DoseMap

Privacy Policy

Effective 22 July 2026. Version 1.1. Last updated 22 July 2026.

The short version

  • Your health records stay on your phone. Everything you enter into DoseMap — medications, sessions, sites, reactions, notes — is stored on your device. We operate no server that receives it. We cannot read it, recover it, or hand it to anyone, because we do not receive it.
  • We do not sell, rent, trade, or disclose your information to advertisers, data brokers, insurers, employers, pharmaceutical companies, researchers, or anyone else.
  • If you email us, we have your email address. We use it to reply to you and nothing else. We do not add it to mailing lists, and we will delete it if you ask.
  • Health details you send us by email get deleted. If you describe your therapy or your condition in a message to us, we remove it once the matter is closed rather than keeping it on file.
  • Crash reports from Apple are used to fix bugs and are not passed on to anyone.
  • Neither the website nor the app runs analytics. No cookies, no trackers, no usage measurement. The only diagnostic information we receive is crash reports.

The rest of this document explains all of that precisely, including the limited technical exceptions, because a privacy policy that overstates its promises is worthless.

1. Who we are and what this covers

DoseMap is operated by DoseMap Health Technologies Inc., a company incorporated federally in Canada and based in Halifax, Nova Scotia. In this policy, "we," "us," and "our" mean that company. "You" means anyone who uses the DoseMap app, visits this website, or contacts us.

This policy applies to:

  • The DoseMap iPhone application, in all versions including pre-release and beta builds
  • The website at dosemap.ca and any subdomain of it
  • Any correspondence you have with us by email

It does not apply to services operated by others that you may reach through us, including Apple's App Store and TestFlight. Those are covered by their own policies, discussed in section 15.

We are the party responsible for the limited personal information described in this policy. For Canadian purposes we are an "organization" under the Personal Information Protection and Electronic Documents Act (PIPEDA). For users in the European Economic Area or the United Kingdom, where those laws apply to us, we act as a "controller" of that limited information.

2. Information stored on your device

This is the section that matters most, because it covers the sensitive information — and the answer is that we do not have it.

When you use DoseMap you may record:

  • Medications, including names you enter yourself, dosages, and colour labels you assign
  • Infusion sessions, including start and end times and duration
  • Infusion sites and your rotation across them
  • Adverse reactions and symptoms, and any notes you write
  • Reminders and schedules you configure
  • Any other free-text notes you choose to add

All of this is written to storage on your device using Apple's on-device data framework. It is not transmitted to us. It is not transmitted to any third party by us. There is no account, no login, no sync, and no cloud copy created by DoseMap.

We have no technical ability to read this information. We could not produce it in response to a subpoena, a request from an insurer, a request from an employer, or a request from a healthcare provider, because it does not exist anywhere we can reach. If you want someone to see it, you show it to them yourself.

What this also means

The same architecture that protects you creates one risk you should understand clearly: if your device is lost, stolen, damaged, wiped, or reset, those records are gone permanently. We cannot restore them, because we hold no copy.

DoseMap marks its data store as excluded from device backup. Your records are therefore not written into iCloud Backup or into encrypted local backups, and restoring a device from a backup will not bring them back. We made that choice so that your health information stays on the one device you control rather than being copied onto servers we have no relationship with. The trade-off is real and we would rather state it plainly: a backup is not a safety net for this data.

An export you can save elsewhere is on our development list. Until it ships, please keep whatever method you use now alongside DoseMap.

3. Information we actually receive

There are exactly three narrow channels through which any information about you reaches us. We describe each one fully.

3.1 Email correspondence

If you write to us — to request beta access, report a problem, suggest a feature, or ask a question — we receive your email address, your name if your mail client includes it, the content of your message, and anything you choose to attach.

We use this only to read and reply to you, and to keep a record of the conversation so that if you write again we have context. We do not add your address to any mailing list. We do not send marketing. We do not sell, rent, or disclose it. We do not use it to build a profile of you.

Please do not send us detailed health information by email. If you want to describe a bug, a general description is enough. Email is not a secure channel and we would rather not hold information we do not need.

