the formal version of a simple idea: your health data stays yours. this exact text ships inside the app.
This Privacy Policy describes how the baro application ("baro", "the App", "we", "us") handles information when you use the App. baro is designed on a local-first principle: your personal health information is stored on your device (and, where enabled, in your own private iCloud storage, which we cannot access — Section 3) and is not transmitted to, stored on, or accessible by our servers, except as expressly described in Section 6 (Optional De-Identified Contributions) with your prior consent, or when you choose to write to us (Section 7, In-App Feedback).
The App stores the following categories of information in local storage on your device: (a) headache entries, including date, time, pain level, duration, and notes; (b) menstrual cycle entries, including start and end dates and notes; (c) daily check-in answers (your confirmation that a day was headache-free, or not), including when and how you answered; (d) a record of the days on which you used the App, kept so your statistics only draw on days you were actually around to log; (e) your chosen city and its geographic coordinates; (f) derived pressure-sensitivity thresholds ("calibration"); (g) your year of birth, used exclusively to determine the applicable feature tier (Section 9), and, if provided, your stated sex (Section 9); (h) if your device has a barometric sensor and you allow motion access, pressure readings taken by your device, including a reading attached to each headache you log and a rolling record of roughly the last two days; and (i) a cached copy of publicly available weather data for your chosen city. We do not receive, process, store, or have any means of accessing this information. If you export a backup file from Settings, that file contains your health information in readable form and is under your control — treat it with the same care as the data itself.
The App stores your personal records (headache entries, cycle entries, check-in answers, usage-day record, and profile) in a private database in your personal iCloud account, using Apple's CloudKit service, so that your data survives device changes and reinstalls. This synchronization is part of how the App works rather than an operating-system backup: the App writes to your private iCloud database directly. The database belongs to your Apple Account; neither we nor any other baro user can read it, and we operate no server that ever holds a copy. Synchronization follows your device's iCloud settings — disabling iCloud for baro in the operating system stops it. The locally cached weather data (Section 2(i)) is deliberately never synchronized. Apple's processing of your iCloud data is governed by Apple's terms and privacy policy.
To display the weather forecast and pressure-risk assessment, the App sends the geographic coordinates of your chosen city and, where available, your locally derived calibration thresholds to our weather service, which in turn retrieves meteorological data from a third-party weather data provider (currently Open-Meteo). Our servers are located in the European Union. These requests are processed transiently to answer the request and are not linked to any account or profile. Standard technical data inherent to network communication (such as your IP address) is recorded in routine server logs kept for security and reliability and automatically deleted within approximately 30 days; it is not used to identify you or for profiling. Your chosen city is a location you select manually; the App does not track your movements. If you use the optional "use my location" feature, your device resolves your position to a city locally; continuous location tracking does not occur.
The App is fully functional without creating an account. If account functionality is introduced in the future, it will be optional and governed by a revised version of this Policy communicated to you in advance.
With your prior, explicit, and freely given consent — requested in the App and switched off by default — the App may transmit de-identified contributions to our servers for the sole purpose of improving the accuracy of pressure-drop alerts for all users. Contributions comprise three kinds of records: (a) headache records, describing weather conditions around a headache you logged; (b) comparison records, describing weather conditions on a small sample of days on which you used the App and did not log a headache; and (c) alert-outcome records, describing whether the severity a fired alert claimed matched the weather that subsequently occurred (limited to the claimed level, the outcome category, the alert's lead-time setting, the calendar month, and the coarse climate classification and hemisphere described below). Comparison records are what make the statistics honest — without them, no baseline exists. Each record is limited to: barometric and meteorological measurements (pressure, pressure changes over 3–24 hours, temperature, humidity, precipitation, weather code); where available, the change in pressure measured by your device's own barometer over the preceding hours (only ever the change — never the absolute reading, which could reveal your altitude); the risk level the App displayed that day; a coarse climate classification and hemisphere derived on your device from your chosen city; your chosen city; the calendar month and a coarse time-of-day category; whether a headache occurred, and if so its pain level and approximate duration category; and — only if you additionally enable the second, separate toggle — a yes/no indication of whether the day fell within a logged menstrual cycle (included on both headache and comparison records, as the comparison is otherwise statistically meaningless). Contributions never include your name, contact details, account identifiers, device identifiers, advertising identifiers, GPS coordinates, or the exact date or time of any event. Contributions are collected on your device and transmitted in periodic batches, ordinarily no more than once per week, or upon the next use of the App following a period without connectivity. Contributions are retained in de-identified form and may be re-analyzed as our statistical methods improve; they are deleted upon withdrawal of consent as described in Section 8. Contributions are keyed by a randomly generated token created on your device. The token allows contributions from the same device to be analyzed as a series, and allows you to delete them; it is not linked to your identity. Each record additionally carries a random one-time identifier used solely to prevent the same record being stored twice if a transmission is retried. To the extent this data constitutes personal data (including data concerning health) under applicable law, the legal basis for processing is your explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR).
If you use the feedback function, we receive what you choose to send: the feedback category, your message, and — only if you attach them — a screenshot and basic device information (App version, device model, system version) to help us reproduce problems. Feedback is direct correspondence: it is stored so we can read it, respond to it where possible, and fix what it reports, and it is not combined with contributions under Section 6 or used for any other purpose. Please do not include health details in feedback unless you are comfortable sharing them with us in identifiable form; anything you write is transmitted as written. The legal basis is our legitimate interest in operating and improving the App (Art. 6(1)(f) GDPR) and, for any health information you volunteer in your message, your explicit consent expressed by sending it (Art. 9(2)(a) GDPR).
You may withdraw your consent at any time in Settings. Upon withdrawal, the App instructs our servers to delete all contributions associated with your token, and the token stored on your device is discarded and replaced, so that any future opt-in cannot be linked to past contributions. Because your health logs are stored only on your device and in your private iCloud database, you may export or delete them at any time using the corresponding functions in Settings, or by deleting the App (for iCloud copies, also delete baro's iCloud data in your device's iCloud settings).
The App is not directed to children under 13 years of age, and use by persons under 13 is not permitted. For users aged 13 to 15, cycle tracking and the optional contribution program described in Section 6 are unavailable. Your year of birth — and, if you choose to answer the optional question during setup, your stated sex — are stored only on your device; neither is ever transmitted. Your year of birth determines the applicable feature tier; your stated sex is used solely on your device to select statistical starting assumptions for your personal insights.
We do not sell, rent, or trade any information, and we do not use any information for advertising, marketing profiles, or cross-service tracking. The App contains no third-party analytics or advertising software.
Your local data is protected at rest by your device's built-in encryption (provided your device has a passcode), all network communication uses encrypted connections (TLS), and iCloud synchronization uses your private, access-controlled database. Health information does not leave your device except as described in Sections 3, 6 and 7. Backup files you export are not additionally encrypted by the App; you are responsible for storing them safely, and for securing your device itself.
Where the GDPR or similar legislation applies, you have rights of access, rectification, erasure, restriction, portability, and objection with respect to personal data we process, and the right to lodge a complaint with a supervisory authority. Because we cannot identify you from de-identified contributions, exercising these rights for Section 6 data is performed through the in-App deletion mechanism (Section 8), which does not require us to identify you. For feedback correspondence (Section 7), contact us at the address in Section 14. For data stored only on your device or in your private iCloud database, these rights are exercised directly through the App's export and deletion functions and your device's iCloud settings.
We may update this Policy from time to time. Material changes will be communicated in the App before they take effect. The version and effective date are shown below.
For privacy inquiries, contact: privacy@heybaro.app. Version 1.1, effective 19 August 2026.