Skip to main content
Rx Challenger — Privacy Policy

Privacy Policy

Version 1.0 • Effective: July 24, 2026

Last Updated: July 24, 2026

Your privacy matters to us. This Privacy Policy explains how IMC collects, uses, and protects your personal information when you use the Rx Challenger application.

1. Introduction

This Privacy Policy governs the collection, use, disclosure, and protection of personal information by Intelligent Mastery Coaching ("IMC," "we," "us," or "our") in connection with the Rx Challenger mobile application (the "App").

Rx Challenger is a free, gamified educational application designed for pharmacy graduates and professionals to master prescription reading through real-world, anonymized patient scenarios. The App is developed by Ahmed Ezzat and published under IMC's Digital Solutions & Technology unit.

By downloading, installing, accessing, or using the App, you agree to the practices described in this Privacy Policy. If you do not agree with this policy, please do not use the App.

This policy complies with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), Brazil's Lei Geral de Proteção de Dados (LGPD), and South Africa's Protection of Personal Information Act (POPIA).

2. Scope and Applicability

This Privacy Policy applies to all users of the Rx Challenger Android application (package name: com.pharmacycafe.goodrx), the Windows desktop application, the Linux desktop application, and the Progressive Web App (PWA) available at https://rx-challenger.vercel.app (collectively, the "Platforms").

This policy does not apply to third-party websites, services, or applications that may be linked from within the App, including the Google Play Store, GitHub download pages, or external websites referenced in the App. We encourage you to review the privacy policies of those third parties.

3. Information We Collect

3.1 Account and Profile Information

When you create an account or sign in to use cloud progress saving, we collect:

• Email address (used as your account identifier and for account recovery)

• Display name (chosen by you, visible on leaderboards if you opt in)

• Authentication credentials (securely hashed password or OAuth token from Google Sign-In)

• Profile preferences (language, notification settings, difficulty preferences)

3.2 Usage and Progress Data

To provide the core learning experience and gamification features, we collect:

• Prescription attempt records (case ID, correctness, time spent, hints used)

• Learning progress (completed cases, mastery levels, skill categories)

• Gamification data (badges earned, leaderboard rankings, streak counts, experience points)

• Session analytics (app opens, session duration, feature usage, error events)

3.3 Device and Technical Information

Automatically collected when you use the App:

• Device model, operating system version, and platform (Android, Windows, Linux, Web)

• App version and build number

• Unique device identifier (Android ID on Android; anonymized hardware ID on desktop)

• IP address (collected transiently for request routing and security; not stored long-term)

• Crash reports and diagnostic logs (via Firebase Crashlytics) including stack traces, device state, and error context

• Network information (connection type, carrier on mobile)

3.4 Cloud Synchronization Data

When you enable cloud progress saving, the following data is synchronized to our backend (Firebase):

• Your account profile and preferences

• All usage and progress data described in Section 3.2

• Timestamps of last sync and device identifiers for conflict resolution

This data is encrypted in transit (TLS 1.3) and at rest (AES-256).

3.5 Information We Do NOT Collect

For clarity, Rx Challenger does NOT collect:

• Precise geolocation (GPS, fine location)

• Contacts, call logs, SMS, or phone state

• Camera, microphone, or sensor data

• Payment or financial information (the App is completely free with no in-app purchases)

• Advertising identifiers (AAID/IDFA) for ad targeting

• Biometric data

• Health or medical data beyond the anonymized educational case content provided by the App

4. Android Permissions Requested

The Android version of Rx Challenger requests the following permissions, each with a specific, limited purpose:

• INTERNET (android.permission.INTERNET) — Required for all network communication: downloading case content, syncing progress to Firebase, authentication, leaderboard retrieval, and crash reporting. The App cannot function without this permission.

• ACCESS_NETWORK_STATE (android.permission.ACCESS_NETWORK_STATE) — Used to detect connectivity status (Wi‑Fi, mobile, offline) so the App can queue sync operations for when a connection is available and show appropriate offline messaging.

• ACCESS_WIFI_STATE (android.permission.ACCESS_WIFI_STATE) — Used in conjunction with network state detection to optimize sync scheduling and avoid metered-data transfers when the user has not enabled background data usage.

