Answers
Are migraine tracking apps private? What to check
Some are; many are not. A migraine diary can reveal your medication use, sleep problems, cycle, and the days illness takes you out of life — and any app that uploads entries to company servers puts that record one policy change, acquisition, or breach away from other hands. Here's how to tell the two kinds apart.
Why a headache diary is more sensitive than it looks
People guard their banking apps and shrug at their symptom trackers, but consider what months of migraine entries actually contain: a timeline of incapacity, a list of medications and how often you need them, menstrual-cycle patterns if you track hormonal triggers, sleep disruption, stress notes. Assembled, that's a health profile an insurer, employer, or data broker would find very legible. Health data outside a clinical setting often falls outside medical-privacy laws — an app developer is usually bound only by its own privacy policy, and policies can be rewritten.
Red flags worth taking seriously
- A mandatory account. If you can't log a single headache without handing over an email, your entries are being tied to an identity on someone's server. Sync is not an excuse on iPhone — iCloud handles that without the developer seeing anything. We've written more on this in whether a migraine app needs an account at all.
- Ads anywhere in the app. Advertising in a health app means ad-tech SDKs inside it, and those SDKs exist to profile. At minimum your usage patterns feed a targeting system; at worst, so does the fact that you're a migraine patient.
- Analytics on health events. Many apps embed third-party analytics that report which screens you open and when. "Logged an attack" is a health event; if it's pinged to an analytics platform, your attack calendar effectively exists outside your phone.
- Broker-shaped policy language. Phrases like "we may share aggregated or de-identified data with partners" deserve suspicion — supposedly anonymized location and timestamp data has been re-identified repeatedly.
- Free with no visible business model. Servers and salaries get paid somehow. If you can't see how — no purchase, no subscription — the data is the leading candidate.
Before downloading any health app, open its App Store privacy label. "Data Used to Track You" and "Data Linked to You" containing health entries is your answer. Then look for one sentence in the privacy policy: where is the data stored? "On your device" and "on our servers" are different products.
Questions to ask any migraine app
- Can I use it without creating an account? If no — why does a personal diary need to know who you are?
- Where do my entries live? On-device (and personal iCloud) means the developer physically cannot leak, sell, or be subpoenaed for what it never had. Company servers mean trusting policy and security forever.
- How does the app make money? A straightforward subscription or purchase aligns the developer with you. Ads and "partnerships" align them with someone else.
- What happens when I leave? A real export — PDF, CSV — means your history is yours. No export means your years of data are hostage to the app's survival.
- What would a breach expose? The honest test: if this company's database appeared online tomorrow, would your diary be in it?
How Dim answers these questions
Dim was designed so the trust question mostly doesn't arise, because there's nothing to trust a server with:
- No account. There is no signup screen. Dim never learns your name or email.
- On-device plus your private iCloud. Entries are stored on your iPhone and synced through your own iCloud — infrastructure the developer can't read. A database breach of Dim's servers is impossible in the plainest way: there are no such servers holding your diary.
- No ads, nothing sold. Dim is funded by the Dim Pro subscription, paid through the App Store. You are the customer, not the product.
- Sharing only on your initiative. Your data leaves the app in exactly one case — you tap export and send the PDF or CSV to someone you chose, typically your doctor.
- Apple Health on your terms. The two-way headache sync and sleep reading run through Apple's HealthKit permissions, which you grant and can revoke in Settings at any time.
This isn't a claim of virtue so much as architecture: an app that never collects your data doesn't need to be trusted not to misuse it. When you compare trackers, weigh promises lightly and structure heavily — and whatever you choose, choose something, because the diary itself is worth keeping.
Quick answers
Is my health data in an app protected by medical privacy law?
Often not. Outside clinical systems, consumer health apps are generally governed by their own privacy policies rather than medical-records law. The app's architecture and policy are what actually protect you — or don't.
What's the single fastest privacy check?
The App Store privacy label. If health data appears under "Data Used to Track You" or is linked to your identity, you know enough. Then check whether the app works without an account.
Does "anonymized data sharing" make an app safe?
Not reliably. Aggregated and de-identified datasets, especially with timestamps and locations, have been re-identified in practice. Data that never leaves your device needs no anonymizing.