ScriptSchedule is a family medication tracker built for individual and family use. This policy explains what data we collect, why, who we share it with, and what control you have over it. It's written in plain language on purpose — if anything here is unclear, contact us using the details at the bottom.
We use a small number of service providers to run the app. None of them are permitted to use your data for their own purposes — they only process it to provide their specific service to us.
| Provider | What they receive | Why |
|---|---|---|
| Supabase | All account and medication data | Database hosting. Data is encrypted in transit and access-controlled so only your household can read it. |
| Netlify | App hosting; routes requests to the providers below | Hosts the app and the small server-side functions that talk to Anthropic and OneSignal on your behalf. |
| Anthropic (Claude) | Photos you choose to scan (prescription labels, pills, documents) | Reads the photo and extracts structured details (medication name, dose, lab values, etc). The photo itself is discarded after processing — only the extracted text is saved to your account. |
| Twilio | Only if you opt in to text alerts: your mobile number, plus a message containing a first name and a dose time (e.g. "Mom's 8:00 AM dose hasn't been marked as taken") — deliberately not the medication name, dose, or condition | Delivers missed-dose text alerts. Nothing is sent to Twilio unless you have verified a number and enabled the feature. |
| OneSignal | Your push subscription ID, plus a generic reminder message (e.g. "Time for [name]'s medication") — deliberately not the medication name or dose | Delivers your reminder notifications. We keep medication details out of this because that content also passes through Apple's/Google's/Mozilla's notification systems on the way to your device. |
The bottle-scan, pill ID, and document-upload features work by sending a photo to Anthropic's Claude API, which reads it and returns the extracted details as text. That photo is sent for that single request and is not stored by us afterward — we save only the extracted text (medication name, dose, lab values, etc), not the image. You'll see a reminder of this directly on those screens before you use them.
Missed-dose text alerts are off by default. Nothing is ever texted to you unless you deliberately turn the feature on, enter your own mobile number, accept the on-screen consent statement, and confirm a 6-digit code we send to that number. Signing up for ScriptSchedule does not enroll you.
What we do with the number:
You can stop the messages at any time by replying STOP to any text, or by disabling the feature in Settings → Text Backup. Message and data rates may apply from your carrier. Full details, including sample messages and message frequency, are on our SMS Messaging Terms page.
Your data stays in your account for as long as you use ScriptSchedule. You can:
Data is encrypted in transit (HTTPS/TLS) between your device and our servers. Access to your household's data is restricted at the database level so that only signed-in members of your household can read or write it — not other ScriptSchedule users, and not us, outside of what's needed to operate the service or respond to a support request you initiate.
ScriptSchedule is intended to be operated by an adult managing medications for their family, which may include minor children or pets. We don't knowingly collect data directly from children; a parent or guardian is assumed to control the account and enter that information themselves.
If we change how we handle your data in a material way, we'll update this page and the "Last updated" date above.
Questions, or want to exercise any of the rights above? Email scriptschedule@gmail.com.