Cephala App Icon
Cephala Migraine Journal
Home / Legal & Policy

Privacy Policy

Official Document for Cephala iOS Application and Services

The Cephala Privacy Architecture

Cephala operates on a strict Local-First, Zero-Account Architecture. We do not require your email, name, phone number or home address. We operate no external cloud servers storing your health logs, run no advertising networks and never sell, trade or broker your sensitive neurological records to third parties, data aggregators or pharmaceutical companies.

1. Personal Information We Do Not Collect

In accordance with Apple App Store Review Guideline 5.1.1 (Data Collection and Storage), apps must minimize data collection. Cephala is engineered from the ground up so that you never have to trust our servers with your personal health history:

  • No User Account Credentials: You do not need to register, log in, create a profile or provide an email address, username or password.
  • No Cloud Symptom Database: We do not operate remote databases storing your headache attacks, pain intensity logs, acute medication names, relief timings or personal notes.
  • No Advertising SDKs or Trackers: Cephala contains zero advertising networks, tracking libraries, cross-app tracking scripts or social media trackers (such as Google Analytics, Meta Pixel, Firebase Analytics, AppsFlyer or Adjust).
  • No Data Monetization: We do not sell, rent, monetize or share health records with health insurance companies, pharmaceutical manufacturers, clinical trial brokers or advertising exchanges.

2. On-Device Storage and Apple CloudKit Security

All entries you record in Cephala (including pain ratings, attack durations, acute medications, barometric pressure readings and custom symptoms) are stored exclusively on your iPhone inside Apple's sandboxed, encrypted local file system.

If you choose to enable Apple iCloud backup or multi-device sync, your records are transmitted and synchronized through Apple's native CloudKit private database. Your data is encrypted in transit and at rest using your personal Apple ID encryption keys. Cephala developers cannot access, decrypt, inspect or view your CloudKit data.

3. Native iOS Device Hardware Permissions

To deliver low-sensory and automated functionality without external cloud calls, Cephala requests only native iOS system permissions:

  • Barometric Pressure Sensor (CoreMotion): Used locally on your iPhone to monitor atmospheric pressure drops (hPa) associated with weather-triggered migraines. Sensor readings are processed and stored exclusively on your device.
  • Local System Notifications: Used strictly to deliver user-configured streak reminders, scheduled check-ins or rapid barometric pressure drop alerts. All notifications are scheduled on-device without remote push notification servers.
  • Siri & Shortcuts (AppIntents): Enables hands-free attack logging using voice commands ("Hey Siri, log migraine in Cephala") so you do not have to look at a bright screen. Voice audio is processed entirely by Apple's on-device Siri speech engine.
  • Document Export (Share Sheet): When you export a 1-Page Doctor Report, the file is compiled locally in device memory and handed directly to Apple's native Share Sheet. The report is never uploaded to our servers.

4. Payments and In-App Purchase Privacy

Cephala offers optional premium upgrades ("Cephala Pro") through Apple's native StoreKit 2 framework. All purchase transactions, subscription renewals and payment processing are handled exclusively by Apple Inc.

We do not collect, process or store credit card numbers, bank details or billing addresses. Apple provides Cephala with cryptographically signed, anonymous transaction receipts verifying whether an active entitlement exists for your installation, without disclosing your identity or payment details to us.

5. User Data Portability and Right to Deletion

Because all health records remain on your device, you possess complete autonomy and control over your records at all times:

  • 1-Tap JSON Data Export: You can export your full headache journal at any time as an open JSON archive directly from App Settings for backup or transfer.
  • Permanent Data Erasure: Deleting the Cephala app from your iOS device immediately and irrevocably erases all locally stored health records from your device. You can also wipe your records anytime within App Settings with one tap.

6. Children's Privacy

Cephala complies with the Children's Online Privacy Protection Act (COPPA) and Article 8 of the General Data Protection Regulation (GDPR-K). The App is intended for individuals aged 13 and older (or aged 16 and older in the European Economic Area). Cephala does not knowingly collect, request or solicit personal information from children under these ages.

7. Compliance with GDPR, UK GDPR and CCPA/CPRA

Although Cephala collects zero personal identification data on external servers, we honor international data privacy frameworks including the General Data Protection Regulation (GDPR), the UK GDPR and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA):

  • Right to Know & Access: All your data is accessible immediately inside the app interface and via the export feature.
  • Right to Delete: You can purge all data at any time directly through the app or by deleting the app.
  • Right to Opt-Out of Sale or Sharing: Cephala does not sell or share personal information for cross-context behavioral advertising.
  • Non-Discrimination: We provide identical core tracking functionality regardless of how you exercise your privacy rights.

8. Website Privacy (cephala.app)

The Cephala marketing website (cephala.app) is hosted statically via Cloudflare Pages. Cloudflare processes standard technical transmission data (such as IP addresses, browser types and request timestamps) strictly for security defenses, DDoS mitigation and global content delivery.

We do not use advertising cookies, pixel trackers or cross-site behavioral telemetry scripts on our website.

9. Changes to this Policy

We may update this Privacy Policy to reflect architectural improvements or regulatory requirements. Any modifications will be posted directly to this web page. Your continued use of Cephala following any revisions signifies your acceptance of the updated policy.

10. Contact Us

If you have questions, feedback or data protection inquiries regarding this Privacy Policy, please contact our team directly:

Email: hello@cephala.app
Subject: Privacy & Data Protection Inquiry

Questions regarding our policies?

Reach out directly to our team anytime.

hello@cephala.app