If you do send us health information, we delete it. Whether we asked for it or not, we remove the message from our mailbox once the matter it relates to is closed, and in any event within 90 days. Where we need a record that the exchange happened, we keep a short note of the outcome with the health details stripped out, rather than the original message.

That deletion covers our live mailbox, including sent items and the deleted-items folder. Copies may survive in our mail provider's own backups for a period afterwards, until those backups cycle out on the provider's schedule — we cannot accelerate that, and we would rather tell you than imply a cleaner guarantee than we can deliver.

3.2 TestFlight and crash reports

While DoseMap is distributed as a beta through Apple's TestFlight, Apple provides us with limited technical information about testers and builds. This can include:

  • The email address associated with your Apple Account, if you join the beta through an invitation
  • Crash reports, which describe where in the app's code a failure occurred
  • Aggregate installation and session counts
  • Device model and operating system version
  • Any feedback you voluntarily submit through TestFlight, including screenshots you choose to attach

Crash reports contain technical information about the application, not the health information you have recorded. They tell us where in the code a failure occurred. We use them solely to identify and fix defects. We do not share crash reports, tester email addresses, or any TestFlight data with any third party, and we do not use them for marketing.

Crash reporting is the only diagnostic channel in the app. We have added no analytics of our own — nothing measures which screens you open, how often you use DoseMap, or what you record in it. The installation and session counts above are figures Apple reports to us about builds, not measurements we take about people, and they do not tell us what any individual did.

Apple collects and processes this information under its own privacy policy and terms, over which we have no control. What Apple does with it is governed by Apple's agreements with you.

3.3 Website server logs

This website is hosted by a third-party hosting provider. Like essentially all web hosting, their servers automatically record technical request data, which may include your IP address, the page requested, the time of the request, your browser type, and the referring page.

We do not use these logs to identify you, we do not combine them with any other information, and we do not have analytics software installed. They exist as a function of how web servers operate. Our host retains them under its own retention schedule.

4. What we don't do

These are commitments, not aspirations, and they describe how DoseMap works today. They are written in the present tense deliberately. If any of them stopped being true, we would update this policy and say so prominently before the change took effect, rather than leaving a promise standing here that we had quietly outgrown.

  • We do not sell your personal information.
  • We do not rent, trade, barter, or otherwise commercially disclose your information.
  • We do not share your email address with any third party for that party's own purposes.
  • We do not share crash reports or technical data with advertisers, analytics firms, or data brokers.
  • We do not disclose information to insurers, employers, pharmaceutical manufacturers, or benefits administrators.
  • We do not include advertising in the app or on this website.
  • We do not embed third-party analytics, advertising SDKs, or tracking pixels.
  • We do not measure how you use the app — no usage analytics, no event logging, no session recording.
  • We do not build behavioural profiles or infer characteristics about you.
  • We do not use your information to train machine learning or artificial intelligence systems.
  • We do not track you across other apps or websites.
  • We do not require an account, a login, or a real name to use the app.
  • We do not collect your location.
  • We do not access your contacts, photos, microphone, or camera.
  • We do not read, and cannot read, the health records you keep in the app.

5. Service providers

We are a two-person company and we use ordinary commercial services to operate. These providers act on our behalf and are not permitted to use information for their own purposes. Naming them is not an exception to section 4 — it is what makes section 4 honest.

ProviderWhat it doesWhat it can see
Microsoft (Microsoft 365)Hosts our emailMessages you send us, including your address and content
AppleApp distribution and TestFlightTester emails, crash reports, install and session counts. Not your app records — DoseMap excludes them from device backup.
NetlifyHosts this websiteStandard server request logs, including IP address
GoDaddyDomain registration and DNSDomain routing only; no user content

Each of these is a substantial organization with its own published privacy commitments and security programme. None of them receives the health information in your app, because that information does not leave your device.

If we add a service provider that changes this picture, we will update this table and note the change in section 19.

6. Legal basis and consent

Under Canadian law we rely on your consent. Installing and using the app, or writing to us, constitutes consent to the limited handling described here. Because we collect almost nothing, and nothing sensitive, the scope of that consent is narrow.

