Summary
- Headmon does not require an account.
- Headmon does not operate a cloud diary or synchronization service.
- Headmon does not include advertising, tracking, third-party analytics or a developer-operated crash-reporting service.
- Diary entries are not sent to the Headmon developer.
- The browser backup viewer processes selected files in memory and does not upload or persist them in browser storage.
- Optional weather features send approximate coordinates to Open-Meteo. No diary content accompanies those requests.
- The Android app requests a small version file from this website at most once every 24 hours while it is opened. No diary content or device identifier is added to the request.
Information stored on your device
Headmon can store diary days, headache and migraine episodes, symptoms, pain levels, medicines, triggers, stress levels, notes, photos, weather context, custom catalog entries, reminders and app preferences. This information is stored locally in the application’s private storage and shared app-group storage needed by Headmon’s own widgets, controls and Live Activities. Headmon excludes this private diary storage from automatic device and cloud backup on both iOS and Android.
Headmon does not transmit this diary information to the developer. Deleting the app removes its private application data, subject to the operating system’s normal deletion behavior. Headmon also provides controls for deleting individual days and resetting all diary data.
Exports, imports and backups
Manual complete ZIP backups, calendar JSON backups, CSV and PDF files are created only when you request them. Recurring complete backup is optional and starts only after you enable it. Headmon keeps the two newest automatic backup files. You choose whether Headmon keeps them in its local-only storage or writes them to a folder you explicitly select through the system Files interface. The selected folder may be on the device or managed by a provider such as iCloud Drive, depending on your choice and system settings. Headmon stores the system-granted folder permission on your device so it can create later backups, but the developer cannot browse or receive files from that folder.
The Headmon backup guide explains what complete and calendar backups contain, what it omits, how storage locations differ and how to move a diary between devices.
Local-only automatic backups remain inside Headmon, use operating-system controls that exclude them from device backup, and are deleted when the app is deleted. A selected Files provider controls its own storage, security, syncing and retention. Copies written outside Headmon can remain after the app is deleted.
Exported files can contain sensitive health information in readable form, including dates, episode times, symptoms, pain levels, medicines, triggers, notes, weather, coordinates and place names. Headmon exports do not add a user account, name, email address, advertising ID, device ID, serial number or hardware identifier. Free-text notes and location history can nevertheless identify a person. Complete ZIP backups, including automatic backups, contain photos, captions and continuous weather history. Calendar JSON backups do not include photo files or continuous weather history.
Export and backup files are readable files, not Headmon-encrypted archives. A photo chosen from the photo library may retain metadata already embedded in that file. Protect exports as you would any other private health record, and delete copies you no longer need.
The browser-based backup viewer processes a selected backup and edits only in the current tab. Its code does not upload backup content or write it to local storage, IndexedDB, a service worker cache or another persistent website store. Closing or reloading the tab discards the working copy unless you explicitly export a file. When the current viewer loads, it also requests deletion of the IndexedDB draft database used by earlier preview versions. Files you export remain wherever your browser or operating system saves them. Browsers and operating systems can still use their own temporary memory, swap, crash recovery, download history or recent-file records; Headmon does not control those platform mechanisms.
Your choices and deletion
You can turn off automatic backup, change its destination, disable weather and location features, revoke location access in system Settings, delete individual diary days, or reset all Headmon data. Files previously exported or written to a selected Files folder must be deleted using that provider. Headmon has no server copy and cannot recover or delete those external copies for you.
Optional location and weather
When you enable weather on iOS, the system may provide a location while Headmon is in use. Apple Maps is used for place search and location labels. Before requesting weather, the iOS app reduces latitude and longitude to two decimal places, which is roughly weather-area precision, and sends those approximate coordinates to Open-Meteo over HTTPS. iOS place-search text and diary content are not sent to Open-Meteo.
The Android app uses Open-Meteo for both manual place search and weather. A manual search sends the entered place text to Open-Meteo. Current-location weather uses Android's approximate-location permission; selecting a place or map pin sends that selected location's coordinates. Diary content is not included in either request.
Open-Meteo states that its free API may retain server logs containing IP addresses and geographic coordinates for technical maintenance, misuse prevention and troubleshooting, and that those logs are deleted after 90 days. Those records are controlled by Open-Meteo, not Headmon. Read the Open-Meteo terms and privacy information.
Android's optional map picker displays OpenStreetMap tiles through MapLibre. Opening or moving that map requests the visible tiles from OpenStreetMap over HTTPS. The OpenStreetMap Foundation states that service logs can include an IP address, application and device type, operating system, request time and the tiles requested. Headmon does not send diary content to OpenStreetMap. Read the OpenStreetMap Foundation Privacy Policy.
Weather is optional. You can disable location access, diary weather, background weather history and pressure alerts in Headmon and system Settings. Headmon does not request background location permission.
Photos, camera and notifications
Camera and Photos access is used only when you choose to attach a picture. Notification permission is used for reminders, active-episode actions and alerts you enable. Headmon does not upload photos or notification content to a developer service. Content displayed on the Lock Screen remains subject to the notification privacy settings you choose in iOS or Android.
Apple, Google and operating-system services
Installing through an app store, using TestFlight, opening system maps, selecting files, receiving notifications, or using device backup may involve Apple, Google or a selected file provider processing information under its own terms. Headmon does not receive their account, purchase or store-analytics data through the app. Headmon includes no analytics or crash-reporting SDK; app stores and operating systems may still provide platform-level diagnostics or aggregated store information under their own terms.
Android version checks
When the Android app is opened after onboarding, it can request a fixed update manifest
from headmondiary.com at most once every 24 hours. A manual check under
Settings → About Headmon can make the same request sooner. The request contains no diary
entry, symptom, medicine, trigger, note, location, advertising identifier or account
information. It uses a generic Headmon update-check user agent rather than a unique device
identifier.
The manifest contains only public release information and directs Android distribution to Google Play. Headmon no longer provides APK downloads through this website or GitHub. Google Play can process installation and update information under Google’s own terms; Headmon does not receive a copy of your diary through the version check. See the Android availability and migration guide.
Website and support
This website is hosted by GitHub Pages. Headmon does not add analytics, advertising or tracking cookies to it, although GitHub may process technical request information under the GitHub Privacy Statement.
The website stores one appearance preference named
headmon-screenshot-appearance in your browser’s local storage when you switch
the screenshots between light and dark mode. It contains only that choice, stays in your
browser, is not used to identify or track you and can be removed by clearing site data.
Project questions, bug reports and feature requests are handled through public GitHub Issues. Headmon does not provide support by email.
GitHub Issues and comments are public. Never post a Headmon backup, CSV or PDF export, private photo, medical record, address, exact location or other personal or health information. A post containing such material may be removed without a response. Removing a public post cannot guarantee that copies, notifications or caches made while it was public will also disappear.
Changes and contact
This policy will be updated if Headmon’s behavior changes. Material changes will be dated on this page. A privacy question that contains no personal or health information can be submitted through GitHub Issues. If it cannot be asked safely in public, do not post it.