Privacy Policy
Last updated: 2026-07-27
2Veo Tracker ("the app") helps you track migraines and other medical conditions, and is expanding to support more conditions over time. This policy explains what data the app handles and how. We aim to collect as little as possible.
Who we are
2Veo Tracker is an independent app. We are the data controller for the limited data described below.
What we collect
- Account: When you sign in with Apple, we receive a stable Apple user identifier and, if you choose to share it, your name and email. Apple may provide a private-relay email instead of your real address.
- Health tracking data: The entries you log for the conditions you track — for example intensity, times, triggers, head locations, medications, notes, and similar details.
- Apple Health (optional): If you grant access, the app reads sleep, heart rate, and step data to show correlations, and your tracked medications to help pre-fill entries. It can write the entries you log back to Apple Health — for example headache events and asthma peak-flow and inhaler readings. This data is read on your device and is not uploaded by us except as part of your own entries.
- Diagnostics in feedback: If you send feedback, we include the app version, OS version, device model, and your device's region (a two-letter country code like "GB" or "US", read from iOS — no IP geolocation) to help us reproduce issues and understand where users are. Bug reports and feature requests carry no personal identifiers in their content. Feedback records are bound to your Apple iCloud identifier by CloudKit automatically, but are visible only to the developer — other users of the app cannot read them. If you send a question and want a reply, we also store the reply-to email you enter on that form — used only to respond to you, and never required for other feedback.
Prescription and inhaler scanning
When you import a photo or PDF of a prescription or inhaler to fill in a medication, the image is processed entirely on your device using Apple's built-in text recognition. The image and the text read from it are never uploaded to us or any third party — they do not leave your device, and we never see them. Only the medication details you review and confirm are saved, and then only as part of your own entries (stored as described below). Discard the scan and nothing is kept.
Where your data is stored
Your personal tracking data is stored in your own private iCloud (Apple CloudKit) database. We do not run separate servers for it and cannot read your private database.
A few small categories of records are stored in CloudKit's shared (public) database: research contributions (described below), feedback you submit, a doctor "invite" record (for medical professionals — your name, speciality, and a public key patients use to secure a connection), and, when you connect with a doctor, a "connection" record (see "Sharing with your doctor"). Feedback and research records carry no personal identifiers in their content; CloudKit binds them to your iCloud identifier in system metadata, but read access is restricted so that only the developer can see them. The doctor invite record is intentionally readable by patients who hold the code, because that's how the connection works. The connection record holds no readable personal or health data — its contents are encrypted so that only the specific doctor you chose can read them.
Sharing with your doctor
Sharing is entirely under your control. The clinician publishes a reusable invite code; you enter (or scan) the code, confirm who you're connecting to, and choose which conditions to share. Your device then creates the share and adds the clinician using their Apple iCloud identity (no email address is involved).
So the clinician's device can find and accept the share, your device publishes a small "connection" record to CloudKit's shared database. The connection details in it — which doctor, which condition, and the link to the shared data — are encrypted so that only the clinician you chose can read them; to anyone else it is an opaque record with no readable personal or health data. Like every CloudKit record it carries, in Apple's automatic system metadata, the anonymous iCloud identifier of your account as its creator. This means another signed-in user could in principle tell that *some* (unnamed) person started a connection, but not who you connected to — the patient ↔ doctor relationship is never publicly readable.
The clinician you connect with can see your name and the data for the conditions you chose to share — and only those. You can revoke access per-condition (or entirely) from Settings → Sharing at any time; revoking also deletes the connection record.
Contributing to research
To support medical research, the app contributes an anonymised copy of the episode data for the conditions you track — for migraine, things like intensity, duration band, triggers, and the specific medications and dosages you took; for asthma, your peak-flow reading (and its band as a proportion of your personal best), your personal-best peak flow, control zone, symptoms, the inhalers you use (and the puffs you took from each), and any add-on therapy you logged; for post-dural puncture headache (PDPH), its intensity, whether it is postural (worse when upright), its impact on your daily activities, where the pain sits, and whether you have had a blood patch; plus a coarse date and your approximate location — the country and time zone your device is set to (taken from your device settings, not from GPS or any precise location).
What is in a research record:
- Anonymised episode fields only (the clinical content above). No name, email, account identifier, free-text notes, or exact times.
- A participant ID — a random identifier created the first time you contribute, stored locally on your device. It is not derived from your name, email, Apple ID, or any other personal data, and we cannot use it to identify you. Researchers need it so they can recognise that several records came from the same anonymous person (for example, to study patterns over time) without ever knowing who that person is.
Who can see your research records, and what they actually see:
- Other users of the app cannot see your records at all. Read access is restricted to the developer at the database level, so no other person using 2Veo Tracker can list, search, or read research contributions.
- The developer, viewing the records, sees the anonymised fields above plus an opaque identifier that Apple's CloudKit attaches to every record so that you can withdraw what you contributed. That identifier is a random-looking hash, not your name, email, or anything readable — and we have no way to reverse it to find out who you are. In practice, looking at a research record tells us what the episode was like, but not who recorded it.
- Apple, as the operator of iCloud, knows which iCloud account is behind each identifier — the same way they know who owns any iCloud-backed data on your phone. We don't see that mapping, we don't ask for it, and we can't request it. This is true of every iCloud-backed app on your device, not just 2Veo Tracker.
- External research collaborators receive only the anonymised content fields and the random participant ID. Apple's CloudKit identifier and any other system metadata are never included in what is shared outside the app.
The combination of coarsened dates, no notes, no exact times, only a coarse location (country and time zone, never a precise position), and a random participant ID means that on its own, a research record cannot be linked back to a named person.
Contributing is on by default and you can turn it off at any time in Settings → Research. Turning it off deletes everything you have contributed.
What we do NOT do
- We do not sell your data.
- We do not use third-party advertising or tracking SDKs.
- We do not access your private health entries on our own infrastructure.
- We do not upload the prescription or inhaler images you scan — they are read on your device and never sent anywhere.
Retention and deletion
Your tracking data remains until you delete it. Deleting your account from Settings removes your data from CloudKit. Anonymised research contributions can be withdrawn by turning off research contribution in Settings.
Age and children
2Veo Tracker is rated 16+ on the App Store (15+ in Korea, per the local rating), and is not directed at, or intended for, anyone under that age. We do not knowingly collect data from users below those ages. If you become aware that a child has used the app and submitted data, contact us via the in-app Feedback → Question flow and we will delete it.
Changes
We may update this policy. Material changes will be surfaced in the app for you to review.
Contact
Questions about this policy? Send us a message from Settings → Feedback in the app and choose the Question type so you can leave a reply-to email — that's the only way we can write back, as other feedback is anonymous.