1. Who we are
Your D.O.S.E ("we", "us") is a wellness application offering personalised movement, breathwork, meditation and nutrition guidance. We are the data controller for the personal data described in this policy.
Company name, registration number and registered address to be inserted on incorporation. Contact: info@yourdose.app.
We have not appointed a Data Protection Officer. We are not required to; our processing is not large-scale monitoring, and we do not process health data as our core activity in the sense Article 37 describes. If that changes, we will appoint one and say so here.
2. What we collect
Only what the app needs to work. Nothing is collected for advertising.
When you create an account
- Your name, email address and a password (which we never store — see §9)
- Your date of birth, to confirm you are 18 or over
- Your gender, if you tell us (optional)
- Your acceptance of our health disclaimer, and when you accepted it
- A referral code, if a friend gave you one
When you use the app as a guest
You can browse without an account. A guest account holds no email address and no name beyond the word "Guest". If you later create a full account, the guest record becomes your account and anything you recorded as a guest stays with it.
When you use the app
- Your practice history — which practice, when, how long, and how much of it you completed
- Your streaks, level, experience points and badges
- Your daily habits: hydration, gratitude and sleep-preparation check-offs
- Your favourites, your chosen goal and any programme you enrol in
- Your reminder times and notification preferences
- Your time zone, theme choice and — if you upload one — a profile photograph
- A push notification token for your device, if you enable reminders
We record when a practice started and periodically confirm it is still running. This is how we verify a session was genuinely completed before awarding progress, and it is also used to detect abuse of the rewards system.
When you subscribe
- Your subscription plan, its state, and the dates it started, renews or was cancelled
- An identifier linking you to your customer record at Stripe
- A record of payments made
We never see or store your card details. Payment is taken by Stripe on their own pages.
3. Health data, and why we treat it separately
Some of what you tell Your D.O.S.E is health data — a special category under Article 9 of the GDPR, which the law protects more strictly than ordinary personal data. We treat it that way.
This is all of it:
| What | When you give it |
|---|---|
| The wellness conditions you select, how severe each one is, and any free-text note you add | The onboarding questionnaire, and any time you retake it |
| Your activity level and the wellness areas you want to work on | The onboarding questionnaire |
| A profile we derive from your answers, indicating which of the four D.O.S.E hormones your plan should emphasise | Calculated by us, from the above |
| Your mood, and any note you write about it | Mood check-ins, and after a practice |
| Your height, weight and biological sex, and the nutrition targets we calculate from them | Only if you use the nutrition calculator |
| Your reproductive life stage, the date of your last period and your typical cycle length | Only if you switch on cycle awareness |
Our legal basis for all of it is your explicit consent (Article 9(2)(a)). You do not have to provide any of it. The app works without the questionnaire, without mood tracking, without the nutrition calculator and without cycle awareness — you will simply get a more general plan. You can withdraw consent at any time by deleting the data or your account, and cycle data has its own delete button that removes it immediately and by itself.
Who can see it
Our staff cannot. The administration panel our team uses does not expose your conditions, your mood entries, your cycle data or your nutrition profile. An administrator can see your name, email, subscription state, streak and level, and the derived hormone emphasis of your plan — and nothing else about your health.
4. Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account; delivering the practices, plans and progress tracking you signed up for | Performance of a contract (Art. 6(1)(b)) |
| Personalising your daily plan and excluding practices unsuitable for the conditions you told us about | Your explicit consent (Art. 9(2)(a)) |
| Taking payment and keeping records of it | Contract (Art. 6(1)(b)); legal obligation for tax and accounting records (Art. 6(1)(c)) |
| Sending you the reminders and notifications you switched on | Contract (Art. 6(1)(b)), and your settings |
| Sending password-reset codes and other messages you ask for | Contract (Art. 6(1)(b)) |
| Keeping the service secure — rate limiting, detecting fraudulent completion of sessions, keeping an audit log of administrator actions | Our legitimate interests in a secure and honest service (Art. 6(1)(f)) |
| Confirming you are 18 or over | Our legitimate interests, and our terms (Art. 6(1)(f)) |
We do not use your data for automated decisions that produce legal or similarly significant effects. Your daily plan is generated automatically from your answers, but it is a suggestion about exercise — you can swap any practice, browse the whole library freely, and ignore the plan entirely.
