Privacy

Minimal collection. Tokenised records. No public model training.

Data minimisation

DoseRelay is built around minimal collection. Clinical records use opaque patient tokens (e.g. Patient-DEMO01) rather than legal names or NHS numbers as the product primary key. Patients log via Telegram (primary) and/or WhatsApp Business Cloud API.

What we use data for

Logged self-report content is used to generate weekly review-prep PDFs for scheduled clinical reviews. We do not sell data. We do not train public foundation models on patient logs.

Where data is processed

Application infrastructure runs on Hetzner servers in the EU (Germany). Traffic to public endpoints uses TLS. Voice notes are transcribed with Google Gemini (paid API) solely to produce text for the log and PDF pipeline.

Messages leave the messenger app when our bot/webhook receives them — that is expected for Telegram bots and WhatsApp Business API integrations. After ingest, processing is under DoseRelay controls (tokenised store + PDF generation).

Retention

  • Structured self-log events: until deletion request or operational retention (~12 months unless deleted sooner).
  • Raw voice files: marked for deletion about 7 days after successful transcription/parse.
  • Server-held weekly PDFs: short-lived operational copies (~90 days order of magnitude).

Roles & clinics

For pilot use with a clinic, the clinic is typically the data controller for care decisions and real identity; DoseRelay processes tokenised self-logs for review-prep. A data processing agreement (DPA) is available on request. DoseRelay is an early pilot and is not NHS DTAC-assessed.

This website

The marketing site is static. The sample report is fictional. Server access logs may retain standard technical metadata (IP, user-agent) for security and reliability.

Data deletion

To request deletion of your DoseRelay self-log data, see Data deletion instructions (or email [email protected] directly).

Contact

Privacy questions: [email protected]. Also see Terms of use.