Privacy
Last updated 7 September 2026
Threshold handles some of the most personal information there is. This page says exactly what it collects, what never leaves your phone, where the rest goes, and how to get all of it deleted.
The short version. Your Apple Health data is read on your phone and the raw numbers are never uploaded. Your migraine log does sync, so it reaches your other devices and survives a lost phone. You can export everything at any time. There are no ads, no third-party trackers, and nothing is sold to anyone.
Who we are
Threshold is made by Undecided Media, LLC, which is the data controller for the purposes of the UK and EU GDPR.
Undecided Media, LLC125 Westgate Center Drive #1005
Hadley, MA 01035
USA
Privacy questions, requests and complaints: contact@thresholdmigraine.com.
What the app collects
What you enter
The times an attack starts and ends, severity, symptoms, medications and doses, stress ratings, and any notes you write or dictate. This is the record the app exists to keep.
Apple Health
If you grant permission, Threshold reads sleep and heart rate from Apple Health. This happens on your device. The app calculates daily summaries locally and only those summaries are stored or synced. The raw Health samples never leave your phone.
In line with Apple's rules for apps that use HealthKit, Health data is never used for advertising or marketing, never used for data mining, and never disclosed to third parties.
You can revoke this permission at any time in the Health app, and the rest of Threshold keeps working.
Location
When you log an attack, Threshold records your location once so it can look up the weather for that place and time. It is used to derive barometric pressure, temperature and humidity, and it is those weather readings that are stored. Threshold does not keep a continuous location trail and does not track your movement.
Your account
If you sign in, Threshold uses Sign in with Apple and stores the identifier Apple provides. Apple's Hide My Email is supported. Signing in is what makes syncing across your devices possible.
What the app does not collect
- No advertising identifiers, and no advertising of any kind.
- No third-party analytics or tracking SDKs.
- No contacts, photos, microphone recordings (dictation is transcribed by iOS and only the text is kept), or browsing activity.
Where your data is stored
Threshold is local-first. Everything is written to a database on your phone and the app works with no network connection at all.
If you are signed in, your migraine log is also synced to a hosted PostgreSQL database provided by Supabase, in the United States. Access is restricted per account at the database level, so your rows are readable only under your own account. Encrypted backups are held on a private machine we control, in the United States.
If you are outside the United States, this means your information is transferred to and stored in the US. Where the UK or EU GDPR applies, that transfer relies on the European Commission's Standard Contractual Clauses.
We are working toward moving sync to Apple's iCloud so that we hold no user data at all. If that happens, this page will be updated before the change ships.
The website and the email list
thresholdmigraine.com collects nothing on its own. There are no cookies, no analytics and no tracking pixels on it.
If you enter your email address to hear about the release, that address is stored by our email provider, Kit, and is used for exactly two messages: an invitation to the TestFlight beta, and a note when the app is available. You will be asked to confirm the address before anything is sent. Every email has an unsubscribe link, and unsubscribing deletes you from the list.
We will not use that address for anything else, and we will never share or sell it.
Why we are allowed to hold it
Where the UK or EU GDPR applies, our legal bases are:
- Your consent, for health data in the app, for Apple Health access, for location, and for the email list. You can withdraw consent at any time.
- Performance of a contract, for the account and sync that let the app do what you installed it to do.
Health information is a special category of personal data under Article 9, and we rely on your explicit consent to process it.
How long we keep it
Your migraine log is kept until you delete it or delete your account. Delete the account and the synced copy is removed, with backups rolling off within 30 days. Email addresses are kept until you unsubscribe, or until the launch announcement has gone out and the list is closed.
Your rights
Wherever you live, you can:
- Get a copy. Export is built into the app, in a format you can open and read, and it includes every field the app stores. You do not need to ask us.
- Correct anything. Every entry is editable in the app.
- Delete everything. Delete your account in the app, or email us and we will do it.
- Withdraw consent for Health access, location, or email, without losing the rest of the app.
If the UK or EU GDPR applies to you, you also have the right to object to or restrict processing, the right to data portability, and the right to complain to your data protection authority. In the UK that is the ICO.
Washington, Nevada and Connecticut consumer health data
If you are a Washington resident, the My Health My Data Act gives you the right to know what consumer health data we collect, to withdraw consent for its collection and sharing, and to have it deleted. We do not sell consumer health data as that law defines selling, and we would need your separate signed authorisation to do so. To exercise any of these rights, email contact@thresholdmigraine.com. If we refuse a request you may appeal by replying, and you may complain to the Washington Attorney General.
California
We do not sell or share personal information as the CCPA defines those terms, and we do not use it for cross-context behavioural advertising. California residents have the rights listed above and will not be treated differently for exercising them.
Who else touches your data
We use a small number of service providers, each under a data processing agreement, and none of them may use your information for their own purposes:
- Supabase, database hosting for sync.
- Apple, for Sign in with Apple, TestFlight and App Store distribution.
- Kit, for the announcement list only.
- Weather data providers, which receive a location and a date to return conditions. They receive no identity and no health information.
Children
Threshold is not directed at children and we do not knowingly collect information from anyone under 16. If you believe a child has given us information, email us and we will delete it.
Security
Data is encrypted in transit and at rest, access to the database is restricted per account, and backups are encrypted. No system is perfectly secure, and we will tell affected users without undue delay if a breach ever puts their information at risk.
Not medical advice
Threshold reports patterns in the data you give it. It does not diagnose anything, does not recommend treatments or doses, and is not a substitute for talking to a doctor.
Changes
If this policy changes in a way that affects what we do with your information, we will say so in the app before the change takes effect, and the date at the top of this page will change.