PixelWeave / Elixis
Privacy Policy
Official policy for the launched Elixis desktop app.
Elixis Privacy Policy
Product: Elixis — Pharmacy Point of Sale, Inventory & Multi-Device Sync
Provided by: PixelWeave ("PixelWeave," "we," "us," or "our")
Last updated: [Insert Date]
This Privacy Policy explains what information Elixis collects, how it is
used, where it is stored, and what happens to it — including in the
optional cloud-backup feature. It is written to reflect how the software
actually works, not a generic template, so please read it alongside your
own legal counsel before publishing it, and update the bracketed fields
below before use.
1. Who This Policy Covers
Elixis is desktop software licensed to pharmacies and retail businesses
("you," "Licensee," or "your business") to run point-of-sale,
inventory, and staff operations. This Policy covers the Elixis
application itself — what it does with data on your device(s) and what
it sends over the network. It does not cover PixelWeave's website,
marketing pages, or any other product, which may have their own
policies.
Because Elixis is installed on your own computer(s) rather than run as a
hosted online service, the relationship between PixelWeave and your data
is different from a typical cloud app. Section 2 explains this before
anything else, because it shapes everything that follows.
2. Our Local-First Approach, in Plain Terms
- Elixis stores your pharmacy's data — inventory, sales, customers,
suppliers, staff accounts — in a database file **on your own
computer**, not on a server operated by PixelWeave.
- PixelWeave does not operate a central server that Elixis reports your
business data to, and does not run any analytics, tracking, or crash-
reporting service inside the app. We generally cannot see your
inventory, sales, or customer records, because they never reach us.
- The only times any information leaves your device(s) are:
1. Local network sync between your own paired devices (if you use
more than one device in-store) — this never leaves your local
network;
2. Google Drive backup — only if you choose to turn it on, and only
to your own Google account;
3. Update checks — a routine, non-personal check against our public
release feed to see if a newer version exists;
4. Support requests you choose to send us — e.g., emailing us to
activate a license.
- If you never enable Drive backup and never contact us for support, no
business or personal data processed by Elixis is ever transmitted to
PixelWeave.
The rest of this Policy details each of these in full.
3. Information Elixis Collects and Stores
3.1 Setup Information
When you first install Elixis, the Setup Wizard asks for your pharmacy's
name, address, phone number, email, and (optional) business/pharmacy
license number, plus your preferred currency. It also creates your
administrator account (see 3.2). This is stored locally in your
database and used to populate receipts, reports, and the app's settings.
3.2 Staff/User Account Information
For each staff member you add, Elixis stores a username, full name,
optional email and phone number, an assigned role (e.g., admin,
cashier), account status, and the date/time of their last login.
Passwords are never stored in plain text — they are hashed with bcrypt
before being saved, so even someone with direct access to the database
file cannot read a password back out of it.
3.3 Customer Information
When your staff record a customer in Elixis (e.g., to track store
credit, purchase history, or contact details), the app stores the name,
phone number, address, and any notes your staff enter, along with a
running total of that customer's spending. This information is entered
by you or your staff, about your customers — Elixis does not collect it
directly from those customers, and PixelWeave has no independent
relationship with them.
3.4 Supplier Information
Similarly, for suppliers you add, Elixis stores the supplier/company
name, contact person, phone, email, address, city, tax registration
number (e.g., NTN), and any notes your staff enter.
3.5 Transaction and Inventory Records
Elixis records sales (invoice number, items, quantities, prices,
discounts, tax, payment method, amount paid/change, which staff member
processed it, and the linked customer, if any), purchases from
suppliers, and returns on both sides. It also tracks medicine/inventory
details (names, batches, expiry dates, quantities, pricing) and stock
movements. Inventory data is generally not personal data, but
transaction records are linked to the staff and customers described
above.
