PRIVACY BY DESIGN & ZERO TELEMETRY

Privacy Policy

Effective Date: September 7, 2026 | Document Revision 2.4

🛡️
Absolute Privacy Guarantee:

Dosezy is engineered around a strict local-first architecture. The core application contains zero analytics SDKs, zero advertising trackers, zero telemetry, and intentionally omits internet permission from its offline manifest. Your health logs never leave your physical device hardware unless you explicitly configure encrypted cloud sync.

01.Zero Telemetry & Zero Network Permissions

Dosezy enforces a strict zero-telemetry policy. Unlike standard health apps, Dosezy does not contain any third-party analytics libraries (such as Google Analytics, Firebase, Mixpanel, or Sentry). The core Android application intentionally omits android.permission.INTERNET from its manifest.

We collect 0 bytes of usage metrics, crash reports, IP addresses, device identifiers (IMEI/Android ID), or behavioral interaction data. Your use of Dosezy is completely invisible to us and any third parties.

02.Local Hardware Storage & Data Ownership

All data entered into Dosezy—including medication names, schedules, dosage histories, emergency contact details, doctor notes, and adherence rates—remains stored exclusively in an encrypted SQLite Room database on your physical device hardware.

You hold 100% legal ownership and physical control over your medical records. Because data is stored locally, the developers and maintainers of Dosezy cannot access, view, restore, or modify your stored information under any circumstances.

03.Optional Caregiver Cloud Sync & End-to-End Encryption (E2EE)

If you voluntarily opt into using the managed Dosezy Caregiver Cloud or deploy your own Docker Self-Host Node, synchronization is protected by Zero-Knowledge End-to-End Encryption (E2EE):

  • Data payloads are encrypted on your local device before transmission using AES-256-GCM encryption and Argon2 key derivation.
  • Our cloud sync servers act solely as blind encrypted relay nodes and store zero plain-text data or decryption keys.
  • Only authorized caregiver devices holding your private passphrase can decrypt your sync payloads.

04.Zero Commercial Data Selling or Aggregation

Dosezy does not monetize, license, rent, trade, or sell user personal health information to third-party data brokers, pharmaceutical companies, advertisers, or insurance providers. We explicitly comply with the California Consumer Privacy Act (CCPA) "Do Not Sell My Info" mandates and EU GDPR Article 13/14 requirements.

05.Children's Privacy Protection (COPPA & GDPR)

Dosezy is a general audience health scheduling utility. We do not knowingly collect personal information from children under the age of 13 (or 16 in the European Union). Because Dosezy operates offline without central data collection, no child data is ever transmitted to or stored by Dosezy maintainers.

06.Disclaimer of Physical Device Hardware Security Liability

While Dosezy implements local SQLite database encryption, you are responsible for securing your physical smartphone (e.g., biometrics, device screen passcode). Dosezy maintainers are not liable for unauthorized access to your health records resulting from stolen hardware, unencrypted device backups, or malware on your local operating system.

07.Policy Updates & Contact Information

We reserve the right to modify this Privacy Policy to reflect technical or legal advancements. Any updates will be posted on this page with a revised effective date. For privacy inquiries or technical questions, contact our maintainers at privacy@dosezy.com.