Privacy Policy

Version 2026-08-v3 · Effective 13 August 2026

1. Who's responsible for this data

The controller under the EU General Data Protection Regulation (GDPR) is:

Sintija Birgele
Henriette-Lustig-Straße 14
12555 Berlin, Germany

Questions about this policy or your data can be sent to the contact address in the footer of every page.

2. What we collect

  • Account data: email address, hashed password, name, gender.
  • Health data you enter: migraine/headache entries, symptoms, intensity, medication and supplement logs, menstrual cycle data, sexual-activity logging (18+ only), sleep, stress, exercise, and any notes you write. This is special category health data under GDPR Article 9 and is treated accordingly — see Sections 3–4.
  • Optional uploads: if you use Conversation Analysis or Cost Statement, the file you choose to upload is processed to extract the specific information you apply to your diary (see Terms, Section 8).
  • Technical data: session cookie, IP address and basic request logs for security and abuse prevention.

3. Why, and on what legal basis

  • To provide the diary itself — performance of our contract with you (Art. 6(1)(b) GDPR).
  • To process the health data you enter — your explicit consent (Art. 9(2)(a) GDPR), given when you complete onboarding and each time you choose to log a data point. You can withdraw this at any time by deleting your account or the specific entries.
  • To keep the Service secure and working — our legitimate interest (Art. 6(1)(f) GDPR) in preventing abuse and maintaining reliability.

4. Reproductive & sensitive health data

Menstrual cycle, fertility-relevant, and sexual-activity data receive the same protection as the rest of your health data, plus these specific commitments: this data is never sold, never used for advertising or profiling, and never shared with data brokers, marketing platforms, or analytics networks, under any circumstance.

If we ever receive a legal request (subpoena, court order, or similar) for this data, our policy is to notify the affected user before disclosing anything, unless we are legally prohibited from doing so, and to disclose only what the request legally compels — never more.

5. Who we share it with

We don't sell your data or share it for advertising, and we don't hand health data to marketing, analytics, or ad-tracking platforms. It's shared only with infrastructure providers who process it on our behalf under a data-processing agreement — primarily our database hosting provider, used to store your account and diary data. Conversation Analysis parsing happens entirely in your browser and is never sent to us or anyone else.

If you connect Plaud voice sync, the text of a matched recording — with your name and email address removed from it before transmission — is sent to our AI processor (OpenRouter, routing to a language model), together with your own trigger, medication and supplement labels, for the single specified purpose of identifying which diary fields that recording describes. This processor does not receive your name, email address, or any other account-identifying information, does not use the data to train any model, and does not retain it beyond that single request; Migraine Today itself does not retain it beyond the review step. This processing occurs under the same data-processing agreement framework described above. Full mechanics are documented on the Plaud voice sync how-it-works page. No other feature sends health data to a third-party AI service.

6. International transfers

We aim to process and store data within the EU/EEA. Where a sub-processor is or becomes located outside the EU/EEA, we rely on the EU Standard Contractual Clauses, an adequacy decision, or another safeguard recognized under GDPR Chapter V before any such transfer takes place.

7. How long we keep it

We keep your data for as long as your account is active. If you delete your account, your diary data and account details are deleted within 30 days, except where we're legally required to retain limited records for longer (e.g. basic billing records, if applicable).

8. Data protection by design

We apply data protection by design and by default (Art. 25 GDPR) — for example, Conversation Analysis parsing in your browser rather than on our server, and strict access controls limiting who can see your data to you alone. As usage grows, we assess whether our processing meets the threshold for a formal Data Protection Impact Assessment under Art. 35 GDPR (broadly, large-scale special-category processing) and will conduct one before that threshold is reached, not after.

9. Breach notification

If a security incident results in unauthorized access to or disclosure of your data, we will notify the relevant supervisory authority within 72 hours where required under Art. 33 GDPR, and notify affected users without undue delay where the incident is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR) — a commitment we apply to every user regardless of where they access the Service from, consistent with breach-notification obligations that exist for health-record vendors under other legal frameworks (e.g. the U.S. FTC Health Breach Notification Rule).

10. Cookies

We do not use advertising or cross-site tracking cookies. Analytics cookies are opt-in only and are not set until consent is given. The table below lists every cookie in use. Consent is collected via the banner shown on your first visit and can be reviewed or withdrawn at any time from “Cookie preferences” in the footer.

NamePurposeCategoryDurationRequires consent?
md_sessionKeeps you logged in.Strictly necessary30 daysNo — TTDSG §25(2) no. 2
consent_analyticsRemembers your analytics choice, so we don't ask every visit.Strictly necessary1 yearNo — storing the preference itself is exempt
ph_…_posthog
+ equivalent local storage
Recognizes repeat visits and groups your usage events, via PostHog (EU-hosted). Session recording is disabled in code. Also covers client-side error/exception tracking — one consent choice for both.Analytics1 yearYes — set only after you accept

11. Your rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate data;
  • Request erasure ("right to be forgotten");
  • Export your data in a portable format;
  • Restrict or object to certain processing;
  • Withdraw consent at any time, without affecting processing already carried out;
  • Lodge a complaint with a supervisory authority — for Berlin-based accounts, the Berliner Beauftragte für Datenschutz und Informationsfreiheit, or your own country's data protection authority.

12. Age restrictions

The Service is not directed at children under 16. Certain optional features are additionally restricted to users 18 and older based on the birth date on file, and are not shown at all below that age — see Terms, Section 4.

13. Changes to this policy

We may update this policy as the Service evolves. Material changes will be announced in-app before they take effect.

This document is a plain-language, good-faith draft and not a substitute for review by qualified legal counsel. See also our Terms & Conditions.