Direct product policy. This Privacy Policy applies only to Dosefolio (com.ryantinklepaugh.dosefolio). It directly states the app’s data practices and is not an owner-site redirect or a portfolio-wide substitute.
Scope, controller, and contact
UNCOMMON WEATHER LLC, 1212 N Walker Ave Apt 207, Oklahoma City, OK 73103, United States, is responsible for the information described here. Contact team@uncommonweather.com for privacy questions, rights requests, or support.
Information Dosefolio handles
- Medication names, custom medication labels, prescribed dose details, and future clinician-provided titration steps
- Dose dates, amounts, injection-site history, adherence summaries, and reminders
- Protein entries and targets, symptom and check-in entries, severity, notes, and on-device patterns
- Weight entries, optional Apple Health body-mass samples, sample identifiers, and deletion tombstones
- Local profile, display, notification, widget, Siri, App Intent, and other product preferences
- User-requested clinician PDF reports, weekly image summaries, and password-encrypted versioned local backup packages
- Anonymous App Store purchase and entitlement metadata
- Privacy-minimal legal-choice evidence
Product-specific practices
Private medication and wellness records
Dosefolio stores medication names and custom labels, clinician-provided regimen and titration details, dose dates and amounts, injection-site history, protein entries and targets, symptom and check-in entries, severity, notes, weight entries, local patterns, reminders, and settings in an on-device SwiftData database. Dosefolio has no product account and does not synchronize this health log to an Uncommon Weather product server or to iCloud.
The app database and its small widget cache are excluded from ordinary device backup. Device loss, app removal, storage failure, or deletion can therefore remove records that the user has not preserved independently or in a restorable encrypted Dosefolio backup. Dosefolio does not send the health log to Uncommon Weather, RevenueCat, or an analytics service.
Apple Health
With permission, Dosefolio reads body-mass samples from Apple Health into the local weight log and can write a weight that the user records back to Apple Health. Apple Health permissions can be changed in iOS Settings. Dosefolio does not send Apple Health data to Uncommon Weather, RevenueCat, or the legal-choice ledger.
Deleting a weight from Dosefolio does not necessarily delete the corresponding sample from Apple Health. Apple Health remains a separate Apple-controlled store, and the user must use Apple controls to review or delete records that remain there.
Voice input and on-device processing
Optional voice check-ins use Apple speech recognition configured to require on-device recognition. Microphone audio is used transiently while the user speaks, is not saved as an audio file, and is not sent to the developer. A transcript becomes part of the local symptom or check-in record only when the user saves it.
Where available, Apple on-device foundation models may help parse a check-in into structured local fields. Dosefolio does not send that prompt or result to a developer-operated AI service.
Widgets, Siri, notifications, and App Intents
Dosefolio can schedule local reminders and expose user-requested actions through Siri and App Intents. Its widget receives a minimal App Group snapshot containing medication and display-dose schedule information, latest dose date, and protein total and target. The snapshot uses device file protection and is limited to the recent access window needed by the widget.
Notification, widget, Siri, and App Intent content may be visible on Apple system surfaces according to the user’s device settings. These features do not send the underlying Dosefolio health log to the developer.
Reports, encrypted backups, and sharing
Dosefolio creates clinician PDF reports and weekly image summaries on the device only after the user requests them. The user chooses a destination through the iOS share sheet. A temporary report file may remain long enough to complete that share flow and is then swept by the app; copies saved or sent by the user remain with the chosen recipient or service.
At the user’s request, Dosefolio creates a versioned backup of the then-current local SwiftData records. The app encrypts the backup on the device with AES-256-GCM using a key derived from the user-provided password with PBKDF2. It does not write an intermediate plaintext backup file. Only the encrypted backup package is made available through the iOS share sheet; Dosefolio does not upload the package or password to an Uncommon Weather service.
The user is responsible for keeping both the encrypted backup file and its password. Uncommon Weather does not receive or retain the password, cannot recover or reset it, and cannot restore a backup without it. Copies saved or sent through the share sheet remain under the retention and access controls of the destination or recipient until the user or recipient deletes them.
Restoring a compatible backup requires the correct password and an explicit replacement confirmation. Dosefolio decrypts the package locally and replaces, rather than merges with, the current SwiftData records. The backup does not contain or replace privacy-minimal legal-choice evidence, the separate Apple Health store, or Apple and RevenueCat purchase or entitlement records. A local Dosefolio record that originated from Apple Health can be present in the SwiftData backup without backing up or changing the Apple Health store itself.
