Legal

Privacy Policy

How RxRecall handles study progress, product analytics, purchases, and support requests.

Effective September 15, 2026

Overview

RxRecall is an educational iOS app and website operated by Experimental Software LLC for practicing brand and generic drug-name recall. The app works without an account and stores your study progress and preferences on your device. We collect usage data and session recordings as described below.

Information stored on your device

RxRecall stores the following information locally so the app can work:

  • onboarding and study preferences;
  • your daily card set and current widget card;
  • drugs you have seen and cards you mark as Still learning or I know this; and
  • local app settings.

Local data is used to run your study plan. Some study activity, preferences, progress counts, and catalog card identifiers are also sent to PostHog as product analytics. You can reset learning progress in the app or delete the app to remove its local data; this does not delete analytics or recordings already sent.

Product analytics

RxRecall uses PostHog to understand how people use the app and where flows need improvement. App-generated installation, session, and interaction identifiers let us associate events and recordings from the same app installation or session. We do not create a named user account or attach your name or email address to these analytics identifiers.

Product analytics includes:

  • app version, build, device and operating-system information, app visits, screen views, time spent, and onboarding progress;
  • access and trial status, study preferences, daily pace, widget setup checks and outcomes, and widget taps that open the app;
  • identifiers and drug classes from the bundled study catalog, daily rotation contents, viewed drugs and detail sections, progress counts, and confidence choices;
  • search length, result counts, selected filters, and sort choices, without the text you type or a hash of it;
  • purchase product identifiers, displayed prices and trial terms, plan choices, purchase and restoration outcomes, timing, and diagnostic codes; and
  • settings changes and support actions, such as viewing our contact details, opening an email app, or copying our support address, without the message, address, subject, or clipboard contents.

Catalog identifiers can tell us which educational drug cards you interacted with. These events describe study activity, not a record of medicines you take or patient care. The widget does not report whether you looked at it on your Lock Screen.

PostHog receives your IP address and uses it to estimate an approximate location, such as your city, region, and country. This information is associated with analytics events. RxRecall does not request GPS or precise-location access.

Analytics events sent by the app do not include typed search or support text, your email address, promo codes, payment receipts, transaction identifiers, arbitrary URLs, or user-supplied error messages. Apple and RevenueCat also process purchase information, and we share an analytics identifier with RevenueCat as described below.

Session replay

We also use PostHog session replay to diagnose layout and interaction problems. Recording is enabled. Replays may show app screens and website pages, study content, ordinary text you type, app-owned purchase screens, and your taps or navigation. Password fields and system-protected content remain subject to platform protections. Replay does not collect network request bodies or headers, or console logs.

Product analytics and session replay are enabled without an in-app preference switch. Contact us using the address below for access, correction, or deletion requests.

We use analytics and recordings for product analysis, troubleshooting, and improving RxRecall. We also measure which acquisition channels lead to visits and purchases. We do not sell this data or use it to target advertisements to you across other companies' apps or websites.

Website analytics

Our website uses first-party cookies and browser storage for anonymous analytics identifiers, session information, and referral context. We measure page visits, App Store link clicks, referring domains, and campaign tags. We remove arbitrary query values from analytics event URLs. Search and quiz actions are not separate analytics events, but visible content and ordinary typed inputs may appear in recordings. These tools are enabled without an Allow/Decline banner. Our app and website identifiers are separate; a website click does not automatically identify the person who later installs the app.

Purchases and billing analytics

Purchases are processed by Apple through the App Store. We do not receive your full payment-card or bank-account information.

RxRecall uses RevenueCat to verify purchases and unlock paid access. RevenueCat receives purchase history, subscription status, transaction context, and an app-user identifier generated for RxRecall. We do not attach your name or email address to that identifier. We use this information for app functionality, fraud prevention, customer support, and purchase analytics.

We also share your app installation's PostHog identifier with RevenueCat. This links the analytics identifier to RevenueCat's customer record so billing activity can be matched with app usage. These records are pseudonymous: they use generated identifiers rather than your name or email address. Sharing this identifier does not change purchase ownership or require an account login.

RevenueCat is configured to send billing events to PostHog, including purchase and subscription activity, product identifiers, amounts, timestamps, and pseudonymous customer and transaction identifiers. This helps us understand trials, payments, renewals, cancellations, and refunds alongside app usage. The app also sends its own purchase and access events as described above.

We use Apple's AdServices attribution through RevenueCat to measure eligible Apple Ads referrals and subsequent purchase activity. Apple may provide campaign information associated with an app installation. We do not collect the advertising identifier (IDFA) for this purpose. Apple also provides aggregate App Store acquisition reports.

Support communications

If you email us, we receive the address and information you choose to include. We use it only to respond, investigate the issue, and maintain appropriate support records. Please do not send private health or patient information.

Third-party services

RxRecall relies on the following service providers:

  • Apple for App Store distribution, subscription billing, and purchase management. See Apple's Privacy Policy.
  • RevenueCat for purchase validation and entitlement management, with the shared PostHog identifier described above. See RevenueCat's Privacy Policy.
  • PostHog for product analytics and session replay. See PostHog's Privacy Policy.
  • Vercel hosts this website and processes web-request information, such as IP address, requested page, browser information, and request status, to deliver and secure it. This also applies when you open our support or legal pages inside RxRecall. See Vercel's Privacy Policy.

We require service providers to handle data consistently with this policy and applicable law.

Data retention and deletion

  • Learning progress remains on your device until you reset it or delete the app. Resetting progress keeps your study preferences and widget setup.
  • PostHog session recordings are configured to expire after 30 days. Product analytics events are retained for ongoing product analysis; they do not currently have an automatic deletion period configured.
  • Support emails are retained only as long as reasonably needed to resolve requests, maintain records, prevent abuse, or meet legal obligations.
  • Apple and RevenueCat retain transaction records according to their policies and legal obligations.

To request deletion of support records or data associated with your RxRecall installation, contact us. We may need information from the app to locate the correct record, and some transaction records may need to be retained by Apple, RevenueCat, or us for legal reasons.

Your choices

  • Manage or cancel a subscription in your Apple Account's subscription settings.
  • Use Restore Purchases to refresh access from Apple and RevenueCat.
  • Reset local study data in the app or delete the app.
  • Contact us about access, correction, or deletion requests.

Children's privacy

RxRecall is intended for pharmacy learners and is not directed to children under 13. We do not knowingly collect personal information from children under 13.

Security and changes

We use reasonable safeguards appropriate to the information we handle, but no system is completely secure. We may update this policy as RxRecall changes. The effective date above will be revised when material changes are published.

Contact

Email privacy questions or requests to support@rx-recall.com.