Privacy Policy
Effective date: August 2, 2026 · Last updated: August 2, 2026
1. Who We Are (Data Controller)
The Relief mobile application (“Relief”, the “App”) is developed and operated by:
Exhalo Inc.
2810 N Church St PMB 99728
Wilmington, DE 19802, United States
Email: support@exhalo.app
For the purposes of the EU General Data Protection Regulation (GDPR), the entity above is the data controller for the limited personal data processed in connection with the App, as described in this Policy. Although we are established in the United States, the GDPR applies to our processing of data of users in the EU/EEA and UK (Art. 3(2) GDPR), and we honor the rights described in this Policy for all users.
The single most important thing to know: Relief was designed so that your health data never leaves your device. We do not operate user accounts, we do not maintain a database of users, and we cannot see, access, or restore your health records. See Section 5 for details.
2. Scope
This Policy applies to:
- the Relief iOS application distributed through the Apple App Store;
- our website at reliefmigraine.app, including the blog.
It does not apply to third-party services you may reach through links (e.g., Apple Health, the App Store), which are governed by their own privacy policies.
3. What Data Is Collected
Because Relief is account-less (there is no registration, login, or profile), we collect far less than a typical health app. Data falls into three categories.
3.1 Health and tracking data you enter (stays on your device)
When you use the App, you may record:
- migraine/headache attacks: time of onset, duration, pain intensity, and pain location;
- accompanying symptoms (e.g., aura, nausea, sensitivity to light or sound);
- potential triggers: sleep quality and duration, stress level, diet, physical activity, hormonal factors, screen time, and weather conditions;
- medications taken and your rating of their effectiveness;
- notes and other entries you choose to add.
This is special-category health data under Article 9 GDPR — and precisely for that reason it is stored exclusively on your device. It is never uploaded to our servers, and we have no technical means of accessing it. Where the GDPR applies to on-device processing at all, the legal basis is your explicit consent (Art. 9(2)(a) GDPR), given when you start using the tracking features; you can withdraw it at any time by deleting your data or the App.
3.2 Data received from Apple Health (stays on your device)
If — and only if — you grant permission through Apple’s HealthKit consent screens, Relief can read the following categories from Apple Health:
- menstrual cycle data (cycle days and phase information), used to show which menstrual phases correlate with your attacks;
- heart rate (HR), used to correlate physiological strain with your attacks;
- heart rate variability (HRV), used as an indicator of stress and recovery in your trigger analysis.
Apple Health data:
- is read locally by the App and processed only on your device;
- is never transmitted to our servers or to any third party;
- is never used for advertising, marketing, attribution, or analytics — this is prohibited both by this Policy and by Apple’s HealthKit rules, which we adhere to;
- can be revoked at any time in iOS: Settings → Privacy & Security → Health → Relief.
Relief may also write data to Apple Health (e.g., logged headache episodes) if you enable that permission. Data written to Apple Health is then governed by Apple’s privacy terms and your Health app settings.
3.3 Technical, analytics, and purchase data (may be transmitted)
To operate, improve, and market the App, we and our processors handle a limited set of non-health data:
- Device and app data: device model, iOS version, App version, language, region, time zone, app events (e.g., screen opened, feature used), crash logs, and pseudonymous identifiers (a randomly generated install/app-instance ID and, only if you allow tracking via Apple’s App Tracking Transparency prompt, the IDFA).
- Purchase data: subscription status, product identifier, purchase and renewal timestamps, price and currency, and a pseudonymous app-user ID. Payments themselves are processed entirely by Apple; we never receive your name, card number, or billing address.
- Attribution data: if you installed the App after tapping one of our advertisements, our attribution partner processes technical signals (e.g., IP address at install time, device data, ad-interaction timestamps) to tell us which campaign the install came from.
- Location data: see Section 4 — location is used on-device and is not stored on our servers.
- Support correspondence: if you email us, we process your email address and the content of your message.
Analytics events describe how the App is used, never what you tracked in it. Your symptom entries, health metrics, Apple Health data, and note contents are never included in analytics payloads.
Legal bases: legitimate interests (Art. 6(1)(f) GDPR) for aggregate product analytics, crash reporting, fraud prevention, and measuring our advertising; consent (Art. 6(1)(a)) for IDFA-based tracking under the ATT prompt; performance of a contract (Art. 6(1)(b)) for delivering subscriptions and support; legal obligation (Art. 6(1)(c)) for tax and accounting records.
4. Geolocation
Why location is required. A core feature of Relief is correlating your attacks with environmental conditions and warning you about high-risk days. To do this, the App needs to know the weather, atmospheric pressure, air quality, and pollutant levels where you actually are. That requires your device’s location.
How it works:
- With your permission (iOS location prompt), the App obtains your device’s precise coordinates on the device.
- To retrieve current and forecast weather, atmospheric pressure, and air-quality data for your area, the App sends your precise coordinates to our weather backend. This transmission is transient: the coordinates are used in memory solely to look up the environmental data for that request and to return the result.
- Precise geolocation is not stored on our servers. Your coordinates are not saved, are not kept as a location history, are not linked to any analytics or attribution identifier, and are not used to build any profile of your movements.
