Privacy policy
In short
Your attacks, your medications and your health data are recorded in a local database, on your phone. Nagi has no server and asks for no account: the publisher has no technical access to your history. The app contacts two outside services — the weather and subscription management — and a usage measurement tool installed on the publisher's own server; none of them receives any health data. You can export everything or erase everything in two taps, without asking us.
Who processes your data
The data controller is Timothé Duc, a natural person, publisher of the Nagi app.
- Publisher and data controller: Timothé Duc, sole trader (entrepreneur individuel under French law) — SIREN 829 368 166
- Address: 358 Les Grands Champs, 07340 Limony, France
- Contact: timotheduc+nagi@gmail.com
- Site: nagimigraine.com
This policy applies to the Nagi mobile app — iOS, then Android when it is released — and to the site nagimigraine.com. It is published in French and in English, in two equivalent versions.
The principle: everything stays on your phone
Nagi is built to work without the publisher ever seeing your data. That is not a marketing promise, it is an architectural constraint:
- The information you enter is written to a local database (SQLite) stored in the app's private space, on your device.
- No account is created. No email address, no name and no phone number is asked for in order to use the app.
- There is no Nagi server that could receive your attack history: the publisher has no technical access to it and therefore cannot read it, pass it on or sell it.
- By default, the database file is explicitly excluded from your iPhone's iCloud backup. It does not leave the device until you turn the corresponding option on.
- The app works entirely offline: recording an attack, completing it and generating a report need no network at all.
What the app records
Every category below is stored on your device only.
| Category | What it contains |
|---|---|
| Attacks | Start and end date and time, intensity from 1 to 10, location of the pain, presence of aura, symptoms, triggers you suspect, free-text notes. |
| Medications | Name of the medication, type (acute or preventive), dosage, timestamps of doses and the relief score you give them. |
| Daily context | Barometric pressure and its 24-hour change, temperature, humidity, sleep duration, heart rate variability, resting heart rate, cycle day and period dates if you enter them. |
| Migraine profile | The answers you give during onboarding: usual frequency, typical symptoms, current medications, suspected triggers. |
| Settings | Display preferences, reminder times, the state of your consents, whether the iCloud backup is on, and the area used for the weather: your location rounded to the kilometre or the city you picked. |
No field is required beyond the time and the intensity of an attack. You can keep a useful diary while filling in nothing else.
Health data, Apple Health and Health Connect
If you explicitly allow it, Nagi reads certain data from the health app on your phone — Apple Health (HealthKit) on iPhone, Health Connect on Android — to save you entering it by hand:
- Sleep duration and quality
- Heart rate variability (HRV) and resting heart rate
- Menstrual cycle, if you track it in your health app
- Noise exposure and daylight, on iPhone only: these two measurements do not exist in Health Connect
This data is read on demand, used on your phone only to compute your correlations and flag the days to watch, and is never passed on to the publisher or to any third-party service. Nagi has no server that could receive it: the tables holding it have no network path anywhere in the code. It is declared as “not collected” in the App Store privacy labels and in the Google Play Data safety section.
It is neither sold, nor used for advertising, nor used to train a model. No data read from Apple Health or Health Connect is shared with any third party whatsoever.
What Nagi keeps from these readings stays in its local database, described in the “Retention periods” section: deleting your data from the “My data” screen, or uninstalling the app, erases it from the device. That does not touch what remains in Apple Health or Health Connect, which is yours and is managed from those apps.
In the other direction, Nagi can write one thing only: the period dates you enter in the app, if you allow it, so that your cycle tracking stays complete. Nothing else is ever written there — no attack, no medication, no note.
You can withdraw this permission at any time, without losing the use of the app:
- on iPhone, from Settings › Privacy & Security › Health;
- on Android, from the Health Connect app › App permissions › Nagi.
The app then keeps working entirely on manual entry: no feature is blocked, only the correlations that rely on this data stop being computed.
iCloud backup and Google backup
The backup option — “iCloud backup” on iPhone, “Google backup” on Android — is off by default. While it is off, the database is explicitly excluded from your phone's backup and never leaves the device.
If you turn it on, the database is brought back into your phone's encrypted backup, on your own Apple or Google account. That copy is a matter between you and Apple or Google: the publisher has no access to it and does not even know whether it exists. If you turn the option off, the exclusion is reapplied immediately, in the same action.
After you delete your data in the app, a copy may remain in your backup until your phone's next backup. That is a limitation of iOS and Android, not a choice made by the app, and the “My data” screen reminds you of it at the moment of deletion.
The outside services contacted
The app communicates with a small number of services. None of them receives any health data: the tables holding your attacks, your medications and your daily context have no network path anywhere in the code.
