This Privacy Policy explains how [Operating Entity Legal Name — insert] ("DrugCheck Africa", "we", "us"), a company/organisation registered in [country/registration number — insert], collects, uses, discloses, and protects information when you use the DrugCheck Africa website, mobile web app, SMS/USSD service, admin dashboard, or manufacturer portal (together, the "Service").
This policy applies to everyone who uses the Service: people verifying a drug, people submitting a report, registered pharmacists, manufacturer accounts, and moderators/administrators. It does not apply to third-party sites or services we link to or forward reports to, which have their own privacy practices.
We collect only what the Service actually needs to function. The list below reflects what this platform collects today, grouped by feature.
What: Full name, email address, password (stored as a salted hash — we never see or store your plain-text password), phone number (optional), country
When: When you register an account
What: GPS coordinates
When: When you submit a report (to show its location on the map), or optionally when you enable nearby-alert push notifications. You control this through your device/browser's location permission; declining it simply means we can't show your position or nearby alerts.
What: Images of drug packaging
When: When you use photo verification, or attach evidence to a report. Photos are resized and compressed on your device before upload.
What: Drug name, where you believe you obtained it, a description of what seemed wrong, your classification (suspected fake / suspicious)
When: When you submit a community report
What: Codes you check, scan results, AI photo-analysis verdicts, timestamps, and the approximate network location (IP address) a check was made from
When: Every time you use the Verify, Scan, or Photo features — including anonymously, without an account
What: Platform, OS and browser version, screen size, approximate connection type, language, timezone, a randomly generated device identifier
When: Automatically, to keep the Service working correctly across a wide range of devices and to detect abuse
What: Pharmacist license number and issuing body; manufacturer company name, country, and business/drug registration documents you upload
When: If you apply for pharmacist or manufacturer trust-tier verification
What: A browser-issued push subscription endpoint and encryption keys (not readable by us as plain text; standard to the Web Push protocol)
When: If you opt in to alerts
What: Your phone number and the text you send, if you verify a code by SMS or USSD instead of the app
When: When you text or dial the service, via Africa's Talking (our SMS/USSD gateway partner)
What: Any dispute you file against a report, and correspondence with our support/moderation team
When: When you contact us or use the dispute feature
We do not knowingly collect payment card details (the Service does not currently process payments), biometric identifiers, or government ID numbers.
We rely on one or more of the following bases, consistent with the general approach taken by most African data protection laws:
We do not sell your personal information, and we do not share it with advertisers or data brokers — the Service carries no advertising and has no such relationships.
We do share limited information in these specific cases:
When you use AI photo verification, your image is sent from our server (never directly from your device) to our AI provider (currently Anthropic) for a preliminary visual analysis, and the result — a verdict, confidence score, and any findings — is returned to you along with a clear disclaimer. This analysis is a preliminary visual check, not a guarantee of authenticity — see the Terms of Service, §4 ("Disclaimers"), for the full explanation of its limits. We do not use your photos to train our own models. We have not independently audited what our AI provider does with submitted images beyond returning the analysis; our understanding, based on that provider's own published policy for this type of API use, is that it is not used to train their models by default — but you should treat any photo you upload as, for a brief period, in that provider's custody under its own terms, which you can review directly with the provider if you want assurance beyond what we state here.
Automated decision-making. The AI verdict is an opinion about the photographed packaging, not an automated decision made about you — it doesn't affect your account, eligibility, or any right you have on the Service. You are always free to disregard it, verify a different way, or ask a moderator to look at a report instead.
We keep information for as long as your account is active, plus a reasonable period afterward for legal, security, and dispute-resolution purposes. In general:
You can ask us to delete your account and associated personal data at any time (see §8); some information may be retained in de-identified or aggregate form, or where we have a legal obligation to keep it.
We use industry-standard safeguards appropriate to the sensitivity of the data involved: passwords are never stored in readable form, access to administrative functions is role- and region-restricted, sessions can be revoked, and traffic to the Service is encrypted in transit. No system is perfectly secure, and we cannot guarantee absolute security — if we become aware of a breach affecting your personal information, we will notify affected users and the relevant authority as required by applicable law.
Most data protection laws across Africa — and the general principles followed even in countries without a dedicated statute yet — recognise some version of the following rights. Subject to the exceptions each law provides:
To exercise any of these, contact us using the details in §13. We will respond within the time limit set by applicable law, or within a reasonable time where none is specified.
Because this Service operates across many countries and uses infrastructure and third-party providers (including AI analysis) that may be located outside your own country — potentially outside Africa entirely — your information may be processed in a country with different data protection standards than your own. Where applicable law requires a specific safeguard for such a transfer (such as a data processing agreement or an adequacy finding), we take reasonable steps to have one in place.
The Service is not directed at children and is not intended for use by anyone under the age of 16, or the minimum age of digital consent in your country if higher. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will take steps to delete it.
The Service uses your browser's local storage (not third-party advertising cookies) to keep you signed in, remember your language preference, and queue a report for automatic sending if you were offline when you submitted it. A randomly generated device identifier is stored locally to distinguish devices for security and service-improvement purposes. We do not use this storage for cross-site tracking or advertising.
We may update this policy as the Service evolves or as legal requirements change. We will update the "Last updated" date above, and where a change is material, we will make reasonable efforts to notify active users in-app before it takes effect.
Questions, requests, or complaints about this policy or your data: [insert privacy contact email, e.g. privacy@yourdomain].
Data Protection Officer / Information Officer (named contact required by some data protection laws for a company of a given size or activity, e.g. South Africa's POPIA and Nigeria's NDPA): [insert name/title, or "not yet appointed — required once (X) applies", once confirmed with local counsel].
See also our Terms of Service, which govern your use of the Service, including important disclaimers about the limits of code, photo, and AI-based verification.