Privacy Policy
Version 2026-08-v3 · Effective 13 August 2026
1. Who's responsible for this data
The controller under the EU General Data Protection Regulation (GDPR) is:
Sintija Birgele
Henriette-Lustig-Straße 14
12555 Berlin, Germany
Questions about this policy or your data can be sent to the contact address in the footer of every page.
2. What we collect
- Account data: email address, hashed password, name, gender.
- Health data you enter: migraine/headache entries, symptoms, intensity, medication and supplement logs, menstrual cycle data, sexual-activity logging (18+ only), sleep, stress, exercise, and any notes you write. This is special category health data under GDPR Article 9 and is treated accordingly — see Sections 3–4.
- Optional uploads: if you use Conversation Analysis or Cost Statement, the file you choose to upload is processed to extract the specific information you apply to your diary (see Terms, Section 8).
- Technical data: session cookie, IP address and basic request logs for security and abuse prevention.
3. Why, and on what legal basis
- To provide the diary itself — performance of our contract with you (Art. 6(1)(b) GDPR).
- To process the health data you enter — your explicit consent (Art. 9(2)(a) GDPR), given when you complete onboarding and each time you choose to log a data point. You can withdraw this at any time by deleting your account or the specific entries.
- To keep the Service secure and working — our legitimate interest (Art. 6(1)(f) GDPR) in preventing abuse and maintaining reliability.
4. Reproductive & sensitive health data
Menstrual cycle, fertility-relevant, and sexual-activity data receive the same protection as the rest of your health data, plus these specific commitments: this data is never sold, never used for advertising or profiling, and never shared with data brokers, marketing platforms, or analytics networks, under any circumstance.
If we ever receive a legal request (subpoena, court order, or similar) for this data, our policy is to notify the affected user before disclosing anything, unless we are legally prohibited from doing so, and to disclose only what the request legally compels — never more.
6. International transfers
We aim to process and store data within the EU/EEA. Where a sub-processor is or becomes located outside the EU/EEA, we rely on the EU Standard Contractual Clauses, an adequacy decision, or another safeguard recognized under GDPR Chapter V before any such transfer takes place.
7. How long we keep it
We keep your data for as long as your account is active. If you delete your account, your diary data and account details are deleted within 30 days, except where we're legally required to retain limited records for longer (e.g. basic billing records, if applicable).
8. Data protection by design
We apply data protection by design and by default (Art. 25 GDPR) — for example, Conversation Analysis parsing in your browser rather than on our server, and strict access controls limiting who can see your data to you alone. As usage grows, we assess whether our processing meets the threshold for a formal Data Protection Impact Assessment under Art. 35 GDPR (broadly, large-scale special-category processing) and will conduct one before that threshold is reached, not after.
9. Breach notification
If a security incident results in unauthorized access to or disclosure of your data, we will notify the relevant supervisory authority within 72 hours where required under Art. 33 GDPR, and notify affected users without undue delay where the incident is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR) — a commitment we apply to every user regardless of where they access the Service from, consistent with breach-notification obligations that exist for health-record vendors under other legal frameworks (e.g. the U.S. FTC Health Breach Notification Rule).
11. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Request erasure ("right to be forgotten");
- Export your data in a portable format;
- Restrict or object to certain processing;
- Withdraw consent at any time, without affecting processing already carried out;
- Lodge a complaint with a supervisory authority — for Berlin-based accounts, the Berliner Beauftragte für Datenschutz und Informationsfreiheit, or your own country's data protection authority.
12. Age restrictions
The Service is not directed at children under 16. Certain optional features are additionally restricted to users 18 and older based on the birth date on file, and are not shown at all below that age — see Terms, Section 4.
13. Changes to this policy
We may update this policy as the Service evolves. Material changes will be announced in-app before they take effect.
This document is a plain-language, good-faith draft and not a substitute for review by qualified legal counsel. See also our Terms & Conditions.