Privacy Policy
Last updated 2 September 2026
What we collect
| What | Why |
|---|---|
| Your name, email and mobile number | So we can reach you about the account and send you missed-dose alerts |
| The recipient's first name, mobile number and timezone | To address the message and send it at the right local time |
| Medications, doses, notes and times, as you type them | To put the right medication name in the right message at the right time |
| The record of each dose: what was sent, what came back, and when | This is the adherence record — the actual point of the service |
| Consent: that permission was given, and when | Legally required, and it is what stops anyone being messaged who did not agree |
| A truncated hash of the IP address a sign-up came from | Rate limiting, so the form cannot be used to text strangers |
What we deliberately do not collect
There is no database field for any of the following, so we could not store them if we wanted to:
- Date of birth
- Social Security number or any government ID
- Home address
- Insurance or member ID, or a medical record number
- Prescriber or pharmacy
- Any diagnosis, condition, or clinical note
We ask you not to type these into the free-text fields either.
What never appears in a message
No condition or diagnosis appears in any message we send. A reminder names the medication, or says "your morning meds", and nothing more. This is deliberate: a text can be read by anyone who picks up the phone.
Who we share it with
We do not sell personal information, and we do not share it for advertising. We share it only with the vendors that make the service work:
- Twilio — delivers the text messages. They receive the phone number and the message content.
- Supabase — hosts the database. Data is encrypted in transit and at rest.
- Netlify — hosts this website.
We will also disclose information if the law requires it, or to protect someone from imminent harm.
How long we keep it
The adherence record — what was scheduled, what came back, and when — is kept for as long as the account is active, because that record is the product. The content of messages is redacted from our logs after a retention period, 400 days by default and adjustable per patient. Counts and timestamps survive that redaction; the words do not.
Your choices
- Stop messages: reply STOP to any message. It works immediately and permanently.
- See what we hold: email us and we will send it to you.
- Delete it: email support@doses.care and we will delete the patient record, the medication schedule and the dose history within 30 days. Some consent and message logs are kept longer where the law requires us to prove a message was authorised.
- Correct it: you can edit medications and times yourself in the app, or ask us.
Depending on where you live you may have additional rights — to know, to delete, to correct, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising them. Email us and we will honour the request; we will not ask you to create an account to do it.
HIPAA
We are not a HIPAA covered entity, and this service is not HIPAA compliant. HIPAA applies to healthcare providers, health plans, clearinghouses and their business associates. Doses is none of those, so the information you give us is protected by ordinary privacy law and by the practices described on this page — not by HIPAA. If that matters for your situation, please take it into account before signing up. If we ever begin working with a pharmacy or health plan, this will change and we will say so here first.
Security
Data is encrypted in transit and at rest. Access is controlled per patient, so a caregiver can only see the people they were explicitly granted. Every message in and out is written to an append-only audit log. Inbound messages from the carrier are signature-checked, so a forged reply cannot be written into anyone's record. No system is perfectly secure, and we do not claim otherwise.
Cookies and tracking
This website sets no cookies, runs no advertising trackers, and uses no third-party analytics. The caregiver app stores a login session in your browser so you do not have to sign in on every visit. That is all.
Children
This service is for adults. It is not directed at anyone under 18 and we do not knowingly collect information about children. If you believe a child's information has been entered, email us and we will delete it.
Where data is held
Data is stored on servers in the United States. If you are outside the US, your information will be transferred to and processed there.
Changes
We will post material changes here with a new date.
Contact
Privacy questions or requests: support@doses.care
Doses, operated by Howard Davner, East Hanover, New Jersey, United States.