Privacy Policy
Effective July 2, 2026 · Last updated August 8, 2026
DosePlot LLC ("DosePlot," "we," "us," or "our") operates the DosePlot mobile and web applications and the website at doseplot.com (together, the "Service"). This Privacy Policy explains what information we collect, how we use and protect it, and the choices and rights you have.
DosePlot is an informational tracking and planning tool. It is not medical advice and is not a substitute for a qualified healthcare provider. See our Terms of Service.
1. The short version
- You can use the DosePlot mobile apps as a guest, with no account — your data stays on your device and is not sent to us. (The web app requires a free account so your data can be encrypted and synced rather than stranded in one browser.)
- We collect only what the Service needs to work: your account email, the protocol and health information you choose to enter, and, if you use the AI assistant, the content of those requests.
- Cloud sync is optional and off until you turn it on. When on, the health and protocol data we sync for you is encrypted. You can also choose a zero-knowledge passphrase mode in which not even DosePlot can read your synced data.
- We do not sell your data, we do not share it with advertisers or data brokers, and we do not use it for advertising or cross-app tracking.
- If you opt in, we also receive small daily usage counts that are blurred with random noise on your devicebefore upload — never your health data, and never on by default.
- If you separately opt in, the app also sends detailed interaction events — screen and step names with timestamps and durations from a fixed public list, never what you entered — under a random identifier that resets every app launch and is never linked to your account.
- You can export or delete your data, including deleting your account from inside the app.
2. Who this applies to and how you use DosePlot
- Guest / on-device use (mobile apps):You can use DosePlot without an account. In this mode your data is stored only on your device and is not transmitted to us, except as needed to provide any feature you actively invoke (for example, the AI assistant — see Section 6).
- Account use: Creating a free account (or signing in) enables cloud sync and account-based features. The web app requires an account.
- Age: DosePlot is intended for adults 18 and older. It is not directed to and not intended for anyone under 18. See Section 12.
3. Information we collect
We collect the following, and only for the purposes described in Section 4:
a. Account information
When you create an account or sign in, we collect your email addressand an account identifier. If you sign in with Apple, Google, or Discord, we receive a provider account identifier and (depending on your choices with that provider) your email; if you use Apple's "Hide My Email," we receive only the relay address. We do not receive your password for third-party sign-ins. If you add an optional recovery phone number(or sign in with an SMS code), we collect that phone number and share it with our SMS delivery provider (Twilio) solely to send verification codes. It is used for account recovery and sign-in only — never for marketing — and you can remove it in Settings at any time.
b. Health and protocol information you enter
This is information you choose to provide, such as: compounds and protocols you build, doses you log, reconstitution recipes, injection sites, inventory and cost data, body weight, and bloodwork/lab values you record. This also includes optional progress photos you choose to attach to weigh-ins (see Section 5 for how they are stored) and health-platform datayou choose to connect — Apple Health (HealthKit) on iOS or Health Connect on Android (item g below). We treat all of this as sensitive personal information (see Sections 5 and 11).
c. AI assistant content
If you use the in-app AI assistant, we process the messages you send it and, only if you have enabled data access (a setting you control — see Section 6), relevant protocol, inventory, and labs context needed to answer you. If you disable AI data access, that context is not sent. You can also attach filesto an assistant message — photos or PDF documents of lab results or DEXA scans — which are sent with that message to the AI provider so the assistant can read the values for you. Attachments require data access to be enabled, anything the assistant extracts is saved to your record only after you review and confirm it, and the file itself is not stored on our servers — your device also removes attachment file data from saved chat history.
d. Payment information
In the mobile apps, subscriptions are billed by Apple or Google through their in-app purchase systems. We use RevenueCatto manage store subscription state: it receives purchase receipts and subscription status from Apple/Google, tied to your account identifier — never your payment details. In the web app, subscriptions are billed by Stripe, our payment processor: you enter your payment details on Stripe's own hosted checkout and billing pages, and Stripe sends us your subscription status and a customer identifier tied to your account — never your card number. In all cases we do not receive or store your credit-card or payment-instrument details, and no health data is shared with any payment provider.
e. Limited technical information
To operate and secure the Service we process basic technical data such as app version, device platform/OS version, and, for cloud features, network request metadata (for example, IP address at the time of a request, used transiently for connection and abuse-prevention). This metadata is handled by our infrastructure providers: our backend host (Supabase) and Cloudflare, which serves our websites and runs the security check that protects sign-in from automated abuse. We do not use it to build a profile of you.
f. Diagnostic / usage information
The app includes a device-local usage log used only to power an on-device owner/diagnostics view; that log stays on your device and is not transmitted to us. Separately, the app and our servers send automated crash and error reportsto Sentry (a diagnostics provider) so we can find and fix defects. These reports contain technical details of the failure — error type, stack trace, app version, device platform/OS — and are configured to exclude your identity and your health data: no account identifiers or email, no protocol, dose log, or inventory contents, and IP-address storage is disabled with the provider. Crash reports are never used for advertising or profiling.
