ("we", "our", "the app") is a migraine and headache tracking app developed by Mahmoud Shaaban. Your health information is sensitive, and protecting it is central to how the app is built. This policy explains what data the app handles, where it is stored, and your choices.

The short version: Your migraine history lives on your device and in your own private iCloud account. We do not run a server that stores your health data, and we have no account system. We use no advertising and no cross-app tracking. We do use one privacy-respecting analytics tool to measure anonymous app usage — never your health data — and you can turn it off in Settings.

1. Data You Provide

2. How Your Data Is Stored

On your device (default): All entries are stored locally using Apple's SwiftData framework, protected by iOS Data Protection (complete file protection).

Private iCloud sync: Your data syncs across your own devices through Apple's CloudKit private database, tied to your Apple ID. This is an extension of your devices — it is encrypted and managed by Apple, and the developer has no access to it.

We do not operate a server that stores your migraine history, and there is no sign-up, email, or password.

3. Apple Health (HealthKit)

If you grant permission, the app reads health metrics — such as sleep, heart rate variability, heart rate, activity, and (optionally) menstrual cycle data — to help you spot patterns related to your migraines. With your permission it can also save headache events back to the Health app.

Health data is read and processed on your device. It is never sold, never used for advertising or marketing, and is not transmitted to our servers.

4. Location & Weather

If you enable it, the app uses your approximate location to look up local weather and barometric pressure through Apple's WeatherKit, so it can help you correlate pressure changes with your migraines. Location is used for this lookup and is not stored on our servers.

5. AI Insights (Optional)

When you choose to run AI trigger analysis or a risk estimate, a minimized, de-identified summary of relevant entries (dates, intensity, triggers, symptoms, weather, and sleep values) is sent over an encrypted connection (TLS) to our secure processing function, hosted on Supabase (AWS infrastructure), which forwards it to Google Gemini for analysis.

6. In-App Purchases

Subscriptions are processed by Apple's App Store and managed through RevenueCat. We never receive your payment details. RevenueCat receives a pseudonymous app user ID to manage your subscription status. See RevenueCat's Privacy Policy.

7. Analytics & Tracking

To understand how the app is used and to improve it, we use Mixpanel, a product-analytics service, to collect anonymous usage data — such as which screens are opened, which features are used, and how the onboarding and subscription flows progress — together with an anonymous device identifier and basic technical details (app version, platform, device language).

This analytics data never includes your health information: your migraine entries, intensity, headache type, symptoms, triggers, notes, sleep, weather readings, or medication names and dosages are never sent to Mixpanel. It is not linked to your identity, is not used for advertising, and is never sold.

You can turn analytics off at any time in Settings → Privacy → "Share Anonymous Usage Data." When turned off, no usage events are collected or sent. The app contains no advertising SDKs and no cross-app tracking, and we do not build advertising profiles.

8. Third-Party Services

9. Data Retention & Your Rights

Your data remains until you remove it. From Settings → Delete All Data you can permanently erase every entry from this device and from your private iCloud copy. You can also generate a doctor-ready PDF report of your data at any time. Deleting the app removes its local data.

10. Children's Privacy

MigraCue is not directed at children under 13, and we do not knowingly collect data from children.

11. Medical Disclaimer

MigraCue is a wellness and informational tool. It is not a medical device and does not diagnose, treat, cure, or prevent any condition. Always consult a qualified healthcare professional about your health.

12. Changes to This Policy

We may update this policy from time to time. The "Last updated" date above reflects the latest revision.

13. Contact

Questions about your privacy? Contact us at support@sheboftek.com.