Privacy Policy
Last updated: 18 August 2026
This Privacy Policy explains how DoseIt collects, uses, and protects your personal information — including your health information — in the DoseIt mobile application and on doseit.io. DoseIt is operated by Bincor Ltd("we", "us", "our"), a company registered in England and Wales.
1. Who we are
DoseIt is the trading name of:
Bincor Ltd66 Paul Street, London, EC2A 4NA
United Kingdom
Companies House number: 17179401
Director: Joshua Corrigan
Contact: doseit.support@gmail.com
For the purposes of UK and EU data protection law, Bincor Ltd is the data controller of personal information collected through the DoseIt app and doseit.io.
2. Scope
This policy covers:
- The DoseIt mobile application for iOS and Android, including your account and all health and fitness data you enter.
- doseit.io, including the waitlist signup form.
3. What information we collect
3.1 Account information
- Email address and display name, which you provide when you create an account.
- Authentication data needed to keep you signed in.
- Profile details you enter during setup — your age, biological sex, height and training experience level. These are used to calculate BMI, body-composition estimates and dose-related insights, and are stored with your account.
3.2 Health and fitness information
The app exists to record health information, and you choose what to enter. Depending on which features you use, this may include:
- Injection and dose records — the peptide, compound or supplement, dose amount and unit, route, injection site, and the date and time each dose was taken, skipped or missed.
- Protocol information — the protocols you build, including schedules, dose escalation stages, and goals.
- Body measurements — body weight, waist and other measurements, and derived values such as BMI and estimated body-fat percentage.
- Daily check-ins — mood, energy, sleep, side effects and symptoms, and any free-text notes you write.
- Workout and performance records — exercises, sets, repetitions and weights lifted.
Under UK and EU data protection law this is special category data (data concerning health). Section 5.2 explains the specific legal basis we rely on to process it.
3.3 Subscription information
If you subscribe to DoseIt Pro, we receive your subscription status and purchase identifiers from Apple or Google via RevenueCat. We never receive or store your card number, bank details, or any other payment credentials — those are handled entirely by Apple or Google.
3.4 Photos you choose to share
The app can log a workout from a photo or screenshot. This is always started by you — we never access your photo library on our own, and nothing is read from it unless you pick an image.
When you do, that image is sent to Anthropicso the activity in it can be read back as structured workout data. It is transmitted for that purpose only, is not used to train anyone's models (see section 6), and we do not keep a copy of the image — it is passed straight through to be read and is never written to our storage. Only the resulting workout entry is saved against your account.
Please bear in mind that a photo may contain more than the activity you intend to log — other people, locations, or health information visible in the frame. Only share images you are comfortable sending.
3.5 Technical information
- Device and app information — device type, operating system version, and app version.
- Usage analytics — screen views and feature events, to understand which parts of the app are used. We do not send your weight, doses, measurements, check-in contents or any other health values as analytics data.
- Crash and error reports — diagnostic information when the app fails, so we can fix it.
3.6 Waitlist (website only)
If you join the waitlist on doseit.io we collect your email address and signup metadata (date, time and source). We do not collect health data, payment information or device identifiers through the waitlist. We do not use cookies, analytics or tracking pixels on doseit.io.
4. How we use your information
- To create and manage your account.
- To store, synchronise and display the health and fitness data you enter, across your devices.
- To calculate the charts, schedules, estimated blood levels, adherence figures and trends the app shows you.
- To send you dose reminders and notifications you have enabled.
- To generate AI insights when you use those features (see section 6).
- To manage your DoseIt Pro subscription, if you have one.
- To diagnose crashes and improve the app.
- To respond to your support requests.
We do not sell your personal data, and we do not share it for advertising or cross-context behavioural advertising.
5. Legal basis for processing (UK / EU users)
5.1 General personal data
- Contract (Article 6(1)(b)) — to provide the app and your account, and to manage your subscription.
- Legitimate interests (Article 6(1)(f)) — to keep the service secure, diagnose faults, and improve the app.
- Consent (Article 6(1)(a)) — for waitlist emails and optional notifications. You can withdraw consent at any time.
5.2 Health data (special category)
We process the health information described in section 3.2 on the basis of your explicit consent under Article 9(2)(a) of the UK GDPR and EU GDPR. You give that consent when you create an account and confirm you accept this policy, and again in substance each time you choose to enter health data.
You can withdraw this consent at any time by deleting your account in the app (Settings → Delete account), which erases the health data we hold about you. Withdrawal does not affect processing carried out before you withdrew. Because health data is the entire purpose of the app, withdrawing consent means you can no longer use it.
6. AI features and how your data is used in them
DoseIt includes optional AI features — the AI check-in and Pro Insights. When you use them, relevant context from your own records is sent to Anthropic's API so a response can be generated for you. That context may include your recent body weight and goal weight, your dose and protocol history, adherence figures, and your recent check-in entries.