Optional usage statistics (opt-in).If you affirmatively opt in when asked (or later in Settings), the app sends us a small once-per-day "sketch" of how much you used app features— never what you entered. The list of counters is fixed and public: app sessions; visits to each of 14 screens (Home, Log, Protocol, Inventory, Compounds, Labs, Compare, Rotation, Calendar, Settings, Assistant, Photos, Watch settings, Reminders); starts and completions of 6 workflows (log dose, log weight, reconstitution, prepare vial, build compound, add protocol); views of 5 upgrade/feature gates; a daily error count; and one-time trial-start and subscription-conversion flags. It never includes your health, protocol, compound, inventory, dose, weight, photo, lab, or chat content — the daily usage counts described in this subsection never include free text, timestamps, event ordering, or durations.
Before anything is uploaded, each daily count is capped and blurred on your device with random noise(local differential privacy: every counter carries a permanent random offset drawn on your device plus fresh daily noise; the formal privacy budget is epsilon = 1 per counter per day, plus a one-time epsilon = 1 per counter protecting your long-run level; a worst-case day across all 35 counters composes to epsilon = 35). We can estimate averages across many users; we cannot recover your true counts. Two limits, stated plainly: (1) the existenceof a day's sketch shows that your account used the app that day — presence is exact, not blurred; (2) sketches are tied to your accountso we can deliver and delete them — they are noised, not anonymous.
Raw sketches are kept for at most 90 days; after that only combined totals spanning at least 10 users are retained and the per-account rows are deleted. You can opt out at any time in Settings (uploads stop immediately), you can delete everything you previously uploaded with one tap, and deleting your account removes your sketches automatically. Days used while opted out are never uploaded retroactively.
Detailed interaction events (opt-in, not linked to your account)
If you opt in, the app also records ordered interaction events with timestamps and durations: which screens you visit, which of six task flows you start and finish (such as logging a dose or preparing a vial), guided-tour steps, app open and background moments, and two performance timers. Event names come from a fixed, public list built into the app; the only values that can travel with them are names from that list, yes/no flags, bounded numbers, and basic device info attached by the analytics library (device model, manufacturer, operating system and app version, screen size, language, and time zone). Your content — health data, compound names, doses, notes, protocols, lab values, photos, chat — is structurally impossible to transmit on this channel.
These events are processed by PostHog Inc. (United States) on our behalf. They are sent under a random identifier that resets every time you launch the app. We never attach your account, email, or any persistent device identifier, and we have person-profile features disabled — PostHog does not connect your sessions to each other or to you. Like any internet service, PostHog's servers receive your IP address to deliver the events; we disable IP-based location enrichment and configure the project to discard IP data rather than record it on events. Events are retained by PostHog for one year.
Both kinds of usage sharing live under the same choice. If you said yes to usage statistics before this section existed, the app will ask you again before sending any detailed events — and if you decline, your existing daily-counts choice stays exactly as it was. Turning the toggle off in Settings stops both immediately; any unsent detailed events are discarded on your device. Because detailed events are never linked to you, we cannot look them up or delete them individually — they age out of the one-year retention window instead.
g. Health-platform data (optional): Apple Health on iOS / Health Connect on Android
Connecting your device's health platform — Apple Health (HealthKit) on iOS or Health Connect on Android — is off by defaultand controlled in Settings → Connected apps. With your permission, DosePlot reads weight, body composition, sleep, heart rate and resting heart rate, steps, blood pressure, and menstrual/cycle data, as available on your platform and only for the data types you allow. This access is read-only import, with one narrow exception: on iOS only, if you separately enable write-back, DosePlot writes the weigh-ins you log in the app to Apple Health. DosePlot does not write data to Health Connect. Health data is processed on your device to power auto-imported weigh-ins and chart overlays. We do not use health-platform data for advertising, marketing, or data mining; we never sell it; and we do not share it with third parties or data brokers. Two narrow, separately consented flows can move health-platform-derived data off your device: (1) imported weigh-ins become part of your weight log, which is end-to-end encrypted and synced only if you have enabled cloud sync (Section 5); and (2) if you separately turn on "Share with Assistant," daily aggregate values can be included in AI assistant requests as described in Section 6. You can disconnect at any time in the app, and revoke DosePlot's access in iOS Settings → Privacy & Security → Health, or on Android in Health Connect's permission settings.
