Privacy policy
Version 2 · Effective 24 August 2026 · Applies to Emimate for Android,
package com.emimate.app, version 1.0.0 and later
Emimate collects no personal data. Everything you record stays in the app's private storage on your device. The developer receives nothing, holds nothing, and has no technical means of obtaining it.
1. Who is responsible for this app
Emimate is published by an independent developer, reachable at gprovenz.dev@gmail.com. Because the app transmits nothing and the developer operates no server, no personal data is processed by the developer, and there is no processing on which a lawful basis under the GDPR would need to be claimed. The data in your diary is processed only by you, on your own device, under your own control.
2. What the app stores, and where
| Information | Where it is kept | What it is for |
|---|---|---|
| Your headache diary: start and end of each attack, and the intensity, medication, triggers and notes you choose to add | A database inside the app's private storage on the device | Showing your diary, the monthly figures and the report |
| Your settings: interface language, theme, and the name you want printed on the report | The same private storage | Keeping the app the way you set it |
Diary entries describe your health, which the GDPR treats as a special category of personal data. That is precisely why the app is built so that this information never leaves the device unless you send it somewhere yourself. No other app can read that storage, and neither can the developer. There is no account, no sign-in, and no server.
3. Why this can be stated rather than merely promised
Emimate does not request the INTERNET permission. Android enforces this: without
that permission the operating system will not allow the app to open a network connection at all.
It is not a setting that can be changed quietly on an installed app — it is declared in the app's
manifest, which anyone can extract from the installed package and read.
Android's automatic backup is also switched off (allowBackup="false"), so the
system does not copy your diary to Google Drive either.
The app contains no advertising network, no analytics library, no crash reporting service and no third-party SDK of any kind. Nobody is told that you opened the app, or when.
4. Permissions the app requests
| Permission | Why |
|---|---|
POST_NOTIFICATIONS |
To show the notification with the running timer and the End button while an attack is in progress. You can refuse it; the rest of the app works unchanged. |
RECEIVE_BOOT_COMPLETED |
To restore that notification and the home screen widget after the phone restarts, so an attack started before the restart is still shown as running. |
The app asks for no other permission. It does not request access to storage, contacts, location, the camera or the microphone. Reading and writing your own CSV and PDF files goes through the system file picker, which grants access to the single file you point at.
5. When data leaves the device, you are the one moving it
Emimate can export your diary as a CSV file and produce a PDF report for your doctor, and can hand either to another app through the Android share sheet. This happens only when you ask for it: you choose the moment, the period covered, where the file is saved and who receives it.
Once a file has left the app it is an ordinary document under your control, and this policy no longer governs it. What happens to it afterwards is subject to the terms of whatever app, mail service or storage you chose.
6. How long data is kept
Your diary stays on the device until you delete it. There is no expiry and no automatic clean-up, because nothing is stored anywhere else and there is nothing for the developer to retain or erase.
7. Deleting your data
- One attack: open it in the app and choose Delete.
- Everything: uninstall the app. Android deletes its private storage along with it. Because there is no backup and no copy on a server, that erasure is complete and final. The same result is obtained from the Android settings, under Apps → Emimate → Storage → Clear storage, if you want to keep the app installed.
Restoring a backup never deletes anything: it adds the attacks the file contains and rewrites those it describes differently, and leaves the rest untouched. Deletion is always an explicit act.
8. Your rights
Under the GDPR you have the right of access to your personal data and the rights to rectification, erasure, restriction, objection and portability. Since the developer holds none of your data, these rights are exercised on the device itself and need no request to anyone: your diary is visible in full in the app, editable entry by entry, deletable as described above, and exportable at any moment to a CSV file in a documented, open format that any spreadsheet can read.
You also have the right to lodge a complaint with a supervisory authority. In Italy this is the Garante per la protezione dei dati personali (garanteprivacy.it).
9. International transfers
None. No data is transmitted, so none is transferred anywhere, inside or outside the European Economic Area.
10. Children
Emimate is not directed at children and collects nothing from anyone, of any age.
11. Medical disclaimer
Emimate is a diary. It records what you write and gives it back to you. It does not diagnose, does not give medical advice, and is not a medical device. Decisions about your health belong with your doctor.
12. Changes to this policy
Any new version is published at this address, with a new version number and date at the top. Since the app collects nothing, a change would concern clarity or a new feature of the app, not new data being gathered. If a future version of the app ever collected or transmitted anything, that change would be described here before it took effect.
Version history. Version 1, 22 August 2026 — first publication. Version 2, 24 August 2026 — restructured; added the permissions and retention sections, the statement of rights, and the note that restoring a backup never deletes; corrected the description of how the whole diary is erased.
13. Contact
Questions about this policy: gprovenz.dev@gmail.com