Under Anthropic's commercial terms, this data is used only to produce your response and is not used to train their models.
Automatic daily summary. Once per calendar day, when you first open the app, DoseIt prepares a short progress summary in advance so that it is ready when you view it. This happens whether or not you open the AI features, and it sends the same categories of context described above to Anthropic. It only runs if you have at least one active protocol and enough recorded history for a summary to be produced. Deleting your account stops it.
AI-generated insights are for informational purposes only and are not medical advice. See our Terms of Service.
7. Who we share your information with
We use the following service providers ("processors" or "sub-processors"), each handling only what is needed for the feature you are using, under written agreements:
- Supabase — database and authentication. Stores your account and the health and fitness data you enter, protected by Row Level Security so your records are accessible only to you. Servers located in the European Union.
- Anthropic — generates AI insights when you use those features (section 6), and reads any workout photo you choose to send (section 3.4). United States.
- RevenueCat — manages DoseIt Pro subscription status. Receives purchase identifiers and subscription state only; it does not receive your health data. United States.
- PostHog — privacy-focused product analytics (screen views and feature events). Does not receive your health values.
- Sentry — crash and error reporting.
- Resend — sends waitlist and transactional emails. United States.
- Apple and Google — process your purchase if you subscribe, under their own privacy policies.
We do not share your information with anyone else, except where required by law (for example, in response to a valid court order).
8. International transfers
Some of the providers above are located outside the UK and EEA, principally in the United States. Where we transfer personal data outside the UK/EEA we rely on the UK and European Commission's adequacy decisions (including the UK Extension to the EU–US Data Privacy Framework) and/or Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, so that your data remains protected to UK/EU standards.
9. How long we keep your information
- Account and health data — retained while your account is active. If you delete your account, your personal and health data is erased from our live systems. Encrypted backups are overwritten on a rolling cycle and purged within 30 days.
- Crash and analytics data — retained in aggregated or pseudonymised form for up to 12 months.
- Waitlist email — until you ask us to delete it, or two years after launch or waitlist closure, whichever is first.
10. Deleting your account
You can delete your account and all associated data at any time from within the app: Settings → Delete account. This is immediate and irreversible. You do not need to contact us, and you do not need to explain why. If you prefer, email doseit.support@gmail.com and we will do it for you.
Deleting your account does not automatically cancel a subscription bought through Apple or Google — see our Terms of Service for how to cancel.
11. Your rights (UK / EU users)
If you are in the UK or the EU (including France, Germany, Italy, Spain), you have the following rights under UK GDPR / GDPR:
- Access — ask for a copy of the personal data we hold about you. You can also export your data directly from the app.
- Rectification — ask us to correct inaccurate data.
- Erasure("right to be forgotten") — delete your account in the app, or ask us to delete your data.
- Restriction — ask us to pause processing of your data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent at any time, including your explicit consent to health-data processing, without affecting processing carried out before withdrawal.
To exercise any of these rights, email doseit.support@gmail.com. We aim to respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. The relevant authorities are:
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- France: Commission Nationale de l'Informatique et des Libertés (CNIL) — cnil.fr
- Germany: Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI), or the data protection authority of your federal state (Land)
- Italy: Garante per la protezione dei dati personali — garanteprivacy.it
- Spain: Agencia Española de Protección de Datos (AEPD) — aepd.es
12. US residents
If you are a resident of the United States, you may have additional rights under your state's privacy law (for example, the California Consumer Privacy Act and similar laws in Virginia, Colorado, Connecticut, Utah, Texas, and other states). These typically include the rights to:
- Know what personal information we have collected.
- Delete personal information.
- Opt out of the "sale" or "sharing" of personal information for cross-context behavioural advertising.
- Limit the use and disclosure of sensitive personal information, which includes health information.
We do not sell or share your personal information for advertising purposes, and we use your health information only to provide the features you use. To exercise other rights, email doseit.support@gmail.com. We will not discriminate against you for exercising these rights.
13. Children
DoseIt is intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, please contact us and we will delete it.
14. Security
We use industry-standard practices to protect your information, including encryption in transit (HTTPS/TLS), encryption at rest, database-level Row Level Security so records are readable only by the account that owns them, and access controls on our systems. The app also offers an optional device lock (Face ID, Touch ID or passcode).
No system is perfectly secure. If we ever discover a personal data breach affecting you, we will notify you and the relevant supervisory authority where required by law.
15. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent change. Material changes will be communicated in the app or by email.
16. Language
This policy is published in English. English is the operative language for any interpretation of this policy. Translations may be provided in the future for convenience, but the English version prevails in case of conflict.
17. Contact
Questions, requests, or complaints:
Bincor Ltd (trading as DoseIt)66 Paul Street, London, EC2A 4NA, United Kingdom
Email: doseit.support@gmail.com