Medical Disclaimer: DoseStream is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Always consult a healthcare professional for medical advice, diagnosis, or treatment.
🔐 Zero-Knowledge Architecture: Your medication data is end-to-end encrypted on your device before it leaves your phone. Our cloud infrastructure (Supabase, Firebase) only stores encrypted data that we cannot read. We have no way to access your medication names, dosages, schedules, or health data — even if we wanted to.
1. Who We Are
DoseStream is developed by an independent developer based in the United Kingdom. For questions about this policy, contact: privacy@dosestream.uk
2. What Data We Collect & Where It Goes
Data Type
Purpose
Stored Where
Encrypted?
Shared?
Medication names & dosages
Core app function — reminders
On device + encrypted cloud sync
Yes — AES-256-GCM before upload
Only with your care circle
Medication schedules & times
Core app function — reminders
On device + encrypted cloud sync
Yes — AES-256-GCM before upload
Only with your care circle
Dose log history (taken/skipped)
Adherence tracking
On device + encrypted cloud sync
Yes — AES-256-GCM before upload
Only with your care circle
Care circle member names & emails
Sharing updates with family/carers
On device + encrypted cloud sync
Yes — AES-256-GCM before upload
Only with your circle members
Device token (FCM)
Route push notifications to your device
Supabase (EU region) — plaintext
No — needed for notification routing
Only with Firebase for delivery
Anonymous auth token
Access Supabase with RLS policies
On device (SharedPreferences)
N/A — no personal data in token
No
Health Connect data (steps, heart rate, blood pressure, blood glucose, weight, exercise)
Display alongside medication schedule
Read-only from Health Connect — never uploaded
N/A — never leaves device
No
Camera (barcode scanning)
Scan medicine barcodes to auto-fill medication details
Not stored — live camera preview only
N/A
No
3. Cloud Infrastructure & Sub-Processors
DoseStream uses the following cloud services to provide sync and push notification features. All services are hosted in the EU/UK region.
Important: Supabase and Firebase only store encrypted ciphertext for your medication data. The encryption key (circle key) is generated on your device and shared only with your care circle members via a join code. Neither DoseStream, Supabase, nor Firebase can decrypt your medication data.
4. How We Use Your Data
Medication reminders: Your medication data is used solely to provide timely reminders on your device.
Care circle sharing: When you invite a family member or carer, encrypted data is synced via Supabase. Only members with the circle key can decrypt the data.
Push notifications: Device tokens (FCM) are stored in Supabase to route nudge and chat notifications between care circle members. Token values are not personal data — they identify a device, not a person.
Health data display: Health Connect data is read-only and displayed alongside your medication schedule. We never upload health data to any server.
Drug interaction alerts: Drug interaction checks use an offline database (200+ UK medicines). The RxNav API is queried with drug names only — no user identity or personal data is sent.
5. Legal Basis (UK GDPR)
Legitimate interest (Art. 6(1)(f)): Providing medication reminders and care circle sync features. The legitimate interest is helping patients and carers manage medication safely.
Consent (Art. 6(1)(a)): Health Connect data access requires explicit user permission via the Android Health Connect dialog.
Contractual necessity (Art. 6(1)(b)): Care circle sharing features when you choose to invite members.
6. Data Sharing
We do not sell your data. We do not share your data with advertisers. We do not use your data for analytics or tracking.
Care circle members receive only the information you choose to share with them — encrypted with your circle key.
Health Connect data is read via the Android Health Connect API — we do not send it anywhere.
Drug interaction data comes from our offline database — no external API calls with personal data.
Device tokens are shared with Firebase for push notification delivery only — Firebase does not use them for any other purpose.
7. Data Retention & Deletion
On Your Device
Your medication data is stored locally on your device in an encrypted Room database. You can delete it at any time by:
Clearing the app data in Android Settings → Apps → DoseStream → Clear Data
Uninstalling the app
Cloud (Supabase)
Encrypted sync operations stored in Supabase are automatically deleted after 30 days. This happens automatically — no action needed from you.
Device tokens are deleted when you leave a care circle or uninstall the app. You can also request immediate deletion by contacting us.
Right to Erasure
To request immediate deletion of any remaining cloud data, contact privacy@dosestream.uk. We will process your request within 30 days as required by UK GDPR Article 17.
8. International Data Transfers
Supabase: Data stored in EU (Frankfurt) region — no transfer outside EEA.
Firebase: Google's infrastructure may transfer data globally, but this is covered by Google's Standard Contractual Clauses (SCCs) and the UK GDPR adequacy mechanisms.
Cloudflare: UK/EU edge nodes used — no transfer outside UK/EEA.
RxNav API (NIH): Only drug name strings are sent (e.g., "paracetamol") — no personal data, no user identity. Not subject to GDPR as no personal data is processed.
9. Security Measures
End-to-end encryption: All medication and care circle data is encrypted with AES-256-GCM on your device before upload. The encryption key never leaves your device unencrypted.
Encryption in transit: All network communications use TLS 1.2+ (HTTPS via Cloudflare Tunnel).
Encryption at rest: Local database uses Android's encrypted Room storage. Cloud data is encrypted ciphertext — no decryption keys stored server-side.
Authentication: Supabase anonymous auth provides per-device JWT tokens. Row-Level Security (RLS) policies ensure devices can only access their own circle's data.
Message authentication: Sync operations are signed with Ed25519 asymmetric signatures (or HMAC-SHA256 on older Android versions) to detect tampering during transmission. The signing key is unique per device and cannot be forged by other parties.
No third-party trackers: DoseStream does not include any analytics SDKs, ad SDKs, or tracking libraries. We do not collect usage data.
10. Children's Privacy
DoseStream is not intended for children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has provided personal data, contact us and we will delete it promptly.
11. Your Rights (UK GDPR)
You have the right to:
Access (Art. 15): Request a copy of your personal data
Rectification (Art. 16): Correct inaccurate data
Erasure (Art. 17): Request deletion of your data
Restriction (Art. 18): Restrict how we process your data
Data portability (Art. 20): Receive your data in a machine-readable format
Objection (Art. 21): Object to processing of your data
Withdraw consent (Art. 7): Withdraw consent for Health Connect data at any time
To exercise any of these rights, contact privacy@dosestream.uk
12. Permissions
Permission
Purpose
Required?
Camera
Scan medicine barcodes for auto-fill
Optional — you can enter manually
Notifications
Medication reminders & nudge alerts
Yes — core function
Exact Alarms
Ensure reminders fire at the exact time
Yes — core function
Boot Completed
Re-schedule reminders after device restart
Yes — core function
Health Connect (steps, HR, BP, glucose, weight, exercise)
Display health data alongside medication schedule
Optional — enhances experience
Activity Recognition
Read daily step count via Health Connect
Optional — part of Health Connect
Vibrate
Haptic feedback on barcode scan
Optional — accessibility
Foreground Service (Health)
Keep reminders running reliably
Yes — core function
Internet
Cloud sync & push notifications
Optional — app works offline, sync requires internet
13. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by updating the "Last updated" date at the top of this page. Your continued use of the app after changes constitutes acceptance of the updated policy.
14. Contact
For privacy questions, data access requests, or deletion requests: