Pharmixy for Android

Legal

Privacy Policy

This policy explains what the Pharmixy app and the service behind it collect, why, who can see it, and how to delete it. It is written to match what the software actually does — not what a template says it might.

At a glance

  • No ads, no tracking, no analytics. The app contains no advertising, analytics, attribution or crash-reporting SDK of any kind.
  • Two permissions. Internet and network-state. Nothing else — no location, camera, contacts, microphone or storage.
  • We never sell your data. It is not shared with anyone for advertising or marketing, ever.
  • No advertising ID. The app does not read the Advertising ID or any hardware identifier.
  • You can delete everything. In the app, in a few taps, immediately and permanently.
  • Encrypted in transit. The app refuses unencrypted connections outright.

1Introduction & Scope

Pharmixy (“the app”) is a pharmacy management application for Android, published by Dvexo (“we”, “us”, “our”) — the data controller responsible for the personal information described here. Our website is https://dvexo.com/.

This policy covers:

  • the Android application with the package name com.pharmacy.management, distributed on Google Play; and
  • the backend service the app connects to, which stores your account and your pharmacy’s records.

It does not cover any other product, website or service, or anything you do outside the app — including websites you reach by following a link from it.

Who the app is for

Pharmixy is a business tool for pharmacy owners and their staff. It is not intended for consumers, patients or the general public, and it is not intended for children.

Two kinds of data, and who is responsible for each

The distinction matters, so it is stated plainly rather than buried:

  • Your account data. Information about you as our user — your name, email address, phone number and pharmacy details. Dvexo is the controller of this data and this policy governs it.
  • Your business records. Information you enter about your own customers, suppliers and patients while running your pharmacy. You are the controller of that data; Dvexo processes and stores it on your behalf, under your instructions, so that the app works. You are responsible for having a lawful basis to collect it and for telling the people concerned how you use it.

By using Pharmixy you accept this policy. If you do not agree with it, please do not use the app. If you disagree with a future change, you can delete your account at any time — see Account & Data Deletion Request.

2Information We Collect

Everything below is collected because a feature needs it. Nothing is collected “just in case”, and nothing is collected in the background while you are not using the app.

Summary of all data the app and service handle.
Category What exactly Source Required?
Identity Full name, email address, phone number You type it when registering Required
Credentials Password (stored only as a salted Argon2 hash) You type it Required
Pharmacy profile Trade name; country, division, district, city/area, union/ward, street address, postal code You type or select it from a list built into the app Name required; address optional
Device record A random per-installation ID, device name (make and model), platform, app version, last-seen time Generated by the app Automatic
Business records Medicines, stock batches, purchases, sales, expenses, stock alerts, settings You enter them Optional — you choose what to record
Third-party contacts Customer and supplier names, phone numbers, email addresses, addresses, outstanding balances You enter them Optional
Prescription records Patient name and phone, prescribing doctor’s name, medicines prescribed, notes You enter them Optional
Team members Name, email, phone and role of staff you add to your pharmacy You enter them Optional
Subscription Plan, status, start and expiry dates Set by us Automatic
Server logs Routine access and error logs, including the address a request came from; plus a short-lived in-memory count of sign-in attempts per address Automatic Automatic

Health information. If you use the Prescriptions feature, the records you create contain health information about identifiable people — a patient’s name and phone number alongside the medicines prescribed to them. We store it so the feature works; we do not analyse it, profile anyone from it, or use it for any purpose other than showing it back to your pharmacy. Please only enter what you are permitted to under the laws that apply to you.

What we do not collect

Stated explicitly, because absence is hard to prove from a list of what is present:

  • No location. The app never reads GPS, Wi-Fi or cell-tower location. The place names you see are a fixed reference list packaged inside the app; choosing one is you typing an address, not the app finding you.
  • No advertising identifier, and no hardware identifier such as IMEI, MAC address or Android ID.
  • No contacts, photos, camera, microphone, calendar, SMS, call logs or files from your device.
  • No browsing history, and no tracking across other apps or websites.
  • No biometric data, and no installed-app list.
  • No payment card or bank details. The app has no in-app purchase flow and never asks for card, bank or mobile-wallet credentials.