You may withdraw consent at any time by deleting the app and asking us to delete any correspondence. Withdrawing consent does not affect anything we did lawfully before you withdrew it, and in some cases we may need to keep a minimal record that a deletion request was made.

Where the General Data Protection Regulation applies, our lawful bases are your consent for correspondence, and our legitimate interests in operating a functioning website and fixing defects in our software. You may object to processing based on legitimate interests as described in section 9.

7. How long we keep things

WhatHow long
Your app recordsOn your device, for as long as you keep them. Deleting the app deletes them. Not included in device backups.
Email correspondenceKept while it is useful for supporting you, and deleted on request. Ordinarily removed within 12 months of a conversation ending.
Health information sent to us by emailDeleted once the matter is closed, and in any event within 90 days.
Crash reportsKept until the defect is fixed and the fix is released, then deleted.
TestFlight tester recordsHeld by Apple under Apple's schedule; removed from our tester list when the beta ends or you ask.
Website server logsHeld by our hosting provider under its own schedule; we do not extract or retain copies.

We do not keep information "just in case." If we have no reason to hold something, we delete it.

8. Security

The strongest security measure we have taken is architectural: we do not collect the sensitive information in the first place. Information that is not transmitted cannot be intercepted, and information we do not hold cannot be breached from our side.

For what does exist:

  • Records on your device are protected by your device's own security — your passcode, Face ID or Touch ID, and Apple's file encryption. We strongly recommend using a passcode.
  • This website is served over HTTPS with a valid TLS certificate.
  • Our email accounts are protected by strong authentication.
  • Access to our developer and hosting accounts is limited to the two of us.

No system is perfectly secure, and we will not claim otherwise. We are a small team and we do not hold certifications such as SOC 2 or ISO 27001. We are telling you this plainly rather than implying assurances we do not have.

9. Your rights

Because your health records are on your device, you already have complete control of them: you can view, edit, or delete any entry at any time, and deleting the app removes all of it. No request to us is required, and none would help, since we have no copy.

For the limited information we do hold — essentially your email correspondence — you have the right to:

  • Access it, and be told what we hold and why
  • Correct it if it is inaccurate
  • Delete it
  • Withdraw consent to further contact
  • Complain to a regulator if you are unhappy with our response

Depending on where you live you may also have rights to data portability, to object to certain processing, or to restrict processing. These derive from the GDPR and UK GDPR, Quebec's Law 25, and laws such as the California Consumer Privacy Act. We extend all of them to everyone regardless of residence, because with a dataset this small it costs us nothing to do so and it is the right posture.

To exercise any right, email support@dosemap.ca. We will respond within 30 days. We will not charge you, and we will not treat you differently for asking.

Under the CCPA we confirm that we have not sold or shared personal information in the preceding twelve months, and we do not knowingly sell the personal information of anyone under 16.

10. International users and transfers

We are based in Canada. Our service providers operate infrastructure in Canada, the United States, and elsewhere. If you email us, that message may be stored on servers outside your country and may be accessible to authorities in those countries under their laws.

Your health records are not affected by any of this, because they remain on your device and are not transferred anywhere by us.

11. Children and young people

DoseMap is intended for adults managing their own therapy, and for parents or guardians managing therapy on behalf of a child. It is not directed at children and we do not knowingly collect personal information from anyone under 13.

If a parent or guardian uses DoseMap to record a child's infusions, that information stays on the parent's device under the same terms as everything else. We do not receive it.

If you believe a child has sent us personal information, email us and we will delete it.

12. Health information and regulatory status

DoseMap is a personal record-keeping tool. It is not a medical device. It does not provide medical advice, diagnosis, treatment recommendations, or dosing guidance. It performs no clinical calculation and makes no clinical determination. Always follow the instructions of your healthcare provider, and speak to them before changing anything about your therapy. In an emergency, contact emergency services.

Health information you record in DoseMap is yours. It is held by you, on your device, under your control. We are not a health information custodian under Nova Scotia's Personal Health Information Act or equivalent provincial legislation, and we are not a covered entity or business associate under the United States Health Insurance Portability and Accountability Act, because we do not receive, hold, or process your health information at all.

