Security
Your medication data, and what we do with it
What happens when you add a medication
When you add a medication by name, the name is sent to a model provider to produce the plain-language explanation, common side effects, and suggested reminder slots. If you snap a label photo, the image is sent first to read the medication name from it, and then that name follows the same path. The result is stored in our database against your account so you can see it again without re-running the model.
The data is transmitted over TLS 1.2 or better and stored encrypted at rest by our database provider, Neon, running on AWS. It is never posted anywhere public, never shared with another user, and never sent to any third party other than the model provider.
Label photos are not stored after the medication name is read from them.
Model providers and training
Dosely routes across leading model providers through a single provider layer. The current live provider is OpenAI. We use these providers under their business API terms, which prohibit training on API traffic.
We do not fine-tune any model on your medication data. We do not use your list to improve prompts without asking. We do not sell or license customer data to anyone for any purpose.
Who at Dosely can read your data
Access to the production database is limited to the engineers who operate it. It is used to keep the service running, not to browse people's medication lists.
If you open a support ticket and share a link to a specific medication card, we may look at that one record to answer your question. If you would rather we did not, say so in the ticket and we will work from your description instead.
How long we keep it
- Medication records and the plain-language information stored with them: until you delete them, or until 30 days after you delete your account, whichever is sooner.
- Account records: for as long as the account is open, then 30 days.
- Form submissions from contact and help forms: 24 months.
- Server logs, which record request paths and timings but not medication names: 30 days.
- Backups: rolling 7 days, after which deleted data is gone from backups too.
Deleting your data
Delete any single medication from its card, which removes the name, the plain-language information, and the reminder schedule for that medication from our database. Delete your whole account from Settings, which removes every medication, every reminder, and the account record.
Both are immediate and neither needs a support ticket. If you want written confirmation for your own records, email us and we will send it.
Accounts and access
- Passwords are hashed with a secure one-way function and a per-user salt. We never store or log a password, and nobody at Dosely can see one.
- Sessions are httpOnly, sameSite cookies signed with a server-side secret, and they expire after 30 days.
- Google sign-in is supported so you do not need another password.
- Every request for a medication record checks that the record belongs to the account asking for it, in the database query itself.
Our own posture
- Two-factor authentication is required on every service Dosely uses, with no exceptions and no shared logins.
- Production access is limited to the engineering team and reviewed quarterly.
- Dependencies are updated on a weekly cadence and security advisories are addressed within 72 hours for anything reachable from production.
- We do not yet hold a SOC 2 report. We are a pre-seed company and would rather say so than imply otherwise. Formal audits are on the roadmap. If you need a completed security questionnaire for procurement, email us and we will fill it in honestly.
Reporting something
Email security@mydosely.tech. We acknowledge within two business days, we will not take action against you for reporting in good faith, and we will tell you when it is fixed. If you want to be credited, say so and we will.
This page describes what Dosely does today. The privacy policy is the legal version of the same thing, and the terms cover the rest. Last reviewed January 2025.