Privacybeleid Dosana

Versie 1.0 — 30 augustus 2026. Geldt voor de iOS-app Dosana.

Dosana is een medicatiedagboek dat is gebouwd op één uitgangspunt: je gezondheidsgegevens verlaten je telefoon niet. Dit beleid legt uit wat dat precies betekent, wat er wél over het netwerk gaat en waarom, en wat je rechten zijn. Het is geschreven om gelezen te worden — niet om je moe te maken.

De kern in vier zinnen

  1. Alles wat je in Dosana bijhoudt — je medicijnen, innames, metingen, gebeurtenissen, foto's en labwaarden — staat uitsluitend op je eigen telefoon, in een versleutelde database.
  2. Dosana heeft geen accounts. Wij weten niet wie je bent, en kunnen dat ook niet weten.
  3. De enige netwerkverbinding die de app zelf legt, is het opzoeken van productinformatie bij een gescande barcode. Daarbij wordt alleen de productcode van de verpakking verstuurd — nooit wie je bent of wat je bijhoudt.
  4. Er zit geen advertentie-, tracking- of analysesoftware in de app. Niets. Ook niet "geanonimiseerd".

Wat op je telefoon blijft (alles)

Alle gezondheidsgegevens die je invoert of vastlegt, blijven lokaal:

Deze gegevens worden beschermd met meerdere lagen:

Rapporten (PDF) worden op het toestel zelf gemaakt. Ze verlaten je telefoon alleen als jij ze deelt, met wie jij kiest.

Wat wél over het netwerk gaat, en waarom

1. Productinformatie opzoeken. Scan je een barcode (of zoek je een product op), dan vraagt de app aan onze server welke naam, vorm en sterkte bij die code horen, en welke bijwerkingen uit de officiële bijsluiter bij dat middel horen. Daarbij wordt verstuurd:

De server bewaart geaggregeerde tellingen (hoe vaak een code is opgevraagd) om de dienst te verbeteren. Die tellingen bevatten geen toestel-kenmerken, geen tijdlijnen per gebruiker en geen mogelijkheid om verzoeken aan elkaar of aan een persoon te koppelen — dat is een bewuste ontwerpkeuze, geen belofte achteraf. Werkt de verbinding niet, dan werkt de app gewoon door; je kunt namen ook zelf invoeren.

2. Aankopen. Word je founding member, dan loopt die aankoop volledig via Apple (App Store/StoreKit). Wij ontvangen daarbij geen naam, e-mailadres of betaalgegevens, en er zit geen betaaldienstverlener of ander bedrijf tussen. Op de aankoop is het privacybeleid van Apple van toepassing. Het enige dat Dosana lokaal bijhoudt is óf er een geldig abonnement is.

Verder niets. Herinneringen zijn lokale notificaties — er is geen pushdienst en de app heeft daar ook geen toestemming voor. Er zijn geen crashrapportages, geen statistiekendiensten, geen sociale koppelingen en geen advertentienetwerken.

Toestemmingen die de app vraagt

Je rechten (AVG)

De eerlijkste samenvatting: wij kúnnen je gegevens niet inzien, corrigeren, exporteren of verwijderen — omdat we ze niet hebben. Alles staat op jouw toestel en jij bent er de enige beheerder van:

Voor het weinige dat onze server ziet (productcodes, IP-adressen voor rate limiting, geaggregeerde tellingen) geldt: het is niet tot jou te herleiden, en dat houden we zo. Vind je dat we daarin tekortschieten, dan kun je een klacht indienen bij de Autoriteit Persoonsgegevens — maar we horen het liever eerst zelf.

Wie verantwoordelijk is

Dosana wordt gemaakt en uitgegeven door:

NorthIT

info@dosana.nl

Vragen over dit beleid of over privacy in Dosana? Mail ons — je krijgt antwoord van de maker, niet van een formulier.

Wijzigingen

Verandert er iets wezenlijks aan hoe Dosana met gegevens omgaat, dan passen we dit beleid aan én melden we dat in de app — niet alleen in kleine lettertjes. De datum bovenaan vertelt je altijd welke versie je leest. De belofte waar dit beleid omheen is gebouwd — gezondheidsgegevens verlaten je telefoon niet — is geen versie-afhankelijk detail maar het fundament van de app; een wijziging die dááraan zou tornen, zou een andere app zijn.

Dosana Privacy Policy

Version 1.0 — 30 August 2026. Applies to the Dosana iOS app. This is the English version of the Dutch privacy policy; if the two ever differ, the Dutch version prevails. Lees in het Nederlands ↑

Dosana is a medication diary built on a single principle: your health data never leaves your phone. This policy explains exactly what that means, what does travel over the network and why, and what your rights are. It is written to be read — not to wear you down.

The essence, in four sentences

  1. Everything you record in Dosana — your medications, intakes, measurements, events, photos and lab values — lives exclusively on your own phone, in an encrypted database.
  2. Dosana has no accounts. We don't know who you are, and we have no way of finding out.
  3. The only network connection the app itself makes is to look up product information for a scanned barcode. Only the product code printed on the packaging is sent — never who you are or what you track.
  4. There is no advertising, tracking or analytics software in the app. None. Not even "anonymised".

What stays on your phone (everything)

All health data you enter or capture stays local:

This data is protected in several layers:

Reports (PDF) are generated on the device itself. They only leave your phone when you share them, with whoever you choose.

What does travel over the network, and why

1. Looking up product information. When you scan a barcode (or search for a product), the app asks our server which name, form and strength belong to that code, and which side effects from the official patient leaflet belong to that medicine. The request contains:

The server keeps aggregate counts (how often a code has been looked up) to improve the service. Those counts contain no device identifiers, no per-user timelines, and no way to link requests to each other or to a person — that is a design decision, not an after-the-fact promise. If the connection is down, the app simply carries on; you can also enter names yourself.

2. Purchases. If you become a founding member, the purchase runs entirely through Apple (App Store/StoreKit). We receive no name, e-mail address or payment details, and there is no payment processor or other company in between. Apple's privacy policy applies to the purchase. The only thing Dosana keeps locally is whether a valid subscription exists.

Nothing else. Reminders are local notifications — there is no push service, and the app does not even hold the entitlement for one. There is no crash reporting, no analytics service, no social integrations and no ad networks.

Permissions the app asks for

Your rights (GDPR)

The most honest summary: we cannot access, correct, export or delete your data — because we do not have it. Everything lives on your device and you are its only administrator:

For the little our server does see (product codes, IP addresses for rate limiting, aggregate counts): it cannot be traced back to you, and we intend to keep it that way. If you believe we fall short, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) — though we would rather hear it from you first.

Who is responsible

Dosana is made and published by:

NorthIT

info@dosana.nl

Questions about this policy or about privacy in Dosana? E-mail us — you will get an answer from the maker, not from a form.

Changes

If anything material changes in how Dosana handles data, we will update this policy and say so in the app — not just in the fine print. The date at the top always tells you which version you are reading. The promise this policy is built around — health data never leaves your phone — is not a version-dependent detail but the foundation of the app; a change that touched it would make this a different app.