Privacy Policy for Dose Keeper
DoseKeeper is a medication reminder utility. It helps you schedule and receive reminders to take your medications and keep a private, on-device record of what you took. DoseKeeper does not provide medical, diagnostic, or treatment advice, and it is not a medical device. Any instruction text you enter for a medication (for example "with food") is your own note — we do not author dosage or clinical guidance. Always follow the directions of your doctor or pharmacist.
This policy explains, plainly, what data stays on your device, what the few third-party services we use collect, and your rights.
The short version
- All of your health information stays on your phone. Your medications, strengths, forms, schedules, dose history (taken / skipped / snoozed / missed), adherence statistics, local profiles, and refill counts are stored only in a private database on your device. We do not have a server, you do not create an account, and none of this information is ever sent to us or to anyone else.
- We do not sell your data. Ever. Your health data is never shared with advertisers, analytics providers, or any third party.
- The app is entirely funded by advertising, and nothing in it costs money. There is no purchase, no subscription, and no paid "Pro" version — there is no way to pay us anything at all. Banner ads appear on nearly every screen (including the reminder/alarm screen, but never while your device is locked, and never during onboarding).
- Optional features are unlocked by watching a video ad, not by paying. Watching a rewarded video unlocks the requested feature for the current app session only — closing the app re-locks it.
- You can earn a 24-hour break from banner ads by watching two rewarded videos back to back. That window is recorded only on your device.
- Ads are served by Google AdMob, which collects an advertising identifier and device/diagnostic information for advertising only — and only after you have been asked for consent.
- We collect anonymous usage and crash diagnostics to improve the app. DoseKeeper uses Firebase Analytics (anonymous usage events) and Firebase Crashlytics (crash diagnostics), both processed by Google. This data is never linked to your identity and never includes your health information. You can turn it off any time in Settings → Privacy → "Share anonymous usage & crash reports".
- The app also uses Firebase Remote Config to fetch its advertising settings at startup (Section 4). It governs ads only and carries no health data.
1. Data stored only on your device (never collected by us)
The following is created and stored exclusively on your device and is never transmitted to us or any third party. We operate no backend and cannot access it:
- Medications you add (name, strength, form, color, instructions/notes, "critical dose" flag).
- Schedules and reminder times (fixed times, intervals, specific days, or "as needed").
- Dose history and outcomes (taken, skipped, snoozed, missed) and the times of each.
- Adherence statistics and reminder-reliability diagnostics computed from that history.
- Local profiles (e.g. "Me", "Mom") — used to manage more than one person's medications on one phone. These are local labels only; they are not accounts and are not linked to any identity.
- Refill / supply counts.
- App preferences (theme, default snooze, quiet hours) and the expiry time of any ad-free window you have earned (Section 2).
Because there is no account and no cloud sync, this information exists only on your device. The services described in Sections 2, 3 and 4 never receive any of it.
Backup: to keep the "stays on your device" promise true, your medication database and app preferences are excluded from Google cloud backup and from device-to-device transfer on all supported Android versions. This deliberately includes the earned ad-free window, which is local to one device and does not travel with a backup. If you want to move your data to a new phone, use Settings → Data → "Back up my data" to write a backup file you control (via Android's Storage Access Framework), then Settings → Data → "Restore from backup" on the new phone. Backup, restore, and CSV export are unlocked by watching a rewarded video ad (Section 2) — they cost no money; Settings → Data → "Reset all data" and uninstalling are always available with no ad.
Storage security: the data is held in your app's private storage, which is protected by Android's app sandbox and, on supported devices, by device encryption. Uninstalling the app removes this data.
2. Advertising (Google AdMob)
DoseKeeper is funded entirely by advertising. Nothing in the app is for sale, and there is no way to pay to remove ads — the only ad-free option is the 24-hour window you can earn by watching ads, described below.
2.1 Banner ads — where they appear
A banner ad may appear at the edge of nearly every screen in the app: Today, Medications, History, Settings, medication details, Profiles, the add/edit medication screen, and the full-screen reminder/alarm screen.
Two deliberate exceptions:
- Onboarding is ad-free — no ad is shown on the first-run introduction.
- No ad is shown on the reminder/alarm screen while your device is locked. The alarm can appear over your lock screen so you don't miss a dose; when it does, the banner is suppressed. The ad only appears if you are already looking at the alarm on an unlocked phone. On the alarm screen the banner is placed at the top, separated from the Taken / Snooze / Skip buttons, so it cannot be tapped by accident while you are acknowledging a dose.
