Privacy Policy
for the Migraine Compass app and the website migraenekompass.bk-apps.online
In short: Everything you enter in the app stays on your device. There is no account, no sign-in and no cloud, and the app has no server of its own. Only if you use the weather with Plus does a rounded location go to the weather service Open-Meteo. The details are below.
1. Controller
Benedikt KoßmannSchaurain 4 1/2
83101 Rohrdorf
Deutschland
Email: info@stavau.com
Further details are in the Legal Notice. You can also contact this address with any questions about data protection.
2. This website
Hosting
The website is a static site on a server of Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, in the data centre in Helsinki, Finland, i.e. within the EU. There is no transfer to a third country. The website of the app PillenKompass by the same provider is also on this server.
A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner.
Server logs
On every request, the web server (nginx) stores in its access log: the IP address of your device, the time, the request line (method, path, protocol), the status code, the amount of data transferred, the previously visited page (referrer) and the identifier of your browser (user agent, i.e. browser and operating system). A field for a user name always stays empty, because the website has no sign-in. The log is shared by all websites on this server. If an error occurs, the error log also contains the IP address.
Purpose: operating and delivering the website, troubleshooting and defending against attacks. Legal basis: Art. 6(1)(f) GDPR; the legitimate interest is the secure operation of the website.
Storage period: The logs are rotated daily, and 14 daily archives are kept. An entry is therefore stored for at most 15 days and is deleted after 30 days at the latest.
No cookies, no tracking
The website sets no cookies, uses no local storage and no JavaScript, loads no external fonts and nothing from third-party servers (CDN), and contains no tracking. The website stores nothing on your device and reads nothing from it; that is why there is no cookie banner.
3. Your data in the app
Everything you enter in the app stays on your device. There is no account, no sign-in and no cloud; the app has no server of its own. I do not receive your entries.
What the app stores
- attacks: start, end, pain intensity, aura and aura types, pain location, throbbing pain, intensity of nausea, vomiting, sensitivity to light, noise and smells, note, time of creation;
- for each attack the selected triggers, including your own labels;
- your medication list (name, type, active, order) and your intakes with medication name, time, dose information and your rating of the effect;
- reminders with type, label, time, weekdays, on/off and discreet mode;
- symptom entries with date, symptom, intensity and note;
- cached weather days from the Plus weather, without location;
- settings (whether the onboarding has been seen, whether the biometric lock is on, whether the question about exact alarms has already been asked) as well as the hash and salt of your app PIN.
Security
The database is encrypted with SQLCipher. The app generates the 256-bit key randomly on first launch and stores it in storage protected by the Android Keystore. The app is excluded from Android backup and from transfer to a new device: your data ends up neither in a Google backup nor on another device.
One limitation: the notification library stores scheduled notifications, including title and text, unencrypted in the app's own storage. Without discreet mode, the title is the label you gave the reminder, for example a medication name. This file does not leave the device, but it would be readable for someone with access to the app directory (for example on a rooted device). Discreet mode replaces title and text with neutral texts, in this storage as well.
Deletion and storage period
The data remains stored until you delete it or uninstall the app; the app deletes nothing on its own. You delete individual entries in the app: an attack together with its triggers, a medication, a reminder and a symptom entry. If you delete an attack, the medication intakes and symptom entries recorded for it currently remain stored.
You delete all data by uninstalling the app or by choosing "Clear storage" for the app in the Android settings. This removes the database, settings, the reminder storage and the key. There is no "delete all data" function in the app.
Storage on your device is strictly necessary for the diary function you requested (§ 25 Abs. 2 Nr. 2 TDDDG).
4. Weather with Plus (Open-Meteo)
The app itself opens exactly one connection: to the weather service Open-Meteo (archive-api.open-meteo.com),
only with Plus and only in the weather tab of the statistics. Without Plus, nothing goes online.
What is transmitted: your current position, rounded to one decimal place (about 10 km), the requested time period and the requested weather fields. The time period always runs from today back over the period selected in the statistics; it is not derived from your attacks. On which days you had attacks does not leave the device; the app matches weather and attacks on the device. As with any connection, Open-Meteo also sees the IP address of your device.
