DoseMe
Privacy Policy
Last updated: August 27, 2026
Privacy Policy — DoseMe
Last updated: 2 July 2026
Effective date: 2 July 2026
This Privacy Policy explains how the DoseMe medication reminder application (the "App") processes your personal data. It has been prepared in accordance with the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the European Union General Data Protection Regulation ("GDPR").
2. Core Principle: Offline-First
DoseMe is designed to operate primarily on your device. You can use the App without creating an account and without an internet connection. In this mode, your medications, dose schedules, medication history, and notifications are stored only on your device and are never transmitted to our servers.
The App only processes data over the internet in two situations:
-
Anonymous usage analytics and crash reports (enabled by default — see Section 4).
-
When you create an optional cloud account (synchronization, family tracking, health records — see Section 5).
3. Data Stored on Your Device
The following information is stored only on your device and, unless you create an account, is never transmitted to any server:
-
Medication names, dosages, intake instructions (before/after meals), repeat schedules, and reminder times
-
Dose events (taken / missed / snoozed) and medication history
-
Medicine package/barcode photos and barcode information
-
Medication stock, expiration date, package opening tracking, and treatment duration
-
Application preferences (language, theme, discreet notification mode, etc.)
Camera and Photos: When you scan a medicine package or barcode, image processing (OCR and barcode recognition) is performed entirely on your device. Photos are never uploaded to any server. Captured images are stored only within the App's local storage. On Android, the system camera is used without requesting a separate camera permission. On iOS, camera permission is requested by the operating system.
Notifications: Medication reminders are scheduled locally on your device and are not delivered from a remote server.
4. Firebase — Anonymous Usage and Crash Data
To improve the quality and reliability of the App, DoseMe uses Google Firebase services. This data collection is enabled by default, and no separate in-app consent screen is displayed.
| Service | Data Collected | Purpose |
|---|---|---|
| Firebase Analytics | Anonymous usage events, device model, operating system version, approximate region, application version | Understand usage trends and improve the product |
| Firebase Crashlytics | Crash reports, stack traces, device state | Diagnose and resolve application errors |
| Firebase Cloud Messaging (FCM) | Device push notification token | Deliver notifications (only when cloud account and family tracking are enabled) |
This information does not directly identify you. DoseMe does not collect custom analytics events; only Firebase's automatic analytics events and crash reports are processed.
Transparency Notice: Because of this telemetry, the App is not strictly "100% offline." Anonymous usage statistics and crash reports may leave your device.
5. Optional Cloud Account (DoseMe)
If you wish to use features such as cloud synchronization, multi-device access, family/caregiver monitoring, health measurement logging, or medication adherence reports, you may create an optional DoseMe account.
Unless you enable these features, the information below is not collected or processed.
5.1 Account and Contact Information
-
Email address
-
Name
-
Optional phone number
-
Password (stored only as a cryptographic hash, never in plain text)
-
Language preference
-
Subscription plan
-
SMS notification consent
5.2 Medication and Dose Information
(Cloud copy of your locally stored medication data)
-
Medication name, dosage, frequency, before/after meal information, stock, treatment dates, notes, doctor's notes, injection details
-
Reminder schedules (hour/minute)
-
Optional location information (latitude, longitude, location name) for location-based reminders
-
Dose records (taken, missed, skipped), confirmation time, and confirmation method
5.3 Health Data — Special Category Personal Data
The following information is considered special category personal data under KVKK Article 6 and is processed only with your explicit consent:
-
Health measurements: blood pressure (systolic/diastolic), blood glucose, weight, body temperature, oxygen saturation (SpO₂)
-
Symptom records: symptom name, severity (1–10), notes
-
Side-effect notes
All health-related features remain unavailable until you provide explicit consent. If consent is not granted, the server rejects requests involving health data. You may withdraw your consent at any time.
5.4 Family / Caregiver Monitoring
If you enable family monitoring, a secure relationship is established between a caregiver and a patient through a QR invitation and mutual approval.
Caregivers may receive notifications regarding:
-
Missed medication doses
-
Daily medication summaries
-
Critical alerts such as low stock, expiration dates, package opening reminders, and treatment completion
Each notification category can be enabled or disabled independently.
5.5 Technical Information
-
Device push notification token (deleted upon logout)
-
Authentication session tokens
6. Purposes of Processing and Legal Bases
| Purpose | Data | KVKK Legal Basis | GDPR Legal Basis |
|---|---|---|---|
| Provide medication reminders | Medication schedules and doses | Performance of a contract | Art. 6(1)(b) |
| Account creation and security | Email, hashed password, authentication tokens | Contract / Legitimate Interest | Art. 6(1)(b), 6(1)(f) |
| Health measurements and symptom tracking | Special-category health data | Explicit Consent | Art. 9(2)(a) |
| Family/caregiver notifications | Relationship information, dose status | Consent / Legitimate Interest | Art. 6(1)(a), 6(1)(f) |
| Product improvement and debugging | Anonymous analytics and crash reports | Legitimate Interest | Art. 6(1)(f) |
| Barcode-based medication lookup | Anonymous barcode query | Legitimate Interest | Art. 6(1)(f) |
7. Data Security
We implement industry-standard security measures to protect your information.
-
Secure transmission: All communications with our servers use HTTPS/TLS encryption. HTTP traffic is redirected to HTTPS, and HSTS is enabled.
-
Encryption at rest: Health notes, symptom records, and side-effect notes are encrypted using AES-256-GCM.
-
Passwords: Passwords are stored only as secure cryptographic hashes.
-
Authentication: Short-lived access tokens and rotating, revocable refresh tokens are used.
8. Third-Party Services and International Transfers
Your data may be shared only when necessary with the following service providers:
-
Google Firebase (Analytics, Crashlytics, Cloud Messaging) for anonymous analytics, crash reporting, and push notifications. Firebase servers may be located outside your country.
-
[Hosting Provider — e.g., AWS, Google Cloud, Microsoft Azure, or another provider] for hosting cloud account data.
Because some providers may process data outside your country, your personal data may be transferred internationally. Such transfers rely on your explicit consent where required by KVKK Article 9 and/or appropriate safeguards such as Standard Contractual Clauses under the GDPR.
DoseMe does not use:
-
Drug interaction databases
-
Automated phone call services
-
Advertising networks
The App currently does not include payment processing.
9. Data Retention
-
Local device data: Stored until you uninstall the App or manually clear its data.
-
Cloud account data: Retained while your account remains active. When you delete your account, all associated medication, health, and family data are permanently removed through cascading deletion.
-
Anonymous analytics: Retained according to Google's Firebase retention policies.
-
Legal retention obligations: Where required by applicable law (such as financial record retention), certain records may be retained for the legally required period.
10. Your Rights
Under KVKK Article 11 and the GDPR, you have the right to:
-
Know whether your personal data is being processed
-
Request information about your personal data
-
Learn the purpose of processing and whether it is used accordingly
-
Request correction, updating, or deletion of your personal data
-
Withdraw consent where processing is based on consent
-
Obtain a portable copy of your personal data
-
Object to decisions based solely on automated processing
-
Request compensation for damages where permitted by law
Controls Available Within the App
You can:
-
Update your profile information
-
Enable or disable SMS notifications
-
Grant or withdraw explicit consent for health data processing
-
Delete your account and all associated data using the in-app Delete Account option
11. Children's Privacy
DoseMe is not intended for children. Parents or caregivers may enter medication information for individuals under their care; however, the account holder is expected to be over 6 years of age.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If significant changes are made, we will notify you within the App or on this page.
The "Last Updated" date at the top of this document indicates when the latest version became effective.