Privacy Policy — Dozsage
Last updated: 25 September 2026
Dozsage (“the App”, “the website”, “we”, “us”) is a personal GLP-1 medication tracker, built first for weekly tirzepatide, with a public informational website. This policy explains what personal data we collect, why, how it is protected, and your rights. We are the data controller.
Contact: support@dozsage.com
The public Dozsage website does not provide account login, health-data entry, analytics, advertising, cookies, or a contact form. Vercel processes ordinary request, security, and operational logs as the website host. Support and privacy requests use your own email application; do not include sensitive health information in an email.
Medical disclaimer
Dozsage is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. It does not provide medical advice or recommend medication or doses. Consult a healthcare professional for medical advice, diagnosis or treatment.
1. What we collect
You create an account and the data below is stored only against your account. We do not sell it, share it for advertising, or use it to train models.
Account data
- Email address (for sign-in and account recovery)
- Display name (optional, from sign-up)
Health & fitness data (this is sensitive personal data under Malaysia’s PDPA and special category data under the EU GDPR — we process it only with your explicit consent, given when you create an account and log data)
- Body weight
- Medication dose and injection site
- Side effects / symptoms and their severity. Saving a Symptom check-in records a rating for each of the six common symptoms, including zero when the symptom was assessed and absent; positive urgent symptoms are stored when reported.
- “Food noise”, hunger, water and protein intake
- Exercise type, duration and intensity
- Your goal weight and injection schedule (used for reminders)
- Progress photos (body images are stored as app-managed local files; a metadata record is stored with your account)
Diagnostic data (enabled in the App Store build)
- Crash reports via Sentry — health values are scrubbed before sending (numbers redacted, health fields removed)
- Anonymous usage analytics via PostHog — which screens are opened, when the app is opened or backgrounded, and which actions are taken (for example “weight logged” or “reminder turned on”, with a category such as “new” or “edit”), plus device OS, model and app version. Events use a random install ID that is not linked to your account, and IP addresses are discarded. No health data is ever sent to analytics. You can turn analytics off at any time in Settings → Share anonymous usage data.
We do not collect your location, contacts, or advertising identifiers. We use the camera only to capture progress photos you choose to save; those images are stored privately on your device and are never uploaded or synced by Dozsage. A small metadata record (date and filename) for each photo is stored with your account, so the history record can appear on another installation even when the image bytes are not present there.
2. Why we process it
- To provide the core function of the App: storing and showing your own health logs.
- To send the local weekly injection reminder you opt into.
- To keep the App working and fix crashes (diagnostics, where enabled).
Legal bases: your consent (health data, given on sign-up and each log) and our legitimate interest in operating and securing the App (account + diagnostics).
3. How it is stored and protected
- Data is stored in Supabase (PostgreSQL), hosted in the Tokyo, Japan region.
- Every row is protected by Row-Level Security — you can only ever access your own data.
- On your device, the local cache of your health data is encrypted at rest (AES-256), with the key held in the device secure enclave (iOS Keychain).
- Traffic between the App and the server is encrypted in transit (TLS).
- Progress-photo image bytes are app-managed local files protected at rest by iOS Data Protection. Only their metadata (not the images) is sent to the server. Ordinary sign-out retains the files for the same account on that installation; another account cannot view them through the App.
- Standard encrypted iOS device backups may include these app-private files and may restore them. Uninstalling the App may remove app-managed copies. Dozsage does not provide its own cloud photo synchronization.
- If you choose Save to Photos, Dozsage creates a separate copy in Apple Photos. That copy is governed by your Apple Photos and iCloud settings; deleting it there does not delete the Dozsage copy, and vice versa.
International transfer: because the server is in Japan, your data is transferred outside Malaysia. We rely on your consent and Supabase’s security commitments for this transfer, consistent with PDPA cross-border requirements.
4. Who we share it with
We do not sell or rent your data. It is processed only by the infrastructure providers that run the App on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, hosting | Japan |
| Sentry | Crash diagnostics (health-scrubbed) | EU/US, only if enabled |
| PostHog | Anonymous usage analytics (no health data) | United States |
| Vercel | Static website hosting and request/security logs | Vercel infrastructure |
5. How long we keep it
We keep your data for as long as your account exists. You can delete an individual progress photo from its viewer or missing-photo management screen. This removes its history metadata and, when present, attempts to remove its app-managed local file.
You can delete your account at any time from Settings → Delete account. This removes your account and health logs from the live database in a single server-side operation, then attempts to remove the active account’s local progress-photo directory and signs you out on this device. If local cleanup fails, the App tells you rather than claiming the files were removed. Account deletion does not remove a separate copy you previously saved to Apple Photos. The server-side deletion is irreversible.
6. Your rights
Under the PDPA, GDPR and similar laws you can:
- Access a copy of your data
- Correct inaccurate data (most is editable directly in the App)
- Delete your data / account
- Withdraw consent (note: the App’s core health features cannot function without it)
- Object to / restrict certain processing, and request portability of your data
To exercise any of these, email support@dozsage.com and we will respond within the period required by law.
7. Children
The App is not intended for anyone under 18 (or the age of majority in your country) and we do not knowingly collect their data.
8. Changes
We may update this policy. The “Last updated” date above will change, and material changes will be notified in the App.