Privacy Policy

Last updated: 15 August 2026 · Version 2026-08-15

Rosheta (روشتة) is a marketplace that connects patients with licensed pharmacies in Egypt. A patient submits a prescription photo or a typed medicine list; nearby partner pharmacies send competing offers (medicine price, substitutions, delivery fee, service fee, and estimated delivery time); the patient accepts an offer; the pharmacy dispenses the medicine and a courier delivers it cash-on-delivery.

This Privacy Policy explains what personal data we collect through the Rosheta patient mobile app (iOS and Android, package/bundle identifier com.rosheta.app) and related services at api.rosheta.io, why we collect it, who we share it with, how long we keep it, and how you can delete your account.

Operator / data controller. These services are operated by the Rosheta team in Cairo, Arab Republic of Egypt, under the trading name Rosheta (روشتة). Privacy questions: support@rosheta.io. We have not published a separately registered commercial-company name in this policy because none is configured in the product records we operate from; this page is the canonical patient-product policy for store listings and in-app legal links.

1. Information We Collect

We collect the following categories when you create an account and use Rosheta. They match what the app actually sends to our backend and processors.

  • Account & contact: your phone number (required; used to sign in with an SMS one-time passcode via Firebase Authentication) and, if you choose to provide it, your name. A referral code may be generated for your account.
  • Delivery addresses & location: saved addresses (label, street text, building/apartment, landmark) and precise GPS coordinates, used to find nearby pharmacies, confirm you are within delivery coverage (currently Cairo-focused), and route delivery. While an order is out for delivery, we also process the assigned driver's live location so it can be shown to you on a tracking map.
  • Health-related information: the most sensitive data we handle. Photos of prescriptions (camera or photo library), medicines and dosages listed on them or entered manually, whether substitutions are allowed, pharmacist/offer substitution details, and — if you use medication reminders — medicine name, dosage, frequency, and schedule, plus reminder logs.
  • Order & delivery: pharmacy offers, accepted orders, itemized pricing, order status, cash-on-delivery as the payment method, cancellation details, and order ratings/feedback.
  • Communications: in-app chat with a pharmacy about an order, and customer-support tickets and messages.
  • Favorites & referrals: pharmacies you mark as favorites, and referral relationships tied to your account.
  • Device, push & diagnostics: Expo push token, app language and platform, notification preferences (orders / offers / promotions), and crash/error diagnostics. Diagnostic reports are linked only to an internal user ID — never to your name or phone number.

We do not collect payment card numbers, bank details, contacts, advertising identifiers, or third-party analytics tracking IDs. Rosheta currently operates on cash-on-delivery only.

2. How We Use Your Information

We use the information above to: verify your identity and keep your account secure; match your prescription or medicine list with nearby partner pharmacies; let pharmacies prepare accurate offers; process, deliver, and let you track your order; enable order chat and support; send order, offer, delivery, and (if enabled) medication-reminder notifications; maintain reliability and security; and comply with applicable Egyptian legal and pharmaceutical recordkeeping obligations.

We do not use your information for advertising, and we do not build advertising profiles.

3. Health Data

Prescription images, medicine names, dosages, and medication reminders reveal information about your health. This data is transmitted over encrypted connections (HTTPS for REST, WSS for realtime), stored in access-controlled infrastructure, shared only with the pharmacy fulfilling your specific order (and, where applicable, the assigned driver), and is not used for any purpose beyond fulfilling your order or the reminder feature you activated.

Prescription submissions that are not converted into an order expire automatically a short time after upload (currently within 24 hours) and are not kept available for browsing afterward.

Rosheta is a marketplace, not a pharmacy. Partner pharmacies are independent licensed businesses. Once a pharmacy has received a prescription in order to dispense medicine, that pharmacy may keep records under its own legal and professional duties, independently of Rosheta.

4. Who We Share Your Information With

Partner pharmacies and drivers receive only what they need to prepare an offer and fulfil a specific order (typically prescription content or medicine list, delivery address, and order details). A courier assigned to delivery receives the address; you may likewise see the driver's live location for that delivery.

Processors acting on our behalf (they process data to operate Rosheta, not for their own advertising):

  • Firebase Authentication (Google) — phone OTP sign-in
  • Amazon Web Services (AWS S3, EU) — prescription images and related files
  • Mapping services (Google Maps/Places and/or OpenStreetMap) — address search, map display, routing
  • Sentry — crash/error diagnostics linked to an internal user ID only
  • Expo push — delivery of device notifications
  • WhatsApp Business (Meta) — notifying partner pharmacies of new prescription requests
  • The Rosheta backend at api.rosheta.io — core orders, chat, prescriptions, and accounts

We do not sell your personal information and do not share it for third-party advertising. We may disclose information where required by law, to protect rights or safety, or in connection with a merger or asset sale, subject to this Policy.

5. Data Retention

We retain personal data only as long as needed for the purposes in this Policy:

  • Account and profile data while your account is active
  • Order and prescription records while needed for history, disputes, and any applicable recordkeeping
  • Chat and support messages while needed to resolve issues and for quality/audit
  • Medication reminders until you delete them or delete the account

When data is no longer needed, we delete it from the application systems we control. See Section 8 for account deletion.

6. Data Security

Traffic between the Rosheta app and our servers is encrypted in transit (HTTPS and secure WebSocket). Access to personal data, including prescription images, is restricted to systems and personnel that need it to operate the service. No method of transmission or storage is 100% secure; we investigate and address incidents promptly.

7. No Advertising or Tracking

Rosheta does not use advertising SDKs, third-party product-analytics/tracking SDKs, IDFA, or advertising identifiers, and we do not track you across other companies' apps or websites.

8. Your Rights and Account Deletion

You can review and update your name, saved addresses, notification preferences, and language in the app. You may request access to or deletion of your personal data.

In the app (fastest): Profile → Delete account → confirm. While you are signed in, this calls our authenticated deletion API and removes from Rosheta's application database: your user account, saved addresses, favorite pharmacies, referrals, medication reminder schedules and logs, prescriptions, offers, orders, order chat, order feedback, and support tickets/messages. We then attempt to delete the Firebase Authentication record for your phone number so that number can be used to create a new account later. This cannot be undone.

On the web: use the account deletion form if you no longer have the app. We verify the phone number and process typically within 30 days.

By email: support@rosheta.io.

What may remain after deletion: (a) copies a partner pharmacy already received to dispense an order, which that pharmacy may have to keep under pharmacy/health rules; (b) short-lived operational backups that expire on their backup cycle and are not used to restore a deleted account; (c) crash reports that contain only an internal user ID.

9. Children's Privacy

Rosheta is not directed to children. You must be at least 18 to use the Service. We do not knowingly collect personal data from children under 18. If you believe a child has provided data, contact us so we can remove it.

10. International Data Transfers

Some processors (authentication, cloud storage, crash reporting, maps, push) may process data outside Egypt, including in the European Union or the United States. We require them to protect it consistently with this Policy and applicable law.

11. Changes

We may update this Policy. We will post the updated version here with a revised date, and where changes are material we will provide additional notice (such as in-app) before they take effect.

12. Governing Law

This Policy is governed by the laws of the Arab Republic of Egypt, including Personal Data Protection Law No. 151 of 2020 and its executive regulations.

13. Contact

support@rosheta.io · Rosheta (روشتة), Cairo, Egypt.

Canonical public URLs for store review: this page, Terms, and Delete account. Arabic: سياسة الخصوصية.