• FOREGROUND_SERVICE (android.permission.FOREGROUND_SERVICE) — Used on Android 14+ to reliably perform background synchronization of learning progress when the App is not in the foreground, ensuring your progress is saved across devices.

• FOREGROUND_SERVICE_DATA_SYNC (android.permission.FOREGROUND_SERVICE_DATA_SYNC) — Required on Android 14+ to declare the foreground service type as data synchronization.

• RECEIVE_BOOT_COMPLETED (android.permission.RECEIVE_BOOT_COMPLETED) — Allows the App to re-register background sync jobs after a device reboot so your progress continues to sync without requiring you to open the App manually.

We do NOT request: CAMERA, RECORD_AUDIO, READ_CONTACTS, ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, READ_PHONE_STATE, READ_SMS, WRITE_EXTERNAL_STORAGE (scoped storage is used instead), BLUETOOTH, or any other permissions not listed above.

You can review and revoke permissions at any time via Android Settings → Apps → Rx Challenger → Permissions. Revoking INTERNET or network state permissions will disable cloud sync and leaderboard features; local progress will still be saved on the device.

5. How We Use Your Information

We process your personal information for the following purposes:

5.1 Service Delivery and Account Management

• Create and maintain your account across Platforms

• Authenticate you securely (email/password or Google Sign-In)

• Synchronize your learning progress, preferences, and gamification state across devices

• Deliver the educational content (anonymized prescription cases, tooltips, patient history modules)

5.2 Personalization and Gamification

• Adapt difficulty and case recommendations based on your performance

• Calculate and display your leaderboard ranking (only if you opt in to public leaderboards)

• Award badges, track streaks, and manage experience points

5.3 Analytics and Improvement

• Aggregate, anonymized analytics to understand feature usage, completion rates, and learning effectiveness

• Crash reporting and diagnostics via Firebase Crashlytics to fix bugs and improve stability

• A/B testing of educational content flows (opt-in, anonymized)

5.4 Security and Fraud Prevention

• Detect and prevent unauthorized access, credential stuffing, and abuse

• Monitor for anomalous sync patterns that may indicate account compromise

5.5 Communication

• Send critical service notifications (security alerts, account changes, data breach notices)

• Respond to your support inquiries sent to imc.hub.eg@gmail.com

• We do NOT send marketing emails or push notifications without your explicit, separate consent.

7. Data Sharing and Third-Party Services

We do not sell your personal information. We share data only as described below:

7.1 Firebase (Google LLC)

The App uses Firebase services hosted by Google LLC:

• Firebase Authentication — for secure email/password and Google Sign-In account management

• Cloud Firestore — for storing and syncing your profile, progress, and gamification data

• Firebase Crashlytics — for crash reporting and stability monitoring

• Firebase Analytics (optional, opt-in) — for aggregated product analytics

Google processes data as a data processor on our behalf under the Firebase Terms of Service and the Google Cloud Data Processing Addendum, which include Standard Contractual Clauses for international transfers. Google's privacy policy: https://policies.google.com/privacy

7.2 Google Play Services (Android only)

The Android App integrates with Google Play Services for:

• Google Sign-In (if you choose this authentication method)

• Play Games Services (leaderboards, achievements — only if you opt in)

• Licensing and app integrity verification

Data shared with Google Play Services is governed by the Google Play Developer Distribution Agreement and Google's Privacy Policy.

7.3 Service Providers

We may engage subprocessors for:

• Cloud hosting (Google Cloud / Firebase)

• Email delivery for transactional messages (e.g., password reset, security alerts)

All subprocessors are bound by written data processing agreements meeting GDPR Art. 28, LGPD Art. 39, and POPIA S. 20 requirements.

7.4 Legal and Safety Disclosures

We may disclose your information if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect rights, safety, or property.

7.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of the transaction, subject to the same privacy protections.

7.6 No Advertising Networks

Rx Challenger does not integrate with any advertising SDKs (AdMob, Meta Audience Network, Unity Ads, etc.), does not serve ads, and does not share data with data brokers or ad exchanges.

8. Data Retention

We retain your personal information only as long as necessary to fulfill the purposes described in this policy:

• Account and Profile Data: Retained while your account is active. Upon account deletion request, data is queued for deletion within 30 days and fully purged from backups within 90 days.

