This Privacy Policy explains how personal data is collected, used, stored and protected when you use the Dosi AI mobile app and related web services (the "App" or the "Service"). By using the App you acknowledge that you have read this policy. For users in Türkiye, the KVKK Information Notice also applies.
1. Data controller and contact
Data controller: —
Address: —
Email: —
Website: —
You can use these contact details for any privacy question and to exercise your rights.
2. In short
Dosi AI is an information and organization app; it does not diagnose or recommend treatment.
Some information, such as your health profile, is optional; you can use the App without providing it.
Scan photos are kept on our servers for no more than 30 days.
You can permanently delete your account at any time in Settings.
We do not sell your data and do not use it for advertising. The App shows no ads.
Usage analytics are collected only after you accept on the welcome screen and never include medicine names, message content or health information.
3. Data we collect
3.1 Account and identity data
An anonymous user ID created when you first open the App.
If you link your account with Google or Apple, the and (if provided) display name from that provider.
Language preference, time zone, app version and platform.
The date you accepted the legal documents and the accepted version.
3.2 Onboarding answers
How you heard about the App, how you would like to be addressed (preferred name), your age range, how often you use medicines, your main medicine-related challenge, why you use the App, your information priorities and your notification preference.
3.3 Health data (special category data)
Optional health profile: allergies, chronic conditions, regularly used medicines, height, weight, gender and year of birth.
Medicines you scan or search for and their results (scan history).
Medicines you save and any notes you add.
Your reminders and dose logs.
Messages you write in the AI chat and the answers you receive.
Medicines, foods or drinks you check in the interaction check.
Because this data may relate to your health, it is processed only with your explicit consent and only as needed to provide the Service. Filling in the health profile is not mandatory; you can update or delete it at any time.
3.4 Photos
When you scan a medicine box or package, the photo you take or choose from your gallery is uploaded to our servers for analysis. Photos are kept for no more than 30 days. Photos of scans that fail are deleted immediately. Please make sure photos do not show faces, names, addresses or prescription numbers.
3.5 Subscription and payment data
Premium subscriptions are paid through the Apple App Store or Google Play. We never receive your card details. Subscription status, product type, and purchase and renewal dates are processed together with your user ID through our subscription management provider RevenueCat.
3.6 Device and technical data
Notification token: if you allow notifications, an anonymous device token (Firebase Cloud Messaging) is stored so we can send you notifications. Medicine reminders run as local notifications on your device.
Crash reports: to keep the App stable, error and crash information (device model, OS version, error log and anonymous user ID) is collected with Firebase Crashlytics. Health data, medicine names and message content are never added to these reports.
Usage analytics: only after you accept the legal documents on the welcome screen, aggregate measurements of which screens and features are used are collected with Firebase Analytics (Google Analytics). These events never contain medicine names, search text, message content or health information.
To prevent abuse, request counts and timestamps (rate-limit records) are kept for a short time.
3.7 Support and contact
When you contact us through the contact form on our website or through in-app feedback, we process your name (optional), email address, topic and message.
4. Purposes and legal bases
Creating your account and providing the Service (scan, search, chat, reminders, history) — identity data, onboarding answers, scan and chat content. Legal basis: entering into and performing the contract.
Personalized information and warnings based on your health profile — allergies, chronic conditions, regular medicines and other health data processed in the App. Legal basis: explicit consent.
Managing subscriptions and free usage limits — subscription status, usage counts. Legal basis: performance of the contract.
Security, abuse prevention and troubleshooting — technical logs, crash reports, rate-limit records. Legal basis: legitimate interests.
Aggregate usage measurement to improve the product — anonymous usage events. Legal basis: consent.
Responding to support requests — contact details and message. Legal basis: legitimate interests and performance of the contract.
Complying with legal obligations — records required by law. Legal basis: legal obligation.
For users in the European Economic Area, health data is processed on the basis of explicit consent under Art. 9(2)(a) GDPR, and other data on the bases set out in Art. 6(1)(a), (b), (c) and (f) GDPR.
5. Processing with artificial intelligence
To identify medicines, explain medicine information, answer chat messages and assess interactions, your photo and the text you write are sent to an AI model through the Google Gemini API. This processing takes place under Google's API service terms.
For official medicine information, only medicine names are queried from openFDA, the open data service of the U.S. Food and Drug Administration (FDA), and related public sources; no personal data is included in these queries.
Dosi AI does not use your data to train AI models.
AI outputs are generated automatically; they may be incorrect or incomplete and are not medical advice. They do not constitute an automated decision that produces legal or similarly significant effects for you.
Emergency expressions in your messages, such as self-harm or poisoning, are detected automatically and you are shown emergency helplines. Such events may be logged for safety purposes without storing the content.
6. Recipients
Your data is shared only as necessary to provide the Service, with the following providers that are bound by confidentiality and security obligations:
Google LLC / Google Cloud and Firebase: authentication, database, server functions, notifications, crash reporting, analytics, remote configuration and the Gemini AI service.
Cloudflare, Inc. (R2): temporary storage of scan photos.
RevenueCat, Inc.: subscription status management.
Apple Inc. and Google LLC: app store, payments, Sign in with Apple/Google and notification infrastructure.
Competent public authorities: only where legally required.
We do not sell your personal data and do not share it for advertising.
7. International transfers
Our infrastructure is hosted in data centers in the United States and the European Union (Google Cloud / Firebase, Cloudflare). Your personal data is therefore transferred abroad. For users in Türkiye, this transfer is based on your explicit consent and/or appropriate safeguards (such as standard contracts) under Article 9 of the KVKK; for users in the European Economic Area, it is based on the European Commission's Standard Contractual Clauses and applicable adequacy decisions.
8. Retention
Your account data and content are kept for as long as your account exists.
Scan photos are deleted automatically after no more than 30 days.
You can delete a scan history entry, chats, saved medicines and reminders in the App; deletion is permanent and cannot be undone.
When you delete your account, your profile, health profile, scan history and photos, chats, reminders, saved medicines, feedback and notification tokens are permanently deleted.
Security and audit logs are kept for up to 12 months in a form that contains no personal content.
Guest (unlinked) accounts that remain unused for a long time may be deleted after being flagged.
Data subject to statutory retention obligations is kept for the period required by law.
9. Your rights
Under Article 11 of the KVKK in Türkiye and under the GDPR in the European Economic Area, you have the right to learn whether your data is processed, to request information, to access and obtain a copy of your data, to request correction, deletion or destruction, to request restriction of processing, to data portability, to object to processing, to withdraw your consent, to object to a result against you arising exclusively from automated analysis, and to claim compensation for damages.
You can delete your account and all your data yourself via Settings > Delete Account.
For other requests, contact — or use the contact form at —. Requests are handled free of charge within 30 days at the latest.
Users in Türkiye may lodge a complaint with the Personal Data Protection Board (KVKK Kurulu); users in the European Economic Area may complain to the data protection authority of their country.
Withdrawing consent does not affect the lawfulness of processing before the withdrawal. You can end consent-based processing by deleting your health profile or your account.
10. Security
Your data is transmitted over encrypted connections (TLS) and stored encrypted on our providers' infrastructure. Access is limited according to the principle of least privilege, and administrative actions are logged. No system is completely risk-free, but we apply reasonable technical and organizational measures to protect your data.
11. Children
The App is not directed at children under 13, and people under that age must not use it. Users aged 13 to 18 (or below the age of digital consent in their country) may use the App only with the permission of a parent or legal guardian. If we learn that data of a child under 13 has been processed, we delete it.
12. Changes
We may update this policy from time to time. We will inform you in the App about significant changes. The current version is always available in the App and on our website.