DEV

You are viewing our development site. Please share feedback with support@dosevault.ai or on our Discord server. See what is new in the changelog.

Security

How we handle data on dosevault.ai

dosevault.ai is a public education site with free peptide calculators. It does not have user accounts and does not store health data. We are not a HIPAA Covered Entity. The controls below describe what the site does today.

The gist

The site serves marketing pages and free calculators. The only personal data it collects is the email address you submit to the early-access list and the details you send through the contact form. Calculator inputs are processed in your browser and are not sent to or stored on our servers.

All traffic is encrypted in transit (HTTPS). This page is a plain-English summary, not a formal compliance attestation.

The DoseVault app is separate

The DoseVault tracker app is currently in development and is not live for users on this site. When it launches it will be governed by its own Privacy Policy and Terms. Nothing on this page describes the app; it describes only the public site at dosevault.ai.

In transit

All traffic to dosevault.ai is HTTPS. HSTS enforces TLS for one year, so a downgrade attack fails before it reaches us. The marketing pages, the free calculators, and the form endpoints share the same HSTS posture.

What we collect

Early-access signups: the email address you submit, plus an optional attribution source and referral code, so we can notify you when the app launches.

Contact form: your name, email, and message. These are forwarded to our team by email and are not stored in a database.

Standard server logs (IP address, user-agent, timestamps) are retained for a short window for security and debugging.

Calculators run in your browser

The free calculators compute results client-side. The doses, weights, and other values you enter are not transmitted to or stored on our servers.

Analytics, privacy-first

Anonymous product analytics are off by default and load only if you opt in through the cookie banner. Analytics events are not linked to your name or email.

Error reports are scrubbed of request bodies, cookies, and identifiers before submission to our error monitoring provider.

Abuse prevention

The early-access and contact endpoints are rate-limited per IP address, and form submissions are checked server-side before any email is sent.

Subprocessors

A small number of third parties may process site data: our cloud database provider (early-access list), our transactional email provider (confirmation and contact forwarding), our hosting and edge provider, our error monitoring provider (identifiers scrubbed), and, only if you opt in, our analytics provider.

Each is bound by their standard data-processing terms.

Your data, on demand

To have your email removed from the early-access list, or to ask what site data we hold about you, email privacy@dosevault.ai.

What we are not (yet)

The site is not HIPAA-certified, not SOC 2, and not HITRUST. Because the public site holds no health data and no user accounts, those frameworks do not currently apply to it.

Reporting a vulnerability

Email security@dosevault.ai. We respond within two business days. Please do not open public GitHub issues for security reports.

Last Updated: June 16, 2026. Material changes to this posture will be reflected on this page and announced in the product changelog.

Not medical advice

Information on DoseVault is for educational purposes only and is not a substitute for medical advice, diagnosis, or treatment from a qualified healthcare provider.