Privacy Policy
How Neologos Development and each app handle your data — the general part applies to the site and every app, and each app's section adds what that app does extra.
Effective from September 25, 2026
This document is translated from the Czech version for your convenience. In case of any discrepancy between language versions, the Czech version is binding.
Documents by app
General — website and shared infrastructure
Data controller
The data controller is Vojtěch Landa, a private individual, contact: vojtajess@gmail.com. Neologos Development is not a legal entity or a registered business — it's the name under which Vojtěch Landa, as a private individual, develops and runs neologos.dev and the apps listed below.
What this page covers
This privacy policy is shared across neologos.dev, vejce.neologos.dev, and the apps Blackout, Eco, WorthIt, Blurt, Migrelog, and Limi. Each app also has its own section below, since it processes different data depending on what it does — the general part applies to all of them, and the app section adds to it.
Website traffic
neologos.dev collects basic, aggregate traffic statistics (visit counts, pages visited, approximate geographic area from IP address) via Vercel Analytics and, if enabled, PostHog. This data only exists to show whether the site is being used at all — it isn't sold, isn't shared with ad networks, and isn't linked to a name or email unless you provide one yourself (e.g. via the support chat).
Support chat and tickets
The Support section on the website and the support chat inside the apps let you report a bug, suggest an app improvement, ask about legal information or ask a general question. Chat messages are saved as a ticket in Firestore (Google/Firebase, see point 5). Messages in every category are answered by an AI assistant through the Anthropic (Claude) API. Anthropic acts as a processor: it handles the message, including the earlier conversation, only to produce a reply and does not use it to train models.
When you report a bug directly from an app, a technical app log (error messages and app state) is attached to the ticket so the problem can be traced. An email or name is stored only if you type it into the form yourself — it is never collected automatically.
Blackout, WorthIt, Blurt and Migrelog also include a short, optional in-app survey. At the end we ask whether you'd like us to get back to you. If you choose "No", your answers are sent without an e-mail address or any contact detail, i.e. anonymously. If you choose "Yes", your answers are sent the same way and the app opens the support chat with your answers pre-filled in the message and the e-mail address you enter yourself. The message and e-mail are then stored as a ticket as described in this section, and the e-mail is used only to reply to your feedback. The survey record itself stays without an e-mail address.
Shared infrastructure
The website and apps run on Firebase/Google Cloud (Firestore, Cloud Functions, Cloud Messaging) — the servers for the apps and site are set to a European region (europe-west3) wherever Firebase allows it. Google acts as a processor there under its own privacy policy (firebase.google.com/support/privacy).
Push notifications (where an app offers them) use the Apple Push Notification service — Apple only needs an anonymous device token for this, not personal data.
Advertising and cookies
The /brief page (Brief → Prompt) is funded by ads through Google AdSense so it can stay free. No ad script or third-party cookie loads until you consent in the cookie banner at the bottom of the page.
Once you consent, Google and its ad partners may set cookies to measure and personalize ads under their own policies (policies.google.com/privacy). You can manage ad personalization or opt out at adssettings.google.com.
You can withdraw consent at any time by clearing this domain's cookies in your browser — the banner will show up again.
Your rights
Under GDPR, you have the right to:
- access your data
- correct inaccurate data
- erasure ("the right to be forgotten")
- restrict processing
- data portability
- object to processing
- withdraw consent at any time, where processing was based on it
- lodge a complaint with the Office for Personal Data Protection (uoou.gov.cz)
You can exercise any of these rights simply — write to vojtajess@gmail.com or via Support (category "Legal information").
What to expect from me: I'll reply no later than 30 days after receiving the request — either sending, correcting, or deleting the data right away, or explaining why (and on what grounds) that isn't possible. For a more complex request this deadline can be extended once by another two months, which I'll tell you about within the first 30 days. To verify identity I may ask for extra information (e.g. the email or nickname used in the app), so the data doesn't end up with someone else under your name.