What we do not collect:We do not use advertising SDKs, we do not track you across other apps or websites, and we do not access your location, contacts, photos (beyond photos you explicitly choose to provide: an optional body-model face photo, which stays on-device, and optional weigh-in progress photos — see Section 5), or microphone.
4. How we use information
We use the information above to:
- provide, maintain, and secure the Service (accounts, sync, the calculators and charts, reminders);
- answer your requests to the AI assistant (when you use it);
- process and manage subscriptions (via Apple/Google);
- respond to support requests;
- detect, prevent, and address fraud, abuse, and security incidents;
- comply with legal obligations and enforce our Terms.
We do not use your health or protocol information for advertising, and we do not sell or rent it. See Section 8.
Legal bases (EEA/UK users). Where the GDPR applies, we process your information to perform our contract with you (providing the Service), based on your consent (for example, enabling cloud sync or AI data access, which you can withdraw), to pursue our legitimate interests (security, abuse-prevention, product reliability) in a way not overridden by your rights, and to comply with legal obligations. Health-related data is processed on the basis of your explicit consent and/or because you have manifestly made it available by entering it into the Service.
5. How your data is stored and protected
On your device.Most on-device data is stored in your device's app storage, protected by your device's operating-system encryption (for example, iOS Data Protection or Android file-based encryption). Your inventory data is additionally encrypted at rest with AES-256-GCM using a key held in your device's secure hardware store (iOS Keychain / Android Keystore).
In the cloud (only if you enable sync). Cloud sync is opt-in. When you enable it, the data we sync (which may include protocols, logs, weight, labs, recon recipes, and inventory) is end-to-end encrypted with AES-256-GCM on your device before it is uploaded. Our servers store ciphertext. There are two key modes:
- Account-managed (default). Your encryption key is wrapped and escrowed to your account so your data stays available across your devices and can be recovered if you lose a device. Because this escrow is recoverable, DosePlot is technically capable of decrypting account-managed data (for example, to provide the Service or if legally compelled). We describe this honestly: the default mode is encrypted and operator-recoverable, not zero-knowledge.
- Zero-knowledge passphrase (opt-in). If you turn on the passphrase mode, your key is wrapped with a passphrase only you know (derived with Argon2id) and the recoverable escrow is destroyed. In this mode DosePlot cannot decrypt your synced data. If you lose the passphrase, the cloud copy cannot be recovered by us or by you; any device that still holds the data locally keeps it.
One limitation we state plainly rather than overclaim: in the account-managed mode, anyone who can sign in to your account can access your synced data — protect your credentials and consider enabling biometric app lock. If you ever suspect your key or account was exposed, you can rotate your encryption key from Settings: DosePlot creates a new key, re-encrypts your synced data (including photo backups) under it, and retires the old key once every one of your devices has picked up the new one.
Progress photos.Photos you attach to weigh-ins are stored in the app's private storage on your device and are not part of the synced documents above. On a paid plan, if you leave photo backup on, each photo is encrypted on your device with AES-256-GCM (using your account's encryption key, in whichever key mode above you use) before upload; our storage holds only ciphertext, subject to a per-account quota. On the free tier, progress photos never leave your device. Deleting a photo also deletes its cloud copy, and deleting your account deletes all photo backups.
Account credentials and sessions are handled by our authentication provider and stored in your device's secure store. No security measure is perfect, and we cannot guarantee absolute security.
6. The AI assistant
The optional in-app AI assistant helps you organize and plan. Two things govern its data handling:
- Data-access toggle. In Settings you control whether the assistant may access your app data. When on, your messages and the relevant protocol, inventory, and labs context are sent to the AI provider to answer you. When off, your app data is not sent; the assistant operates without it.
