Privacy by default

Privacy Policy

This policy applies to dosetally.com and the DoseTally web app. The service is intended only for adults aged 18 or older.

Last updated: 4 August 2026

Who operates DoseTally

DoseTally is operated by Pavel Krylou, Belarus. For the limited server-side processing described below, Pavel Krylou is the data controller. The product name is DoseTally and the website is dosetally.com.

Server data we receive

When you request a page or app file, standard server access logs may contain your IP address, user-agent, requested URL, request time, response status, and referrer. We use them to deliver the service, keep it secure, diagnose failures, and prevent abuse. The legal basis is our legitimate interests in operating and protecting DoseTally. Access logs are retained for 14 days.

If you email support, we receive your email address and the contents of your message. We use them to answer your request and retain the conversation for up to 90 days after the issue is closed. Please do not include medication names, diagnoses, dosages, or other medical information in support messages.

Consent-based page-view analytics

If you give consent, the landing page and this policy page use PostHog Cloud EU to count page views and returning visits and understand referrers, campaign parameters, and general browser and device characteristics. We use this limited information to understand website usage and improve DoseTally. The legal basis is your consent. Analytics remains disabled until you choose “Allow analytics”.

Analytics is limited to page-view and page-leave events. Autocapture and session recording are disabled. We do not send medication data, form contents, clicks, names, email addresses, or account identifiers to PostHog.

After consent, PostHog receives request metadata such as the page URL, referrer, timestamp, IP address, and user-agent. It stores a random analytics identifier in a first-party cookie and localStorage so the same browser can be recognised across visits. The PostHog cookie expires after 365 days; localStorage and the saved consent choice remain until you change your choice or clear site data.

You can reject analytics or withdraw consent at any time through “Analytics settings” in the page footer. Withdrawing consent stops further collection and removes PostHog analytics persistence from this browser.

Data kept only on your device

The web app stores medication names, dosages, notes, schedules, reminders, and dose history in a local SQLite database backed by browser storage such as IndexedDB or OPFS. This information is not sent to us and remains until you delete a course or clear site data for dosetally.com.

The app also stores your theme choice in localStorage under the key localStorage.theme until you change it or clear site data.

Cache Storage, a service worker, and a browser persistent-storage request may be used to keep the app files and local database available reliably. These are technical browser mechanisms, not analytics or advertising trackers.

PDF schedules are created entirely on your device. A PDF is sent only to the download or share destination that you choose; it is not uploaded to DoseTally.

Local health data and household use

You decide whether to enter medication information, control it in a compartmentalised browser environment, and use it for personal purposes. DoseTally provides the software but cannot access the resulting local health data. On this basis, that local processing is intended to fall within the personal or household activity exemption. If the app gains cloud access to health data, this assessment and policy must change before launch.

Cookies and similar storage

Before consent, PostHog does not store analytics persistence or send analytics events. Your analytics consent choice is saved in localStorage so it can be respected on later visits. If you decline, only that choice is retained. If you allow analytics, PostHog also uses a first-party cookie and localStorage for its random browser identifier. The web app separately uses the functional browser storage described above.

What DoseTally does not do

DoseTally has no user accounts, advertising, cross-site tracking, sale of personal data, cloud synchronisation, or automated decision-making. The limited page-view analytics described above is not linked to a name, email address, account, or medication data.

Service providers and disclosures

PostHog Cloud EU processes the limited analytics data described above as our analytics provider. Hosting and email providers may process access-log or support data only to provide those services to us. We may also disclose server data where required by law. We do not provide local medication data to anyone because we cannot access it.

Retention and deletion

Delete an individual course inside the app. To delete all local DoseTally data, clear the site data for dosetally.com in your browser settings; this removes the local schedules and related browser storage. Browser caches may also be replaced automatically when the app is updated.

Server access logs are deleted after 14 days. Analytics events are retained for up to 12 months. Support correspondence is deleted no later than 90 days after the issue is closed unless a longer period is required by law.

Your rights

Depending on the law that applies to you, you may request access to, correction of, deletion of, restriction of, or objection to our processing of server logs, analytics data, and support correspondence. You may also complain to your local data-protection authority. We may need enough information to locate and verify the relevant records.

You may withdraw analytics consent at any time through “Analytics settings”. Because DoseTally does not link the random browser identifier to an account or contact details, we may be unable to locate analytics events belonging to a particular visitor without additional identifying information.

We cannot retrieve, export, correct, or delete medication data stored only in your browser because we never receive it. Use the in-app course controls or your browser site-data controls instead.

EEA and UK representatives

DoseTally has not appointed a representative in the EEA or the UK. We currently rely on the applicable exemptions because our processing is limited to access logs, consent-based page-view analytics, and support correspondence, and we do not have access to health data. This position will be reviewed before adding advertising, accounts, cloud synchronisation, more extensive analytics, or active promotion in the EEA or UK.

Changes to this policy

We will update this page before materially changing how data is handled. In particular, advertising, more extensive analytics, accounts, cloud synchronisation, or server access to medication data require a new review and an updated policy before release.

Contact

Privacy questions and requests can be sent to support@dosetally.com.

Allow PostHog Cloud EU to measure page views and returning visits. PostHog will store an analytics identifier in this browser. We do not send medication data, form contents, or clicks.

Read the privacy policy