Data retention
Tickets and incidents are kept for as long as needed to resolve the request, plus a reasonable period after for traceability (typically up to 24 months), then deleted. Data stored directly in the apps (see the app sections below) follows each app's own rules — most of it can be deleted immediately right in the app.
A conversation with the assistant where you leave no email is kept on the server only as a hidden draft, so it can still be handed to a person if you add an email. Nobody reads it, and it is deleted automatically after 7 days.
Changes to this policy
This policy may change as the site and apps evolve. The current version is always on this page; the date of the last change is shown in the header.
Blackout
Effective from September 16, 2026
App philosophy
Blackout is designed so your data never leaves the device. It doesn't run on any cloud, has no accounts, and includes no third-party analytics, advertising, or telemetry SDKs.
What the app processes
All data is stored exclusively on the device and never leaves the iPhone without an explicit user action (e.g. manually exporting an encrypted backup):
- Guides, checklists, and notes the user creates themselves
- An anonymous device identifier stored in the Keychain, used only for pairing on the local SafeZone network
- App settings and the address entered for weather alerts, stored locally
What the app doesn't collect
- Name, email, or any contact details
- Device location (GPS or IP address)
- Diagnostic data or crash reports on remote servers
- Advertising identifiers (IDFA/IDFV)
- Clipboard, photo library, or contacts content
This is about the app itself — none of it is sent automatically. If you report a bug via Support on the website, the description you write there (device, iOS version, steps) is handled as a regular support ticket per point 4 in the general section above, including possible processing via Anthropic.
The app offers a short, optional survey. Answers are sent without any device identifier or e-mail, only with the app version and language. If you choose at the end that you'd like to be contacted, the support chat opens with your answers pre-filled and the e-mail address you enter, which is handled as a support ticket under section 4 of the general part.
Local network — SafeZone
SafeZone uses Apple Multipeer Connectivity for direct peer-to-peer connections with nearby devices over Bluetooth/Wi-Fi Direct, with no internet server involved. A new device must always be manually approved by the user; communication is encrypted (TLS 1.3) and none of it leaves the local network.
Weather alerts
The app can download current alerts from the Czech Hydrometeorological Institute's public, open API (opendata.chmi.cz). The device's location is not sent — filtering happens locally based on the address the user enters, which is only processed via Apple's CLGeocoder (the address itself never goes to CHMI's servers).
Rights and data deletion
Since the app doesn't collect data on any servers, there's no need to request deletion — all data disappears when you uninstall the app or reset the device.
Contact
Write via Support — that's the fastest way to reach me.
Eco
Effective from September 28, 2026
Controller and contact
The controller of personal data processed in connection with the Eco mobile app (the "App") is Vojtěch Landa, a natural person, email: vojtajess@gmail.com (the "Operator", "we" or "us").
The Operator has not appointed a data protection officer because it is not required to do so under Article 37 of Regulation (EU) 2016/679 (the "GDPR"). For any data protection matter, contact us at the email above or through the support chat in the App.
Data that stays on your device
During a trip, and while automatic trip detection is on, the App processes GPS location and speed and data from your phone's motion sensors (accelerometer, gyroscope). From this data it calculates the route, score and trip events directly on the device.
Trips, routes, events, statistics and the fines, offences and points you enter are stored only on your device and, if iCloud is enabled, in your private iCloud storage (Apple CloudKit). They are not transferred to the Operator, the Operator has no access to them and is not their controller. The same applies to the car photo you can add in the Garage: the car is cut out of it on your device and the photo is never uploaded to the Operator. iCloud storage is governed by Apple's terms. The same applies to debug logs and reports of misjudged events until you expressly choose to share them.
Trip scoring is an automated evaluation of your driving behaviour. It runs only on your device, is for your information only and has no legal or similarly significant effect on you, so it is not automated decision-making under Article 22 GDPR. Fine estimates and the points log work with offence data that you enter yourself and that stays only on your device. Please enter only your own data.