When: If you have granted the location permission, the app requests the position once per app session when you open the weather tab. Otherwise only when you explicitly tap "Use location" or "Try again". Without a position, no request takes place.
Storage in the app: The rounded position is kept only in memory while the app is running. The app caches the retrieved weather days encrypted and without the position. Older app versions had also stored the rounded position; since the database update to schema version 3, these values are removed on first launch.
Recipient: OpenMeteo GmbH, Switzerland. According to its terms of use, access logs are kept there for 90 days. Switzerland has an adequacy decision of the EU Commission (2000/518/EC); the transfer is permitted under Art. 45 GDPR without additional safeguards.
Legal basis: Art. 6(1)(b) GDPR: the weather request is a function covered by the Plus contract that you explicitly request in the weather tab.
Responsibility: I am responsible for collecting the rounded position and transmitting it to Open-Meteo. OpenMeteo GmbH itself is responsible for the processing at Open-Meteo after receipt, for example the access logs.
5. RevenueCat (not active today)
The app contains the purchase package from RevenueCat. It is not set up today: the app does not call it, and without this call it sends nothing. Today there is no working purchase process in the app yet.
6. Google Play and Android
As soon as purchases of Plus are possible, payment runs through Google Play Billing, not through a server of my own. In Germany and the EU, Google is the contracting party for the purchase. Processing by Google is governed by Google's Privacy Policy.
For the location, the app uses the location services of Google Play services on your device. These determine the position not only via GPS but also via Wi-Fi, mobile network and Google's own location database. This is behaviour of the platform, not a network request made by the app itself.
7. Contact by email
If you write to info@stavau.com, I process your address and your message in order to answer your request. This only happens if you write yourself. If you open the email from the app, the app only opens your mail app with recipient and subject; it attaches no app or Android version, no log and no data.
I run the mail server myself (Mail-in-a-Box) on a rented server of Hetzner Online GmbH in the data centre in Nuremberg, within the EU. No email service provider receives your message on my behalf.
Legal basis: Art. 6(1)(b) GDPR if your request concerns a contract (for example Plus), otherwise Art. 6(1)(f) GDPR (interest in answering enquiries). Storage period: until your request has been dealt with; the message is then deleted. If it is a business letter that must be retained for tax purposes (for example about a purchase of Plus), it remains stored until the end of the statutory period of six years (§ 147 AO).
8. Links from the app
The app opens this Privacy Policy, the Legal Notice and the Terms of Use in your browser and the email in your mail app. The browser loads the page and the mail app sends the email; the app itself opens no connection in doing so.
9. Permissions
The app's manifest contains these Android permissions:
- Location (precise and approximate): only for the Plus weather, see section 4.
- Internet: for the Plus weather; in the free version there is no network traffic (section 10).
- Notifications, exact alarms, start after reboot, vibration: for your reminders.
- Biometrics: for the biometric lock.
Included libraries add the following in the final package: Google Play Billing (purchase), fingerprint (part of the
biometrics library) and network state (Google's library datatransport). A permission for the
advertising ID is not in the package.
10. No advertising ID, no network traffic without Plus
The app uses no advertising ID. The purchase package from RevenueCat brings further modules into the package: a connection to the
Amazon Appstore, Google's library for the advertising ID and Play Billing with Google's logging library
datatransport. The app itself calls none of these modules.
A network capture on the emulator (debug build) has checked this: in the free version, across all main areas, the start and a second start, the app opens not a single connection and resolves no name. This also applies to the libraries mentioned.
11. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) GDPR (Art. 21). To do so, write to info@stavau.com.
Your diary data is stored only on your device; I have no access to it. You manage and delete it yourself in the app (section 3).
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for me is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Postfach 1349, 91504 Ansbach, with an online complaint form at lda.bayern.de.
12. No obligation, no automated decision-making
You are not obliged to provide data. Without location there is no weather request; all other functions work without a connection.
There is no automated decision-making and no profiling (Art. 22 GDPR): your entries do not reach me, and the website uses no tracking.
Migraine Compass is not a medical device and does not replace professional medical advice.
Last updated: 18 September 2026