DrugCheck Africa

Back to app
Status of this document. This is a good-faith draft prepared to give users a clear, honest account of what this platform does with their data, and to give the operator a reasonable, non-abusive starting point for its terms — not a jurisdiction-verified legal instrument. It has not been reviewed by qualified counsel in any of the countries this platform operates in. Data protection, consumer protection, and health-information law differ meaningfully across African jurisdictions (compare, for example, Nigeria's NDPA 2023, South Africa's POPIA, Kenya's Data Protection Act 2019, and Ghana's Data Protection Act 2012), and several countries have no dedicated data protection statute at all yet. Qualified local counsel should review and, where necessary, adapt this document before it is relied upon as a compliance instrument in any specific country of operation.

Contents

  1. Who this policy covers, and who operates the platform
  2. What information we collect
  3. Why we collect it, and our legal basis
  4. Who we share information with
  5. Photo analysis and AI processing
  6. How long we keep information
  7. How we protect information
  8. Your rights, and how to exercise them
  9. International data transfers
  10. Children's privacy
  11. Cookies, local storage, and device identifiers
  12. Changes to this policy
  13. How to contact us

Effective date: [insert date]  ·  Last updated: [insert date]

1. Who this policy covers, and who operates the platform

This Privacy Policy explains how [Operating Entity Legal Name — insert] ("DrugCheck Africa", "we", "us"), a company/organisation registered in [country/registration number — insert], collects, uses, discloses, and protects information when you use the DrugCheck Africa website, mobile web app, SMS/USSD service, admin dashboard, or manufacturer portal (together, the "Service").

This policy applies to everyone who uses the Service: people verifying a drug, people submitting a report, registered pharmacists, manufacturer accounts, and moderators/administrators. It does not apply to third-party sites or services we link to or forward reports to, which have their own privacy practices.

2. What information we collect

We collect only what the Service actually needs to function. The list below reflects what this platform collects today, grouped by feature.

Account information

What: Full name, email address, password (stored as a salted hash — we never see or store your plain-text password), phone number (optional), country

When: When you register an account

Location

What: GPS coordinates

When: When you submit a report (to show its location on the map), or optionally when you enable nearby-alert push notifications. You control this through your device/browser's location permission; declining it simply means we can't show your position or nearby alerts.

Photos

What: Images of drug packaging

When: When you use photo verification, or attach evidence to a report. Photos are resized and compressed on your device before upload.

Report content

What: Drug name, where you believe you obtained it, a description of what seemed wrong, your classification (suspected fake / suspicious)

When: When you submit a community report

Verification activity

What: Codes you check, scan results, AI photo-analysis verdicts, timestamps, and the approximate network location (IP address) a check was made from

When: Every time you use the Verify, Scan, or Photo features — including anonymously, without an account

Device & technical information

What: Platform, OS and browser version, screen size, approximate connection type, language, timezone, a randomly generated device identifier

When: Automatically, to keep the Service working correctly across a wide range of devices and to detect abuse

Professional verification details

What: Pharmacist license number and issuing body; manufacturer company name, country, and business/drug registration documents you upload

When: If you apply for pharmacist or manufacturer trust-tier verification

Push notification data

What: A browser-issued push subscription endpoint and encryption keys (not readable by us as plain text; standard to the Web Push protocol)

When: If you opt in to alerts

SMS / USSD data

What: Your phone number and the text you send, if you verify a code by SMS or USSD instead of the app

When: When you text or dial the service, via Africa's Talking (our SMS/USSD gateway partner)

Communications

What: Any dispute you file against a report, and correspondence with our support/moderation team

When: When you contact us or use the dispute feature

We do not knowingly collect payment card details (the Service does not currently process payments), biometric identifiers, or government ID numbers.

3. Why we collect it, and our legal basis

We rely on one or more of the following bases, consistent with the general approach taken by most African data protection laws:

4. Who we share information with

We do not sell your personal information, and we do not share it with advertisers or data brokers — the Service carries no advertising and has no such relationships.

We do share limited information in these specific cases:

5. Photo analysis and AI processing

When you use AI photo verification, your image is sent from our server (never directly from your device) to our AI provider (currently Anthropic) for a preliminary visual analysis, and the result — a verdict, confidence score, and any findings — is returned to you along with a clear disclaimer. This analysis is a preliminary visual check, not a guarantee of authenticity — see the Terms of Service, §4 ("Disclaimers"), for the full explanation of its limits. We do not use your photos to train our own models. We have not independently audited what our AI provider does with submitted images beyond returning the analysis; our understanding, based on that provider's own published policy for this type of API use, is that it is not used to train their models by default — but you should treat any photo you upload as, for a brief period, in that provider's custody under its own terms, which you can review directly with the provider if you want assurance beyond what we state here.

Automated decision-making. The AI verdict is an opinion about the photographed packaging, not an automated decision made about you — it doesn't affect your account, eligibility, or any right you have on the Service. You are always free to disregard it, verify a different way, or ask a moderator to look at a report instead.

6. How long we keep information

We keep information for as long as your account is active, plus a reasonable period afterward for legal, security, and dispute-resolution purposes. In general:

You can ask us to delete your account and associated personal data at any time (see §8); some information may be retained in de-identified or aggregate form, or where we have a legal obligation to keep it.

7. How we protect information

We use industry-standard safeguards appropriate to the sensitivity of the data involved: passwords are never stored in readable form, access to administrative functions is role- and region-restricted, sessions can be revoked, and traffic to the Service is encrypted in transit. No system is perfectly secure, and we cannot guarantee absolute security — if we become aware of a breach affecting your personal information, we will notify affected users and the relevant authority as required by applicable law.

8. Your rights, and how to exercise them

Most data protection laws across Africa — and the general principles followed even in countries without a dedicated statute yet — recognise some version of the following rights. Subject to the exceptions each law provides:

To exercise any of these, contact us using the details in §13. We will respond within the time limit set by applicable law, or within a reasonable time where none is specified.

9. International data transfers

Because this Service operates across many countries and uses infrastructure and third-party providers (including AI analysis) that may be located outside your own country — potentially outside Africa entirely — your information may be processed in a country with different data protection standards than your own. Where applicable law requires a specific safeguard for such a transfer (such as a data processing agreement or an adequacy finding), we take reasonable steps to have one in place.

10. Children's privacy

The Service is not directed at children and is not intended for use by anyone under the age of 16, or the minimum age of digital consent in your country if higher. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will take steps to delete it.

11. Cookies, local storage, and device identifiers

The Service uses your browser's local storage (not third-party advertising cookies) to keep you signed in, remember your language preference, and queue a report for automatic sending if you were offline when you submitted it. A randomly generated device identifier is stored locally to distinguish devices for security and service-improvement purposes. We do not use this storage for cross-site tracking or advertising.

12. Changes to this policy

We may update this policy as the Service evolves or as legal requirements change. We will update the "Last updated" date above, and where a change is material, we will make reasonable efforts to notify active users in-app before it takes effect.

13. How to contact us

Questions, requests, or complaints about this policy or your data: [insert privacy contact email, e.g. privacy@yourdomain].

Data Protection Officer / Information Officer (named contact required by some data protection laws for a company of a given size or activity, e.g. South Africa's POPIA and Nigeria's NDPA): [insert name/title, or "not yet appointed — required once (X) applies", once confirmed with local counsel].

See also our Terms of Service, which govern your use of the Service, including important disclaimers about the limits of code, photo, and AI-based verification.