2.2 Rewarded video ads — watching an ad instead of paying
Some optional features are unlocked by watching a rewarded video ad: adding more than 5 medications, adding more than one profile, refill tracking, and backup / restore / CSV export.
- You always choose to start a rewarded ad. It never plays on its own.
- The feature unlocks only if you finish the video and Google confirms the reward. If you close the ad early, or no ad can be loaded, nothing is unlocked and you can try again.
- The unlock lasts for the current app session only. It is held in memory and is never saved: when the app is closed and reopened, the feature is locked again and you may watch another ad.
- If ads cannot be served to you at all (for example because ads are switched off, or the consent flow does not permit ad requests), the feature is simply unlocked without an ad rather than being left unreachable.
- Reminders themselves are never ad-gated. Scheduling and receiving reminders, the full-screen alarm, snooze/skip/mark-taken, and your dose history never require watching anything.
2.3 Earning a 24-hour break from banner ads
In Settings you can choose to watch two rewarded video ads back to back to hide all banner ads for 24 hours. If you stop after the first video, nothing is granted. When the window is earned, only the expiry time is stored on your device (in the app's private preferences); it is not sent to us or anyone else, is excluded from backup and device transfer, and the banners return by themselves when it lapses. Rewarded videos still work during the window — that is how the unlocks in Section 2.2 stay available.
2.4 What AdMob collects
To serve banner and rewarded ads, Google AdMob collects and processes:
- Advertising ID (a resettable device identifier) and related device and diagnostic information (e.g. device type, OS version, coarse ad-interaction and performance signals).
The same advertising identifier and device data applies to rewarded video ads as to banner ads — a rewarded ad is an ordinary AdMob ad that you choose to watch.
AdMob uses this for advertising and related fraud-prevention/measurement purposes only. This data is processed by Google as our advertising provider; your health data is never included and is never shared with advertisers.
Consent. Before any ad is loaded, we run Google's User Messaging Platform (UMP) consent flow. Where required (for example in the EEA, the UK, and Switzerland), you are asked to consent, and ads are personalized or non-personalized according to your choice. You can review or change your choice at any time via Settings → About → Privacy options (this entry appears where the consent form offers it). You can also reset or limit your advertising ID in your device settings (Settings → Google → Ads).
- Google's privacy policy: https://policies.google.com/privacy
- How Google uses information from apps that use its services: https://policies.google.com/technologies/partner-sites
3. Analytics and crash reporting (Firebase)
To understand how DoseKeeper is used and to find and fix bugs and crashes, the app uses two Google Firebase services. Both are optional and you can switch them off at any time.
- Firebase Analytics records anonymous usage events — for example that a screen was viewed, that a dose was marked as taken, that onboarding finished, or that a rewarded-ad unlock was granted — along with anonymous counts, generic categories, timings, and true/false flags. We use this to see which features people use so we can improve the app.
- Firebase Crashlytics records crash and stability diagnostics (crash and ANR reports, device model, OS version, and the anonymous event names leading up to a crash) so we can find and fix problems.
No health data, ever. Neither service ever receives your medication names, strengths, doses, schedule times, profile names, or notes. Usage parameters are filtered against an allow-list before anything is sent, so only anonymous, non-identifying values leave the device. Your health information always stays on your phone (Section 1).
This data is processed by Google (Firebase Analytics / Firebase Crashlytics) as our service provider, is not linked to your identity, and is used only to improve the app and fix problems — never to advertise to you, and never sold.
Turning it off. Sharing is on by default but fully optional. Open Settings → Privacy → "Share anonymous usage & crash reports" and turn it off; DoseKeeper then stops all analytics and crash collection on your device. Your choice is remembered across app launches.
- Firebase privacy & security: https://firebase.google.com/support/privacy
- Google's privacy policy: https://policies.google.com/privacy
4. App configuration (Firebase Remote Config)
So we can adjust how ads behave without shipping a new app update, DoseKeeper uses Firebase Remote Config, a Google/Firebase service. At startup the app fetches a small set of settings and then carries on (if the fetch fails or you are offline, the app uses its built-in defaults and works normally).
What it controls: advertising settings only — whether ads are enabled at all, whether banner ads are enabled, whether rewarded ads are enabled, and which ad units to request. It does not control, read, or transmit your health data, and it is not used to profile you or to target content at you individually.
