DoseStream Privacy Policy

Last updated: 25 June 2026

Medical Disclaimer: DoseStream is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Always consult a healthcare professional for medical advice, diagnosis, or treatment.
🔐 Zero-Knowledge Architecture: Your medication data is end-to-end encrypted on your device before it leaves your phone. Our cloud infrastructure (Supabase, Firebase) only stores encrypted data that we cannot read. We have no way to access your medication names, dosages, schedules, or health data — even if we wanted to.

1. Who We Are

DoseStream is developed by an independent developer based in the United Kingdom. For questions about this policy, contact: privacy@dosestream.uk

2. What Data We Collect & Where It Goes

Data TypePurposeStored WhereEncrypted?Shared?
Medication names & dosagesCore app function — remindersOn device + encrypted cloud syncYes — AES-256-GCM before uploadOnly with your care circle
Medication schedules & timesCore app function — remindersOn device + encrypted cloud syncYes — AES-256-GCM before uploadOnly with your care circle
Dose log history (taken/skipped)Adherence trackingOn device + encrypted cloud syncYes — AES-256-GCM before uploadOnly with your care circle
Care circle member names & emailsSharing updates with family/carersOn device + encrypted cloud syncYes — AES-256-GCM before uploadOnly with your circle members
Device token (FCM)Route push notifications to your deviceSupabase (EU region) — plaintextNo — needed for notification routingOnly with Firebase for delivery
Anonymous auth tokenAccess Supabase with RLS policiesOn device (SharedPreferences)N/A — no personal data in tokenNo
Health Connect data (steps, heart rate, blood pressure, blood glucose, weight, exercise)Display alongside medication scheduleRead-only from Health Connect — never uploadedN/A — never leaves deviceNo
Camera (barcode scanning)Scan medicine barcodes to auto-fill medication detailsNot stored — live camera preview onlyN/ANo

3. Cloud Infrastructure & Sub-Processors

DoseStream uses the following cloud services to provide sync and push notification features. All services are hosted in the EU/UK region.

ServiceProviderWhat They ProcessLocationGDPR Status
Sync & auth databaseSupabase (EU region)Encrypted medication data, device tokens, anonymous authEU (Frankfurt)GDPR-compliant — DPA available
Push notification deliveryFirebase Cloud Messaging (Google)Device tokens, notification payloadsGlobal (Google infrastructure)GDPR-compliant — Google DPA covers this
Relay server tunnelCloudflareEncrypted sync payloads onlyUK/EU edge nodesGDPR-compliant — Cloudflare DPA
Drug interaction databaseNational Library of Medicine (NIH RxNav)Drug name lookup only — no user data sentUSNo personal data transmitted
Important: Supabase and Firebase only store encrypted ciphertext for your medication data. The encryption key (circle key) is generated on your device and shared only with your care circle members via a join code. Neither DoseStream, Supabase, nor Firebase can decrypt your medication data.

4. How We Use Your Data

5. Legal Basis (UK GDPR)

6. Data Sharing

We do not sell your data. We do not share your data with advertisers. We do not use your data for analytics or tracking.

7. Data Retention & Deletion

On Your Device

Your medication data is stored locally on your device in an encrypted Room database. You can delete it at any time by:

Cloud (Supabase)

Encrypted sync operations stored in Supabase are automatically deleted after 30 days. This happens automatically — no action needed from you.

Device tokens are deleted when you leave a care circle or uninstall the app. You can also request immediate deletion by contacting us.

Right to Erasure

To request immediate deletion of any remaining cloud data, contact privacy@dosestream.uk. We will process your request within 30 days as required by UK GDPR Article 17.

8. International Data Transfers

9. Security Measures

10. Children's Privacy

DoseStream is not intended for children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has provided personal data, contact us and we will delete it promptly.

11. Your Rights (UK GDPR)

You have the right to:

To exercise any of these rights, contact privacy@dosestream.uk

12. Permissions

PermissionPurposeRequired?
CameraScan medicine barcodes for auto-fillOptional — you can enter manually
NotificationsMedication reminders & nudge alertsYes — core function
Exact AlarmsEnsure reminders fire at the exact timeYes — core function
Boot CompletedRe-schedule reminders after device restartYes — core function
Health Connect (steps, HR, BP, glucose, weight, exercise)Display health data alongside medication scheduleOptional — enhances experience
Activity RecognitionRead daily step count via Health ConnectOptional — part of Health Connect
VibrateHaptic feedback on barcode scanOptional — accessibility
Foreground Service (Health)Keep reminders running reliablyYes — core function
InternetCloud sync & push notificationsOptional — app works offline, sync requires internet

13. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes by updating the "Last updated" date at the top of this page. Your continued use of the app after changes constitutes acceptance of the updated policy.

14. Contact

For privacy questions, data access requests, or deletion requests:

Email: privacy@dosestream.uk