Privacy Policy

Last updated: 2026-07-27

2Veo Tracker ("the app") helps you track migraines and other medical conditions, and is expanding to support more conditions over time. This policy explains what data the app handles and how. We aim to collect as little as possible.

Who we are

2Veo Tracker is an independent app. We are the data controller for the limited data described below.

What we collect

Prescription and inhaler scanning

When you import a photo or PDF of a prescription or inhaler to fill in a medication, the image is processed entirely on your device using Apple's built-in text recognition. The image and the text read from it are never uploaded to us or any third party — they do not leave your device, and we never see them. Only the medication details you review and confirm are saved, and then only as part of your own entries (stored as described below). Discard the scan and nothing is kept.

Where your data is stored

Your personal tracking data is stored in your own private iCloud (Apple CloudKit) database. We do not run separate servers for it and cannot read your private database.

A few small categories of records are stored in CloudKit's shared (public) database: research contributions (described below), feedback you submit, a doctor "invite" record (for medical professionals — your name, speciality, and a public key patients use to secure a connection), and, when you connect with a doctor, a "connection" record (see "Sharing with your doctor"). Feedback and research records carry no personal identifiers in their content; CloudKit binds them to your iCloud identifier in system metadata, but read access is restricted so that only the developer can see them. The doctor invite record is intentionally readable by patients who hold the code, because that's how the connection works. The connection record holds no readable personal or health data — its contents are encrypted so that only the specific doctor you chose can read them.

Sharing with your doctor

Sharing is entirely under your control. The clinician publishes a reusable invite code; you enter (or scan) the code, confirm who you're connecting to, and choose which conditions to share. Your device then creates the share and adds the clinician using their Apple iCloud identity (no email address is involved).

So the clinician's device can find and accept the share, your device publishes a small "connection" record to CloudKit's shared database. The connection details in it — which doctor, which condition, and the link to the shared data — are encrypted so that only the clinician you chose can read them; to anyone else it is an opaque record with no readable personal or health data. Like every CloudKit record it carries, in Apple's automatic system metadata, the anonymous iCloud identifier of your account as its creator. This means another signed-in user could in principle tell that *some* (unnamed) person started a connection, but not who you connected to — the patient ↔ doctor relationship is never publicly readable.

The clinician you connect with can see your name and the data for the conditions you chose to share — and only those. You can revoke access per-condition (or entirely) from Settings → Sharing at any time; revoking also deletes the connection record.

Contributing to research

To support medical research, the app contributes an anonymised copy of the episode data for the conditions you track — for migraine, things like intensity, duration band, triggers, and the specific medications and dosages you took; for asthma, your peak-flow reading (and its band as a proportion of your personal best), your personal-best peak flow, control zone, symptoms, the inhalers you use (and the puffs you took from each), and any add-on therapy you logged; for post-dural puncture headache (PDPH), its intensity, whether it is postural (worse when upright), its impact on your daily activities, where the pain sits, and whether you have had a blood patch; plus a coarse date and your approximate location — the country and time zone your device is set to (taken from your device settings, not from GPS or any precise location).

What is in a research record:

Who can see your research records, and what they actually see:

The combination of coarsened dates, no notes, no exact times, only a coarse location (country and time zone, never a precise position), and a random participant ID means that on its own, a research record cannot be linked back to a named person.

Contributing is on by default and you can turn it off at any time in Settings → Research. Turning it off deletes everything you have contributed.

What we do NOT do

Retention and deletion

Your tracking data remains until you delete it. Deleting your account from Settings removes your data from CloudKit. Anonymised research contributions can be withdrawn by turning off research contribution in Settings.

Age and children

2Veo Tracker is rated 16+ on the App Store (15+ in Korea, per the local rating), and is not directed at, or intended for, anyone under that age. We do not knowingly collect data from users below those ages. If you become aware that a child has used the app and submitted data, contact us via the in-app Feedback → Question flow and we will delete it.

Changes

We may update this policy. Material changes will be surfaced in the app for you to review.

Contact

Questions about this policy? Send us a message from Settings → Feedback in the app and choose the Question type so you can leave a reply-to email — that's the only way we can write back, as other feedback is anonymous.