🛸 DoseFlow UK Privacy Policy

Last updated: 22 May 2026  |  Effective: 22 May 2026

DoseFlow UK ("we", "us", "our") operates the DoseFlow UK mobile application ("App"). This Privacy Policy explains how we collect, use, share, and protect your information when you use our App.

Key promise: Your health data is encrypted end-to-end before it leaves your device. We cannot read your medication data, dose logs, or care circle content. We never sell your data. We never use your health data for advertising.

1. Information We Collect

1.1 Information You Provide

1.2 Information Collected Automatically

1.3 Health Connect Data (Read-Only)

With your explicit permission, DoseFlow UK reads the following data from Android Health Connect:

Important: DoseFlow UK only reads this data. We never write to Health Connect. This data is displayed locally on your device and is never synced, uploaded, or shared with anyone — including your care circle members.

1.4 Information We Do NOT Collect

2. How We Use Your Information

3. How We Share Your Information

RecipientData SharedPurposeEncrypted?
Supabase (hosted in EU)Auth credentials, sync operations (encrypted payloads), device tokensAuthentication, care circle data sync, push notification delivery✅ AES-256-GCM for sync payloads
Firebase Cloud MessagingFCM token, notification payloadDelivering push notifications✅ HTTPS in transit
Firebase AnalyticsAnonymised usage eventsApp stability and feature usage✅ HTTPS in transit
Self-hosted relayNudge delivery request (sender name, circle path)Routing nudge alerts to circle members✅ HTTPS in transit
Ampoule APIMedication barcode (GTIN/EAN)Medication identification lookup✅ HTTPS in transit
Open Food Facts APIProduct barcodeFallback medication identification✅ HTTPS in transit
Emergency contacts (SMS)Escalation messageCare escalation when member misses medication⚠️ Plain SMS
We do NOT share data with: Advertising networks, data brokers, social media platforms, or any other third parties not listed above.

4. End-to-End Encryption

All care circle sync data (medications, dose logs, tasks, member changes) is encrypted on your device using AES-256-GCM before being uploaded. Each care circle has a unique shared key. The Supabase server stores only encrypted blobs — we cannot read, access, or decrypt your circle data.

Sync payloads are additionally signed with HMAC-SHA256 to detect tampering in transit.

5. Data Retention

6. Your Rights and Choices

7. Data Security

8. Children's Privacy

DoseFlow UK is not intended for use by children under 18. We do not knowingly collect personal information from children. If you are under 18, do not use this app. If we learn that we have collected data from a child under 18, we will delete it promptly.

9. International Data Transfers

Supabase infrastructure is hosted in the EU (Ireland region). Firebase infrastructure may process data in the US under Google's EU Standard Contractual Clauses. By using DoseFlow UK, you consent to these transfers.

10. Third-Party Links

The App links to external health resources (NHS.uk, etc.) and uses third-party APIs (Ampoule, Open Food Facts). These third parties have their own privacy policies. We are not responsible for their data practices.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via an in-app notification or email. Continued use after changes constitutes acceptance.

12. Contact Us

If you have questions about this Privacy Policy or your data, contact us: