Privacy Policy
Effective September 14, 2026
1. Who we are
PepProtocol, formerly DoDose, is operated by Evergoods Holdings. It is a record-keeping app for protocols, shots, nutrition, hydration, symptoms, and progress. This policy covers the app and trydodose.com, including the changes introduced in version 0.5.0.
You can use the app without creating a PepProtocol account or providing an email address. Basic tracking stays free. Optional paid features and AI do not change ownership of your records.
2. Your records and device permissions
The app stores the records you enter locally on your device. These may include compound names, amounts, schedules, injection sites, inventory, symptoms, food and protein, water, activity, weight, measurements, photos, notes, private templates, and saved assistant conversations.
Camera and photo-library access are optional. A selected photo is saved or sent only for the feature you choose. Notifications use the reminders you configure. You can manage these permissions in iOS Settings.
If you enable Apple Health access, the app reads or writes the data types you authorize for tracking and progress features. Health data is not used for advertising. Manage or revoke access in the Health app. Imported data may remain in your local records until you remove it.
3. Optional AI food estimates and assistant
Before the first AI request for each feature, the app asks for permission to share data with our gateway hosted by Railway and with OpenAI, which generates the response. You can decline and continue manual tracking. You can change the AI-sharing choice in the app; changing it stops future requests and does not recall requests already processed.
- Food estimates: the selected food photo, description, meal category, and notes are sent to estimate food items and nutrition.
- Assistant: your prompt, optional attached photo, up to 12 recent messages, and the relevant tracking context shown by the feature, such as medication, dose, injection site, weight range, and symptoms, are sent to produce a contextual reply.
- Request metadata: the gateway and providers also process network and technical information, including IP addresses, request times, and an app installation identifier used to limit requests.
Photos, prompts, conversation text, and health context may identify you or contain sensitive information. These inputs are not automatically anonymized before they are sent.
AI responses can be inaccurate. Review and edit estimates before saving. The assistant is not a medical provider and does not determine a treatment plan.
Our gateway does not intentionally save AI prompts, photos, or replies in its database. It requests that OpenAI not store responses for later retrieval. This does not mean zero retention: OpenAI may keep API content in abuse-monitoring logs, normally for up to 30 days, with legal and safety exceptions. Its default API policy does not use API data for model training unless a customer opts in. Hosting and provider operational records are subject to their own retention practices.
See OpenAI API data controls, OpenAI Privacy Policy, and Railway Privacy Policy. We do not promise zero provider retention or processing exclusively in your country.
4. Backups, exports, and sharing
On supported Apple devices, iCloud sync can store an app snapshot in your private CloudKit database when available and enabled. A snapshot can include your saved tracking records, photos, and assistant conversations. Apple device backups may also include app data according to your device settings. These services use your Apple account, not a PepProtocol account.
You can create a manual backup or data export and choose where to save or share it. A clinician PDF is generated from the records you select; you choose its recipient through the share sheet. Exported files and copies already shared remain with you or that recipient until separately deleted. Community references and copied drafts are private local content; the app does not publish them to a social network.
5. Purchases and the free preview
Basic tracking is free. The 14-day Premium preview starts in the app without payment or automatic billing. Optional Premium subscriptions are purchased through Apple. Apple and RevenueCat process purchase receipts, product identifiers, subscription status, and a pseudonymous app-user or installation identifier to provide and restore access. We do not receive your full payment-card details.
Restoring a purchase restores Premium access, not your tracking records. Those restore from your device, iCloud snapshot, or exported backup. See RevenueCat privacy information and Apple privacy information.
6. Analytics, advertising measurement, and diagnostics
The app uses PostHog for limited product usage information, such as generic navigation, onboarding progress, service status, and purchase events, together with technical device or installation information. Automatic touch capture, session replay, and health-record events are disabled. Clinical values, free-text notes, photos, and HealthKit-derived values are excluded from analytics.
On iOS, TikTok advertising measurement and related advertising identifiers are enabled only after your App Tracking Transparency permission. These events are limited to app launch, onboarding completion, paywall, and subscription activity. You can change that permission in iOS Settings > Privacy & Security > Tracking. Denying permission does not prevent basic tracking or purchases.
Sentry helps diagnose errors using sanitized error types, app release information, and code locations. The current app and gateway exclude submitted record content, request bodies, screenshots, and free-text error details from their diagnostic events. Providers still receive network metadata when requests reach them.
The website is hosted by Vercel, which processes technical request information to serve and secure pages. This website release does not load advertising pixels. We do not sell personal information or use user-entered health records for advertising targeting.
7. Support and other disclosures
If you contact support, we receive your email address and the information you choose to include. Please avoid sending medical details or complete backups unless needed for your request. We use support information to respond and resolve the issue. We may disclose information when legally required, to protect the service, or in a business transfer subject to applicable privacy protections.
8. Retention, deletion, and your choices
Local records remain until you remove them or erase the app data. Deleting local data does not automatically remove separate iCloud/device backups, exported files, records written to Apple Health, or information previously sent to a provider. Manage those copies through the relevant app, device settings, or provider.
We retain support, purchase, security, and operational records as needed for their purpose and legal obligations. Retention depends on the record and service; the app does not provide a single deletion command for every provider. There is no PepProtocol account to delete.
Depending on your location, you may request access, correction, deletion, or a copy of personal information we hold, or object to certain processing. Contact admin@evergoodsholdings.com. We may need enough information to verify and locate the relevant request, without asking for your entire health history. You may also contact your local data-protection authority.
Deleting the app or its records does not cancel an Apple subscription. Manage subscriptions in your Apple account settings.
9. Security, international processing, and updates
We use encrypted connections and access controls to protect data in transit and limit access to service systems. No system is completely secure. Providers may process information in the United States or other countries with different privacy laws.
We may update this policy when the product or data handling changes. We will update the effective date and provide an appropriate notice for material changes.
For privacy requests or product help, visit Support or email admin@evergoodsholdings.com.