How this maps to the Google Play Data safety section

Google Play shows a Data safety summary on the app’s store listing. The table below is the same information in Play’s own vocabulary, so that what you read here and what you read on Play agree. None of it is shared — under Play’s definition, transferring data to a hosting provider acting on our instructions is processing, not sharing.

Data safety declaration for com.pharmacy.management.
Play data type Collected Shared Optional? Purpose
Personal info — NameYesNoRequiredApp functionality; Account management
Personal info — Email addressYesNoRequiredApp functionality; Account management
Personal info — Phone numberYesNoRequiredApp functionality; Account management
Personal info — User IDsYesNoRequiredApp functionality; Account management
Personal info — AddressYesNoOptionalApp functionality
Personal info — Other info (customer, supplier and staff contact details you enter)YesNoOptionalApp functionality
Health and fitness — Health info (prescription records)YesNoOptionalApp functionality
Financial info — Other financial info (sales, purchases, expenses, balances)YesNoOptionalApp functionality
App activity — Other user-generated content (inventory, notes)YesNoOptionalApp functionality
Device or other IDsYesNoRequiredApp functionality; Fraud prevention, security and compliance
Financial info — User payment infoNoNo——
Location — Approximate or preciseNoNo——
App activity — App interactions, search history, installed appsNoNo——
App info and performance — Crash logs, diagnosticsNoNo——
Contacts, Messages, Photos and videos, Audio, Files and docs, Calendar, Web browsingNoNo——

We also declare the following security practices, each of which is described in Data Security:

  • Data is encrypted in transit — yes.
  • You can request that your data be deleted — yes, and you can do it yourself in the app.
  • Independent security review — none has been carried out, and we do not claim one.

On search queries. Searching the medicine catalogue or the pharmacy directory sends what you typed to our service so it can answer. The query is used to produce the result and is then discarded: it is not saved against your account and no search history is ever built — which is why “in-app search history” is declared as not collected. As with any web request, the address it was sent to may appear in the routine server access log described in Device & Usage Information.

3Personal Information

To create an account, the app asks for:

  • Your full name — shown in the app and attributed to actions such as recording a sale.
  • Your email address — your sign-in identifier and how we reach you about your account.
  • Your phone number — an alternative sign-in identifier and a support contact.
  • Your pharmacy’s name — the workspace your records belong to.

Email addresses and phone numbers must be unique across the service, so registration will tell you if one is already in use.

Address information

You may optionally record a country, division, district, city or area, union or ward, street address and postal code for your pharmacy. The division, district, area and union values are chosen from an administrative reference list that ships inside the app; selecting from it does not contact any server and does not reveal where you are.

Information about other people

Customer, supplier, patient and staff details are personal information about people who are not our users. We hold it only to provide the app to you, and we never contact those people, market to them, or use their details for any purpose of our own.

4Account & Authentication Data

Passwords

Your password is never stored in a readable form. It is hashed with Argon2, a memory-hard algorithm, and only the hash is saved. We cannot read, recover or tell you your password — if you lose it, it has to be reset, not retrieved.

Sessions

Signing in issues two tokens, held in the app’s private storage on your device:

  • an access token, valid for one hour, sent with each request; and
  • a refresh token, valid for thirty days, used to obtain a new access token so you are not signed out mid-shift.

When you sign out or delete your account, the token you were using is added to a revocation list on the server, so a copy of it stops working immediately rather than remaining valid for the rest of its lifetime.

Roles and access

Your role and permissions decide what you can see and do. They are held on the server and checked there on every request. The app cannot grant itself a role, a permission or a subscription plan; a modified copy of the app gains no additional access.

Separation between pharmacies

Every record belongs to exactly one pharmacy, and every request proves your membership of that pharmacy in the database before any data is returned. A request for a pharmacy you do not belong to is refused outright.

5Device & Usage Information

So that you can see which devices are signed in to your account, and so an error can be attributed to a particular app version, each installation registers:

  • An installation identifier — a random value generated on your device the first time the app runs, stored in the app’s private folder. It is not derived from any hardware identifier, is not shared with anyone, and is not used for advertising or cross-app tracking. Uninstalling the app destroys it; reinstalling produces a new one.
  • A device name, from the manufacturer and model reported by Android — for example “Google Pixel 8”.
  • The platform (“android”) and the app version you are running.
  • The time the device last contacted the service.