• Learning Progress and Gamification Data: Retained for the lifetime of your account to preserve your achievement history. Anonymized upon account deletion.

• Crash Logs and Diagnostic Data: Retained for 90 days in Firebase Crashlytics, then automatically deleted.

• Aggregated Analytics Events: Retained for up to 14 months in Firebase Analytics (if enabled), then automatically deleted.

• Authentication Logs (sign-in timestamps, IP hashes): Retained for 12 months for security auditing, then anonymized.

• Support Correspondence: Retained for 2 years after last interaction.

You may request deletion of your account and all associated personal data at any time (see Section 10).

9. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

• Encryption in Transit: All network communication uses TLS 1.3 with modern cipher suites. Certificate pinning is enforced for Firebase endpoints.

• Encryption at Rest: Firestore data is encrypted at rest using AES-256 with Google-managed keys. Crashlytics data is encrypted at rest per Google Cloud security practices.

• Password Security: Passwords are hashed using scrypt (via Firebase Auth) with a cost factor of 14, never stored in plaintext.

• Access Control: Role-based access within our Firebase project; only authorized IMC personnel with MFA-enabled accounts can access production data.

• Scoped Storage: On Android, all local data uses scoped storage (no broad WRITE_EXTERNAL_STORAGE).

• Security Headers: The PWA and web endpoints implement strict CSP, HSTS, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy headers.

• Incident Response: We maintain a security incident response plan. In the event of a personal data breach, we will notify affected users and the relevant supervisory authority within 72 hours as required by GDPR Art. 33, LGPD Art. 48, and POPIA S. 22.

While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

10. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal data:

10.1 General Rights (GDPR / CCPA / LGPD / POPIA)

• Right of Access: Request a copy of the personal data we hold about you.

• Right to Rectification: Request correction of inaccurate or incomplete data.

• Right to Erasure ("Right to be Forgotten"): Request deletion of your account and associated personal data. We will comply within 30 days (GDPR) / 45 days (CCPA) / 15 days (LGPD) / as soon as reasonably possible (POPIA), subject to legal retention obligations.

• Right to Restriction of Processing: Request that we limit processing of your data in certain circumstances.

• Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format (JSON/CSV) and transmit it to another controller.

• Right to Object: Object to processing based on legitimate interests (Section 6), including analytics and crash reporting.

• Right to Withdraw Consent: Where processing is based on consent (leaderboards, optional analytics), withdraw consent at any time without affecting the lawfulness of prior processing.

• Right to Opt-Out of Sale (CCPA): We do not sell personal information, so this right is not applicable.

• Right to Non-Discrimination (CCPA): You will not be discriminated against for exercising your privacy rights.

10.2 How to Exercise Your Rights

• In-App: Use the "Delete Account" option in Settings → Account (coming in v1.2; see Section 11).

• Email: Contact imc.hub.eg@gmail.com with "Privacy Request — Rx Challenger" in the subject line. Include the email address associated with your account.

• We will verify your identity before processing requests (typically by sending a confirmation link to your registered email).

• We respond within the timeframes required by applicable law (30 days GDPR, 45 days CCPA, 15 days LGPD).

10.3 Supervisory Authority Complaints

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority:

• EU: Your national DPA (list: https://edpb.europa.eu/about-edpb/board/members_en)

• UK: Information Commissioner's Office (https://ico.org.uk/)

• Brazil: Autoridade Nacional de Proteção de Dados (https://www.gov.br/anpd/)

• South Africa: Information Regulator (https://inforegulator.org.za/)

• Other jurisdictions: Your applicable data protection authority.

11. Account Deletion

Rx Challenger currently supports account deletion via email request to imc.hub.eg@gmail.com. An in-app self-service account deletion feature is planned for release v1.2 (target Q3 2026).

When you request account deletion:

1. We verify your identity via email confirmation.

2. Your Firebase Authentication account is permanently deleted.

3. All associated Firestore documents (profile, progress, gamification data) are deleted within 30 days.

4. Crashlytics logs linked to your installation ID are disassociated and purged within 90 days.

5. Aggregated, anonymized analytics events are retained but can no longer be linked to you.

6. You receive email confirmation of completion.

Note: If you use Google Sign-In, deleting your Rx Challenger account does not delete your Google Account. You may separately revoke Rx Challenger's access to your Google Account via https://myaccount.google.com/permissions.

