Privacy Policy

Last updated June 2026

Your health data is yours. We are committed to being transparent about what we collect, why we collect it, and how you can control it.

Who we are

Signals: Migraine Insights (“Signals”, “we”, “us”, or “our”) is an independent mobile application designed to help individuals track migraine and headache attacks, identify patterns, and communicate more effectively with their healthcare providers.

For privacy-related questions, contact us at:
support@migraine-signals.com

What Data We Collect

  • Account Information: Your name, email address, and password (stored securely via Supabase Auth). If you sign in with Google, we receive your name and email from Google.
  • Health & Attack Logs: Attack type (migraine or headache), headache subtype (tension/cluster where applicable), severity, duration, pain location, triggers, symptoms, medications and dosages, medication effectiveness, and personal notes you choose to enter.
  • Sleep Quality Logs: Nightly sleep quality ratings (1–5 scale), estimated hours slept, and optional notes you log within the app.
  • Assessment Scores: HIT-6 and MIDAS questionnaire responses and scores, used to personalise your experience and generate doctor reports.
  • Profile & Preferences: Your display name and avatar, default triggers, symptoms, and medications, notification preferences (reminders, alerts, summary frequency), and app settings.
  • Guided Setup Profile: Information you provide during initial setup: how long you have had migraines, baseline attack frequency, typical duration and severity, known triggers, and whether you experience aura.
  • Appointment Data: Healthcare appointments you add, including dates, provider names, location, notes, and recurrence settings.
  • Subscription & Billing: Subscription status, plan type, and renewal date. Payment processing is handled entirely by Stripe — we do not store your card details. We store a Stripe customer ID and subscription ID to manage your account.
  • Usage Counters: A running count of how many attack logs you have submitted and how many CSV imports you have completed. These counters are used to enforce free-tier limits and are never reset by deleting logs.

How We Use Your Data

  • To provide the app: Storing and displaying your logs, generating insights, and powering all app features.
  • To personalise your experience: Pre-filling log defaults, generating AI-powered pattern analysis (Premium), and tailoring dashboard content to your history.
  • To generate reports: Creating PDF doctor reports and CSV exports that you can share with your healthcare team.
  • To send notifications: Log reminders, weekly summaries, and assessment reminders — only if you enable them in Preferences.
  • To process payments: Managing your Premium subscription via Stripe.
  • To improve the app: Anonymised, aggregated usage data helps us understand which features are most useful and where to focus improvements.

Data Storage & Security

Your data is stored securely using Supabase, which provides:

  • Encryption in transit (TLS/HTTPS) for all data sent between your device and our servers.
  • Encryption at rest for all stored data.
  • Row-level security policies ensuring your data is only accessible to your own account.
We do not store your data on your device beyond what is necessary for the app to function. We do not use third-party advertising networks or sell your data to any third party.

Data Sharing

We do not sell, rent, or share your personal health data with third parties for marketing purposes. Data may be shared only in the following limited circumstances:

  • Stripe: For payment processing. Stripe’s privacy policy applies to payment data.
  • Supabase: As our database and authentication provider. Data is processed under their data processing agreement.
  • Google (if applicable): If you use Google Sign-In, Google’s privacy policy applies to that authentication flow.
  • Legal requirements: If required by law, court order, or to protect the rights and safety of users.

Your Rights & Controls

  • Access your data: Export all your attack logs as a CSV file from Preferences at any time.
  • Correct your data: Edit any log, profile detail, or preference within the app.
  • Delete your data: Delete your account and all associated data permanently from Settings → Delete Account. This action is irreversible.
  • Control notifications: Enable or disable all notification types individually in Preferences.
  • Portability: Export your data as CSV at any time. Premium users can also generate PDF reports.

Health Data Disclaimer

Signals is a personal tracking and journaling tool. It is not a medical device and does not provide medical advice, diagnosis, or treatment recommendations. The information you log and the patterns the app surfaces are intended to support conversations with your healthcare provider — not to replace professional medical judgement.

Always consult a qualified healthcare professional for medical advice.

Children’s Privacy

Signals is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at support@migraine-signals.com and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will notify you within the app. The “Last updated” date at the top of this policy reflects the most recent revision. Continued use of Signals after changes are posted constitutes your acceptance of the updated policy.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Email: support@migraine-signals.com

We aim to respond to all privacy-related enquiries within 5 business days.