Skip to content

Privacy policy

The short version: PlainScript has no accounts, no analytics, and no advertising. Your saved medicines, doses and reminders are stored only on your phone. Scans and lookups are answered and forgotten, and photos of packaging are never stored.

Last updated 13 August 2026.

This policy explains what happens to information when you use the PlainScript app and this website. It is written to be read, so the plain explanation comes first and the legal detail follows.

Who is responsible

Kamiar Azvine is the data controller for PlainScript, trading as a sole trader in the United Kingdom.

You do not have an account

There is no sign-up, no sign-in, and no profile. The app never asks you for your name, email address, date of birth, NHS number, or any detail about your health or your prescriptions. It has no way to know who you are, and no way to connect one scan to another. The one way an email address reaches us is if you choose to email us, and that is set out below.

What happens when you scan something

Looking up a medicine needs a server, because the information comes from published sources that are checked and refreshed centrally. When you scan, the app sends only what is needed to identify the product:

  • The barcode number, if you scanned a barcode.
  • A photo of the packaging, if you photographed a label instead. The photo is used to read the text printed on it and is then discarded. It is held in memory for the few seconds that takes and is never written to a disk, never added to a dataset, and never seen by a person.
  • Text you typed or confirmed, such as choosing between two possible matches.
  • Your device's region and language setting, so the app knows to show UK information.

The result is sent back and the request is over. No record of the scan, the barcode or the medicine is kept on the server.

Your address on the internet

As with any app that talks to a server, the server can see the network address (IP address) your request arrives from. It is used for one thing beyond delivering the response: working out which country the request came from, because some of the clinical guidance PlainScript shows is licensed for use in the UK only. The country is used and dropped. IP addresses may appear in the server's technical logs, which are kept for no more than 30 days and are used only to keep the service running and secure. They are never stored alongside a scan, and never used to build a picture of you.

What stays on your phone

The parts of the app that are actually about you are the parts that never leave your device. Held in the app's own private storage, which other apps cannot read:

  • the medicines you save to My Medicines
  • your dose history and any doses you mark as taken
  • reminders you set, which are scheduled by your phone itself
  • recent scan results, kept for up to seven days so the app still works without a signal
  • your answers to "what do you take this for?" in the Beyond medicines tab, and the suggestions it last showed you

None of this is backed up to us or visible to us. It is not a health record we hold on your behalf; it is a note on your own phone. Deleting the app deletes all of it, and there is nothing left behind for you to ask us to erase. The one moment any of it touches a server is described in the next section, and nothing is kept there either.

If you use the Beyond medicines tab

The Beyond medicines tab suggests non-drug approaches, such as talking therapies or a pain management programme, that fit the medicines you have saved. Matching happens on the server, because the suggestions are maintained and updated centrally like the rest of the app's information. When you open the tab, the app sends:

  • the names of your saved medicines, such as "Sertraline 50mg tablets"
  • your answer, if a medicine has more than one common use and the app asked what you take it for — the broad area you picked, such as "long-term pain", nothing freer than that

Nothing else goes with them: no name, no account, no identifier that could connect the list to you. The server matches the names against its own dataset, sends back the suggestions, and the request is over. It keeps no record of the list or the answers. Your answers are stored on your phone alongside your medicines, and the latest suggestions are kept there too so the tab still works without a signal.

Feedback, if you choose to send it

Each result has buttons to say whether it was useful and whether the product was identified correctly. This is the only information the app stores on the server, and only when you tap to send it. It contains:

  • the date and time
  • the name and type of the product, and its barcode
  • whether you found it useful, and whether the match was right
  • how confident the app was in the match, which is what makes the feedback worth collecting
  • anything you type in the optional notes box

It does not contain your name, your device, your location, or anything linking it to you or to your other scans. Feedback is read only to fix wrong matches and unclear wording.

Please do not type personal or medical details into the notes box. It is a free-text field, so whatever you write is stored as written. Tell us what was wrong with the information, not what is wrong with you.

What the app does not do

Worth stating plainly, because most apps in this category do some of it:

  • No analytics or tracking. There is no analytics library, no crash reporting service, no advertising identifier and no third-party software development kit in the app at all. Nobody, including us, receives a record of which screens you opened.
  • No advertising and no selling of data. Your information is not sold, rented, shared for advertising, or used to train anyone's artificial intelligence.
  • No AI processing of your data. The app uses text recognition to read the words printed on packaging. Nothing you scan is sent to a generative AI service, and no code path exists that could send it.
  • No cookies on this website. Every page here is a plain file, and there are no forms. The contact buttons open your own email app rather than sending anything themselves. No cookie banner, because there are no cookies to consent to.

