Privacy Policy
Last updated: 2026-05-03
This Privacy Policy describes how DoseVault, Inc. (“DoseVault”, “we”, “our”, or “us”) collects, uses, shares, and protects personal information when you use dosevault.ai, the DoseVault web application, the DoseVault progressive web app, our APIs, and any related services (collectively, the “Service”).
DoseVault is a personal peptide tracker and educational resource. We are not a healthcare provider, do not prescribe, and do not provide medical advice. Nothing in this Policy is medical advice. See our Disclaimer for details on the educational nature of the Service.
1. Information we collect
1.1 Information you provide
- Account information: name, email address, password hash, and any profile fields you choose to fill in (date of birth, biological sex, body weight). These are used to authenticate you and to scope your data to your account.
- Health-adjacent data: peptide vials you track, reconstitution parameters, doses you log, injection sites, protocol definitions, reminder schedules, optional bloodwork values, photos of vials or labels you upload, and notes you write. You provide this data voluntarily; we do not collect health information without your input.
- Payment information: when you subscribe to a paid plan, billing details (card number, expiry, billing address) are collected and stored by Stripe, our payment processor. We never see, store, or transmit raw card data; we receive only a customer ID, the last four digits, the card brand, and subscription status.
- Communications: messages you send to support, contact-form submissions, replies to onboarding emails, and similar correspondence.
1.2 Information we collect automatically
- Device and log data: IP address, browser user-agent, device type, operating system, referring URL, pages visited, and timestamps. We retain this data in server logs for up to 90 days for security, abuse detection, and debugging.
- Cookies and similar technologies: see our Cookie Policy for the specific cookies we set and how to control them.
- Product analytics: if you consent via the cookie banner, we collect anonymized event data (page-view, feature-clicked, calculator-used) through Amplitude and/or PostHog. These events are not linked to your name or email.
- Error telemetry: Sentry captures stack traces and client errors so we can fix bugs. We scrub request bodies, URL parameters, and form values from these reports.
1.3 Information from third parties
If you sign in with an OAuth provider (e.g. Google, Apple), Clerk passes us your name, email, and a stable user identifier from that provider. We do not request access to your contacts, calendars, or files.
2. Why we collect it
- To provide the Service: store your vials, doses, and protocols; calculate reconstitution math; render your dashboards; deliver reminders.
- To authenticate you: Clerk maintains a session token so that only you can read or modify your data.
- To bill you (if applicable): Stripe charges your card and notifies us when subscriptions change.
- To send transactional email: Resend delivers verification emails, dose reminders, receipts, and security notifications.
- To improve the Service: aggregate analytics and error reports help us prioritize fixes and new features.
- To meet legal obligations: respond to lawful requests, enforce our Terms, prevent fraud and abuse.
We rely on the following GDPR Article 6 lawful bases: (a) performance of a contract for account, billing, and core feature data; (b) legitimate interests for security logging, fraud prevention, and product improvement; (c) consent for non-essential analytics and marketing cookies; and (d) legal obligation for tax records and lawful-request compliance.
3. Subprocessors and sharing
We share your information with the third-party processors listed below. Each is bound by a data-processing agreement that limits use of your data to providing services to DoseVault.
| Subprocessor | Purpose | Region |
|---|---|---|
| Neon | Managed PostgreSQL database that stores your account, vials, doses, protocols, reminders, and bloodwork. | United States / European Union |
| Clerk | Authentication, session management, and identity verification (email, password, OAuth providers). | United States |
| Stripe | Payment processing, subscription billing, refunds, and tax calculation. Card data never touches our servers. | United States / European Union |
| Resend | Transactional email delivery (account verification, dose reminders, billing receipts, lifecycle drips). | United States |
| Anthropic | Large language model inference for the AI assistant and bloodwork-summary features. Inputs are not used to train Anthropic models. | United States |
| xAI | Alternative LLM provider used as a fallback for AI features. Inputs are not used to train xAI models under our enterprise terms. | United States |
| Vercel | Web hosting, edge networking, and serverless function execution for dosevault.ai. | Global edge network |
| Sentry | Error monitoring and performance telemetry. We scrub PII from stack traces before submission. | United States / European Union |
| Amplitude | Product analytics: feature usage, funnel conversion, retention. Disabled when you opt out via the cookie banner. | United States |
| PostHog | Product analytics and session replay (replay disabled by default). Disabled when you opt out via the cookie banner. | United States / European Union |
We do notsell your personal information for money. We do not share your personal information with advertisers or data brokers. The only “sharing” that may meet the broad CCPA/CPRA definition of “sale” or “sharing” is the use of cookie-based analytics (Amplitude, PostHog) for cross-context behavioral analysis. You can opt out of this at any time via the cookie banner, the Cookie Policypage, or by toggling “Opt out of analytics” in Settings.