- Provider. With the managed assistant (default paid tier), your requests are processed through our backend and sent to Anthropic(the Claude API) to generate a response. We meter usage but do not use your content for advertising, and we do not sell it. With bring-your-own-key (Premium+), if you configure your own API key, your requests go directly to the provider you choose (for example, Anthropic, OpenAI, or Google), under your account and that provider's terms; in this mode DosePlot is not an intermediary for the request content. In BOTH modes, assistant traffic is TLS-protected in transit but is not end-to-end encrypted: unlike synced documents (Section 5), your messages and any shared app context are necessarily processed as plaintext by the AI provider so it can respond. In the managed mode our backend passes them through and records usage metering only, not message content; in bring-your-own-key mode they do not pass through our backend at all.
The assistant is informational only, may be inaccurate, is not medical advice, and stages any changes for your explicit approval. See the Terms of Service.
7. Service providers (subprocessors)
We share information with a limited set of vendors that process data on our behalf to run the Service. They are contractually bound to protect it and use it only to provide their services to us:
| Provider | Role | Data involved |
|---|---|---|
| Supabase | Backend hosting, database, authentication (US) | Account identifiers/email; encrypted (ciphertext) synced documents and photo backups; request metadata |
| RevenueCat | Subscription management (receipt validation, entitlement state) | Account identifier (app user ID); purchase receipts and subscription status from Apple/Google — no payment-card details |
| Stripe | Payment processing for web-app subscriptions (hosted checkout and billing portal) | Email address and payment details you enter directly on Stripe's pages; subscription status and customer identifier tied to your account — we never receive card numbers; no health data |
| Anthropic | Managed AI assistant responses | Your assistant messages and, if enabled, protocol context (managed tier only) |
| Twilio | SMS delivery for optional recovery-phone verification and SMS sign-in (US) | Phone number and the verification message — only if you add a recovery phone; never used for marketing |
| Sentry | Crash and error reporting (US) | Technical failure details (error type, stack trace, app version, device platform/OS) — configured to exclude identity, health data, and stored IP addresses |
| PostHog Inc. | Product analytics (US) | Anonymous interaction events: names from a fixed public list, timestamps, durations; basic device info (model, OS/app version, language, time zone); no account identifiers; opt-in only |
| Cloudflare | Web hosting, encrypted backup storage (R2), bot protection (Turnstile) | Encrypted (ciphertext) database backups, which Cloudflare cannot read; IP address and request metadata when you visit our sites or complete the sign-in security check |
| Resend | Transactional email delivery (sign-in confirmations, email-change links) | Your email address and the contents of that message, including its sign-in or confirmation link — never used for marketing |
| Apple / Google | App distribution, sign-in, in-app billing, push delivery | Account/sign-in identifiers; subscription status; push tokens |
| Your chosen AI provider (BYOK, optional) | AI responses using your key | Your assistant requests (governed by that provider's terms) |
We may update this list as our infrastructure evolves and will keep this section current. We do not authorize any of these providers to use your health or protocol information for their own advertising.
8. We do not sell or share your health data
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are used under California law). We do not disclose your health or protocol information to advertisers or data brokers. We have no advertising business model for your data. This applies with equal force to health-platform data (Apple Health / Health Connect) and progress photos: they are never used for advertising, marketing, or data mining, and are never sold.
9. When we may disclose information
We may disclose information outside the vendors in Section 7 only:
- With your direction(for example, a protocol share code you generate contains protocol structure you chose to share — it does not include your logs, labs, or inventory);
- For legal reasons— to comply with a valid legal process, or to protect the rights, safety, or security of users, the public, or DosePlot (note that we cannot produce plaintext of data held under the zero-knowledge passphrase mode);
- In a business transfer— if DosePlot is involved in a merger, acquisition, or asset sale, information may transfer as part of that transaction, subject to this Policy or a successor policy with equivalent protections and notice to you.
10. Data retention
We retain account information and synced data for as long as your account is active or as needed to provide the Service. When you delete your account (Section 11), we delete the associated account and synced data from our production systems, except where we must retain limited records to comply with legal obligations, resolve disputes, or enforce our agreements. Opt-in usage sketches (Section 3.f) are retained for at most 90 days before being reduced to k-anonymous aggregates and deleted; you can delete them earlier at any time from Settings. Opt-in detailed interaction events (Section 3.f) are retained by PostHog for one year and age out of that window; they carry no account identifiers, so they are not covered by account deletion and cannot be individually retrieved. Guest/on-device data is under your control and is removed when you delete it or uninstall the app.
