Privacy Policy & Consumer Health Data Notice
Effective and Last Updated: August 26, 2026
Privacy promises about health data should be specific. This notice explains what the Cefalea iOS app (the “App”) processes, what the developer can and cannot access, how the website works, and the rights available in different regions.
The short version
- Cefalea has no account system, advertising SDK, analytics SDK, or developer-operated health-data server.
- Your headache diary, medication records, symptoms, notes, and attachments are processed and stored locally on your device.
- The developer cannot view your in-app diary.
- Apple Health integration is optional and controlled through Apple’s permission interface.
- Cefalea does not sell personal information or consumer health data, share it for cross-context behavioral advertising, or use it to profile you.
- You decide when an export leaves the App and where it goes.
Who is responsible
Cefalea is provided by Ezequiel França (the “Developer,” “Cefalea,” “we,” “us,” or “our”).
For privacy questions or requests concerning information we actually hold, use the Ezequiel Support portal. Please do not include headache records, medication details, or other health information unless strictly necessary for the request.
Scope
This notice applies to:
- the Cefalea iOS App;
- the website at
cefalea.ezequiel.appand its temporary GitHub Pages address; and - support communications sent directly to us.
It does not govern Apple Health, iCloud or device backups, the App Store, your email provider, or any destination you choose through Apple’s share sheet. Those services operate under their own terms and privacy notices.
Data processed locally by the App
Depending on what you choose to record, the App may process:
- headache start and end times, duration, frequency, and intensity;
- pain position, fever status, accompanying symptoms, possible triggers, medications, and medication timing;
- notes, selected photos, and selected documents;
- headache samples read from or written to Apple Health after authorization;
- preferences such as onboarding completion, default selections, and whether app locking is enabled;
- information needed to display an active tracking session or Live Activity; and
- reports or CSV files generated at your request.
These categories may constitute health data or sensitive personal information under applicable law. They are processed to provide the diary, tracking, review, export, attachment, app-lock, and optional Apple Health features you request.
Sources
The App receives this information only from:
- information you enter;
- photos or documents you deliberately select;
- Apple Health, after you grant the relevant permission; and
- technical state created on your device when you use App features.
Where it is stored
Diary records and attachments are stored in the App’s local container on your device. Cefalea does not operate a server that receives those records. The App marks its health-data storage directories and newly written attachments or local export files as excluded from system backup. Apple documents this flag as guidance to the operating system rather than an absolute guarantee, so you should not assume a device restore will recover the diary.
Apple Health
With permission, Cefalea can read and write Apple Health headache samples so your history remains consistent across the experiences you choose to use. Permission is granular and can be changed in Apple Health or system privacy settings.
Cefalea does not use HealthKit information for advertising, marketing, data mining, eligibility decisions, insurance decisions, or sale to a data broker. Deleting an entry inside Cefalea may not delete a separate sample already stored in Apple Health. Review or delete that sample in Apple Health and revoke access through Apple’s settings if desired.
Face ID, Touch ID, and device authentication
If you enable app locking, iOS performs the biometric authentication. Cefalea receives only the success or failure result. The App does not receive or store your face image, fingerprint, biometric template, or device passcode.
Photos, documents, exports, and sharing
Cefalea copies only items you select into its local container. When you generate or share a PDF, CSV, image, document, or other export, Apple’s system share interface lets you choose the recipient or destination. Once shared, the copy is governed by that destination and the recipient’s practices, not by Cefalea.
Information the Developer receives
The Developer does not receive your in-app diary merely because you use Cefalea. We may receive limited information in these separate situations:
Support communications
If you contact us through the support portal, we receive the contact details, message, and anything you voluntarily submit. We use it to respond, investigate the issue, maintain necessary business records, prevent abuse, and establish or defend legal claims. Do not submit health information unless it is strictly necessary and you intentionally choose to do so.
Website connection data
The website does not intentionally set advertising cookies or run product analytics. It is delivered through GitHub Pages and may use Cloudflare for domain, security, and delivery services. Those providers may automatically process connection information such as IP address, request headers, timestamps, device/browser information, and security events under their own notices. Cefalea does not combine that infrastructure data with an in-app headache diary.
App Store information
Apple may provide aggregated sales, download, crash, or product-performance information through App Store services. Apple controls the information it collects and the details it makes available. Cefalea does not use Apple Health data for those purposes.
Purposes and legal bases
Where a legal basis is required, processing is limited to:
- providing requested functionality or performing a contract, such as responding to support requests;
- your consent or explicit action, such as authorizing Apple Health or choosing an export destination;
- legitimate interests, such as securing the website, diagnosing a reported defect, preventing abuse, and protecting legal rights, balanced against your rights; and
- legal obligations, when retention or disclosure is required by valid law or binding legal process.
If you voluntarily send health information in a support request, we process it only as necessary to respond to your explicit request, protect vital or legal interests where applicable, or as otherwise permitted by law. We will not use it for advertising or unrelated profiling.