Important for Google Play Submission: Google Play requires that apps with user accounts provide an in-app account deletion option. We are implementing this feature prior to the next production release. Until then, the email-based process above satisfies the functional requirement.

12. Children's Privacy

Rx Challenger is not directed to children under 13 (or under 16 in the EEA/UK/Brazil/South Africa where applicable). We do not knowingly collect personal information from children below the applicable age threshold.

The App's content is designed for pharmacy graduates and professionals. If we become aware that we have collected personal information from a child below the applicable age without verified parental consent, we will take steps to delete such information promptly.

If you are a parent or guardian and believe your child has provided personal information to us, please contact us at imc.hub.eg@gmail.com.

13. International Data Transfers

Your personal data may be transferred to and processed in countries other than your country of residence, including the United States (where Google Cloud / Firebase data centers are located).

We ensure appropriate safeguards for such transfers:

• Standard Contractual Clauses (SCCs) approved by the European Commission (GDPR Art. 46) and the UK ICO are in place with Google LLC for Firebase/Google Cloud services.

• For Brazil (LGPD), the SCCs are supplemented by the ANPD's standard contractual clauses where required.

• For South Africa (POPIA), transfers rely on SCCs and the recipient's adequate level of protection as recognized by the Information Regulator.

• Google Cloud participates in the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. Data Privacy Framework.

You may request a copy of the applicable safeguards by contacting imc.hub.eg@gmail.com.

14. Third-Party Services and Libraries

The App incorporates the following third-party services and open-source libraries. Their privacy practices are governed by their respective policies:

• Firebase Authentication, Firestore, Crashlytics, Analytics (Google LLC) — https://policies.google.com/privacy

• Google Play Services / Play Games Services (Android) — https://policies.google.com/privacy

• React Native / Expo (if applicable) — https://expo.dev/privacy

• Kotlin / Java standard libraries, AndroidX libraries — no independent data collection

• OkHttp / Retrofit — network libraries, no data collection

• Material Design Components — UI library, no data collection

• Gson / Kotlinx Serialization — data parsing, no data collection

We do not use: Facebook SDK, Adjust, AppsFlyer, Branch, Amplitude, Mixpanel, Sentry (self-hosted), Bugsnag, or any other third-party analytics, attribution, or crash reporting SDKs beyond Firebase Crashlytics.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the App's features.

• Material changes will be communicated via in-app notification and/or email to your registered address at least 30 days before the effective date.

• The "Last Updated" date at the top of this policy will be revised.

• Your continued use of the App after the effective date constitutes acceptance of the updated policy.

• We encourage you to review this policy periodically. The current version is always available at https://imc-hub.github.io/digital-solutions/rx-challenger/privacy and linked from within the App's Settings screen.

16. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Data Controller: Intelligent Mastery Coaching (IMC)

Developer: Ahmed Ezzat

Email: imc.hub.eg@gmail.com

Subject line: "Privacy Request — Rx Challenger"

Mailing Address: IMC Inc., Attn: Privacy Team, Giza, Egypt

We aim to respond to all inquiries within 30 days (or sooner as required by applicable law).

17. Google Play Data Safety Form Alignment

This Privacy Policy is designed to be consistent with the Google Play Console Data Safety form declarations for Rx Challenger (package: com.pharmacycafe.goodrx). Key alignment points:

• Data Collected: Email, Name, User IDs, App Activity (progress, interactions), Crash Logs, Device IDs — all declared.

• Data Shared: Shared with Google (Firebase, Play Services) as processor — declared. Not sold. Not shared with data brokers.

• Data Security: Encryption in transit (TLS 1.3), encryption at rest (AES-256), secure authentication — declared.

• User Controls: Account deletion (email request now, in-app coming v1.2), data access/portability via email, opt-out of leaderboards/analytics — declared.

• Children: Not directed to children under 13 — declared.

• Permissions: INTERNET, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC, RECEIVE_BOOT_COMPLETED — all declared with purpose.

If you are reviewing this policy for Play Console submission, please ensure the Data Safety form selections match the above. Contact imc.hub.eg@gmail.com for the latest Data Safety form mapping document.