- We do not track your location in the background beyond what is needed to refresh environmental data, and you can restrict this in iOS at any time: Settings → Privacy & Security → Location Services → Relief (e.g., “While Using”, or off entirely).
If you decline location access, the App remains usable; weather-based features will be unavailable.
5. What Stays Local vs. What Is Transmitted
| Data | Stored on your device | Transmitted to servers |
|---|---|---|
| Attack logs, symptoms, triggers, medications, notes | Yes — only here | Never |
| Apple Health data (menstrual cycle, heart rate, HRV) | Yes — only here | Never |
| Reports/exports you generate | Yes (until you share them yourself) | Never |
| Precise location | Obtained on device | Transmitted transiently for weather lookup only; never stored |
| Anonymous app-usage events, crash logs | Partially | Yes — to analytics processors |
| Subscription/purchase metadata | Partially | Yes — to Apple and our subscription processor |
| Install-attribution signals | — | Yes — to our attribution processor |
Consequence of this architecture: we cannot recover your data for you. If you delete the App or lose your device without a device backup, your entries are gone. Your data may be included in your encrypted iCloud or local device backup, which is controlled by you and Apple, not by us.
6. Advertising, Attribution, and Model Training
- We do not sell your personal data. We have never sold personal data and do not share it for cross-context behavioral advertising.
- We do not show third-party ads inside the App, and your data is not used to target you with ads inside the App.
- Attribution: we advertise Relief on external platforms (e.g., social networks). We use an attribution service solely to measure which of our own campaigns lead to installs and subscriptions. This uses technical device signals — never your health data.
- Model training: your personal data is not used to train machine-learning models. Our prediction algorithms are improved using aggregated, anonymized usage statistics that cannot be linked back to any individual (see Section 12). Your identifiable health entries are never used for this purpose — they never reach us in the first place.
7. Key Data Processors and Analytics Services
We use a small number of carefully selected processors, each bound by a data-processing agreement under Art. 28 GDPR:
| Service | Provider | Purpose | Data involved |
|---|---|---|---|
| Amplitude | Amplitude, Inc. (USA) | Product analytics | Pseudonymous app-usage events, device data |
| Firebase Analytics / Crashlytics | Google Ireland Ltd. / Google LLC | Product analytics, crash reporting | Pseudonymous usage events, crash logs, device data |
| AppsFlyer | AppsFlyer Ltd. (Israel/EU) | Marketing attribution | Install-attribution signals, device data, IDFA (only with ATT consent) |
| RevenueCat | RevenueCat, Inc. (USA) | Subscription management and payment analytics | Purchase metadata, pseudonymous app-user ID |
| Apple | Apple Inc. / Apple Distribution International Ltd. | App distribution, payment processing, HealthKit | Purchase processing; App Store data per Apple’s terms |
| Weather/air-quality backend hosting | Our cloud hosting provider | Serving weather and air-quality data | Transient request data (see Section 4) |
| Website and blog hosting | Vercel Inc. (USA); Webflow, Inc. (USA) | Operating our website and blog | Standard web server logs |
International transfers. We are based in the United States, and some processors are also located outside the EEA (notably in the USA and Israel). Where data of EU/EEA or UK users is transferred to the US or other third countries, transfers rely on the EU–US Data Privacy Framework (where the provider is certified), the European Commission’s adequacy decision for Israel, and/or Standard Contractual Clauses with supplementary measures. Copies of relevant safeguards are available on request via the contact in Section 15.
8. Data Retention
| Data | Retention period |
|---|---|
| Health and tracking data, Apple Health data | On your device only — retained until you delete it or uninstall the App. We hold no copy. |
| Precise location | Not retained (transient processing only) |
| Analytics events (Amplitude, Firebase) | 24 months from collection, then deleted or irreversibly aggregated |
| Crash logs | 90 days |
| Attribution data (AppsFlyer) | Up to 24 months, per platform policy |
| Subscription records (RevenueCat) | For the life of the subscription relationship, plus as required by applicable tax, accounting, and commercial-record laws (typically up to 7 years) |
| Support emails | 24 months after the ticket is closed, unless a dispute requires longer |
| Aggregated, anonymized statistics | Indefinitely (no longer personal data) |
9. Security and Encryption
- In transit: all network communication between the App and our backend or processors is encrypted using TLS 1.2 or higher (HTTPS). The App does not send data over unencrypted connections.
- At rest on your device: your entries are stored in the App’s private sandbox and protected by iOS Data Protection, which encrypts data using hardware-backed keys tied to your device passcode. Apple Health data resides in Apple’s encrypted HealthKit store.
- At rest on servers: we do not store health data or location on servers. The limited operational data held by our processors (analytics, purchase metadata) is encrypted at rest by those providers (AES-256 or equivalent).
- Organizational measures: access to processor dashboards is restricted, protected by strong authentication, and limited to personnel who need it.
No system is perfectly secure, but the App’s local-first architecture means the most sensitive category of data — your health records — is never exposed to server-side risk at all.
