🛸 DoseFlow UK Privacy Policy
Last updated: 22 May 2026 | Effective: 22 May 2026
DoseFlow UK ("we", "us", "our") operates the DoseFlow UK mobile application ("App"). This Privacy Policy explains how we collect, use, share, and protect your information when you use our App.
Key promise: Your health data is encrypted end-to-end before it leaves your device. We cannot read your medication data, dose logs, or care circle content. We never sell your data. We never use your health data for advertising.
1. Information We Collect
1.1 Information You Provide
- Account credentials — Email address and password (stored by Supabase Auth; password is bcrypt-hashed, never stored in plaintext)
- Medication data — Names, dosages, frequencies, schedules, quantities, and treatment dates you enter
- Dose logs — Records of when you marked medications as taken
- Tasks — Care circle task items you create
- Profile information — Display name, optional phone number (for SMS escalation alerts)
- Care circle data — Circle name, membership, invite codes
1.2 Information Collected Automatically
- Device identifier — A random UUID generated on first launch, used for sync conflict resolution and deduplication
- FCM push notification token — Required to deliver nudge alerts and medication reminders to your device
- Basic analytics — Firebase Analytics collects anonymised usage data (screen views, session duration, crash reports). No personally identifiable information is collected through analytics.
1.3 Health Connect Data (Read-Only)
With your explicit permission, DoseFlow UK reads the following data from Android Health Connect:
- Daily step count
- Heart rate readings
- Blood pressure readings
- Blood glucose readings
- Weight measurements
- Exercise session records
Important: DoseFlow UK only reads this data. We never write to Health Connect. This data is displayed locally on your device and is never synced, uploaded, or shared with anyone — including your care circle members.
1.4 Information We Do NOT Collect
- ❌ Location data (neither precise nor approximate)
- ❌ Contacts or address book
- ❌ Photos or videos (camera is used only for real-time barcode scanning; images are never stored or uploaded)
- ❌ Audio or microphone data
- ❌ Files or documents
- ❌ Web browsing history
- ❌ Advertising identifiers
2. How We Use Your Information
- Core features — Medication reminders, dose tracking, refill management, interaction alerts
- Care circle coordination — Encrypted sync of medication and task data between circle members
- Push notifications — Medication reminders and nudge alerts via Firebase Cloud Messaging
- SMS escalation — If enabled, sending SMS to emergency contacts when a member misses medication (uses Android SmsManager locally; SMS content is not sent to our servers)
- Barcode scanning — Identifying medications by scanning barcodes (lookups go to Ampoule API and Open Food Facts; barcode data is not stored)
- App stability — Crash reporting and anonymised analytics via Firebase
3. How We Share Your Information
| Recipient | Data Shared | Purpose | Encrypted? |
| Supabase (hosted in EU) | Auth credentials, sync operations (encrypted payloads), device tokens | Authentication, care circle data sync, push notification delivery | ✅ AES-256-GCM for sync payloads |
| Firebase Cloud Messaging | FCM token, notification payload | Delivering push notifications | ✅ HTTPS in transit |
| Firebase Analytics | Anonymised usage events | App stability and feature usage | ✅ HTTPS in transit |
| Self-hosted relay | Nudge delivery request (sender name, circle path) | Routing nudge alerts to circle members | ✅ HTTPS in transit |
| Ampoule API | Medication barcode (GTIN/EAN) | Medication identification lookup | ✅ HTTPS in transit |
| Open Food Facts API | Product barcode | Fallback medication identification | ✅ HTTPS in transit |
| Emergency contacts (SMS) | Escalation message | Care escalation when member misses medication | ⚠️ Plain SMS |
We do NOT share data with: Advertising networks, data brokers, social media platforms, or any other third parties not listed above.
4. End-to-End Encryption
All care circle sync data (medications, dose logs, tasks, member changes) is encrypted on your device using AES-256-GCM before being uploaded. Each care circle has a unique shared key. The Supabase server stores only encrypted blobs — we cannot read, access, or decrypt your circle data.
Sync payloads are additionally signed with HMAC-SHA256 to detect tampering in transit.
5. Data Retention
- Local database (Room): Stored on your device until you delete the app or clear app data
- Supabase sync operations: Last 1,000 operations per circle (auto-pruned); deleted when circle is dissolved
- Supabase device tokens: Retained until app uninstall or token expiry; deleted on account deletion
- Firebase Analytics: 2–14 months (Google default); you can delete via Google Activity Controls
- Self-hosted relay: In-memory only; no persistent storage; cleared on server restart
- Health Connect data: Never stored by DoseFlow UK; read on-demand from Health Connect only
6. Your Rights and Choices
- Delete account: You can delete your account and all associated data from within the app (Settings → Account → Delete Account)
- Leave care circle: You can leave any care circle at any time; your local data remains, sync stops
- Revoke Health Connect permissions: Android Settings → Health Connect → DoseFlow UK → Revoke access
- Disable push notifications: Android Settings → Apps → DoseFlow UK → Notifications → Off
- Disable SMS escalation: Do not grant SEND_SMS permission during setup
- Opt out of analytics: Android Settings → Google → Ads → Opt out of Ads Personalisation (affects Firebase Analytics)
- Export your data: Backup & Restore feature exports your local database (Settings → Backup)
- Clear app data: Android Settings → Apps → DoseFlow UK → Storage → Clear Data
7. Data Security
- All network traffic uses HTTPS/TLS 1.2+ (except SMS, which uses the cellular network)
- Care circle data is encrypted end-to-end with AES-256-GCM
- Passwords are bcrypt-hashed via Supabase Auth
- Local database (Room) is stored in the app's private sandbox (not accessible to other apps)
- FCM tokens and device identifiers are stored in Supabase with row-level security (RLS)
- The relay server runs in-memory with no persistent storage
8. Children's Privacy
DoseFlow UK is not intended for use by children under 18. We do not knowingly collect personal information from children. If you are under 18, do not use this app. If we learn that we have collected data from a child under 18, we will delete it promptly.
9. International Data Transfers
Supabase infrastructure is hosted in the EU (Ireland region). Firebase infrastructure may process data in the US under Google's EU Standard Contractual Clauses. By using DoseFlow UK, you consent to these transfers.
10. Third-Party Links
The App links to external health resources (NHS.uk, etc.) and uses third-party APIs (Ampoule, Open Food Facts). These third parties have their own privacy policies. We are not responsible for their data practices.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via an in-app notification or email. Continued use after changes constitutes acceptance.
12. Contact Us
If you have questions about this Privacy Policy or your data, contact us: