Privacy Policy
Effective date: August 1, 2026
This Privacy Policy describes how Migsy ("we", "us", or "our") collects, uses, and protects information when you use the Migsy mobile application and related services. By using Migsy, you agree to this policy.
Who we are
Migsy is a migraine tracking and wellness app. Contact for privacy questions: support@migsy.app.
Information we collect
Account information
- Email address and authentication credentials when you sign up or sign in
- If you use Sign in with Apple on iOS, we receive the identifiers and profile details Apple provides for authentication
Health and wellness data you provide
- Migraine attack logs, including severity, timing, symptoms, and medications taken
- Date of birth and onboarding profile details you provide, including sex-related education preferences
- Pain location selections on the in-app head map
- Medication lists and doctor report exports you generate in the app
Your exact date of birth is stored in your Migsy product profile using Supabase. Migsy uses it to personalize the product and determine an age range. The exact date is not sent to product analytics.
Location information
With your permission, Migsy may access coarse or fine location to show local barometric pressure and related environmental context. You can deny or revoke location access in your device settings at any time.
Usage and technical data
- App interactions and feature usage collected through PostHog in production builds
- Device type, app version, and diagnostic information needed to operate and improve the service
- Approximate market-level location inferred from the network address used to send analytics events
- Subscription and purchase status processed through RevenueCat and the Apple App Store or Google Play
Optional health-related product analytics
If you explicitly choose to share health analytics, Migsy sends a limited, pseudonymous dataset to PostHog so we can analyze product usage at scale. It may include:
- Broad categories such as sex, age range, migraine attack frequency, onboarding goal, and prior app experience
- Attack, recovery, aura, prodrome, cycle-question, forecast-risk, medication-category, statistics, and doctor-report feature events
- Counts and broad categories associated with those events, plus their event timestamps
This analytics dataset is linked to a pseudonymous Migsy user identifier. We do not send your name, email address, exact age or date of birth, free-text notes, exact location, medication names, or full attack records to PostHog. Health analytics are not used for advertising and are not required to use Migsy. Migsy does not enable health analytics for users whose provided date of birth indicates they are under 18.
How we use information
- Provide and personalize migraine tracking, guidance, history, statistics, forecasts, and related app features
- Authenticate your account and keep your data synced across sessions
- Process subscriptions and restore purchases
- Improve reliability, security, and product experience
- With your consent, understand aggregate health patterns and how well Migsy features serve different groups
- Respond to support requests
What Migsy is not
Migsy is for personal wellness tracking and education. It does not provide medical diagnosis, treatment, or emergency services. Risk estimates and patterns are informational only and are not a substitute for professional medical advice.
How we store and protect data
Account and app data are stored using Supabase and related cloud infrastructure with industry-standard safeguards. Data is encrypted in transit. We limit access to systems that need it to operate the service.
Third-party services
- Supabase — authentication and database hosting
- RevenueCat — subscription management and purchase validation
- Apple / Google — in-app purchases and platform sign-in where applicable
- PostHog — pseudonymous product analytics, including optional health-related analytics when you consent
- Sentry — scrubbed crash and reliability diagnostics
These providers process data according to their own privacy policies and our agreements with them.
Data retention and deletion
We retain your information while your account is active and as needed to provide the service. You may request account deletion through the in-app flow where available, or by contacting us at the email above.
Your choices
- Manage location permissions in device settings
- Grant or withdraw optional health analytics consent at any time in Migsy Settings
- Manage subscription renewal or cancellation through the App Store or Google Play
- Request access, correction, or deletion of your data by contacting us
Withdrawing health analytics consent stops future health-related analytics and removes the health categories from your PostHog person profile. Events collected while consent was active may be retained for up to 84 months unless you delete your account or request deletion. Non-health product analytics remain enabled in production builds. Account deletion removes the associated PostHog and RevenueCat records before your Migsy identity is removed.
Children
Migsy is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
International users
Your information may be processed in countries where our service providers operate, including PostHog infrastructure in the United States. Where required, we rely on contractual and other appropriate safeguards for international transfers.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date above.
Contact
Questions about this Privacy Policy: support@migsy.app