Server logs

Like any internet service, our servers keep two kinds of log:

  • An access log, recording each request — the time, the address it came from, the endpoint called and the response status. This is standard operational logging, used to diagnose faults and investigate abuse. It is rotated in the ordinary course of operations and is not loaded into any analytics system.
  • An error log, written when a request fails, so the fault can be found and fixed.

Separately, the IP address of sign-in, registration and password-change attempts is counted so that repeated attempts can be rate-limited. That counter lives in the server’s memory for a few minutes and is never written to the database or attached to your account.

We do not record which screens you visit, how long you spend in the app, what you tap, or any other behavioural telemetry.

6App Permissions

The app declares exactly two Android permissions, and no others:

Every permission in the app’s manifest.
PermissionWhy it is neededPrompt?
android.permission.INTERNET To reach our service so your records sync and you can sign in. None — a normal permission granted at install.
android.permission.ACCESS_NETWORK_STATE To tell whether you are online, so the app can show an accurate offline indicator and queue changes instead of failing. None — a normal permission granted at install.

Neither is a “dangerous” or sensitive permission, so Android never asks you to approve them and there is nothing to revoke. The app requests no location, camera, microphone, contacts, storage, SMS, call-log, calendar or notification permission, and declares no restricted permission of any kind.

7Cookies & Local Storage

Cookies

The app uses no cookies. It contains no web view, no embedded browser and no advertising or tracking pixel; it talks to our service directly over HTTPS. This policy page itself sets no cookies and loads nothing from any third party — no fonts, no scripts, no analytics.

Storage on your device

Pharmixy keeps a local copy of your data so that it opens instantly and keeps working when the network does not. That copy lives in the app’s private storage, which other apps cannot read, and holds:

  • your pharmacy’s records — medicines, batches, sales, purchases, customers, suppliers, prescriptions and expenses;
  • your session tokens;
  • changes made offline, waiting to be sent;
  • a sync position marker, your subscription status and your app preferences; and
  • the installation identifier described above.

This local copy is deliberately excluded from Android cloud backup and from device-to-device transfer, so your records and session tokens are not copied off the handset by the operating system. Uninstalling the app deletes all of it.

Copying data out of the app

The Backup screen can generate a backup of your records as text and place it on your device’s clipboard, so you can paste it wherever you choose to keep it. What happens to it afterwards is entirely in your hands — anything you paste into another app is governed by that app’s privacy policy, not ours. Be aware that other apps may be able to read the clipboard.

8Analytics & Diagnostics

The app contains no analytics SDK, no crash-reporting SDK, no attribution SDK and no advertising SDK. There is no Firebase Analytics, no Google Analytics, no Crashlytics, no Sentry, no Facebook SDK, no AppsFlyer and no equivalent. We collect no usage statistics, build no behavioural profile, and run no A/B tests on you.

The app’s entire third-party code consists of the Android platform libraries (AndroidX), the Jetpack Compose user-interface toolkit and the Kotlin standard libraries. These render the interface and run the code; none of them collects data or contacts a server of its own.

On our side, we keep the routine access and error logs described in Device & Usage Information, so that faults can be found and fixed. An error log may contain the request that failed and the account it came from. These logs are used for diagnosis and abuse investigation only, never for profiling or marketing, and they are not fed into any analytics product.

Diagnostics collected by Google, not by us

Because Pharmixy is distributed through Google Play, Android may report crashes and performance data about the app to Google, which we see only as anonymous aggregate statistics in the Play Console. That collection is performed by Google under Google’s Privacy Policy and your device settings, not by code we wrote. We never receive your identity through it.

9AI & Third-Party Services

Artificial intelligence

Pharmixy uses no artificial intelligence or machine-learning service whatsoever. Your data — and in particular your prescription and customer records — is never sent to any AI provider, never used to train any model, and never processed by any generative or predictive system. There is no on-device model either. Every calculation the app performs is ordinary arithmetic over your own records.