What it transmits. To fetch those settings the Firebase Remote Config SDK contacts Google's servers and sends:
- a Firebase installation ID — a resettable, pseudonymous identifier for this installation of the app on this device (it is not your name, not an account, and not your advertising ID) — and an associated authentication token;
- basic technical information about the app and device: package name, app version, Firebase SDK version, operating system version, and language/region;
- as with any network request, Google receives the IP address the request comes from, and may derive an approximate country from it. We do not receive or store your IP address.
Because DoseKeeper also includes Firebase Analytics, the Remote Config request may additionally carry the anonymous Firebase app-instance identifier that Firebase uses to target configuration. We set no user properties and do not aim configuration at individual users.
Please note: this configuration fetch is part of how the app runs, so — unlike the analytics and crash reporting in Section 3 — it is not covered by the "Share anonymous usage & crash reports" toggle and happens at startup regardless of that setting. It carries no health data and no advertising identifier.
- Firebase privacy & security: https://firebase.google.com/support/privacy
- Google's privacy policy: https://policies.google.com/privacy
5. Notifications and alarms
DoseKeeper posts reminder notifications and full-screen alerts at the times you schedule. This happens entirely on your device. Notification content (which medication, at what time) is derived from the on-device data described in Section 1 and is not transmitted anywhere. No ads are shown in reminder notifications.
6. What we do and don't collect
- We do collect anonymous usage and crash diagnostics via Firebase (Section 3), an advertising identifier via AdMob for users who consent (Section 2), and a pseudonymous installation identifier via Firebase Remote Config (Section 4). None of these ever contains your health data.
- We do not collect your name, email, phone number, or any account information (there is no account).
- We do not collect any payment information, because nothing in the app is for sale.
- We do not collect your location.
- We do not collect contacts, photos, camera, microphone, or body-sensor data.
- We do not collect, transmit, or share your health information — medications, doses, schedules, dose history, and profiles never leave your device, and are never sent to Firebase, AdMob, or anyone else.
- We do not sell personal information.
7. Children's privacy
DoseKeeper is intended for adults managing their own or a family member's medications. It is not directed to children, and we do not knowingly collect personal information from children. Because the app serves ads and requests an advertising identifier, it is not designed for a child audience under Google Play's Families policy.
8. Your rights
Because your health data lives on your device, you are in direct control of it:
- Access / portability: all of your data is visible in the app at any time. Settings → Data → "Back up my data" writes a full backup file you control, and Settings → Data → "Export history (CSV)" exports your dose history as a spreadsheet file — both via Android's Storage Access Framework. These two export features are unlocked by watching a rewarded video ad, for the current app session; they cannot be bought, and they cost no money. If ads cannot be served to you at all, they unlock without an ad, so your data always remains exportable.
- Deletion: delete individual medications or profiles in the app, use Settings → Data → "Reset all data", or uninstall the app to remove all on-device data. Deletion is always available and never requires watching an ad.
- Analytics & crash choices: turn anonymous usage & crash reporting on or off any time in Settings → Privacy → "Share anonymous usage & crash reports" (default on).
- Advertising choices: manage consent in Settings → About → Privacy options and reset/limit your advertising ID in your device settings.
EEA / UK (GDPR): where consent is the basis for ad personalization, you may withdraw it at any time; the anonymous analytics and crash reporting can be switched off in Settings. You also have rights of access, rectification, erasure, restriction, portability, and objection. For on-device data you can exercise these directly in the app; for advertising, analytics, crash and configuration data processed by Google, see Google's privacy policy and controls above.
California (CCPA/CPRA): we do not sell or "share" (for cross-context behavioral advertising) personal information in a way that we control beyond the consented AdMob advertising described above; the analytics and crash diagnostics are anonymous and are not sold. You can decline/limit ad personalization via the consent flow and your device advertising settings, and disable analytics/crash reporting in Settings.
9. Data retention
On-device data is retained until you delete it or uninstall the app. We hold no copy because we operate no server. Advertising data processed by Google, the anonymous usage and crash diagnostics processed by Google/Firebase, and the configuration requests described in Section 4 are retained per Google's policies; you can stop new analytics and crash collection at any time in Settings → Privacy. The earned ad-free window is stored only on your device and expires by itself after 24 hours.
10. Changes to this policy
If we change this policy we will update the "Effective date" above and post the revised version at the same public URL. Material changes will be reflected in the app's Settings → About → Privacy policy link.
11. Contact
Email: shivart.dev@gmail.com
Comments
Post a Comment