Legal
Privacy Policy
Effective 6 July 2026 · Last updated 6 July 2026
The short version. DoseSignal is a medication reminder and check-in tool. We collect only what we need to run the app, we never sell your data, and we do not use it for advertising. You can delete your account and all your data from inside the app at any time.
1. Who we are
"DoseSignal", "we", "us", and "our" refer to the operator of the DoseSignal iOS app and the dosesignal.app website. If you have a question about this policy, contact us at privacy@dosesignal.app.
2. What DoseSignal does
DoseSignal helps a person remember a scheduled medication and lets an invited Care Partner know whether the person completed a visually verified medication check-in. DoseSignal does not verify ingestion, guarantee medical adherence, diagnose anything, authenticate a prescription drug, or replace medical care. It is not an emergency service.
3. Information we collect
3.1 Account information
- Name and email address, used to sign in and label your account.
- Apple Sign in with Apple identifier, if you sign in with Apple.
- Apple Push Notification service device token, used to deliver reminders and Care Partner alerts.
3.2 Medication and check-in data
- Medications you add (name, schedule, grace period, notes).
- Check-in events (time, status, whether a visual match succeeded).
- Live check-in photos captured with the camera. Photos are never pulled from your photo library. Retention defaults to 30 days and is user-configurable to Immediate, 7, 30, or 90 days.
- Care Partner relationships you approve, and the permissions you grant each partner (view schedule, receive alerts, view history).
3.3 Diagnostic data
If enabled, aggregated crash and performance data helps us keep the app reliable. It contains no medication names, no photos, and no personally identifiable information.
3.4 What we do not collect
- Precise location, contacts, calendar, browsing history, or microphone data.
- Data for advertising, marketing profiling, or tracking across other companies' apps or websites.
- Data from Apple Health (unless you explicitly connect it in a future release, which will prompt separately).
4. How we use information
- Deliver reminders and Care Partner alerts.
- Run the on-device visual-match check against reference photos you register yourself.
- Show your adherence history and streaks.
- Provide subscription features and handle billing via Apple.
- Keep the service secure and prevent abuse.
5. Legal bases (for users in the EU/UK)
- Contract — to provide the reminder, check-in, and Care Partner features you asked us to run.
- Consent — for optional features like push notifications and Care Partner sharing. You may withdraw consent by disabling the feature or revoking a partner.
- Legitimate interests — keeping the service secure and preventing fraud.
6. Sharing
We share your data only with the parties listed below, only to the extent needed for the app to work:
- Care Partners you invite. Each partner sees only what you permit (schedule, alerts, history), and you can revoke access at any time. Every sharing event is recorded in the in-app Consent Audit Log.
- Apple. For sign-in, push, and App Store billing.
- Supabase, Inc. — our backend host (auth, database, storage, edge functions). Data is encrypted in transit (TLS) and at rest, and is stored under Row-Level Security policies so each account can only see its own rows.
We do not sell, rent, or share your personal information for third-party advertising or marketing. We do not receive payment for disclosing your information.
7. Retention
- Photos: your chosen retention setting (default 30 days).
- Check-in history: 7 days on Free, 90 days on paid plans.
- Account records: kept until you delete your account.
- Audit log: kept for the life of the account for your own review.
8. Your rights
You can, from inside the app or by contacting us:
- Access, export, or correct your data.
- Delete your account and all associated data (Settings → "Delete account & all data"). This is immediate and irreversible.
- Revoke any Care Partner's access at any time.
- Withdraw consent for push notifications (in iOS Settings).
- Manage or cancel subscriptions in iOS Settings → your name → Subscriptions.
If you are in the EU/UK, you may also lodge a complaint with your local data protection authority. Users in California have additional rights under the CCPA/CPRA; we do not sell personal information and we honor verified requests to access, delete, or correct.
9. Security
Data is encrypted in transit and at rest. Access to backend systems is limited to authorized personnel and logged. Visual matching runs on-device using Apple Vision and Core ML; reference images and live check-in captures are stored per your retention setting.
10. Children
DoseSignal is not directed to children under 13 (or under 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact privacy@dosesignal.app and we will delete it.
11. International transfers
Our processors may operate outside your country. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.
12. Changes
We will post any changes to this policy on this page and update the "Last updated" date. Material changes will also be announced in-app before they take effect.
13. Contact
Privacy questions: privacy@dosesignal.app
General support: dosesignal.app/support