Purchases and legal choices
Apple processes subscription purchases and payment credentials. RevenueCat receives an anonymous app-user identifier and limited app, device, transaction, purchase, and entitlement metadata needed to present offerings, restore purchases, and determine Pro access. Dosefolio does not set an account identifier or custom customer attributes and does not send medication, dose, symptom, protein, weight, Apple Health, voice, or report content to RevenueCat.
The legal-choice service receives only signed, privacy-minimal evidence of an acceptance, decline, or withdrawal, including product and document identifiers, versions and hashes, the choice, adult age band and acceptor role, pseudonymous installation and request identifiers, app version and build, timestamps, locale, source and sequence, cryptographic proof, and receipt linkage. It does not receive Dosefolio health or product content.
Retention and deletion
Available controls delete individual medication, dose, symptom, protein, and weight records. A separate Delete All Local Data control erases all health-log categories stored in Dosefolio’s SwiftData database after confirmation. Removing the app ordinarily removes its backup-excluded local database, subject to Apple’s storage behavior. Neither action deletes samples already written to Apple Health, reports or encrypted backup files already shared by the user, Apple or RevenueCat purchase records, or privacy-minimal legal-choice evidence.
Uncommon Weather does not receive or retain user-created Dosefolio backup files. A backup copy remains wherever the user or a recipient saved it until it is deleted there. Restoring a backup changes the local SwiftData records only and does not shorten the separate retention periods that apply to legal-choice or purchase evidence.
Purchase records remain with Apple and RevenueCat under their applicable obligations. Privacy-minimal legal-choice evidence follows the separate legal retention schedule stated below and is not product health content.
Service providers and disclosures
Apple provides iOS, App Store billing, and the Apple frameworks identified above. RevenueCat provides subscription-entitlement infrastructure. Supabase provides the separate legal-choice service and, where the product-specific sections say so, account, storage, synchronization, or server-function infrastructure. Cloudflare delivers and protects the public website. Other named providers process only the information needed for the selected function.
Ordinary connection metadata, such as IP address, route, response status, and timing, can be processed transiently by network, security, and hosting providers to deliver and protect a request. Information may also be disclosed when required by valid legal process, to protect rights or safety, to investigate abuse or security incidents, or in a business transaction with legally required safeguards.
Uncommon Weather does not sell personal information, share it for cross-context behavioral advertising, serve third-party ads, or track users across unrelated products.
Retention and deletion
Product data follows the product-specific retention and deletion boundaries above. Copies deliberately exported, uploaded, or shared remain wherever the user, recipient, or selected service saved them. Support correspondence is retained while needed to handle the request and for reasonable operational, security, and legal purposes. Apple, RevenueCat, Supabase, OpenAI where applicable, and other independent providers retain records under their own policies and legal duties.
Legal-choice events and acceptance receipts are append-only evidence retained until the verified relationship ends plus seven years. Related challenge, key-registration, request-audit, signing-key incident, receipt-integrity, and retention-purge records follow their security and legal-claims schedules. Immutable legal evidence may be retained where needed to establish, exercise, or defend legal claims.
Security
The legal-choice system uses HTTPS, P-256 signatures, keyed pseudonyms, replay-resistant single-use challenges, strict product allowlists, rate limits, restricted service credentials, append-only evidence, and signed receipts. Apple security frameworks and the product-specific controls above protect other data where stated. No system is perfectly secure.
Choices and privacy rights
Users can decline, later withdraw to limited mode, review the current documents, or affirmatively accept from Legal & Privacy settings. Available product controls can manage permissions, delete or export product data, manage or restore purchases, and delete an account where applicable. Depending on location, rights may include access, correction, deletion, restriction, objection, appeal, withdrawal, or a regulator complaint.
A current affirmative acceptance takes effect after it is durably saved on the device. Main-app access remains available while signed-receipt delivery retries after a non-terminal network, Apple, or service outage. Widgets, Live Activities, and other extension surfaces that require a verifiable cross-process receipt may wait until the server-signed receipt is received and verified. An explicit terminal rejection of the exact saved acceptance causes the client to quarantine that failed record and return to the appropriate decision or limited-state screen.
Children and eligibility
Dosefolio is intended only for adults age 18 or older. The legal flow records only a broad adult age band and acceptor role, not a birth date.
Changes and related documents
Material changes receive a new immutable document version. Previously accepted users are asked to make one new choice for a materially changed family; continued use alone does not silently create acceptance. A stored decline or withdrawal remains limited without a recurring prompt. Read the Dosefolio Terms of Service and Dosefolio Product Schedule.
UNCOMMON WEATHER LLC
1212 N Walker Ave Apt 207
Oklahoma City, OK 73103
United States
team@uncommonweather.com