Privacy Policy — Osszevet
1) Who we are
Osszevet is provided by independent developer Saifullah Ahad (“we”, “us”, “our”). Contact: www.saifullah.ai@gmail.com. Website: saifullah.ai.
2) What the app does
Osszevet lets two independent participants photograph the same medicine name and batch, compare seven packet regions, and record neutral visual observations. It does not authenticate medicine and does not provide medical advice, a diagnosis, or a safety verdict.
3) Data handled
When you start and submit a comparison, the app may handle:
- the medicine label and batch or lot text you enter;
- seven packet photographs, on-device OCR text, perceptual hashes, and photo-quality values;
- an optional country or broad-region label; the app does not request precise location;
- your Same, Different, or Cannot compare observations and image-registration confidence;
- an anonymous Firebase account identifier, a one-way device-proof value, session identifiers, timestamps, block choices, and notification token;
- reports you submit about another participant’s photograph, including the selected reason.
4) Permissions
CAMERA: capture packet photos after you choose Camera.INTERNETand network state: upload evidence, match independent packets, receive findings, submit reports, and use cloud account controls.POST_NOTIFICATIONSon supported Android versions: notify you when an independent match is ready. You may deny it.USE_BIOMETRIC: optional local app lock. Android performs the biometric check; Osszevet does not receive or store biometric data.
You may choose existing images through Android’s system photo picker without granting broad photo-library access.
5) How data is used
- normalize medicine and batch text and find a different account and device with a potentially matching packet;
- show the two photo sets for human review and calculate aggregate observation weights;
- reduce coordinated or related submissions from the aggregate;
- deliver match notifications, retry queued uploads, enforce blocks, investigate reports, and protect the service;
- prepare an evidence PDF locally when you ask, and prepare a cloud account export when you ask.
We do not use packet evidence to advertise to you and do not sell personal information.
6) Service providers
Osszevet uses Google Firebase services: Anonymous Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Firebase Cloud Messaging, and App Check with Play Integrity. Google processes data under its applicable terms and privacy documentation. ML Kit text recognition runs on the device; Google Play services may download the recognition component.
If you open About Developer → Send feedback, Osszevet prepares a draft and opens your chosen email app. Osszevet does not transmit or store the draft; your email provider handles it only if you choose to send it.
7) Sharing and visibility
A matched participant can temporarily view signed links to the seven packet photos for the paired comparison. They do not receive your contact details, precise location, or device identifier. Authorized service administrators may access evidence when required for security, abuse review, support, legal compliance, or service operation. We may disclose information when required by law or to address a serious safety risk.
8) Retention
- submitted packet contributions and packet photos are scheduled for deletion after 30 days;
- safety and abuse reports may be retained for up to 180 days to investigate and document enforcement;
- cloud export download links expire after 15 minutes, and generated export files are scheduled for deletion within 24 hours;
- local evidence remains on your device until you clear it, delete the app data, or uninstall.
Backups are disabled for Osszevet app data.
9) Your controls
Inside Privacy & access controls, you can request an account export, delete your anonymous cloud account and local evidence, clear local evidence, enable a PIN or biometric app lock, and limit screenshots. You can also revoke permissions in Android Settings, block a matched participant, and report every partner photo.
Some report records may remain for the stated safety-retention period after account deletion. To request help, email www.saifullah.ai@gmail.com.
10) Security
Osszevet uses HTTPS, access-controlled Firebase rules, short-lived signed photo URLs, App Check enforcement in callable services, anonymous account boundaries, one-way hashes, and server-side validation. No system is perfectly secure, so do not photograph information unrelated to the packet comparison.
11) Children and user content
Osszevet is not directed to children under 13. User-submitted photos must not contain child sexual abuse material or any content that exploits or endangers a child. See the separate Child Safety Standards. We review reported content and may remove content, restrict accounts, preserve evidence, and report to appropriate authorities when required.
12) International processing
Firebase may process data in countries different from yours. By using the cloud evidence workflow, your data may be transferred and processed where Google operates, subject to its safeguards and applicable law.
13) Changes
We may update this policy as the app or legal requirements change. The current version will remain at privacy.saifullah.ai/osszevet.html with a revised effective date.
14) Contact
Saifullah Ahad
Email: www.saifullah.ai@gmail.com
Website: https://saifullah.ai
Location: Dhaka, Bangladesh