Backups.We keep encrypted backups of our database so we can recover from a failure. They are encrypted before they leave our systems, and our storage provider cannot read them. Backups are retained on a tiered schedule — every backup for 7 days, one per day for 30 days, and one per month for 12 months — and are then permanently deleted. When you delete your account, your data is removed from our production systems right away; copies that remain inside older encrypted backups age out on that schedule, and we never use a backup to restore an account you deleted. To be able to keep that last promise, we retain one minimal record of the deletion itself — an internal account identifier and the date, with no name, email, or health data attached — so that if we ever restore a backup we can tell which accounts must stay deleted. It exists only to prevent a deleted account from being brought back, and it is never used for any other purpose. Administrative security logs (a record of privileged actions taken on the Service) are retained separately for security and legal-compliance purposes, so a deletion cannot erase the record of it.
Progress photo backups after a plan ends. Backing progress photos up to the cloud is a Premium feature. If your paid plan ends, the photos already backed up stay in place and remain viewable and exportable in the app for 180 daysfrom the date the plan ended — you can save them to your device's photo library at any time during that period from the Photos tab. We will email you before anything is removed, including notices about 30 days, 7 days and 1 day beforehand. Resubscribing at any point stops the clock and restores cloud backup. After 180 days we permanently delete the backed-up photo files from our storage; this cannot be undone, and we do not use a backup to restore them. Photos stored only on your own device are not affected by this and remain under your control. Plans that do not expire — including Lifetime and complimentary accounts — are never subject to this. This applies only to plans ending on or after July 26, 2026: if your plan had already ended before that date, your existing photo backups are not deleted under this policy.
11. Your rights and choices
You can exercise the following at any time. Many are available directly in the app; for others, contact us (Section 15).
- Access / portability. You can view your data in the app, generate share codes, and export your account data from Settings as a machine-readable JSON file. You may request a copy of the personal information we hold.
- Correction. Edit your data in the app, or ask us to correct account information.
- Deletion.You can delete your account and its synced data from inside the app (Settings → Account → Delete account). You may also request deletion by contacting us.
- AI data access.Turn the assistant's access to your data on or off in Settings.
- Usage statistics.Off unless you opt in. Toggling off stops both the daily counts and detailed events immediately; uploaded daily counts remain deletable in one tap; detailed events carry no account link, cannot be individually retrieved or deleted, and age out of PostHog's one-year retention window (Section 3.f).
- Cloud sync. Sync is opt-in; you can leave data on-device only.
- Marketing. We do not send behavioral-advertising communications. Any operational or optional email you receive will honor your preferences and applicable law.
California (CCPA/CPRA).California residents have the rights to know, access, correct, and delete personal information, to data portability, to limit the use of sensitive personal information, and to opt out of sale/sharing — noting that we do not sell or share personal information. We will not discriminate against you for exercising these rights. Health and protocol data are treated as sensitive personal information.
Consumer health-data laws (Washington, Nevada, and similar).For residents covered by the Washington My Health My Data Act and comparable consumer-health-data laws, the health-related information you enter is "consumer health data." We collect it only to provide the Service with your consent, do not sell it, and honor requests to access and delete it.
EEA/UK (GDPR). You have the rights of access, rectification, erasure, restriction, objection, and portability, and the right to withdraw consent and to lodge a complaint with a supervisory authority. Our legal bases are in Section 4.
To exercise any right, email privacy@doseplot.com. We may need to verify your identity. We will respond within the timeframe required by applicable law.
12. Children
DosePlot is intended for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact privacy@doseplot.com and we will delete it.
13. International users and data transfers
DosePlot is operated from the United States, and our infrastructure providers process data in the United States. If you use the Service from outside the U.S., you understand your information is processed in the U.S. Where required, transfers of EEA/UK personal data are made under appropriate safeguards (for example, Standard Contractual Clauses).
14. Security incidents
If we become aware of a security breach affecting your personal information, we will notify you and the appropriate authorities as required by applicable law, including, where applicable, the FTC Health Breach Notification Rule and state breach-notification statutes.
15. Changes and contact
Changes.We may update this Policy. If we make material changes, we will update the "Last updated" date and, where appropriate, provide additional notice (for example, in-app). Your continued use after an update means you accept the revised Policy.
Contact.
DosePlot LLC
2108 N St #7682, Sacramento, CA 95816
Privacy: privacy@doseplot.com · Support: support@doseplot.com