Purposes, scope and legal bases
a) User account (optional). Nickname, profile colour, the name from Sign in with Apple if you share it, and a random Firebase UID. Purpose: creating and managing the account and linking the subscription across devices. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
b) Leaderboard, groups, family sharing and feature voting. Average score, fuel saved and number of trips per week and month; group name, code and members; in a group, after each trip, an entry with nickname, score, distance and whether a significant event occurred, without route or location; for votes, the Firebase UID and time of the vote. Group and leaderboard data are visible to other group members. Legal basis: performance of a contract.
c) Eco Premium subscription. Customer identifier at RevenueCat, the Firebase UID of a signed-in user, purchased product, subscription status and history, and App Store country. Payment details are processed exclusively by Apple; the Operator never sees them. Legal basis: performance of a contract.
d) Anonymous usage statistics (Firebase Analytics), only with your consent. App instance identifier, usage events (for example opening the App, progress through onboarding, saving a trip and the number of trips in the last 7 days, features used, permission decisions), App and system version, device model, language and approximate country or region derived from the IP address. No location, routes, trip content or fines are sent. The advertising identifier (IDFA) is not collected and advertising signals are disabled. Purpose: understanding which features are used and improving the App. Legal basis: consent (Article 6(1)(a) GDPR and Article 5(3) of Directive 2002/58/EC as implemented in national law). Nothing is collected without consent. You can withdraw consent at any time in the App (Settings → Legal → Anonymous usage statistics); collection then stops and locally stored analytics data are deleted. Withdrawal does not affect the lawfulness of processing before it. With the same consent the App also sends the Operator's server (Google Cloud, European Union region) daily aggregate counts of the screens shown and of the screen on which the App was closed, without any user or device identifier; only these totals are stored.
e) Security (Firebase App Check). Cryptographic verification that a request comes from the genuine App (Apple App Attest) and technical request data. Purpose: protecting the services against abuse and automated attacks. Legal basis: legitimate interest in securing the service (Article 6(1)(f) GDPR).
f) Measuring the Premium offer. Without any user or device identifier, the Operator's server receives the fact that the offer was shown, where it was opened from and whether a trial, purchase, restore or dismissal followed. The server stores only daily aggregate counts; the IP address is processed only transiently in transit. Legal basis: legitimate interest in evaluating the offer (Article 6(1)(f) GDPR).
g) Support chat. Message text including the previous conversation, request category, language and App version; when reporting a bug, also a technical App log (error messages and App state); an email address only if you enter it yourself. Messages are stored as a request on the Operator's server (Google Cloud, European Union region) and answered by an artificial intelligence assistant via the API of Anthropic (Claude model). Purpose: handling your request and fixing bugs. Legal basis: performance of a contract and legitimate interest in improving the App.
h) Satisfaction survey. Your answers, App version and device language, without a user identifier. Participation is voluntary. Legal basis: consent given by submitting the answers.
i) AI trip summary and weekly recap, where available. Trip statistics: score, event types, distance, average speed, weather and a verbal description of where an event happened, without GPS coordinates. Processing takes place on the Operator's server via the Anthropic API. Legal basis: performance of a contract.
j) Weather. To show the weather and driving tips, your location is sent to Apple WeatherKit. According to Apple, it is not linked to your Apple ID. Legal basis: performance of a contract.
k) ČHMÚ warnings (Czech Republic only). The App downloads the public file of current warnings from the Czech Hydrometeorological Institute and determines the administrative district for your location directly on the device. Your location is not sent to ČHMÚ; as the server operator, ČHMÚ sees only the IP address of the request.
l) Speed limits. During a trip, roughly once every 1–2 km, the coordinates of the area around your location are sent, without a user identifier, to the Overpass API service (overpass-api.de) to load OpenStreetMap map data. The service operator sees the IP address of the request. Road signs (stop signs, crossings, level crossings, traffic lights) are downloaded as files covering an area of roughly 10 × 10 km from Firebase Hosting (Google); a request reveals only that area and the IP address. If you enter a destination, the search text, the coordinates of your stops and your location are sent to Apple Maps (MapKit) to find the address and calculate the route and arrival time; Apple does not associate this data with your Apple ID. Recent destinations and your saved home and work addresses are stored only on your device. Legal basis: performance of a contract.
iOS permissions and whether you must provide data
You grant access to location, motion sensors and notifications in iOS and can change it at any time in the iPhone Settings. A system permission is a technical precondition for features, not a legal basis for processing under the GDPR.
Providing personal data is neither a statutory nor a contractual requirement. The data described in point 3(a)–(c) and (g)–(l) are necessary for the respective features, which cannot be used without them. Consent to usage statistics and taking part in the survey are entirely voluntary, and declining has no effect on the App's features.
Recipients
We do not sell personal data or use it for advertising. Recipients are:
- Google Ireland Limited and Google LLC (Firebase Authentication, Cloud Firestore, Cloud Functions, Analytics, App Check) as processor
- RevenueCat, Inc., USA (subscription management) as processor
- Anthropic, PBC, USA (support chat and AI summaries) as processor; under its commercial terms it does not use API message content to train models
- Apple Distribution International Ltd. and Apple Inc. (App Store, iCloud, WeatherKit, Apple Maps, App Attest); Apple processes purchase data as an independent controller
- the operator of the Overpass API service (Germany) and the Czech Hydrometeorological Institute to the extent described in point 3(k) and (l)
- other members of groups you join, to the extent described in point 3(b)
- public authorities where required by law
Transfers to third countries
Some recipients are established in or process data in the USA. Transfers rely on the European Commission's adequacy decision (EU–US Data Privacy Framework) for certified recipients and otherwise on standard contractual clauses approved by the European Commission (Article 46(2)(c) GDPR). We will provide information about the safeguards used on request.
Retention
- Account, leaderboard, groups and votes: for as long as the account exists. After the account is deleted, the data are removed without undue delay, and from the provider's backup systems within its standard periods.
- Usage statistics: data linked to the instance identifier for no longer than 14 months, then only aggregate reports without identification.
- Subscription: for the duration of the relationship and afterwards for as long as required by law; Apple and RevenueCat according to their own rules.
- Support chat and survey: for as long as needed to handle them, at most 24 months.
- Security and server logs: generally no longer than 30 days.
- Data on your device and in iCloud: until you delete them (Settings → App data, Settings → Account → Delete Account) or uninstall the App.
Your rights
Under the GDPR you have the right:
- of access (Article 15)
- to rectification (Article 16)
- to erasure (Article 17)
- to restriction of processing (Article 18)
- to data portability (Article 20)
- to object to processing based on legitimate interest (Article 21)
- to withdraw consent at any time (Article 7(3))
- to lodge a complaint with a supervisory authority (Article 77)
You can exercise your rights by email at vojtajess@gmail.com or through the support chat, free of charge. We will reply within one month; in complex cases this may be extended by a further two months, and we will let you know in time. If we have reasonable doubts about your identity, we may ask for additional information. You can delete your account and Firebase data yourself in the App (Settings → Account → Delete Account).
The supervisory authority in the Czech Republic is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz. You may also lodge a complaint with the supervisory authority in the country where you live or work.
Security
Data are transmitted encrypted (TLS). Only the Operator has access to server data. The databases are protected by access rules that let each user write only their own data, and by App Check.
Age
The App is intended for drivers. It is not intended for anyone under 16, and we do not knowingly process their personal data.
Changes
We update this policy as the App and the law evolve. We will inform you in the App about material changes. If a new purpose of processing requires consent, we will ask for it in advance.
This policy is effective from 18 September 2026.
WorthIt
Effective from September 28, 2026
What the app does
WorthIt judges whether a specific product is worth buying at its current price. The input is a product link from an online shop, a screenshot from a shop, or a product name.
What is sent to the server
The link, screenshot or name you enter is sent through Anthropic's API (Claude), which acts as a processor: it identifies the product, loads the shop page and looks up comparison prices at other shops. The data sent is not used to train models.
A screenshot contains whatever it captured — before uploading one, check that it does not include your personal data (name, address, cart contents, an email inbox in the background).
The finished result of a link or name analysis is kept for 6 hours in a shared cache in Firestore (Google/Firebase, europe-west3 region), with no user identifier of any kind. Anyone who enters the same link or name in the same language and currency during that time gets the same result without a new request to the model. Screenshots are never cached. Expired entries are deleted once a day. The only part of a result stored permanently is the price record described in section 4.
The sources card in a result loads the logos of the sites the analysis drew on directly from those sites — just as if you opened the page in a browser.
What stays on the device only
- your analysis history
- favourite products
- chosen currency and language
- the counter of free analyses in the current month
- a link shared from another app via “Share → WorthIt”, until WorthIt picks it up (30 minutes at most)
None of this is synced to the cloud. Deleting the app deletes it.
Shared price archive
When you submit a product link, the price the server read from the shop's page is stored in Firestore (Google/Firebase, europe-west3 region), together with the product name, the shop name and the date. This lets another user who looks at the same product later see how the price actually moved.
No user identifier is stored with this record — not even an anonymous one. The archive therefore cannot reveal who viewed a product, nor link several searches together.
Only prices from a link the server fetched itself are stored. A price entered as text or taken from a screenshot never enters the archive. Alongside this, a count of how often each product was searched is kept so the app can show the most-searched products — again with no link to any user.
Price watching and notifications
When you turn on price watching, the following is written to Firestore (Google/Firebase, europe-west3 region): an anonymous user identifier from RevenueCat, the product link, its name and image, the current and target price, currency, language and the date of the last check. No name, no email, no account — the identifier is random and not linked to your identity.
Once a day the server re-checks the product's price, and when it drops to your target price it sends a push notification via Firebase Cloud Messaging and the Apple Push Notification service. A device registration token for notifications is stored for that purpose.
You can turn watching off in the app at any time — the product record is deleted from the server immediately. Once you are no longer watching anything, the notification registration token is deleted too.
Limits against abuse
WorthIt Pro includes up to 20 analyses a week and the app’s interface is public, so the server counts analyses that actually call the model (a cached result does not count). Only a count and the time of the last change are written to Firestore (Google/Firebase, europe-west3 region): one counter per calendar week for the anonymous RevenueCat identifier (the same one used for price watching), and one per day for a fingerprint of the IP address. The fingerprint is an HMAC-SHA-256 with a key known only to the server — the IP address itself is not stored and cannot be recovered from the fingerprint.
An analysis pack (a one-time purchase) adds a balance of unused analyses to the same anonymous identifier, together with Apple’s transaction id so that one purchase cannot be credited twice. Unlike the counters, that balance is not deleted after 14 days — it stays until you use it up.
No analysis content is stored with the counters. The records are deleted automatically after 14 days.
Purchases
WorthIt Pro subscriptions are handled by Apple via In-App Purchase and managed through RevenueCat. The app never sees or stores payment details — they stay with Apple. RevenueCat works with an anonymous identifier, not a name or email.
An analysis pack is a one-time Apple In-App Purchase. The server verifies it directly from Apple’s signature on the transaction; no payment details ever reach us.
What the app does not collect
- name, email or contact details
- location
- advertising identifiers (IDFA)
- contacts, calendar or photo library (only the screenshot you pick yourself is uploaded)
Feedback
The app offers a short survey (3 multiple-choice questions plus a free-text field), shown automatically after a few completed analyses, or any time from Settings → Feedback.
Answers are stored in Firestore (Google/Firebase, region europe-west3) along with the app version, language, and an anonymous RevenueCat identifier — the same one the app uses for price watching. No name or e-mail is stored; don't put anything in the free-text field you wouldn't want to share.
At the end of the survey the app asks whether you'd like us to get back to you. If you choose "Yes" and enter your e-mail, the support chat opens with your answers pre-filled. The message and e-mail are stored as a support ticket under section 4 of the general part; the survey answers themselves stay without an e-mail address.
Anonymous usage statistics
To improve the app, it sends daily counts: how often each screen was shown, on which screen the app went to the background, and how often the WorthIt Pro offer was shown and for which feature it ended in a purchase. Only these totals are sent, without any user or device identifier and without links, screenshots or any content of your analyses. They are stored in Firestore (Google/Firebase, region europe-west3) and cannot be linked to a specific person.
Contact
Reach out via Support.
Blurt
Effective from September 28, 2026
What the app does
Blurt is a voice notes app. You record a note on Apple Watch, your iPhone transcribes it and files it into a category (shopping, work, ideas…) on its own. The core principle: the content of your notes is processed only by your devices, not by our servers.
What stays on your device and in your iCloud
- Recordings, transcripts, categories and their keywords
- App settings (transcription language, recording clean-up, interests picked during onboarding)
- Subscription status, shared between iPhone and Apple Watch
Data is stored on your device and, if iCloud is on, in your private iCloud storage (Apple CloudKit) so it syncs between iPhone and Apple Watch. I have no access to that storage and I am not the controller of that data. Recordings travel between Apple Watch and iPhone directly via Apple Watch Connectivity.
Speech transcription
Transcription runs on your iPhone using Apple's speech recognition (Speech framework). Neither recordings nor transcripts are sent to my server for transcription. iOS downloads the Czech or Slovak language model from Apple on first use. Categorisation and detecting a due date ("tomorrow at 12:00") or priority ("urgent") happen on the device using rules, with no cloud AI.
Reminders
When you send notes to Reminders, manually or automatically for a chosen category, the app writes them into the Reminders app on your device, including the detected due date, alert and priority. This needs your permission in iOS, which you can revoke any time in iPhone Settings. Reminders are then handled by Apple under its own terms.
Subscription
Blurt Premium is purchased through Apple In-App Purchase. Only Apple sees payment details. The app verifies purchases directly with Apple (StoreKit), with no other third-party service and no user account.
Anonymous usage statistics
To improve the app, it sends daily counts: how often each screen was shown, on which screen the app went to the background, and how often the Blurt Premium offer was shown and for which feature it ended in a purchase. Only these totals are sent, without any user or device identifier and without any content of your notes or recordings. They are stored in Firestore (Google/Firebase, region europe-west3) and cannot be linked to a specific person.
Survey and support
The survey in Settings is optional. Answers are stored in Firestore (Google/Firebase, region europe-west3) with only the app version and language, without any user or device identifier and without an e-mail. If you choose to be contacted, the process in section 4 of the general part applies: the support chat opens with your answers pre-filled and the e-mail you enter yourself.
The in-app support chat works as described in section 4 of the general part. The app never attaches note content or recordings automatically; only what you type into the chat is sent.
What the app doesn't collect
- Note content or recordings on my servers
- Location
- Contacts, calendar or photos
- Advertising identifiers (IDFA) or statistics linked to you (the counts in section 6 are anonymous totals)
- Your name or e-mail, unless you enter it in the support chat
Retention and deletion
You can delete notes directly in the app. The app can delete recording audio automatically after a period you choose (Settings → Recordings); the note text stays. Delete iCloud data in iPhone Settings → [your name] → iCloud. Survey answers and support tickets are kept for at most 24 months; you can ask for earlier deletion under section 7 of the general part.
Contact
Reach out via Support or straight from the app (Settings → Support).
Migrelog
Effective from September 19, 2026
What the app does
Migrelog is a headache diary. You log an attack and medication on Apple Watch or iPhone, with a tap or by voice. The app adds up monthly totals and, on request, prepares a PDF for your doctor. It only records data: it does not diagnose, assess your health, recommend treatment, and it is not a medical device.
Core principle: records about your health are processed only by your own devices. They are never sent to my server.