Service providers we do use

The complete list of third parties involved in running the service.
ProviderRoleWhat it can access
Supabase Managed PostgreSQL database hosting Stores the service’s data at rest, as our processor. It does not use the data for its own purposes.
Google Play (Google LLC) App distribution and updates Your Google account relationship with Play — installation, updates and Play’s own diagnostics. We do not receive your Google identity.
Render (Render Services, Inc.) Runs the API server Operates the server the app connects to, as our processor. It handles the traffic between the app and the service; it does not use the data for its own purposes.
Brevo (Sendinblue SAS) Sends the service’s email Receives your email address and name, and the text of the message, so that it can deliver it. Used only for account email — the code that verifies your address when you sign up, and the code that lets you reset a forgotten password. No marketing email is sent, and your address is not added to any mailing list.

These providers act on our instructions and are not permitted to use your data for their own purposes. There is no other third party in the path: no advertising network, no data broker, no analytics vendor, no SMS provider, and no payment gateway.

Notifications

Notifications in Pharmixy — low-stock warnings, expiry alerts and similar — are generated by our own service and shown inside the app. The app does not currently register for Android push notifications and includes no push messaging library, which is why it needs no notification permission. If that changes, this policy will be updated before the feature ships.

Email and SMS

The service sends email for two purposes only: the code that verifies your address when you create an account, and the code that lets you set a new password if you have forgotten yours. Both are sent through Brevo, which receives your email address, your name and the message text in order to deliver it.

We send no marketing email. Your address is not added to any mailing list, not sold, and not shared with anyone but the provider that delivers the message. There is no “unsubscribe” to manage, because there is nothing to unsubscribe from — the only email you receive is one you asked for by signing up or by requesting a reset.

The service sends no SMS at all. Your phone number is stored to identify your account and so that our support team can reach you if you contact us; no message is sent to it.

10How We Use Information

We use the information described above only for these purposes:

Purpose of each category of data.
PurposeData used
To provide the app — store your records, keep them consistent across your devices, and show them back to you Business records, pharmacy profile, settings
To sign you in and keep you signed in Email or phone, password hash, session tokens, installation identifier
To keep your account secure — limit repeated sign-in attempts, revoke sessions, show you which devices are signed in Device record, IP address of sign-in attempts (in memory only), revocation records
To manage your subscription — apply the limits of your plan and record its status Subscription record, pharmacy identity
To support you when you contact us with a problem Name, email, phone, and the specific records relevant to your question
To fix faults and keep the service running correctly Server error logs, app version
To meet legal obligations and respond to lawful requests Whatever the obligation specifically requires

We do not use your information to:

  • show you advertising, or build an advertising profile;
  • sell, rent or trade it to anyone;
  • train artificial-intelligence models;
  • track you across other apps or websites; or
  • make automated decisions that produce legal or similarly significant effects about you.

Legal bases

Where a data protection law requires us to identify a legal basis, we rely on:

  • Performance of a contract — to give you the service you signed up for;
  • Legitimate interests — to secure the service, prevent abuse and fix faults, balanced against your rights; and
  • Legal obligation — where a law requires us to retain or produce something.

11Data Sharing & Disclosure

We do not sell your personal information, and we never share it for advertising or marketing.

Your information is disclosed only in these circumstances:

  • To staff of your own pharmacy. People who are members of your pharmacy can see the records their role permits. Membership and roles are controlled by the pharmacy owner, and a member’s access ends as soon as they are removed. Members are managed through the service; the Android app currently only lists them.
  • To our service providers, listed in AI & Third-Party Services, strictly to run the service on our behalf.
  • To our platform operators. A small number of authorised Dvexo staff can access accounts through an internal administration panel in order to provide support, activate subscriptions and investigate abuse. Actions that change your service — suspending an account, granting a plan, confirming a payment — are recorded in an audit trail identifying who did what and when.
  • When the law requires it — in response to a valid legal process, or where disclosure is necessary to protect someone’s safety or to investigate fraud or abuse.
  • In a business transfer. If Dvexo is involved in a merger, acquisition or sale of assets, your information may transfer to the successor. We will notify you, and the successor remains bound by this policy until it is lawfully replaced.

The pharmacy directory

So that pharmacies can find one another, a signed-in user can search a directory of pharmacies. It returns only a pharmacy’s trade name and its general area (upazila, district and division) — deliberately nothing else. Contact details, ownership, stock, customers and every other record are never included. Only pharmacies with an active account appear, and your own is excluded from your results.

If you would rather your pharmacy did not appear in that directory, email us and we will remove it from the listing.

