Dose Trace

Privacy, explained

Your records.
Your choices.

What stays on your device, what sign-in shares, and how to manage your information.

Privacy policy · iOS 1.21, build 27
Effective October 2, 2026

About this policy

This policy describes Dose Trace for iOS 1.21 (build 27) and the informational pages at dosetrace.net. It is effective October 2, 2026. The app is in private beta testing; this page does not announce public availability.

Dose Trace is independently operated by one individual, who manages the app and handles support and privacy requests. The private test is intended for adults aged 18 and over in the United States; it is not intended for children. This audience statement does not claim that the app verifies age or blocks access by location.

Your medication records

Dose Trace saves medication profiles, dose amounts and times, injection areas, symptoms, notes, schedules, preparation and syringe settings, optional saved calculation snapshots attached to dose logs, and supply information on your device. These entries support your history, estimates, calculations and reminders. Starting with version 1.25, you can separately opt in to account cloud backup. Signing in alone does not upload health records.

Each signed-in account has a separate local space. Guest records use their own space. Switching accounts does not merge histories or display another account’s records. The guest space is available to anyone who can open the app and choose guest access; it has no separate password.

Records from older versions are preserved for an explicit review and ownership choice. The app never silently combines them with a new space. You can claim a copy for an empty space, review or export preserved records separately, or explicitly move guest records into an empty account space. Once assigned, old records are not offered to another space. These choices rely on you confirming that the records belong to you.

Optional sign-in

You can use Dose Trace as a guest. On a fresh guest launch, the app defers Firebase authentication initialization. An account action, such as sign-in, account creation or password reset, can initialize it. The app may also restore a previously chosen signed-in session. Returning to guest mode does not unload a provider SDK already running in the current app session.

Email sign-in uses Firebase Authentication and sends the email address and password you enter to that service. Verification and password-reset messages use Firebase’s account-email service. The tracker file does not contain your raw password; password fields are cleared after the operation finishes or when you leave the form.

Google sign-in exchanges identity and access tokens with Firebase and may process basic profile information such as your name, email address and provider identifier. Apple sign-in requests your email address, which may be an Apple relay address, and exchanges an identity token with Firebase. The app does not request your Apple full name, Google email messages, contacts or Drive files.

The app uses account identifiers, email address, verification status and provider information to display your account state. Provider SDKs manage session credentials. Signing in alone does not back up or transfer your medication history. Cloud backup and restoring a saved copy require separate choices.

Sign-in providers and technical data

Authentication providers process account information and technical data for operation, security and abuse prevention. Firebase describes IP addresses and user-agent information in its privacy information. Dose Trace disables Firebase’s default data-collection setting where supported. This does not disable all authentication or security processing.

The bundled Google Sign-In SDK declares possible collection of names, email addresses, phone numbers, user and device identifiers, coarse location, usage data and other data, including some analytics purposes. These declarations cover the SDK’s supported uses; they do not establish which fields are received in every Dose Trace sign-in. The app has no phone-number field or location-permission request. See Google’s SDK privacy guidance.

Dose Trace does not integrate Firebase Analytics, Crashlytics or an advertising SDK, or send app-authored usage events. Provider diagnostics and Apple beta-testing data are separate. Provider processing may take place outside your country. Google and Apple explain their practices in the Google Privacy Policy and Apple Privacy Policy.

Reminders

When you enable reminders, Dose Trace asks iOS for permission and schedules local notifications on your device. Lock-screen wording is general and does not include the medication name or dose. Internal record, space and schedule identifiers let a tap open the relevant occurrence without automatically recording a dose.

Switching spaces clears the app’s queued and delivered reminders, then prepares reminders for the active space. Taps for another space do not open its records. Erasing records also cancels the app’s associated reminders. Future notifications are queued within iOS limits and refreshed when the app runs or saved data changes; they are not an unlimited months-long delivery guarantee. No remote push service is used for dose reminders.

Exports and device backups

You can export dose history as CSV or a full active-space snapshot as JSON to a destination you choose. Before creating the file, the app warns that it contains readable health information. Dose Trace does not encrypt or password-protect exports. A recipient or cloud storage provider may gain access under its own practices.

The app clears its pending export document when the export flow finishes or closes. Copies saved elsewhere, or held by the operating system or a document provider, are outside that cleanup. You must manage those copies separately.

The app marks its health-data directory, saved files and local migration recovery copies as excluded from future automatic device backups. It does not change your device’s backup settings or remove copies from older backups. Optional account cloud backup and cloud restore are available in version 1.25. Importing a separately exported JSON file is not available. Without a saved cloud or exported copy, losing the device, deleting the app or erasing a space can mean losing its records.

Optional cloud backup and requested email

In Settings → Cloud backup & email, a verified account can opt in to saving the latest complete account-space snapshot in Google Firebase Firestore in the United States (us-central1). This includes medication profiles, doses, weights and targets, symptoms, notes, schedules, injection sites, and preparation and measurement settings. The snapshot is linked to your account identifier. Guest records are not uploaded automatically.