5. Who we share it with
We do not sell your data and we never will. We share it with four service providers, each doing one job:
| Provider | What they do | What they receive | Where |
|---|---|---|---|
| Stripe | Takes payment and manages subscriptions | Your email address, your name, and an identifier for your account. Your card details go to Stripe directly and never reach us. | United States |
| Brevo | Sends transactional email — password-reset codes, and your data export if you request it by email | Your email address and the contents of the message. | France (EU) |
| Expo, and through them Apple and Google | Delivers push notifications to your device | Your device's push token, and the text of the notification — which may contain your first name, your streak length or your level. | United States |
| DigitalOcean | Hosts the server and the database | Everything described in this policy, as the underlying infrastructure. | United States (see §6) |
No health data is ever put into a push notification. The system that composes them can only insert your first name, your streak, your level and your session count — nothing about your conditions, mood, cycle or nutrition.
When you ask for a copy of your data
You can request a copy of everything we hold (see §8). The file itself is never sent by email. We create a private download link that works for one hour and only for your account, open it on your device, and email you the same link as a backup. So your health data travels from our server to you and to nobody else — the email provider sees a web address and your first name.
Other disclosures
We may disclose personal data if we are legally required to, or to establish or defend a legal claim. If the business is sold or merged, your data would transfer to the buyer, and we would tell you before that happened.
6. Where your data is stored
Your data is stored on a private server we operate, located in the United States (Santa Clara, California), hosted by DigitalOcean. Our email provider, Brevo, is in France.
What this means if you are in the EU or UK.
Storing your data in the United States is a transfer to a country outside the EEA. Such transfers are lawful when protected by an approved safeguard — in our case, the Standard Contractual Clauses in our agreements with our providers. The same applies to Stripe and to Expo's push delivery. You can ask us for details of these safeguards using the contact address in §14.
We are reviewing whether to move our primary storage to a European region. If we do, we will update this section and tell existing users.
7. How long we keep it
| Data | Kept for |
|---|---|
| Your account and everything attached to it | Until you delete it. Deletion is final after a 14-day grace period, during which you can change your mind. |
| Cycle data | Until you delete it, which happens immediately and does not wait for the grace period. |
| Your practice history, mood entries, plans and progress | For as long as your account exists. We do not currently expire them, because your progress and streak history are the point of the product. |
| Sign-in sessions | Access tokens last 15 minutes. The token that renews them lasts 30 days and is replaced each time it is used. |
| Password-reset codes | 15 minutes, then they stop working. Using one cancels it. |
| Email delivery records — that a message to your address was delivered, bounced or was rejected | Kept for deliverability troubleshooting. See the note below. |
| Payment records | Retained as long as tax and accounting law requires, which is longer than your account. |
| Administrator audit logs | Retained for security. They record which administrator changed what, and their IP address — not your data. |
An honest limitation. Three of our internal tables — email delivery events, payment provider events, and payment records — are not linked to your account record, so our automatic deletion does not currently reach them. They can contain your email address and, in the case of payment events, your name. We are changing this. In the meantime, if you delete your account and want these removed too, email us and we will do it by hand.
8. Your rights
If you are in the EU, EEA or UK, you have the following rights. They are free to exercise, and we will respond within one month.
- Access — ask what we hold about you.
- Portability — get a machine-readable copy. This is built into the app: Profile → Data & privacy → export.
- Rectification — correct anything wrong. Most of it you can edit yourself; email us for the rest.