Sharing between pharmacies

The app contains screens for collaborating with another pharmacy. That feature is not currently active, and no data is shared between pharmacies today. Nothing you record leaves your own pharmacy’s workspace. Should collaboration be switched on in a future release, it will be something you opt into for a specific partner and specific categories of data, and this policy will be updated before it ships.

12Data Retention & Deletion

We keep your data for as long as your account exists, and no automatic process deletes it. Your records are yours; we do not expire them, archive them away from you, or remove them because you stopped using the app for a while.

If a paid plan lapses, your data is not deleted. Features that belong to the paid plan stop being available, but every record you created remains, and returns in full when the plan is renewed.

What happens when you delete your account

Deletion is immediate and permanent. It removes:

  • your user profile — name, email address, phone number and password hash;
  • every pharmacy you own, and with it every medicine, batch, sale, purchase, supplier, customer, prescription, expense, alert, notification and setting belonging to it;
  • your registered devices and every active session; and
  • the local copy on your device, which is removed when you uninstall the app.

Pharmacies where you are a member but not the owner are not deleted — that data belongs to the owner, who may still be relying on it. Your membership of them ends.

There is no undo and no recovery period. Deleted data is gone. If you want to keep a copy, generate a backup from the Backup screen before you delete the account.

What may be kept afterwards

  • Records the law requires us to retain — such as financial or tax records of completed transactions — for the period the applicable law specifies, and then deleted.
  • Security and audit records needed to investigate fraud or abuse, kept for as long as that purpose requires.
  • Server error logs, which are rotated in the ordinary course of operations.

Nothing retained is used to rebuild your account, to contact you, or for marketing.

13Data Security

The measures below are implemented in the software, not merely intended:

  • Encryption in transit. All communication between the app and our service uses HTTPS. The app is configured to refuse unencrypted connections outright, so a downgrade attempt or a misconfigured address fails rather than sending your session in the clear.
  • Passwords are never stored readably. Only a salted Argon2 hash is kept — a memory-hard algorithm chosen to make offline cracking expensive.
  • Short-lived sessions with real revocation. Access tokens last one hour, and signing out revokes the token immediately instead of waiting for it to expire.
  • Enforced separation between pharmacies. Access is proved against the database on every request; there is no silent fallback to your own data that could hide a failed attempt.
  • Server-side authorisation. Roles, permissions and subscription status are decided by the server and never taken from the app, so modifying the app grants nothing.
  • Rate limiting on sign-in, registration and password changes, to blunt automated guessing.
  • Private on-device storage, excluded from cloud backup and device transfer, and removed on uninstall.
  • Least-privilege internal access, with an audit trail for administrative actions that affect an account.

Our database is hosted on managed infrastructure operated by Supabase, which states that it encrypts data at rest; that protection is provided by them, under their terms.

No system is perfectly secure. We cannot guarantee absolute security, and we do not claim to. You also have a part in it: choose a strong, unique password, do not share your account, and sign out on devices you no longer use. If you believe your account has been compromised, contact us at bitwithlab@gmail.com immediately.

If a breach affects your personal information, we will notify you and any relevant regulator as the applicable law requires.

14Account & Data Deletion Request

You can delete your Pharmixy account and its data yourself, at any time, without asking us and without giving a reason.

Delete it yourself, in the app

  1. Open Pharmixy and go to Settings.
  2. Scroll to the ACCOUNT section at the bottom of the screen.
  3. Tap Delete account.
  4. Read what the confirmation lists, then tap Delete permanently.

Deletion takes effect immediately and cannot be undone.

If you have already uninstalled the app

You do not need to reinstall it. Email bitwithlab@gmail.com from the address registered to the account, with the subject “Account and data deletion request”, so that it is not mistaken for a support question. A web request form is also published at https://pharmixy.onrender.com/account-deletion.

We verify that a request comes from the account holder before acting on it, and complete verified requests within 30 days. What is deleted, what is kept and for how long is set out in Data Retention & Deletion.

Deleting some data without closing your account

You do not have to delete everything to delete something. Individual medicines, customers, suppliers and expenses can be deleted inside the app, and your pharmacy’s profile and address can be edited there at any time.

Sales and prescriptions cannot be deleted individually. They are your pharmacy’s financial and dispensing history, and the app keeps them so that your reports and stock figures stay correct. They are removed when the account is deleted. If you need a specific record removed sooner, ask us at bitwithlab@gmail.com.