Disclosure and recipients
We do not sell or rent personal information or consumer health data. We do not disclose your local diary to advertisers, data brokers, employers, insurers, or social networks.
Information may be handled by:
- Apple, when you use the App Store, Apple Health, device authentication, backups, Live Activities, or the share sheet;
- GitHub, which hosts the website;
- Cloudflare, which may provide DNS, security, and delivery for the website;
- support infrastructure providers, when you contact support;
- destinations and people you select, when you export or share information; and
- authorities or professional advisers, only when reasonably necessary to comply with law, protect rights or safety, or establish or defend legal claims.
No third party receives in-app consumer health data from the Developer because the Developer does not possess that diary data. Apple Health or a user-selected share destination receives data only through the action and permission you initiate.
Retention and deletion
- Local App data: remains until you delete individual entries or attachments, erase the App’s data, or uninstall the App. Cefalea marks its health-data directories as excluded from system backup.
- Apple Health data: remains under Apple Health controls until managed there.
- Exports: remain wherever you save or send them until deleted there.
- Support messages: retained only as long as reasonably necessary to respond, secure the service, keep necessary records, or resolve and defend claims, then deleted or anonymized when no longer needed.
- Website security records: retention is determined principally by the infrastructure provider and its security settings.
Because the Developer cannot access your local diary, we cannot remotely retrieve, correct, export, or erase it for you. The App’s edit, delete, and export controls—and Apple Health’s controls—are the operative tools for that data.
Security
Cefalea minimizes network exposure by keeping the diary on device. iOS app sandboxing and device protections apply, and optional app locking can add a local authentication step. No device, software, transmission, or storage method is perfectly secure. You are responsible for protecting your device passcode, Apple account, and exported files.
If a security incident affects information actually controlled by us, we will investigate and provide legally required notices. U.S. health apps can be subject to the Federal Trade Commission’s Health Breach Notification Rule even when HIPAA does not apply.
Consumer Health Data Notice — Washington and Nevada
For the Washington My Health My Data Act, Nevada consumer-health-data law, and similar laws, this section supplements the rest of the notice.
Categories and purposes
The App locally processes the headache, symptom, trigger, medication, timing, note, attachment, Apple Health, and tracking-session categories listed above solely to provide features requested by the user. The Developer does not receive those categories through normal App use.
Sources
The sources are the user, user-selected files or photos, Apple Health after permission, and feature state generated locally on the device.
Sharing
Cefalea does not sell consumer health data. It does not share consumer health data for advertising. Data can reach Apple Health or a user-selected export destination only when the user requests or authorizes that operation. We do not use geofencing around health-care facilities or infer health status for advertising.
Rights
Where applicable, you may request confirmation, access, correction, deletion, withdrawal of consent for future processing, or an appeal of a denied request. For local App data, exercise these rights using the App, Apple Health, device settings, or by uninstalling the App. For support information actually held by us, submit a request through the Ezequiel Support portal and label it Privacy Request. We may need to verify your identity without asking for unnecessary health information. We will not discriminate against you for exercising a privacy right.
European Economic Area, United Kingdom, and Switzerland
Health data is specially protected. Cefalea’s architecture is designed so the Developer does not receive the local diary. For personal information we do control, you may have rights to access, correct, erase, restrict, object, withdraw consent, and receive portable data, subject to legal limits. You may also complain to your local supervisory authority. If information is processed outside your region by a service provider, applicable contractual or statutory safeguards are used where required.
Brazil
Health data is dado pessoal sensível under the Lei Geral de Proteção de Dados Pessoais (LGPD). Where the LGPD applies to information actually controlled by us, you may request confirmation of processing, access, correction, portability where applicable, information about sharing, review of applicable automated decisions, anonymization/blocking/deletion where legally available, and withdrawal of consent. Cefalea does not sell health data or make automated decisions producing legal or similarly significant effects.
California and other U.S. states
Where applicable, residents may request access/knowledge, deletion, correction, portability, limitation of certain sensitive-data uses, or an appeal, and may exercise rights without unlawful discrimination. Cefalea does not sell personal information, share it for cross-context behavioral advertising, or use local health data for targeted advertising. Because the Developer does not receive the local diary, a request to us cannot produce data we do not possess.
Children and families
Cefalea is not directed to children under 13. A minor should use the App only with the involvement and permission of a parent or legal guardian where required by local law. Please do not send a child’s health information to support. If you believe a child sent personal information to us through support, contact us so we can assess and delete it where required.
No HIPAA representation
Cefalea is a consumer app and is not offered as a system on behalf of a HIPAA-covered health-care provider or health plan. We do not represent that the App is a HIPAA-compliant clinical record system or business associate service. A clinician’s recommendation to keep a diary does not make Cefalea part of that clinician’s medical record system.
Changes
We may update this notice when the App, providers, or law changes. Material changes will receive reasonable notice through the website, App, App Store release notes, or another appropriate channel before they take effect where required. The effective date above identifies the current version.
Contact
Privacy questions, rights requests, and complaints: support.ezequiel.app
Please use the subject Privacy Request and do not include unnecessary health information.