FinishDose
Privacy policy
Last updated: August 21, 2026
FinishDose is a private, local-first companion for tracking finite medication courses. It does not require an account and does not send medication-course data to a FinishDose server.
Data stored on your device
The app stores course names, dose instructions, schedules, dose logs, local household profile labels, preferences, optional pronunciations, and optional medicine reference photos in the app's private device storage. Photo contents are encrypted in app-private files; a course can contain up to eight reference photos, with three megabytes per photo. Older raw photos up to 20 MB are moved into protected storage during migration; an unusually large legacy file may be retained and omitted from a later portable backup rather than silently deleted. Course, template, profile, pronunciation, and photo records are encrypted at rest with AES-256-GCM. Settings and pending snoozes are not encrypted because they contain no medicine name and settings must be readable before App Lock can be evaluated.
Permissions
- Notifications: requested only when you enable reminders or test one. On Android, exact-alarm access is declared for finite-course reminders; FinishDose provides a Settings link to the device's special-access screen and does not silently request it.
- Camera: requested only when you choose to take an optional medicine reference photo.
- Biometric authentication: requested only when you enable App Lock. Authentication is handled by the operating system; FinishDose never receives or stores biometric data.
FinishDose does not request photo-library, general device-storage, microphone, location, contacts, health-record, or advertising-tracking access.
Backups and sharing
You can export a portable JSON backup containing your courses, dose history, saved rhythms, profiles, settings, pronunciations, and embedded reference photos. Backup files are intentionally not encrypted. Export and share are user-directed system actions; FinishDose does not receive the file. You decide where to save or share it and should use a private destination you trust. Local notifications use generic lock-screen text and do not show medicine or profile names.
Collection, sale, and advertising
FinishDose does not collect, sell, rent, or use your medication data for advertising, analytics, profiling, or cross-app tracking. The app has no advertising SDK and no FinishDose cloud account. If you choose to hear a medicine name pronounced, FinishDose passes that name to the operating system's text-to-speech engine so the device can read it aloud. This is user-initiated and is not sent to a FinishDose server; any processing by the device's speech provider follows that provider's operating-system settings and policy.
Security and deletion
Device sandboxing and record encryption protect the protected records, but FinishDose is not an encrypted medical-data vault. App Lock controls access to the interface in addition to storage encryption; anything running as the app can still access the keystore key. You can delete individual courses or clear all FinishDose data from Settings. Clear All Data removes local records, managed photo files, and the device-only encryption key; deleting an individual course also removes its managed photo files. If secure-key, course-photo, or temporary-photo removal fails, the app reports that deletion is incomplete and keeps a retry record rather than claiming success. Exported backup copies live outside the app and must be deleted separately.
Medical boundary
FinishDose is a reminder and tracking tool, not a medical device. It does not diagnose, prescribe, check interactions, or replace advice from a qualified professional.
Contact
Privacy questions: wpgglabs@gmail.com.