Privacy Policy
Who we are
HoraDose is a personal health management application published by Poulinsoft. This policy covers this marketing website (the "site") and the HoraDose mobile app (the "app"). For any privacy question, you can write to us at privacy@horadose.com.
What this website collects — the waitlist
This website has a single form: signing up for the waitlist of people who want to test the app before it is released. Apart from that form, the site asks for no personal data and offers no account creation.
When you sign up, we collect: your email address (required), the type of phone you will use — iPhone, Android or both (required), your first name (optional), and where your visit came from, as a general keyword such as "facebook" or "direct". We also keep the date of your signup and the version of the consent text you were shown, so we can demonstrate, if needed, what you agreed to and when.
This information is used for three things and nothing else: to send you the test invitation, to send you the instructions, and to give you occasional news about the app's progress.
It is stored on Supabase servers located in Canada (region ca-central-1). We do not sell it, do not rent it, and never use it for advertising.
Addresses of Android testers — disclosure outside Québec
Android internal testing requires each tester's address to be entered in the Google Play Console, operated by Google in the United States. Without that entry, the invitation link does not work.
As a result, if you select "Android" or "both", your email address will be disclosed to Google, outside Québec, for that sole purpose. If you select "iPhone", your address is never sent there.
Nothing beyond your email address is shared with Google in this context: not your first name, not where your visit came from, and no health data whatsoever.
Cookies, trackers and traffic measurement
This website sets no advertising or tracking cookies.
We use Vercel Web Analytics and Vercel Speed Insights, provided by Vercel Inc., to measure traffic and the site's technical performance. These tools work without cookies and collect: the page viewed, the referring page, the approximate country or region, the device type, and a visitor identifier turned into a non-reversible fingerprint.
This measurement exists only to know how many people visit the site and whether it works properly. It cannot identify you, and it is never cross-referenced with the waitlist.
Legal bases
Waitlist signup relies on your consent, which you give by submitting the form after reading the text shown immediately above the button. You may withdraw it at any time.
Aggregate analytics are based on our legitimate interest in keeping the site secure and working properly.
At a high level, these activities are framed by the General Data Protection Regulation (GDPR, art. 13), Québec's Law 25, and Canada's PIPEDA.
Retention
We automatically delete waitlist signups on the following schedule: 60 days after an unsubscribe; 12 months after a signup that never led to an invitation; 24 months with no invitation and no message.
These are maximums. As soon as the test programme ends, the list is destroyed without waiting for them.
When someone unsubscribes, we keep a non-reversible fingerprint of their address indefinitely — never the address itself. It is the only way to guarantee they are not contacted again by mistake.
Your rights
You can unsubscribe at any time in one click, from the link included in every message we send. The withdrawal takes effect immediately.
You also have the right to access, correct and delete your information. To exercise these rights, or for any privacy question, write to us at privacy@horadose.com. We answer at that address.
The HoraDose app — your health data stays on your device
All the health data you enter in the app (medications, schedules, doses, mood, journal, appointments, contacts) is stored on your device, in an encrypted database. By default it never leaves it.
If you turn on a feature that moves it — sharing with a caregiver, backup, or syncing between your devices — it is encrypted on your device BEFORE it leaves, and the key never leaves your device. Anything passing through our servers is therefore unreadable to us. Each of those features is described below.
HoraDose is not a medical device and does not replace the advice, diagnosis, or treatment of a healthcare professional.
What the app collects when you use certain features
Account: the app works without an account, and never asks you for an email address or a password. The features that connect two devices — the "Ensemble" caregiver mode, backup and sync through our servers — rely on an anonymous identity created automatically on your device. It holds nothing that identifies you: no name, no email address, no phone number.
Caregiver sharing (optional): if you choose to share information with a caregiver, it is end-to-end encrypted on your device before being sent. Our servers act only as a temporary relay: they cannot read the content, and it is deleted after delivery to the recipient.
Backup and sync (optional): your data is encrypted on your device before anything is sent, and the encryption key stays on your device. When your own personal cloud space is available (iCloud or Google Drive), the backup goes there: it stays entirely with you. When it is not — and to sync your data between several of your devices — it passes through our servers. Either way the content is unreadable, to us and to your cloud provider alike: we do not hold the key.
Crash reports: to fix technical failures, the app sends anonymized crash reports (device model, OS and app version, technical trace). These reports never contain your health data.
Purchases and subscriptions: payments are processed by Apple or Google. We receive a transaction identifier and your subscription status to activate your features — no health data and no banking information.
Anonymous usage statistic: the app sends a daily anonymous signal (a random identifier generated on your device, not linked to your account, along with the app version, platform, and language) that lets us measure overall usage. When that signal arrives, our servers derive the COUNTRY the connection comes from, from the request's IP address: that address is neither stored nor logged, only a per-country counter is incremented, and the precision never goes below the country. It contains no health data, no activity pattern can be tied to a person, and you can turn it off in the app settings. These signals are automatically purged after at most 400 days.
Anonymous usage counters: the app also counts which screens are used and which features are turned on (initial setup steps reached, screens opened, reminders allowed, a device or a loved one connected, subscription screen shown). These counters carry NO identifier — neither the random number above nor any other — and keep no time more precise than the calendar day: nothing lets us, or anyone, tie a use to a person or reconstruct an individual's path. They are governed by the same setting as the daily signal, in the app settings, and purged after at most 400 days.
Deleting your app data
You can erase all your data directly in the app (since your data lives on your device, deletion is immediate and permanent), or delete your account if you have one. For any request, see our Data Deletion page or write to us at privacy@horadose.com.
Version 1.4 — last updated 2026-08-13