Privacy Policy

Last updated 5 May 2026

Dosey is a tool that helps parents track when their children take medication like Calpol and Ibuprofen. We take your data, and your child's data, seriously. This policy explains what we collect, why, and what your rights are.

Who we are

Dosey is operated from the United Kingdom. You can contact us at hello@dosey.info. We are the data controller for the personal information described below.

What we collect

Account information: your email address, an encrypted password hash, and the date you signed up.

Child information you enter: first name, date of birth, and an avatar emoji. We do not require last names, photos, or any other identifying information.

Tracking entries you create: dose records (medication, amount, time), temperature readings (with optional notes), free-text notes, and household partner-share invitations.

App-derived data: device type and OS version (for crash reporting and bug fixes), preferred theme (light/dark), and an opaque push notification token if you grant push permissions.

Purchase information: if you upgrade to Premium, Apple or Google handle the purchase; we receive an entitlement flag from RevenueCat indicating that you have an active Premium plan. We do not see your card details.

We do not collect: location, contacts, photos, browsing history, advertising identifiers, biometrics, or any data we don't directly need to track doses safely.

Children's data

Dosey is used by parents and guardians to record information about their children. We do not knowingly allow anyone under 13 to create their own Dosey account. If you are a parent and believe your child has signed up directly, contact us and we will delete the account.

Information about a child (name, date of birth, avatar, dose history) is entered by the parent. Under UK GDPR and the Data Protection Act 2018 you, the parent, are responsible for that data; we process it on your behalf only to provide the tracking features of the app.

Why we collect it

We do not sell your data, share it with advertisers, or use it for behavioural targeting.

Where it lives

Your data is stored on servers in the United Kingdom or European Union. We use the following sub-processors:

How long we keep it

We keep your data for as long as your account is active. If you delete your account from within the app, your data is removed from our database immediately. Server backups are purged within 30 days. If you're sharing a household with a partner and you delete only your account, the partner retains access to the household's dose history.

Your rights

Under UK GDPR you have the right to:

To exercise any of these rights, email hello@dosey.info.

Security

Communication between the app and our servers is encrypted in transit via HTTPS. Passwords are stored as bcrypt hashes; we never see your plaintext password. Authentication uses short-lived JWT access tokens and rotating refresh tokens. We do our best to keep your data safe but no system is perfect; in the unlikely event of a breach affecting your data we will notify you within 72 hours.

Disclaimer

Dosey is a logging tool, not medical advice. Always follow the dosage instructions on the medicine packaging and consult a healthcare professional if unsure.

Changes to this policy

If we change this policy materially we will notify you via the app and/or email. Continued use of Dosey after a change indicates acceptance of the updated policy.