The app does not currently include a screen for editing your own name, email address or phone number. Email us and we will correct them for you.

15Children’s Privacy

Pharmixy is a business tool for licensed pharmacy operators and their staff. It is intended for adults and is not directed at children, and it contains nothing designed to appeal to children.

We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it promptly. A parent or guardian who believes a child has given us information should contact bitwithlab@gmail.com and we will remove it.

This applies to accounts. If your business records happen to include a young patient’s details because you dispensed medicine to them, that data is yours as controller, and the paragraph above does not change your obligations towards it.

16Your Rights

We honour the following requests from every user, wherever you live — not only where a law compels us to:

  • Access — ask what personal information we hold about you.
  • Correction — fix anything inaccurate. Your pharmacy’s profile and address you can edit yourself in the app; write to us to correct your own name, email address or phone number.
  • Deletion — delete your account and its data, as described in section 14.
  • Portability — obtain a copy of your records in a machine-readable form. The Backup screen produces one on demand, as structured text.
  • Objection and restriction — object to, or ask us to restrict, a particular processing activity.
  • Withdraw consent — where we relied on consent, withdraw it, without affecting what was done beforehand.
  • Complain — raise a concern with your local data protection authority, if your country has one.

To exercise any of these, email bitwithlab@gmail.com from the address registered to your account. We will verify that the request is genuinely yours, respond within 30 days, and never charge you for a reasonable request or penalise you for making one.

Depending on where you live, you may hold additional statutory rights — for example under the EU or UK GDPR, or under a state privacy law in the United States. Nothing in this policy limits a right the law gives you.

Requests about a customer, supplier or patient whose details are in your pharmacy’s records should be made to you, as the controller of that data. We will support you in answering them, but we will not act on such a request without your instruction.

17International Data Transfers

Dvexo operates the service from Bangladesh. Our database is hosted by Supabase on infrastructure in the Asia-Pacific (Mumbai, India) region, and the application server is operated by Render (Render Services, Inc.), in the region shown at [Render region — confirm in the Render dashboard before publication].

This means your information — including your account details and your pharmacy’s records — is stored and processed in a country other than your own, whose data protection laws may differ from those where you live. By using Pharmixy you understand that this transfer is necessary to provide the service.

We choose providers that offer contractual and technical protections for the data they hold, require them to process it only on our instructions, and take reasonable steps to see that it is treated according to this policy wherever it is processed. If we move the service to a different region or provider, this section will be updated.

19Acceptable Use, Content & Safety

Pharmixy is a business record-keeping tool for licensed pharmacy operators and their staff. It is rated for adults (18+) and is not designed for or directed at children. This section sets out what the app contains, what you may and may not do with it, and what we do when someone misuses it.

What the app contains

Pharmixy ships no violent, hateful, sexual, shocking or extremist content, no gambling or simulated gambling, no user-facing advertising, and no third-party content feed of any kind. Its screens show your own pharmacy’s records — stock, sales, purchases, customers, prescriptions dispensed and reports — and nothing else. There is no chat, no social feed, no public profile and no comment surface.

Medicines: what this app is not

Pharmixy does not sell, advertise, promote, recommend or supply medicines to the public, and it is not a pharmacy or a marketplace. It records what a licensed pharmacy already holds and has already dispensed, for that pharmacy’s own inventory and regulatory records — including the controlled-substances log a pharmacy is required to keep.

It gives no medical advice: no diagnosis, no dosage guidance, no treatment recommendation, no symptom checking and no telehealth. Nothing in the app is a substitute for a qualified professional. Dispensing decisions are made by the pharmacist, under the law that applies to them — never by this software.

You are responsible for holding the licences your jurisdiction requires and for using the app only within them.

Content you enter, and who can see it

Almost everything you type — medicine names, customer records, notes, prescriptions, supplier details — stays inside your own pharmacy’s workspace. It is not published, not shared with other pharmacies, and not visible to other users of the app. See section 11.

There is one exception, and it is the only content of yours another user can see: your pharmacy’s trade name and general area appear in the directory that signed-in users search to find a collaboration partner. Because that name is chosen by you and displayed to others, it is subject to the rules below. Nothing else about your pharmacy — no contact details, no stock, no customers, no staff — is ever included.

