Your privacy, plainly stated.
This is the real privacy policy, written in plain English. No lawyer-speak buried 12 scrolls down.
What we collect
- Your email address (for sign-in).
- A password hash (bcrypt — we can't read your password).
- Your accessibility preferences (font size, high-contrast, TTS speed).
- The medicines you save to your history — the NDC code + the text extracted from the label. We never save an image of the bottle.
- An audit log of security events (login, logout, delete) with a hashed version of your email. No cleartext identifiers.
What we don't collect
- We don't save scanned images. When you point the camera at an NDC on a bottle, a box, or a pharmacy receipt, the image is sent to Groq to read the code off it, then discarded. We never write it to disk, never cache it, and never log it. The extracted NDC is the only thing we keep, and only if you tap Save. See “Who else touches your data” below for what Groq may and may not do with it.
- No advertising, no ad pixels, no fingerprinting, and no data sold to anyone. No Google Analytics, no Meta pixels, no ad networks. This website does use two privacy-focused analytics tools — Cloudflare Web Analytics and HeyCatch — to count visits and see which features get used, so we know what to fix and build next. Both are named in full below, neither is ever sent your medicines, and neither is used in the iPhone or Android app at all.
- We don't sell your data, and nobody reads it. Your saved medications are visible only to you. Nobody at Duskfield Studios reads them for marketing, analytics, or any other purpose, and we never sell them. We do rely on a small number of service providers to run the app — they are named in full below.
Who else touches your data
We use a handful of service providers to run VerifyDrugLabel. This is all of them, and exactly what each one sees.
- Groq — reads the NDC off a label photo, and rewrites label text into plain English when you ask it to. It therefore receives the photo you scan and the label text. Under our agreement, Groq is not permitted to use inputs or outputs to train or fine-tune any model. We have also enabled Zero Data Retention on our Groq account, so the photo and the label text are not stored by Groq at all — not even the short-term operational logging its standard terms would otherwise permit. They are processed to read the code, and then gone. Processing happens in the United States. See Groq's privacy policy.
- Cloudflare — serves this website and sits in front of our API, so every request passes through them on its way to us. Like any host, they see your IP address and the request itself in order to deliver the page and to block attacks. We also use Cloudflare Web Analytics on this website to count page views, referrers, countries and device types. It is cookieless — it sets nothing on your device, does not fingerprint you, and does not follow you to other sites. It is not used in the iPhone or Android app. See Cloudflare's privacy policy.
- HeyCatch — product analytics for this website only (never the iPhone or Android app). It records which pages you visit and which buttons you click, and once you sign in it links that activity to your account — your email address, display name, and whether you are on the free or paid plan. It is never sent the medicines you save, your lookup history, your label photos, or anything else about your health. We use it to see which features are worth building, not to profile you, and we do not sell or share what it collects. See HeyCatch's privacy policy.
- Sentry — receives crash and error reports so we can fix bugs. Configured not to include your IP address, and not to include the contents of your medicine history.
- Resend — sends sign-in and reminder email. Receives your email address and the message itself.
- Stripe — handles payment if you subscribe. We never see or store your card number.
- Railway — runs our server and database, so your account and saved medicines live on their managed infrastructure.
- openFDA — the public FDA drug database we look codes up in. It receives the NDC being looked up, and nothing about you.
How we store it
- Encryption in transit: every request is HTTPS. We never accept plain HTTP.
- Encryption at rest: our database runs on managed PostgreSQL with encrypted storage.
- Minimum data: we only keep what's needed to power the features you use.
- Access control: you can only see your own data. Even when you're logged in, every API call is scoped to your user ID.
- Token expiry: your sign-in token expires automatically. Logging out revokes it server-side.
Your controls
- Export: download every row we have about you as a JSON file at any time.
- Delete individual scans: from the My Scans page.
- Delete your entire account: one click and everything goes — your profile, your preferences, your saved medicines. We keep the security audit log (with your email already hashed) for 90 days to protect against fraud, then it's purged.
Important honesty about HIPAA
VerifyDrugLabel is a consumer accessibility app, not a healthcare provider, insurer, or clearinghouse. We're not a "covered entity" under HIPAA, and HIPAA does not apply to consumer apps that patients voluntarily put their own information into.
That said, we build the app like HIPAA did apply — because the technical safeguards are just good privacy hygiene and they prepare us if we ever partner with a provider in the future.
If you're a healthcare provider looking to integrate VerifyDrugLabel, reach out — we'd want a Business Associate Agreement (BAA) in place before any protected health information flowed through us.
Questions or concerns
Email privacy@duskfieldstudios.com and a real human will reply.
Last updated: August 29, 2026.