Answers

Are migraine tracking apps private? What to check

Some are; many are not. A migraine diary can reveal your medication use, sleep problems, cycle, and the days illness takes you out of life — and any app that uploads entries to company servers puts that record one policy change, acquisition, or breach away from other hands. Here's how to tell the two kinds apart.

Updated August 2026 · 6 min read

Why a headache diary is more sensitive than it looks

People guard their banking apps and shrug at their symptom trackers, but consider what months of migraine entries actually contain: a timeline of incapacity, a list of medications and how often you need them, menstrual-cycle patterns if you track hormonal triggers, sleep disruption, stress notes. Assembled, that's a health profile an insurer, employer, or data broker would find very legible. Health data outside a clinical setting often falls outside medical-privacy laws — an app developer is usually bound only by its own privacy policy, and policies can be rewritten.

Red flags worth taking seriously

A two-minute check

Before downloading any health app, open its App Store privacy label. "Data Used to Track You" and "Data Linked to You" containing health entries is your answer. Then look for one sentence in the privacy policy: where is the data stored? "On your device" and "on our servers" are different products.

Questions to ask any migraine app

  1. Can I use it without creating an account? If no — why does a personal diary need to know who you are?
  2. Where do my entries live? On-device (and personal iCloud) means the developer physically cannot leak, sell, or be subpoenaed for what it never had. Company servers mean trusting policy and security forever.
  3. How does the app make money? A straightforward subscription or purchase aligns the developer with you. Ads and "partnerships" align them with someone else.
  4. What happens when I leave? A real export — PDF, CSV — means your history is yours. No export means your years of data are hostage to the app's survival.
  5. What would a breach expose? The honest test: if this company's database appeared online tomorrow, would your diary be in it?

How Dim answers these questions

Dim was designed so the trust question mostly doesn't arise, because there's nothing to trust a server with:

This isn't a claim of virtue so much as architecture: an app that never collects your data doesn't need to be trusted not to misuse it. When you compare trackers, weigh promises lightly and structure heavily — and whatever you choose, choose something, because the diary itself is worth keeping.

Quick answers

Is my health data in an app protected by medical privacy law?

Often not. Outside clinical systems, consumer health apps are generally governed by their own privacy policies rather than medical-records law. The app's architecture and policy are what actually protect you — or don't.

What's the single fastest privacy check?

The App Store privacy label. If health data appears under "Data Used to Track You" or is linked to your identity, you know enough. Then check whether the app works without an account.

Does "anonymized data sharing" make an app safe?

Not reliably. Aggregated and de-identified datasets, especially with timestamps and locations, have been re-identified in practice. Data that never leaves your device needs no anonymizing.

Private by architecture, not by promise

Dim keeps your migraine diary on your device and in your own iCloud. No account, no ads, no servers with your data on them.

Download Dim migraine tracker on the App Store

No account · No ads · Nothing sold

Dim is a diary, not a medical device. This article is general information, not medical advice — it does not diagnose, treat, or prevent any condition. Always consult a qualified clinician about your health.