Acceptable use

You agree not to use Pharmixy to:

  • enter, as your pharmacy name or anywhere else that another user can see, anything obscene, hateful, harassing, threatening, sexual, violent, extremist, or degrading to a person or group;
  • impersonate another pharmacy, business or person, or misrepresent your licence or affiliation;
  • record or facilitate the supply of medicines outside the law that applies to you, including supply without a valid prescription where one is required;
  • upload unlawful content, or content that infringes someone else’s rights;
  • attempt to reach another pharmacy’s data, defeat the plan limits, probe or overload the service, or interfere with anyone else’s use of it;
  • use the app to store data you have no lawful basis to hold, or to process a patient’s information in breach of the duties you owe them.

Reporting something

If you see a pharmacy name in the directory that breaks these rules, or anything else in the service that looks abusive, unlawful or unsafe, report it to bitwithlab@gmail.com. Tell us what you saw and where. Reports reach a person, not an automated queue.

We aim to review every report within 3 working days, and sooner where there is a risk to someone’s safety. You do not need an account to report something, and you will not be penalised for reporting in good faith.

Moderation and enforcement

Content is reviewed by our operations team when it is reported to us, and pharmacy names are also checked when an account is set up. Where we find a breach, the action we take is proportionate to it, and can include:

  • removing a pharmacy from the searchable directory, so its name is no longer shown to other users;
  • requiring a name or record to be corrected;
  • suspending the account or a member of its staff, which ends their access immediately;
  • terminating the account, and reporting the matter to the relevant authority where the law requires it.

We will tell the account holder what we did and why, unless the law prevents it, and you can challenge a decision by replying to that message. Suspension does not delete your records: see section 12 for what is kept and section 14 for how to have it erased.

Google Play compliance

Pharmixy is distributed through Google Play and is built to comply with the Google Play Developer Programme Policies, including those on Restricted Content — Inappropriate Content, Violence, Hate Speech, Violent Extremism, Sensitive Events, Illegal Activities and Health Content — as well as User Data, Permissions, and Families. In particular:

  • the app requests only internet and network-state permissions, and no sensitive permission of any kind (section 6);
  • it contains no advertising, analytics, attribution or crash-reporting SDK (section 8);
  • it is declared for an adult audience and is not directed at children (section 15);
  • you can delete your account and data from inside the app and from the web (section 14).

If you believe the app breaches a Google Play policy, write to us at bitwithlab@gmail.com. You can also report an app to Google directly from its Play Store listing.

20Changes to This Privacy Policy

We may update this policy as the app changes or the law does. The current version is always published at this address, and the “Last updated” date at the top tells you when it last changed.

If a change is material — if we begin collecting a new category of data, use your data for a new purpose, or share it with a new kind of recipient — we will publish the updated policy here before the change takes effect, and give notice in the app. Where the law requires your consent for the change, we will ask for it rather than assume it.

Continuing to use Pharmixy after an update takes effect means you accept the updated policy. If you do not accept it, you can delete your account as described in section 14.

Superseded versions are retained by us and available on request.

21Contact Information

For any question about this policy, about your data, or to exercise any right described in section 16, contact the data controller:

Data controller

Dvexo

Privacy contact

bitwithlab@gmail.com

Application

Pharmixy for Android
com.pharmacy.management

Registered address

[Dvexo’s registered postal address — to be completed before publication]

We aim to answer every privacy enquiry within 30 days. Please write from the email address registered to your account so we can verify who you are; if you cannot, tell us so and we will suggest another way to confirm your identity.

22Effective Date & Versions

Version history of this policy.
VersionDateChange
1.1 Added Acceptable Use, Content & Safety, covering what the app contains, the rules for the one field other users can see, how to report something, and how we enforce. Corrected the statement that no email is sent: account verification and password-reset codes are sent through Brevo, now listed as a processor. Named Render as the application host and published the account-deletion URL.
1.0 First published, for the initial Google Play release of Pharmixy.
  • Effective date:
  • Last updated:
  • Applies to: the Pharmixy Android application com.pharmacy.management and the Dvexo service it connects to.

This document is the complete privacy policy for Pharmixy. It replaces any earlier statement about how we handle your information.