3.6 Audit Logs
For accountability, Elixis keeps an internal log of significant actions
(e.g., who created, edited, or deleted a record, and when). This log
exists to help you investigate discrepancies in your own store and is
stored locally alongside the rest of your data.
3.7 Multi-Device Sync Information
If your pharmacy uses more than one computer, one device acts as the
host (it holds the real database) and others connect as clients.
To make this work, Elixis stores, per device: a device identifier, a
device name (defaulting to that computer's own hostname, e.g. what shows
up in Windows/macOS as the machine's name), a shared pairing secret, and
the paired device's local IP address and port. Devices discover and
connect to each other only over your local network (via a short-range
broadcast and direct connections between your own machines) — this
information is never sent outside your network, and PixelWeave does not
receive it.
3.8 Licensing and Hardware Identification
Elixis uses an offline, device-locked licensing system. On each
installation, it computes a Hardware ID — a one-way hash derived
from an operating-system identifier (such as a Windows registry GUID, a
macOS hardware UUID, or a Linux machine ID). This value cannot be
reversed back into any identifying information about your computer or
you, and the app does not transmit it automatically. It is shown to you
on request so that, if you need a license issued or reissued, you can
send it to us yourself (e.g., by email); we then issue a signed license
file that Elixis verifies entirely on your own device. We do not operate
a license-check server that your app contacts automatically.
3.9 Google Account Information (Optional Cloud Backup)
Elixis includes an optional feature to back up your database to your own
Google Drive. If you choose to enable it, Elixis opens Google's own
sign-in screen (via your system browser) and requests two permissions:
- Your Google account email address, so the app can show you which
account is connected; and
- Access to a private, app-only storage area in your Drive (Google
calls this "appDataFolder"), which is hidden from your normal Drive
view and cannot be read by any other app.
Elixis stores the resulting sign-in email and an encrypted refresh token
locally on your device (encrypted using your operating system's own
credential store where available). When a backup runs, a complete
snapshot of your local database — which includes the staff, customer,
supplier, and transaction information described above — is uploaded
directly from your device to that private folder in your own Google
Drive. **This upload goes directly to Google; PixelWeave is not a party
to it and does not receive a copy.** Google's handling of that data is
governed by Google's own privacy policy, not this one. You can disconnect
this feature and revoke access at any time from within the app or from
your Google Account settings.
3.10 Local Backups
Elixis can also save backup snapshots of your database to a folder on
your own computer (or an external drive you choose), and keeps a local
record of when backups were made. These stay entirely on your hardware.
3.11 Application Update Checks
Periodically, Elixis checks a public update feed to see if a newer
version is available. This is a standard network request that, like any
web request, inherently includes technical information such as your IP
address and the app's current version — Elixis does not attach any
business or personal data to this request, and update checks do not
require you to sign in or identify yourself.
3.12 Information You Send Us Directly
If you contact PixelWeave for support, licensing, or any other reason
(for example, by email), we receive whatever you choose to include in
that communication — such as your name, contact details, your Hardware
ID, or screenshots/log excerpts you share to help us troubleshoot. We
use this only to respond to you and provide the support requested.
4. Information Elixis Does Not Collect
To be explicit about what is *not* happening: Elixis does not include
analytics, advertising, or tracking SDKs; does not run background
telemetry or crash reporting; does not sell or share your data with data
brokers or advertisers; and does not process payments through any
third-party payment processor (the "payment method" field is simply your
own staff's record of how a sale was paid — e.g., cash or card — not a
live card-processing integration).
5. How Information Is Used
Information collected by Elixis is used to:
- Operate the core features you're using it for — sales, inventory,
customer and supplier records, staff accounts, and reporting;
- Authenticate staff logins and enforce role-based permissions;
- Keep multiple in-store devices synchronized in real time;
- Activate and verify your software license;
- Perform backups you request or schedule, including optional Google
Drive backup, so you can recover your data if something goes wrong;
- Maintain an audit trail for your own accountability and troubleshooting;
- Check for and deliver software updates;
- Respond to support requests you send us.