If your clinician suggested DoseMap to you, that does not create any relationship between us and your clinician regarding your data. We do not report your usage back to them. If you want them to see your records, you show them.

13. Beta and pre-release software

DoseMap is currently distributed as pre-release software through Apple's TestFlight. Beta software may contain defects, may behave unexpectedly, and may lose data. Please do not rely on DoseMap as your only record of your therapy during the beta. Keep whatever method you use now alongside it.

Test builds expire after a period set by Apple, currently 90 days. When a build expires, the app stops opening until a newer build is installed. Data on your device is not deleted by expiry.

Because DoseMap excludes its records from device backup (section 2), those records cannot be recovered from a backup if the device is lost or reset. During the beta especially, keep a second record of anything you would not want to lose.

Participating in the beta means Apple provides us the technical information described in section 3.2. If you would prefer not to share that, do not join the beta.

14. Cookies, tracking, and analytics

This website sets no cookies. It loads no external scripts, no analytics, no advertising, no social media widgets, and no tracking pixels. Every file it serves, fonts included, comes from our own domain.

The app carries no analytics either. Nothing in DoseMap measures which screens you open, how long you spend in them, or what you record. There is no event logging, no session recording, and no third-party SDK reporting on your behaviour. The only diagnostic information that reaches us is the crash reporting described in section 3.2.

Apple separately reports to us, through App Store Connect, how many people have installed a given beta build and how many sessions those builds have had. Those are counts Apple holds about builds rather than measurements we take about people, and they tell us nothing about what any individual did in the app.

This is why you have not been shown a cookie consent banner. There is nothing to consent to.

Because we run no analytics, we do not respond to Do Not Track signals in any particular way — there is nothing for them to switch off.

15. Links to other services

This website and the app link to services operated by others, most importantly Apple's App Store and TestFlight. Once you follow such a link you are governed by that organization's privacy policy and terms, not ours. We have no control over how they handle your information and we are not responsible for their practices. We encourage you to read Apple's privacy policy, which is available on Apple's website.

16. Data breaches

If we became aware of a breach of security affecting personal information we hold, and that breach created a real risk of significant harm, we would notify affected individuals and the Office of the Privacy Commissioner of Canada as required by PIPEDA, and any other regulator whose rules applied. We would tell you what happened, what information was involved, and what you should do.

The realistic scope of any such breach is our email correspondence. Your health records are not exposed to this risk, because we do not hold them.

17. Automated decisions and profiling

We make no automated decisions about you and perform no profiling. Nothing in DoseMap scores, ranks, categorizes, or makes predictions about you, and no output of the app is used to make any decision affecting you.

18. Business changes

If DoseMap Health Technologies Inc. were sold, merged, restructured, or wound up, our limited records — essentially email correspondence — could transfer to a successor. If that happened, we would notify affected individuals and the successor would be bound by commitments no weaker than those in this policy, or would have to obtain fresh consent.

Your health records could not be transferred in such a transaction, because they are not ours to transfer.

If we ever intended to change the on-device architecture — to add cloud sync, accounts, or any server-side storage of health information — we would not do so silently. We would explain it, publish an updated policy in advance, and obtain your express consent before any health information left your device.

19. Changes to this policy

We may update this policy as the app develops or as the law changes. When we do, we will change the effective date and version number at the top of this page.

For any change that materially reduces the protections described here, we will give notice in the app before it takes effect, rather than relying on you to re-read this page.

Version history

  • Version 1.1 — 22 July 2026 — recorded that app records are excluded from device backup; added deletion commitment for health information sent by email; clarified that neither the website nor the app runs analytics; rewrote section 4 in the present tense.
  • Version 1.0 — 21 July 2026 — initial publication.

20. Complaints and contact

Write to us first. We are two people and we read every message.

Email: support@dosemap.ca
Post: DoseMap Health Technologies Inc., Halifax, Nova Scotia, Canada

We will acknowledge privacy enquiries promptly and respond substantively within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, or to your provincial privacy commissioner. If you are in the European Economic Area or the United Kingdom, you may complain to your national supervisory authority. Complaining to a regulator does not require our permission and we will not object.