Last updated: 6 August 2026
This Privacy Policy explains how Zenski ("we", "us", "our"), the provider of the PharmaOS application ("the App"), collects, uses, stores and protects information when you create an account and use the App. By using PharmaOS, you agree to this Policy.
PharmaOS is a pharmacy-management application for retail pharmacies in Nepal. It is a business tool used by a pharmacy's owner and staff — it is not a consumer health app and it is not used by patients.
The App is available on Android, iOS and on the web at pharmaos-zenski.web.app. A single account can belong to more than one pharmacy, with a role (owner, pharmacist or staff) in each.
What the App does:
| Data | Source | Why we process it |
|---|---|---|
| Name | Registration / Google or Apple sign-in profile | Account, receipts, "prepared by" attribution |
| Email address | Supabase Auth (email/password, Google, Apple) | Account creation, sign-in, essential service emails |
| Phone number | Owner registration; staff/customer records | Account, WhatsApp/SMS payment reminders |
| Pharmacy business records (inventory, sales, purchases, suppliers, and customer names/phones the pharmacy enters) | Entered in the App | Core functionality — running the pharmacy |
| Payment record — method & amount of each sale/purchase (cash / QR / card / udhar) | Entered in the App | Record-keeping. No card numbers are collected and no card payments are processed by the App. |
| Push notification token (device token) | Firebase Cloud Messaging | Delivering in-app notifications you enable |
| Crash logs & diagnostics optional | Sentry (only if enabled in the build) | Diagnosing crashes and improving stability |
| Product-analytics events, tagged with your account ID (no email/PII) optional | Mixpanel (only if enabled in the build) | Understanding feature usage to improve the App |
PharmaOS keeps a copy of some data on the device so the counter keeps working when the internet drops — a real requirement for pharmacies in Nepal.
Signing out or uninstalling the App removes this local data from that device. On the web version the equivalent data is held in your browser's local storage. We do not use advertising or tracking cookies.
We do not sell your personal data, and we do not use it for advertising or cross-app tracking.
We share data only with service providers that process it on our behalf to run the App, under contract and appropriate safeguards:
We may also disclose information where required by law, or to protect the rights, safety and security of our users and the service.
Our providers may process and store data on servers located outside your country. Where that happens, the data remains protected by this Policy and by our providers' safeguards, and is encrypted in transit.
We retain your account and business records for as long as your account is active, and as needed to provide the service and meet legal, accounting and tax obligations. When you close your account or a deletion request is processed, we delete or de-identify the associated data within a reasonable period, except where we are required to retain certain records by law.
When a deletion request is processed, your personal data is always erased or irreversibly anonymised:
If you never created any record that must be retained, your account is hard-deleted entirely.
A pharmacy's sales, purchases, ledgers and audit history are financial and regulatory records that record-keeping law requires be retained. Those records belong to the pharmacy, not to your personal account. So if you created any of them, they remain — but attributed to the now-anonymous "Deleted user" rather than to you. Nothing in them identifies you after anonymisation.
This is why deletion is not a one-tap cascade: erasing them would destroy a pharmacy's legally required books and its audit trail.
Deleting your account does not delete the pharmacy. Remaining staff keep working normally. If you were the last active member, the pharmacy's access is suspended and its records are retained rather than destroyed — so the business can be recovered or its books produced if required.
Requests are reviewed and processed by an administrator, normally within 30 days. We will confirm by email when it is done. You can withdraw a request before it is processed by contacting us.
Because the pharmacy — not Zenski — is the controller of its own business records, a request to delete an entire pharmacy's data must come from that pharmacy's owner. Contact us and we will verify ownership before acting.
We protect your data with industry-standard measures: encryption in transit (TLS/HTTPS), row-level access controls that isolate each pharmacy's data, credentials stored in the device's secure keystore, and least-privilege server access. No method of storage or transmission is 100% secure, but we work to protect your information and review our practices regularly.
PharmaOS is a business tool for pharmacies and is not directed to children. We do not knowingly collect personal data from children.
We may update this Policy from time to time. We will revise the "Last updated" date above and, for material changes, provide notice within the App. Continued use after an update means you accept the revised Policy.
Questions or requests about this Policy or your data:
Zenski — info.zenski@gmail.com