| Service | What is sent to it |
|---|---|
| Open-Meteo (Germany) |
Geographic coordinates rounded to the kilometre, to obtain the barometric pressure and the weather for your area, and, if you pick your city by hand, the name you type into the search box. No identifier, no health data, no history. Legal basis: performance of the service. |
| RevenueCat (United States) |
An anonymous installation identifier, the subscription events (trial start, purchase, renewal, cancellation) and the platform. Legal basis: performance of the contract. |
| App Store (Apple) |
Payment and billing are handled entirely by Apple. The publisher receives no bank details, no name and no address. On Android, Google Play will play the same role. |
| OpenPanel (the publisher's server, France) |
Anonymous usage events: screens opened, taps on the main actions, app version, platform. Never the content of an attack, a medication or a note. OpenPanel is open-source software installed by the publisher on his own server: no analytics provider receives these events. Legal basis: legitimate interest, with the right to object at any time. |
| Meta and TikTok (with your permission) |
Only if you allowed it: install, open, trial start, purchase and amount, to measure how well campaigns perform. No health data, no attack timestamp. Legal basis: consent. |
| OVH (host of the site, France) |
The site nagimigraine.com is served from an OVH server located in the European Union. That server keeps no access log. Legal basis: legitimate interest. |
| Cloudflare (relay for the site, United States) |
When you visit the site, your request passes through Cloudflare, which protects and speeds it up. Cloudflare sees your IP address and processes it for security and performance, under its own privacy policy. The app itself never goes through Cloudflare. Legal basis: legitimate interest. |
Advertising, usage measurement and consent
No measurement tool is started before you have made a choice. In practice:
- On the very first launch, a consent screen appears before onboarding. At that point, no third-party tool has been initialised.
- Advertising attribution (Meta, TikTok) goes through the iOS “App Tracking Transparency” prompt. If you decline, those tools are never started and the question is never asked again.
- Anonymous usage measurement is on by default. It uses no cookie and no persistent identifier — the technical identifier is a hash regenerated every day — does not keep your IP address and cannot be used to re-identify you. You can turn it off in Settings › My data, with immediate effect.
- The events describe the action, never its content: the app sends “attack recorded” with no properties at all — no intensity, no location, no symptom, no date.
- Declining degrades no feature, triggers no reminder and shows no wall. It is a stable state.
- The site nagimigraine.com uses the same usage measurement, with no cookie and no persistent identifier: it sets no tracker and therefore does not have to show a consent banner.
Notifications
The evening reminder and the “day to watch” alert are local notifications, scheduled by your phone from your own data. No push server is involved, and their content never leaves the device. You can turn them off in the app's settings or in those of iOS.
Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Keeping your attack diary and computing your correlations | Explicit consent to the processing of health data — Art. 6(1)(a) and 9(2)(a). The processing is exclusively local, on your device. |
| Managing your subscription and access to premium features | Performance of the contract — Art. 6(1)(b). |
| Measuring app usage anonymously | Legitimate interest — Art. 6(1)(f), with the right to object in Settings › My data. |
| Measuring how well advertising campaigns perform | Consent — Art. 6(1)(a), collected through the iOS prompt and withdrawable at any time. |
Retention periods
- The data you enter stays on your device for as long as the app is installed on it. Uninstalling it deletes the local database.
- Anonymous usage measurement events are kept for twelve months at most, then deleted.
- Subscription data is kept by Apple and RevenueCat for as long as their accounting and tax obligations require.
Your rights, and how to exercise them
Since the publisher has no access to your history, most of your rights are exercised directly in the app. It is faster, and it avoids having to send us data in order to have it deleted.
| Your right | How to exercise it |
|---|---|
| Access and portability | Settings › My data › Export. You get your whole database as CSV and JSON, without having to write to us. |
| Rectification | Every attack, every medication and every onboarding answer can be edited directly in the app, at any time. |
| Erasure | Settings › My data › Delete all my data. Deletion is immediate and final on the device. |
| Objection and withdrawal of consent | The switches in Settings › My data, with immediate effect and no consequence for the features. |
| Restriction | Write to us at timotheduc+nagi@gmail.com, setting out your request. |
For any question or complaint, write to timotheduc+nagi@gmail.com: you will get an answer within a month at the latest. You can also lodge a complaint with the French data protection authority, the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, 75007 Paris — cnil.fr.
Minors
The app is not intended for people under sixteen. No data is knowingly collected from a minor under sixteen without the permission of the holder of parental authority. If you notice that such a case has occurred, write to timotheduc+nagi@gmail.com.
Transfers outside the European Union
Open-Meteo is hosted in the European Union and the usage measurement (OpenPanel) runs on the publisher's server, in France. RevenueCat is established in the United States: the transfer relies on the standard contractual clauses adopted by the European Commission. No health data is involved in that transfer, which is limited to an anonymous installation identifier and to subscription events.
The site, for its part, is relayed by Cloudflare, a US company certified under the EU–US Data Privacy Framework: only your IP address, at the moment you visit a page, is involved. If you have allowed advertising attribution, Meta and TikTok receive the events described above under their own transfer safeguards.
Security
- The database is stored in the app's private space, protected by the device's encryption and the iOS sandbox.
- All network communication uses HTTPS.
- No table containing health data has a network path anywhere in the code. That property is checked before every release: with the network cut off, the app must remain fully functional, and outgoing traffic is inspected to make sure no health data crosses it.
Amendments to this policy
Any substantial change will be flagged in the app and the update date, at the top of this page, will be changed. Previous versions remain available on request at timotheduc+nagi@gmail.com.
Contact us
For any question about this policy or about the processing of your data:
- By email: timotheduc+nagi@gmail.com
- By post: Timothé Duc, 358 Les Grands Champs, 07340 Limony, France
- Supervisory authority: CNIL — 3 place de Fontenoy, 75007 Paris — cnil.fr
A question about your data?
Write to timotheduc+nagi@gmail.com — you will get an answer within a month at the latest.