- Erasure — delete your account and your data, from Profile → Delete account, subject to the limitation noted in §7.
- Withdraw consent — for health data, at any time, without giving a reason. Withdrawing does not affect processing we did before you withdrew.
- Restriction and objection — ask us to pause processing, or object to processing we base on legitimate interests.
- Complain — to your national data protection authority. You do not have to come to us first, though we would like the chance to fix it.
9. How we protect it
- Passwords are never stored. We keep a bcrypt hash at cost 12, which cannot be reversed into your password.
- Sign-in tokens are short-lived and rotate. An access token lasts 15 minutes and is cryptographically signed. The renewal token is single-use: presenting one that has already been used revokes the entire family of tokens for that account, on the assumption it was stolen.
- Everything travels over HTTPS.
- Health responses are never cached. Every response from our API is marked not to be stored, specifically because they can carry your plan and your safety warnings.
- Requests are rate limited, and sign-in attempts more strictly than the rest.
- Uploads are checked by their actual content, not by what the file claims to be.
- Administrator actions are logged — who, what, when and from where — and the log deliberately never records the body of a request, so an administrator's own password can never end up in it.
- Administrators cannot read your health data (see §3).
We do not currently encrypt individual database fields beyond the protections above. We would rather say so than imply a safeguard we have not built.
One thing to be aware of: profile photographs are served without authentication. If you upload one, anyone who obtains its URL can view it. If that matters to you, use one of the emoji avatars instead.
10. What we do not do
Stated plainly, because most apps in this category do some of these.
- No analytics or tracking of any kind. There is no Google Analytics, no Tag Manager, no PostHog, Mixpanel, Amplitude, Segment, Plausible or Matomo anywhere in the app, the admin panel or this website.
- No advertising, no advertising SDK, no tracking pixel, no attribution service.
- No cookies — not in the app, not in the admin panel, not on this website.
- No location data. No GPS, no IP geolocation. The only location-like information we hold is the time zone you choose, so that your reminders arrive at the right hour.
- No access to your contacts, calendar, microphone or photo library, beyond the single photo you pick if you set a profile picture.
- No sharing between users. There are no public profiles, no social feed and no leaderboard. Nobody using Your D.O.S.E can see anything about you.
- No selling of data, ever, to anyone.
The one exception to "no sharing between users" is the referral programme: if you invite a friend, you can see that someone joined with your code, shown as a partly-masked name and email. If you use a referral code, the person who invited you learns that their code was used and whether it led to a subscription.
11. Children
Your D.O.S.E is for adults. You must be 18 or over to create an account, and we check your date of birth when you register. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, email us and we will delete it.
12. This website
This website sets no cookies and runs no analytics. Every font and image on it is served from our own server, so loading this page contacts no one but us — no third party receives your IP address or browser type. This paragraph previously said images came from an outside image service and that we were working on it; that work is done.
13. Changes to this policy
If we change this policy we will update the version and date at the top. If a change materially affects how we use your data — particularly your health data — we will tell you in the app or by email before it takes effect, and where the law requires it, ask for your consent again.
14. Contact and complaints
Email info@yourdose.app for anything in this policy, including to exercise any of the rights in §8.
If you are unhappy with our response, you have the right under Article 77 of the GDPR to complain to a supervisory authority. You can always complain to the data protection authority in the country where you live, work, or where you think the problem occurred — you never have to come to ours.
Once the operating company is registered, we expect to be established in Malta, which would make our lead supervisory authority the Office of the Information and Data Protection Commissioner (IDPC): Level 2, Airways House, High Street, Sliema SLM 1549, Malta · idpc.info@gov.mt · idpc.org.mt. We name it now, with the caveat, rather than leaving the question unanswered: until incorporation is complete there is no lead authority to name, and pretending otherwise would be the false half of a true sentence.
Who we are as a legal entity, under which law, and our regulatory position as a wellness rather than a medical product, are set out in the legal notice.