Health data stays with you
- Attack records: start and end, type of pain, intensity, location, symptoms and notes
- Medication taken, stock, purchases and their price
- Sleep and cycle day, if the app adds them from Health (section 4)
- Optional “possible trigger” tags, the attack’s impact on your day, pain two hours after medication and preventive treatment doses
This is data concerning health, a special category of personal data under Art. 9 GDPR. It is stored only on your devices (iPhone and Apple Watch) and is not synced via iCloud. It is part of your regular iPhone backup, which you control. Between Apple Watch and iPhone it is transferred directly via Apple Watch Connectivity. I have no access to this data and I am not its controller.
Doctor visits stay on the iPhone
Your doctor, the practice's contact details, appointment dates, questions for the doctor and visit notes stay on your iPhone only. They are not synced via iCloud and never appear in the PDF export.
Apple Health
Connecting to Health is optional and works only with your permission in iOS. The app reads how long you slept before an attack and menstrual data, to add sleep and cycle day to the record. It writes attacks as “Headache” with a severity. It reads nothing else from Health.
Health data is never sent anywhere, never used for advertising and never shared with anyone. You can revoke access at any time in iPhone Settings → Privacy & Security → Health → Migrelog.
Voice entries
A recording from the watch is transferred to the iPhone (or you record it on the iPhone directly) and transcribed on the iPhone itself using Apple's speech recognition. It is not sent to my server. The app extracts pain type, location, intensity and medication from the sentence itself using fixed rules, without cloud AI. The recording is deleted as soon as you confirm the entry. The language model is downloaded by iOS from Apple.
Export for your doctor
The PDF is created on the iPhone. It contains records for the chosen period and monthly totals, without your name, address, national ID number or any details about your doctor. You decide whom you send or print it for.
Reminders
The appointment reminder, the low-stock alert, the next preventive dose reminder and the “How is it now?” question two hours after medication are local notifications scheduled on the device (the answer is only written to the diary). They need no server and can be turned off in the app's or iPhone's Settings.
Subscription
Migrelog Premium is bought through Apple In-App Purchase. Only Apple sees payment details. The app verifies purchases directly with Apple (StoreKit), without other third-party services and without a user account.
Anonymous usage statistics
To improve the app, it sends daily counts: how often each screen was shown, on which screen the app went to the background, and how often the paywall was shown and for which feature it ended in a purchase. Only these totals are sent, without any user or device identifier and without any content of your records. They are stored in Firestore (Google/Firebase, region europe-west3) and cannot be linked to a specific person.
Survey and support
The survey in Settings is optional and does not ask about your health: it asks how you heard about the app, why you use it, how you log and whether it helped at the doctor's. Answers are stored in Firestore with only the app version and language, without an identifier or e-mail. If you want to be contacted, section 4 of the general part applies.
Support chat works as described in section 4 of the general part. The app never attaches your records or recordings; only what you type is sent. Please do not write details about your health into the chat or the survey. If you do anyway, I will use them only to handle your request and delete them on request.
What the app does not collect
- Records, recordings or Health data on my servers
- Name, e-mail or an account (an e-mail only if you give it to support yourself)
- Location
- Contacts, calendar or photos
- Advertising identifiers (IDFA)
Retention and deletion
You delete records, medication and doctor details directly in the app; deleting the app removes everything that exists only on the device. Attacks written to Health are deleted in the Health app. Survey answers and support tickets are kept for at most 24 months; you can ask for earlier deletion under section 7 of the general part. Anonymous daily totals contain no personal data.
Contact
Write via Support or directly from the app (Settings → Contact support).
Limi
Effective from September 28, 2026
What the app does
Limi is a personal overview of your habits and what they cost. You log what you want to track (cigarettes, coffee, time on social media, water or anything of your own), and the app works out amounts, money and trends. It doesn't judge and doesn't recommend anything.
The core principle: your entries are processed only by your own devices. They are never sent to my server. Limi has no account and no ads. The only things that reach a server are the anonymous daily counts described in section 10 and whatever you send yourself in the survey or the support chat (section 9).
What is stored and where
- Habits: name, icon, colour, unit, price, usual amount and goal
- Entries: amount, time, price at the time of the entry and an optional note
- Savings goals: name, target amount and money set aside
- App settings: currency, appearance and whether you have Limi Plus
Everything is stored only on the device, in the app's shared storage (App Group) so that widgets on your iPhone can read it too. I have no access to this data and I am not its controller.