Automatic backup runs while the app is open. Offline changes remain local and retry when the app runs again or you choose Back up now. This is backup and explicit restore, not automatic multi-device merging. On a new device, review and restore the existing cloud copy before replacing it. Restore keeps a local recovery copy of the previous device records. The current cloud limit is 450,000 bytes per complete snapshot; larger records remain available through local export.

Requested email exports send the saved cloud snapshot as a JSON backup, dose CSV and weight CSV to the account’s current verified email, through support@dosetrace.net in Google Workspace. The service does not accept an arbitrary recipient, and no email is automatically sent for every logged dose. A sender acceptance receipt does not guarantee inbox delivery. The email sender requests send-only permission, not access to read your inbox.

Cloud records and attachments are readable by the services that process them; this is not end-to-end encryption. Google processes records and messages to provide Firebase and Workspace, and the Dose Trace operator can access them to operate and support the service. There is no sale, advertising use, or cross-app tracking of these records.

The latest cloud snapshot is retained until you delete it or delete your account. Email request receipts are retained until cloud/account deletion. Deleting a cloud copy pauses backup on that device; another device detecting the deletion pauses its automatic backup. Explicitly enabling backup again can upload that device’s records. Emails already sent or in flight cannot be recalled. Readable attachment copies may remain in the sender’s Sent mailbox, the recipient’s mailbox, exports, or provider recovery systems after cloud/account deletion. No automatic retention deadline is currently configured for sent export messages; contact support to request removal of operator-held email copies.

Keeping and deleting data

Local records remain until you remove them. You can delete individual doses in History. In Settings → Local data & privacy, you can erase the active space after confirmation, or separately choose to erase every local space on the device. Erasure removes the selected health records, plans and local recovery copies; it also closes pending record editors and clears reminders. It does not delete your sign-in account, external exports or older backups. Erasing every space also removes other accounts’ local records and unassigned legacy records.

Signing out preserves the account’s local space and does not delete the account. Settings → Account → Delete account requests fresh authentication before asking Firebase to delete the account. Apple account deletion also requests token revocation through Apple authorization. Version 1.25 removes saved cloud records and email request receipts as part of account deletion. Local records are managed separately, so erase or export them before deleting an account. Already-sent email copies are separate and cannot be recalled. The erase-all option remains available for local spaces you can no longer sign into.

Firebase states that authentication IP logs are retained for a few weeks; after account deletion is initiated, other authentication information is removed from live and backup systems within 180 days. See Firebase’s retention description. This is not a promise of immediate deletion from every provider or device service. Removing the app alone does not delete your Firebase account or necessarily clear credentials held by platform services.

Device security and beta testing

Saved health files use iOS file protection. Account spaces separate records within the app; they are not independent encrypted vaults. There is no additional app PIN, biometric lock or end-to-end encryption claim. Protect access to your device. Erasing a file is not a guarantee of forensic removal from every storage layer.

Apple processes TestFlight testing information and may share crash data, usage information and feedback with the developer. Screenshots or feedback you send can contain visible health information. See TestFlight & Privacy. Avoid including sensitive records in voluntary feedback.

Version 1.25 introduces optional cloud backup and requested email exports for this private beta. Payments and subscriptions are not available. Changes to these practices will require an updated policy.

This website and external links

These informational pages use local assets and contain no forms, sign-in interface, advertising or analytics scripts, or external fonts. Their page code does not set cookies or use browser storage. Firebase Hosting serves dosetrace.net.

For hosted requests, Firebase processes IP addresses to detect abuse and analyze usage. Its published privacy information describes Hosting IP-data retention as a few months. This Hosting retention description is separate from the Firebase Authentication periods above. See Firebase’s privacy information.

Firebase-managed authentication routes, including /__/auth/, are separate from these informational pages. Sign-in provider processing described above applies when you use authentication; the static-page description is not a claim that those authentication routes use no cookies or storage.

Links to manufacturer or provider information open third-party websites. Those sites receive normal browser requests and apply their own privacy practices.

Contact

For support or privacy questions, email support@dosetrace.net.

Messages you choose to send can include your email address, message contents and attachments. They are used to respond to your support or privacy request. The inbox is hosted in Google Workspace. On the Dose Trace side, only the sole operator manages and accesses it; Google also processes messages to provide the email service. Please do not include passwords or sensitive health records in your first message.

The support-email policy is to manually delete resolved conversations 90 days after resolution, unless an ongoing issue or legal reason requires keeping them longer. This is a manual practice, not a configured automatic deletion rule. Deleting a conversation from the inbox does not promise immediate removal from provider recovery systems or backups, or from copies held by recipients. Google’s handling is governed by its data processing terms.

You can use this address to ask about, correct or request deletion of information you sent to support. App records and sign-in accounts have the separate controls described above.