Privacy Policy - Captain: Migraine Logbook
Effective date: September 25, 2026. Contact: captainlog@icloud.com.
Captain is a migraine diary for iPhone made by an individual developer. This policy explains what the app stores, what leaves your phone, and what we keep on our side. The short version: your diary stays on your iPhone; a voice note is processed once to fill in an entry and is not stored; we keep a small anonymised technical record about each request - no personal information and nothing you said, only what is needed to diagnose technical problems.
What stays on your phone
Everything you enter - attacks, symptoms, medicines, factors, clear-day marks, notes and settings - is stored only on your iPhone. There is no account, no sign-up and no cloud sync. We cannot see your diary.
Two small technical values are kept in your phone's secure storage: a random device identifier generated by the app and a counter of voice requests for the current month. They are not linked to your name, Apple ID or any other identity, and they may persist if you delete and reinstall the app.
Deleting the app deletes your diary. Before that, you can export your full history as CSV or JSON files at any time from Settings and decide where to send them.
Voice and text entry
When you use "Say it" (voice) or type a free-text description, the recording or text is sent over an encrypted connection to our server and then to Google's Gemini API, which converts it into the fields of your entry. You review the result before anything is saved.
- The recording is deleted from your phone as soon as it stops. The transcript is saved only in your diary, on your phone.
- Our server does not store the recording, the text, the transcript or the recognized fields. It forwards the request and returns the result.
- We use the paid tier of the Gemini API. Google processes the request under its Gemini API terms for paid services, which do not allow Google to use it to train or improve its products; any handling on Google's side is governed by those terms: https://ai.google.dev/gemini-api/terms
- Voice entry is the only feature that needs an internet connection and the only case where anything you enter leaves your phone. You are asked for consent before the first use, and you can withdraw it in Settings.
The technical record
For each voice or text request our server keeps one technical record so that we can find and fix failures. It contains: the random device identifier, app and iOS version, interface language, whether the input was audio or text and its approximate length, the outcome of the request (response codes, number of attempts, timing), how many tokens the AI service used, and how many items of each kind were recognized (for example, "4 factors, 0 medicines"). It does not contain the recording, the text, the transcript, the names of medicines or factors, or anything else you said.
These records are stored with our hosting provider, Cloudflare, for up to two years, and are used only to operate and improve the service. They are not sold, not shared with advertisers and not used for tracking.
Notifications
Reminders (the question whether a medicine helped, the evening check-in) are local notifications scheduled on your phone. No notification server is involved, and nothing about your notifications leaves the device.
What we do not do
- No advertising, no ad networks, no tracking across apps or websites.
- No analytics SDKs and no analytics of your health data.
- No sale or sharing of personal data with third parties. The only processors are Cloudflare (hosting the server and the technical records) and Google (processing voice and text entries as described above).
- No access to Apple Health. The app does not read or write HealthKit data.
Your rights
Your data is under your control on your phone: you can view, edit, export and delete everything yourself. If you are in the EU, EEA, UK or Switzerland, you also have the rights under the GDPR to access, correct, export and erase personal data and to object to processing. For the technical records held on our side, write to captainlog@icloud.com with your device identifier (shown in Settings) and we will delete them.
Children
Captain is not directed at children under 16, and we do not knowingly process their data.
Medical note
Captain is not a medical device. It does not diagnose, treat or predict anything. Discuss what you notice in your diary with a healthcare professional.
Changes
If this policy changes, the new version is published on this page with a new effective date. Changes that expand what leaves your phone will be announced in the app before they take effect.