Product-specific document. This schedule applies only to Dosefolio (com.ryantinklepaugh.dosefolio). It supplements the separate Dosefolio Terms of Service and Privacy Policy, each with its own immutable version and SHA-256 hash.
Product purpose
Dosefolio is a private personal-record tool for logging a clinician-provided medication regimen, self-administered doses, injection sites, protein, symptoms, check-ins, and weight.
Purpose and adult eligibility
Dosefolio is intended for adults age 18 or older who want a private record of a regimen and actions determined with their own licensed clinician. It is not designed for children, dependent dosing, institutional medication administration, or emergency use.
Not medical advice or a medical device
Dosefolio records information the user supplies. It does not diagnose, prescribe, calculate a treatment plan, recommend a medication or dose, choose an injection site, detect an emergency, or replace a clinician, pharmacist, medication label, or official instructions. Pattern summaries, schedules, reminders, and reports may be incomplete or wrong and must be checked against the user’s actual prescription and clinical advice.
A user must contact an appropriate clinician or emergency service for medical questions, severe symptoms, suspected overdose, allergic reaction, or any urgent concern. Do not delay care because of information in Dosefolio.
Local storage, backups, and independent records
The primary Dosefolio health log is local and excluded from ordinary device backup. The user can create a password-encrypted, versioned Dosefolio backup and choose where to save or send the encrypted file through the iOS share sheet. The user is responsible for retaining both the file and its password; Uncommon Weather cannot recover the password or an unreadable backup.
A restore requires the correct password and explicit confirmation, then replaces rather than merges the current local SwiftData records. It does not restore or alter privacy-minimal legal-choice evidence, the Apple Health store, or Apple and RevenueCat purchase or entitlement records. The user remains responsible for keeping any independent record needed for treatment, taxes, insurance, employment, or clinical care and for preserving needed information before deleting the app or changing devices.
Subscriptions
Dosefolio Pro may be offered as an auto-renewable subscription through Apple. The price, duration, trial, renewal terms, and included features shown by Apple at purchase control. Apple handles billing, cancellation, refunds, and subscription management. Restoring a purchase remains available from the app.
Limited mode
A user who declines or withdraws remains able to review legal documents and support information, manage or restore an Apple purchase, export or delete available local records, and reconsider from Legal & Privacy settings. Features that create new records, schedule new reminders, or require Pro access may remain unavailable until the current product documents are affirmatively accepted. A durably saved local acceptance unlocks the main app while signed-receipt delivery retries; a non-terminal network or service outage does not return the main app to limited mode. Widgets and other extension surfaces that require a verifiable cross-process receipt may wait until the server-signed receipt is received and verified.
Current product data boundary
The following categories and operational boundaries are specific to Dosefolio and form part of this schedule.
- Medication names, custom medication labels, prescribed dose details, and future clinician-provided titration steps
- Dose dates, amounts, injection-site history, adherence summaries, and reminders
- Protein entries and targets, symptom and check-in entries, severity, notes, and on-device patterns
- Weight entries, optional Apple Health body-mass samples, sample identifiers, and deletion tombstones
- Local profile, display, notification, widget, Siri, App Intent, and other product preferences
- User-requested clinician PDF reports, weekly image summaries, and password-encrypted versioned local backup packages
- Anonymous App Store purchase and entitlement metadata
- Privacy-minimal legal-choice evidence
Private medication and wellness records
Dosefolio stores medication names and custom labels, clinician-provided regimen and titration details, dose dates and amounts, injection-site history, protein entries and targets, symptom and check-in entries, severity, notes, weight entries, local patterns, reminders, and settings in an on-device SwiftData database. Dosefolio has no product account and does not synchronize this health log to an Uncommon Weather product server or to iCloud.
The app database and its small widget cache are excluded from ordinary device backup. Device loss, app removal, storage failure, or deletion can therefore remove records that the user has not preserved independently or in a restorable encrypted Dosefolio backup. Dosefolio does not send the health log to Uncommon Weather, RevenueCat, or an analytics service.
Apple Health
With permission, Dosefolio reads body-mass samples from Apple Health into the local weight log and can write a weight that the user records back to Apple Health. Apple Health permissions can be changed in iOS Settings. Dosefolio does not send Apple Health data to Uncommon Weather, RevenueCat, or the legal-choice ledger.
Deleting a weight from Dosefolio does not necessarily delete the corresponding sample from Apple Health. Apple Health remains a separate Apple-controlled store, and the user must use Apple controls to review or delete records that remain there.