10. Your Rights and How to Exercise Them
Under the GDPR you have the rights of access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent, plus the right not to be subject to solely automated decisions producing legal effects (Relief makes no such decisions — risk forecasts are informational only).
10.1 How to download (export) your data
- In the App: Settings → Export / Reports lets you generate a report (e.g., PDF) of your logged data, suitable for your own records or for sharing with your doctor.
- Because your health data exists only on your device, in-app export is your data-portability mechanism — there is no server-side copy for us to produce.
- For the limited server-side data (analytics, purchase metadata), you may request a copy via the contact in Section 15. Note that analytics data is pseudonymous; to locate it we may need technical identifiers from your device.
10.2 How to delete your data
- In the App: use Settings → Delete all data to erase all entries, or delete individual records.
- Uninstalling the App removes all locally stored App data from your device. (Data you previously wrote into Apple Health is managed in the Health app; data in your device/iCloud backups is controlled through your Apple backup settings.)
- Server-side data: email us (Section 15) to request deletion of support correspondence or, where technically feasible, analytics/attribution records linked to your device identifiers. You can also reset your IDFA or disable tracking in iOS settings at any time.
10.3 How to delete your account
Relief has no user accounts — there is nothing to register and therefore nothing to delete on our side. There is no login, no profile, and no server-side identity associated with you. Deleting your data (10.2) removes everything that exists.
11. Subscriptions and What Happens After Cancellation
- Relief offers auto-renewing subscriptions purchased through Apple, typically with a free trial. Manage or cancel anytime in iOS Settings → [your name] → Subscriptions, or via the App Store app. Cancelling at least 24 hours before the trial or period ends prevents the next charge.
- After cancellation: premium features are disabled at the end of the paid period, but you keep access to the core logging and statistics features, and — critically — all your data remains on your device. Nothing is deleted, locked, or held hostage when a subscription ends.
- Refunds for App Store purchases are handled by Apple under Apple’s refund policy (request at reportaproblem.apple.com).
- Cancelling a subscription does not, by itself, delete any data; use Section 10.2 if you also want your data removed.
12. Anonymized Information and Research
We use aggregated, anonymized statistics — for example, the percentage of users who log attacks on high-pressure-change days, or which features are most used — to improve the App and refine our prediction algorithms. This information:
- is derived from the pseudonymous analytics events described in Section 3.3, never from your on-device health records;
- is aggregated across many users so that no individual can be identified or re-identified;
- once anonymized, is no longer personal data under the GDPR.
We do not share individual-level data with academic institutions or commercial research partners. If we ever publish aggregate insights — for example, a “migraine and weather” report on the blog — they are based solely on such anonymized aggregates.
13. Data Breach Notification
Despite the local-first design, we treat security incidents seriously:
- Detection and containment. Upon becoming aware of a suspected personal-data breach (whether in our systems or reported by a processor), we immediately investigate, contain it, and assess the risk to affected individuals.
- Notification to supervisory authorities. Where a breach affects the personal data of EU/EEA or UK users and is likely to result in a risk to their rights and freedoms, we notify the competent supervisory authority (or authorities) of the affected users without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33 GDPR). Where US state breach-notification laws apply (e.g., for residents of California or other states), we notify the relevant authorities and individuals within the timeframes those laws require.
- Notification to you. If the breach is likely to result in a high risk to your rights and freedoms, we will inform affected users without undue delay (Art. 34 GDPR) — via an in-app notice, a prominent notice on our website, and/or email where we have it — describing the nature of the breach, likely consequences, measures taken, and recommended steps.
- Processors are contractually required to notify us of any breach without undue delay.
- Records. We document all breaches, their effects, and remedial actions, regardless of whether notification thresholds are met.
Because your health data is never stored on our servers, a server-side breach cannot expose your symptom logs, Apple Health data, or location history.
14. Children
Relief is not directed at children under 16, and we do not knowingly process their data. If you believe a child has provided data through the App’s transmitted channels, contact us and we will delete it.
15. Contact — GDPR and Security Inquiries
- Privacy / GDPR requests: support@exhalo.app
- Security reports and vulnerability disclosures: support@exhalo.app with the subject line “SECURITY”
- Postal address: Exhalo Inc., 2810 N Church St PMB 99728, Wilmington, DE 19802, United States
We respond to GDPR requests within one month, extendable by two further months for complex requests (with notice). We may ask you to verify that a request originates from the device in question, since we hold no account data to verify identity otherwise.
Right to lodge a complaint (EU/EEA/UK): you may lodge a complaint with the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement (e.g., in Germany, your Landesdatenschutzbehörde; in the UK, the ICO).
US residents: depending on your state (e.g., California under the CCPA/CPRA, and equivalent laws in Colorado, Virginia, Connecticut, and others), you may have rights to know, access, correct, delete, and opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information beyond the purposes permitted without an opt-out. You may exercise applicable rights via the contacts above; we do not discriminate against you for doing so.
16. Changes to This Policy
We may update this Policy as the App evolves or the law changes. Material changes will be announced in the App and/or on our website before they take effect, with the “Last updated” date revised above. Continued use of the App after the effective date constitutes acceptance of the updated Policy; where new processing requires consent, we will ask for it.