We may also disclose information when required by law, in response to a valid subpoena or court order, or to protect the rights, property, or safety of DoseVault, our users, or the public. We will notify affected users of legal-process disclosures unless prohibited by law.
4. International transfers
DoseVault is operated from the United States. If you access the Service from the European Economic Area, the United Kingdom, or Switzerland, your information will be transferred to and processed in the United States. Where required, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum to lawfully transfer personal data.
5. How long we keep your information
- Account & tracker data: retained for as long as your account is active. When you delete your account, we permanently remove your profile, vials, doses, protocols, reminders, bloodwork, and uploads within 30 days, except where we must retain a record for legal or accounting purposes (e.g. tax records associated with a paid subscription, retained for 7 years).
- Server logs: 90 days, then deleted.
- Backups: encrypted backups are retained for 30 days on a rolling window. Deleted data is purged from backups within that window.
- Email-suppression lists: if you unsubscribe, we keep a hashed record of your email so we do not contact you again. This persists indefinitely unless you ask us to remove it.
6. Your rights
6.1 Rights for everyone
- Access: request a copy of the personal information we hold about you. You can self-serve this any time via Settings → Your data → Export.
- Correction: update inaccurate information directly in the app, or email us if a field is not user-editable.
- Deletion: delete your account and all associated data via Settings, or by emailing privacy@dosevault.ai.
- Portability: the export tool returns your data in a structured, machine-readable JSON format.
6.2 GDPR / UK GDPR (EEA & UK residents)
In addition to the rights above, you may: object to processing based on legitimate interests, restrict processing, withdraw consent at any time (without affecting the lawfulness of prior processing), and lodge a complaint with your local supervisory authority. For users in Ireland, that is the Data Protection Commission (dataprotection.ie).
6.3 CCPA / CPRA (California residents)
California residents have the right to know what categories of personal information we collect, the categories of sources, the business purposes for collection, and the categories of third parties we share with — all of which are detailed in this Policy. You also have the right to:
- Opt out of “sale” or “sharing”of personal information for cross-context behavioral analysis. Use the “Necessary only” choice on our cookie banner, or toggle “Opt out of analytics” in Settings. We honor Global Privacy Control (GPC) signals automatically.
- Limit use of sensitive personal information. We do not use sensitive personal information for purposes that require a limit-use right under CPRA.
- Non-discrimination: we will not deny you service, charge you different prices, or provide a different level of quality because you exercised your privacy rights.
To exercise any right, email privacy@dosevault.ai. We will verify your identity (typically by confirming control of the email address on the account) and respond within 30 days for GDPR requests and 45 days for CCPA requests.
7. Children
DoseVault is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@dosevault.ai and we will delete it.
8. Security
We protect your data with TLS in transit, AES-256 encryption at rest, hashed passwords (handled by Clerk), least-privilege database access, audit logging on administrative actions, automated dependency-vulnerability scanning, and regular third-party security reviews. No system is perfectly secure; in the unlikely event of a breach affecting your information, we will notify you and the relevant supervisory authorities within the timelines required by law.
9. Do Not Track and Global Privacy Control
We honor the Global Privacy Control (GPC) signal. If your browser sends GPC, we treat it as an opt-out of “sale” / “sharing” under CCPA/CPRA and disable non-essential analytics on that browser. Because the Do Not Track standard was not finalized, we do not respond to generic DNT headers separately, but GPC has equivalent or stronger effect on this Service.
10. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and, where required by law, notify you by email or in-app banner. Your continued use of the Service after the updated Policy takes effect constitutes acceptance of the changes.
11. Contact us
Privacy questions, rights requests, or complaints: privacy@dosevault.ai.
Postal address: DoseVault, Inc., Attn: Privacy, 1209 Orange Street, Wilmington, DE 19801, United States.
Not medical advice
Information on DoseVault is for educational purposes only and is not a substitute for medical advice, diagnosis, or treatment from a qualified healthcare provider.