Skip to content

Privacy policy

The short version: PlainScript has no accounts, no analytics, and no advertising. Your saved medicines, doses and reminders stay on your phone. Scans are looked up and forgotten, and photos of packaging are never stored.

Last updated 1 August 2026.

This policy explains what happens to information when you use the PlainScript app and this website. It is written to be read, so the plain explanation comes first and the legal detail follows.

Who is responsible

Kamiar Azvine is the data controller for PlainScript, trading as a sole trader in the United Kingdom.

You do not have an account

There is no sign-up, no sign-in, and no profile. The app never asks you for your name, email address, date of birth, NHS number, or any detail about your health or your prescriptions. It has no way to know who you are, and no way to connect one scan to another. The one place an email address can reach us is the website, if you choose to write to us, and that is set out below.

What happens when you scan something

Looking up a medicine needs a server, because the information comes from published sources that are checked and refreshed centrally. When you scan, the app sends only what is needed to identify the product:

  • The barcode number, if you scanned a barcode.
  • A photo of the packaging, if you photographed a label instead. The photo is used to read the text printed on it and is then discarded. It is held in memory for the few seconds that takes and is never written to a disk, never added to a dataset, and never seen by a person.
  • Text you typed or confirmed, such as choosing between two possible matches.
  • Your device's region and language setting, so the app knows to show UK information.

The result is sent back and the request is over. No record of the scan, the barcode or the medicine is kept on the server.

Your address on the internet

As with any app that talks to a server, the server can see the network address (IP address) your request arrives from. It is used for one thing beyond delivering the response: working out which country the request came from, because some of the clinical guidance PlainScript shows is licensed for use in the UK only. The country is used and dropped. IP addresses may appear in the server's technical logs, which are kept for no more than 30 days and are used only to keep the service running and secure. They are never stored alongside a scan, and never used to build a picture of you.

What stays on your phone

The parts of the app that are actually about you are the parts that never leave your device. Held in the app's own private storage, which other apps cannot read:

  • the medicines you save to My Medicines
  • your dose history and any doses you mark as taken
  • reminders you set, which are scheduled by your phone itself
  • recent scan results, kept for up to seven days so the app still works without a signal

None of this is uploaded, backed up to us, or visible to us. It is not a health record we hold on your behalf; it is a note on your own phone. Deleting the app deletes all of it, and there is nothing left behind for you to ask us to erase.

Feedback, if you choose to send it

Each result has buttons to say whether it was useful and whether the product was identified correctly. This is the only information the app stores on the server, and only when you tap to send it. It contains:

  • the date and time
  • the name and type of the product, and its barcode
  • whether you found it useful, and whether the match was right
  • how confident the app was in the match, which is what makes the feedback worth collecting
  • anything you type in the optional notes box

It does not contain your name, your device, your location, or anything linking it to you or to your other scans. Feedback is read only to fix wrong matches and unclear wording.

Please do not type personal or medical details into the notes box. It is a free-text field, so whatever you write is stored as written. Tell us what was wrong with the information, not what is wrong with you.

What the app does not do

Worth stating plainly, because most apps in this category do some of it:

  • No analytics or tracking. There is no analytics library, no crash reporting service, no advertising identifier and no third-party software development kit in the app at all. Nobody, including us, receives a record of which screens you opened.
  • No advertising and no selling of data. Your information is not sold, rented, shared for advertising, or used to train anyone's artificial intelligence.
  • No AI processing of your data. The app uses text recognition to read the words printed on packaging. Nothing you scan is sent to a generative AI service, and no code path exists that could send it.
  • No cookies on this website. These pages are plain files. No cookie banner, because there are no cookies to consent to.

If you ask to be told when it launches

This one is about the website, not the app. Until PlainScript is released, the "Tell me when it launches" button on the home page opens an email to us, so sending it hands us your email address. We hold that address, and whatever you chose to write, for one purpose: a single message on the day the app is out. The list is deleted once that message has gone. It is never sold, never used for anything else, and never shared with anyone beyond the company that hosts our mailbox.

If you change your mind before then, reply to us or email kamiarazvine@plainscript.co.uk, and your address is deleted. You do not have to give a reason.

Other organisations involved

To identify a product and describe it, the server looks things up in published sources: the NHS website, the NHS dictionary of medicines and devices, NICE guidance, a barcode database, and the research registries PubMed and ClinicalTrials.gov.

These lookups are made by our server, not by your phone. Those organisations therefore see a request from PlainScript and never see your device, your network address, or anything about you. Which sources are used, and what each licence requires, is set out on the sources page.

The server itself runs on hosting provided by a third party, which processes data on our instructions under a written agreement. If you downloaded the app from Apple or Google, that store has its own relationship with you which this policy does not cover.

Email to us arrives in a mailbox hosted by Fasthosts, a UK company that also registers our domain. That is everything sent to the support address, not only the launch list: anything you email in as feedback sits there too. They process it on our instructions under a written agreement.

Under the UK GDPR, we rely on:

  • Legitimate interests for looking up a scan and returning a result, and for keeping short technical logs so the service stays available and secure. The interest is providing the service you asked for at the moment you asked for it, and it is hard to see how it could prejudice you when nothing is retained.
  • Consent for feedback. You give it by tapping the button, and you can decline simply by not tapping it.
  • Consent for the launch list. You give it by sending us the email, and you withdraw it by asking us to take your address off.

Information about medicines can imply something about health, which the law treats as a special category needing stronger protection. This is why scans are not retained at all. Where feedback names a product and so might imply something about health, we rely on your explicit consent under Article 9(2)(a), which is what the sending step is for. If you would rather not, do not send feedback; the app works exactly the same either way.

How long anything is kept

WhatWhereHow long
Scans, barcodes, photos, extracted textNowhereNot kept. Discarded as soon as the result is sent
Saved medicines, doses, remindersYour phone onlyUntil you delete them or remove the app
Cached results, so the app works offlineYour phone onlyUp to 7 days
Feedback you chose to sendOur serverUp to 24 months, then deleted
Your email address, if you asked about the launchOur mailboxUntil the launch message goes out, then deleted
Technical server logsOur hostingUp to 30 days

Your rights

You have the right to ask for a copy of any personal data we hold about you, to have it corrected or deleted, to restrict or object to how it is used, and to receive it in a portable form. Where we rely on your consent, you can withdraw it at any time.

In practice there is usually little for us to find. Unless you are on the launch list, we hold no account and no identifier for you, so a request to see "your data" cannot be matched to you unless you can point us at a specific piece of feedback. If you are on the launch list, your email address is the identifier, and we can show you or delete it straight away. If you sent feedback and want it removed, email us with roughly when you sent it and which medicine it was about, and we will find and delete it. Everything else the app knows about you is on your phone, where you can already see and delete it yourself.

If you are unhappy with how we have handled your information you can complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113. We would rather you told us first, so we can put it right.

Children

PlainScript is intended for adults in the United Kingdom. It is not designed for children, and it is not built for anyone to make decisions about someone else's medicines.

If you are outside the UK

PlainScript describes UK medicines using UK sources, and some of the clinical guidance it shows is licensed for UK use only. Packs, brand names, strengths and advice differ between countries. If you are elsewhere, please use a source for your own country instead.

Changes to this policy

If what we do with information changes, this page changes with it and the date at the top is updated. Anything that materially affects you will be flagged in the app rather than quietly amended here.

Contact

Email kamiarazvine@plainscript.co.uk and a real person will reply. The support page covers the questions that come up most.