Sensitive habits
What you track is up to you. Some habits may reveal information about health or sex life (special categories of data under Art. 9 GDPR). They are treated like everything else: they stay on the device and, optionally, in your iCloud, and go nowhere else.
You can mark a habit as private. It then doesn't appear in widgets, Control Center, on Apple Watch or in Siri, and is never sent to the watch.
iCloud sync
Sync is optional and is turned on in the app's Settings (Limi Plus). Data is then copied to your private iCloud database (CloudKit) at Apple, signed in with your Apple Account. I can't see this database and have no access to it. Processing is governed by iCloud's terms. The app works without iCloud and offline.
Apple Watch, widgets, Siri and Shortcuts
The watch receives only today's habit status (without private habits) directly from the iPhone via Apple Watch Connectivity, without a server. Widgets, Control Center controls and Siri and Shortcuts actions run on the iPhone and read the same local data. Siri voice requests are processed by Apple under its own policies.
Reminders, the evening fill-in and the weekly summary are local notifications: iOS schedules them right on your iPhone, with no server and no push service. Tapping a button in a notification (also on Apple Watch) records the entry only on your iPhone. The “Good to know” card only links to public sources (WHO, EFSA and others). Their website opens only when you tap the link, and the app passes nothing to it.
Apple Health
Connecting to Health is optional, part of Limi Plus and turned on for each habit separately. The app then reads only the type you choose for that habit: steps, exercise minutes, mindful minutes or water intake. It writes nothing to Health and reads nothing else from it.
Daily totals from Health are stored only in a local file on the iPhone that is excluded from backup. They are not synced via iCloud, not sent to any server, not used for advertising and not shared with anyone. The watch receives only today's total, directly via Apple Watch Connectivity. You can revoke access at any time in iPhone Settings → Privacy & Security → Health → Limi.
Export
CSV export is created on the iPhone. Where you send or save the file is your decision.
Purchases
Limi Plus is bought via Apple In-App Purchase, as a subscription or a one-time purchase. Only Apple sees payment details. The app verifies purchases directly with Apple (StoreKit), without other third-party services and without a user account.
Survey and support
The survey in Settings is optional: it asks how you heard about the app, why you use it, what kind of habits you track (you can answer “I'd rather not say”), what helps you and how the app feels to you. It never asks about specific habits, amounts or money. Answers are stored in Firestore with only the app version and language, without an identifier or e-mail. If you want to be contacted, the support chat opens with your answers pre-filled and the e-mail you enter yourself, and section 4 of the general part applies.
Support chat works as described in section 4 of the general part. The app never attaches your habits or entries; only what you type is sent. If you share sensitive details in the chat (for example about your health), I will use them only to handle your request and delete them on request.
Anonymous usage statistics
To improve the app, it sends daily counts: how often each screen was shown, on which screen the app went to the background, and how often the Limi Plus offer was shown and for which feature it ended in a purchase. Only these totals are sent, without any user or device identifier and without habit names, amounts, money or any other content of your entries. They are stored in Firestore (Google/Firebase, region europe-west3) and cannot be linked to a specific person.
What the app does not collect
- Entries or habits on my servers
- Name, e-mail or account (e-mail only if you enter it for support yourself)
- Statistics linked to you: the counts in section 10 are anonymous totals without an identifier
- Crash reports other than those collected by iOS itself with your consent in Settings
- Location, contacts or photos
- Health data outside your iPhone
- Advertising identifiers (IDFA) or cross-app tracking
Retention and deletion
Delete entries, habits and goals directly in the app. Deleting the app removes everything on the device. Delete iCloud data in iPhone Settings → [your name] → iCloud → Manage Storage → Limi. If you contact me through support, section 4 of the general part applies to your message. I keep survey answers and support tickets for at most 24 months. You can ask for earlier deletion under section 7 of the general part.
Contact
Write via Support.