If you email us

This one is about the website, not the app. The site invites pharmacies interested in a pilot, and anyone with a question, to email kamiarazvine@plainscript.co.uk. If you do, your address and whatever you write arrive in our mailbox, and nowhere else: there is no mailing-list company, no database, and no form on this site collecting anything.

We use it to reply to you and for nothing else. Correspondence is kept while we are dealing with it and deleted when it is no longer needed. It is never sold, never used for marketing, and never shared with anyone beyond the company that hosts the mailbox. If you would like what you sent deleted, say so, and it is. You do not have to give a reason.

Other organisations involved

To identify a product and describe it, the server looks things up in published sources: the NHS website, the NHS dictionary of medicines and devices, NICE guidance, a barcode database, and the research registries PubMed and ClinicalTrials.gov.

These lookups are made by our server, not by your phone. Those organisations therefore see a request from PlainScript and never see your device, your network address, or anything about you. Which sources are used, and what each licence requires, is set out on the sources page.

The server itself runs on hosting provided by a third party, which processes data on our instructions under a written agreement. This website is hosted the same way. If you downloaded the app from Apple or Google, that store has its own relationship with you which this policy does not cover.

Email to us arrives in a mailbox hosted by Fasthosts, a UK company that also registers our domain. That covers everything sent to the support address: pilot enquiries, questions, and anything you email in as feedback. They process it on our instructions under a written agreement.

Under the UK GDPR, we rely on:

  • Legitimate interests for looking up a scan and returning a result, and for keeping short technical logs so the service stays available and secure. The interest is providing the service you asked for at the moment you asked for it, and it is hard to see how it could prejudice you when nothing is retained.
  • Consent for feedback. You give it by tapping the button, and you can decline simply by not tapping it.
  • Legitimate interests for reading and replying to email you choose to send us, and holding the correspondence while it is being dealt with.

Information about medicines can imply something about health, which the law treats as a special category needing stronger protection. This is why scans are not retained at all. Where feedback names a product and so might imply something about health, we rely on your explicit consent under Article 9(2)(a), which is what the sending step is for. If you would rather not, do not send feedback; the app works exactly the same either way.

How long anything is kept

WhatWhereHow long
Scans, barcodes, photos, extracted textNowhereNot kept. Discarded as soon as the result is sent
Medicine names sent for Beyond medicines matchingNowhereNot kept. Discarded as soon as the suggestions are sent
Saved medicines, doses, remindersYour phone onlyUntil you delete them or remove the app
Cached results, so the app works offlineYour phone onlyUp to 7 days
Feedback you chose to sendOur serverUp to 24 months, then deleted
Email you send us, including pilot enquiriesOur mailboxWhile we are dealing with it, then deleted
Technical server logsOur hostingUp to 30 days

Your rights

You have the right to ask for a copy of any personal data we hold about you, to have it corrected or deleted, to restrict or object to how it is used, and to receive it in a portable form. Where we rely on your consent, you can withdraw it at any time.

In practice there is usually little for us to find. Unless you have emailed us, we hold no account and no identifier for you, so a request to see "your data" cannot be matched to you unless you can point us at a specific piece of feedback. If you have emailed us, your address is the identifier, and we can show you or delete the correspondence straight away. If you sent feedback and want it removed, email us with roughly when you sent it and which medicine it was about, and we will find and delete it. Everything else the app knows about you is on your phone, where you can already see and delete it yourself.

If you are unhappy with how we have handled your information you can complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113. We would rather you told us first, so we can put it right.

Children

PlainScript is intended for adults in the United Kingdom. It is not designed for children, and it is not built for anyone to make decisions about someone else's medicines.

If you are outside the UK

PlainScript describes UK medicines using UK sources, and some of the clinical guidance it shows is licensed for UK use only. Packs, brand names, strengths and advice differ between countries. If you are elsewhere, please use a source for your own country instead.

Changes to this policy

If what we do with information changes, this page changes with it and the date at the top is updated. Anything that materially affects you will be flagged in the app rather than quietly amended here.

Contact

Email kamiarazvine@plainscript.co.uk and a real person will reply. The support page covers the questions that come up most.