Voice input and on-device processing
Optional voice check-ins use Apple speech recognition configured to require on-device recognition. Microphone audio is used transiently while the user speaks, is not saved as an audio file, and is not sent to the developer. A transcript becomes part of the local symptom or check-in record only when the user saves it.
Where available, Apple on-device foundation models may help parse a check-in into structured local fields. Dosefolio does not send that prompt or result to a developer-operated AI service.
Widgets, Siri, notifications, and App Intents
Dosefolio can schedule local reminders and expose user-requested actions through Siri and App Intents. Its widget receives a minimal App Group snapshot containing medication and display-dose schedule information, latest dose date, and protein total and target. The snapshot uses device file protection and is limited to the recent access window needed by the widget.
Notification, widget, Siri, and App Intent content may be visible on Apple system surfaces according to the user’s device settings. These features do not send the underlying Dosefolio health log to the developer.
Reports, encrypted backups, and sharing
Dosefolio creates clinician PDF reports and weekly image summaries on the device only after the user requests them. The user chooses a destination through the iOS share sheet. A temporary report file may remain long enough to complete that share flow and is then swept by the app; copies saved or sent by the user remain with the chosen recipient or service.
At the user’s request, Dosefolio creates a versioned backup of the then-current local SwiftData records. The app encrypts the backup on the device with AES-256-GCM using a key derived from the user-provided password with PBKDF2. It does not write an intermediate plaintext backup file. Only the encrypted backup package is made available through the iOS share sheet; Dosefolio does not upload the package or password to an Uncommon Weather service.
The user is responsible for keeping both the encrypted backup file and its password. Uncommon Weather does not receive or retain the password, cannot recover or reset it, and cannot restore a backup without it. Copies saved or sent through the share sheet remain under the retention and access controls of the destination or recipient until the user or recipient deletes them.
Restoring a compatible backup requires the correct password and an explicit replacement confirmation. Dosefolio decrypts the package locally and replaces, rather than merges with, the current SwiftData records. The backup does not contain or replace privacy-minimal legal-choice evidence, the separate Apple Health store, or Apple and RevenueCat purchase or entitlement records. A local Dosefolio record that originated from Apple Health can be present in the SwiftData backup without backing up or changing the Apple Health store itself.
Purchases and legal choices
Apple processes subscription purchases and payment credentials. RevenueCat receives an anonymous app-user identifier and limited app, device, transaction, purchase, and entitlement metadata needed to present offerings, restore purchases, and determine Pro access. Dosefolio does not set an account identifier or custom customer attributes and does not send medication, dose, symptom, protein, weight, Apple Health, voice, or report content to RevenueCat.
The legal-choice service receives only signed, privacy-minimal evidence of an acceptance, decline, or withdrawal, including product and document identifiers, versions and hashes, the choice, adult age band and acceptor role, pseudonymous installation and request identifiers, app version and build, timestamps, locale, source and sequence, cryptographic proof, and receipt linkage. It does not receive Dosefolio health or product content.
Retention and deletion
Available controls delete individual medication, dose, symptom, protein, and weight records. A separate Delete All Local Data control erases all health-log categories stored in Dosefolio’s SwiftData database after confirmation. Removing the app ordinarily removes its backup-excluded local database, subject to Apple’s storage behavior. Neither action deletes samples already written to Apple Health, reports or encrypted backup files already shared by the user, Apple or RevenueCat purchase records, or privacy-minimal legal-choice evidence.
Uncommon Weather does not receive or retain user-created Dosefolio backup files. A backup copy remains wherever the user or a recipient saved it until it is deleted there. Restoring a backup changes the local SwiftData records only and does not shorten the separate retention periods that apply to legal-choice or purchase evidence.
Purchase records remain with Apple and RevenueCat under their applicable obligations. Privacy-minimal legal-choice evidence follows the separate legal retention schedule stated below and is not product health content.
Legal choices and verification
A decline or withdrawal takes effect locally at once and remains limited without a recurring prompt. A user can review the current documents and affirmatively accept from Legal & Privacy settings. A current affirmative acceptance takes effect after it is durably saved on the device and unlocks main-app access while signed-receipt delivery retries in the background. A non-terminal network, Apple, or service outage does not lock the main app or create another prompt. Widgets, Live Activities, and other extension surfaces that require a verifiable cross-process receipt may wait until the server-signed receipt is received and verified. If the server explicitly rejects the exact saved acceptance as terminal, the client quarantines that failed record and returns to the appropriate decision or limited-state screen. A current choice is not repeatedly requested.
Related documents
Dosefolio Terms of Service · Dosefolio Privacy Policy · Legal Center