We do not use your business or customer data for advertising, profiling,
or any purpose unrelated to providing and supporting the software.
6. Where Your Information Is Stored
- Primary storage: a local database file on the device designated as
the "host" for your pharmacy, inside Elixis's application data folder
on that computer.
- Synced copies: none — client devices do not hold their own copy of
the database; they connect live to the host over your local network.
- Local backups: wherever you configure them to be saved (typically a
folder on the host machine or an external drive).
- Cloud backups (optional): the private app-data area of your own
Google Drive, if you enable that feature. This is governed by your
Google account's own region/storage settings, which PixelWeave does
not control.
- License records: a small file on each licensed device, plus
whatever you send us directly (e.g., by email) to obtain a license.
7. How Information Is Shared
We do not sell your data. We do not share it with advertisers or data
brokers. Information may be shared only in these limited circumstances:
- With Google, solely for the optional Drive backup feature you
enable, and solely to your own Google account, under Google's privacy
practices;
- **With hosting/version-control providers we use to distribute software
updates** (e.g., GitHub), which only ever receive a routine,
non-personal "is there a new version" request;
- As required by law, if PixelWeave is compelled by a valid legal
process to disclose specific information we hold (which, for most
users, will be limited to whatever you have directly sent us, such as
license correspondence);
- In connection with a business transfer, such as a merger,
acquisition, or sale of assets, in which case we would take reasonable
steps to ensure continued protection of any information we hold and
notify affected customers as required by law.
Because your business, customer, and inventory data lives on your own
device(s) by default, in practice there is nothing for PixelWeave to
share unless you have enabled Drive backup or contacted us directly.
8. Data Security
We've built Elixis with several concrete protections: staff passwords
are hashed (never stored in plain text); device-to-device sync on your
local network is authenticated with a shared secret established during
pairing; and, where your operating system supports it, your Google
sign-in credential for backup is encrypted using your OS's own secure
credential storage rather than kept in plain text.
That said, no software, storage method, or transmission method is
completely secure. Because your database lives on your own hardware, you
are responsible for reasonable physical and account-level security on
your own devices and network — for example, using strong staff
passwords, keeping your operating system updated, and restricting who
has physical or network access to your host device.
9. Data Retention and Your Control
Since your data is stored on hardware you control, you decide how
long it is kept. Elixis does not automatically delete your records, and
we do not hold a separate copy that persists after you delete yours. To
remove data:
- Delete individual records (customers, suppliers, staff, etc.) from
within the app, subject to your own record-keeping obligations (see
Section 10);
- Delete local backup files from wherever you saved them;
- Delete backups from your Google Drive's app-data area, or fully
disconnect the Drive integration, from within the app or your Google
Account settings;
- Uninstall the application and remove its application-data folder to
remove the local database entirely.
If you send us information directly (e.g., for licensing or support), we
retain it only as long as reasonably necessary for that purpose, or as
required by law.
10. Your Business's Responsibilities
Because Elixis stores data you collect about **your own customers and
employees**, your business is generally the one responsible for
complying with data protection, consumer protection, and record-keeping
laws that apply to that information — for example, laws governing how
long pharmacy/sales records must be kept, or requirements to honor
requests from your customers or staff about their own data. PixelWeave
provides the software as a tool; we do not control what data you choose
to enter, how long you keep it, or how you use it within your business.
We encourage you to have your own privacy notice for your customers and
staff, consistent with the laws that apply to your business.
11. Children's Privacy
Elixis is business software intended for use by adult staff operating a
pharmacy or retail business. It is not directed at children, and we do
not knowingly collect personal information from children through the
application itself.
12. International Data Transfers
Elixis itself does not transfer your data internationally — it stays on
your own device(s) and local network. If you enable Google Drive backup,
your data will be stored and processed according to Google's own
infrastructure and policies, which may involve servers outside your
country. Please review Google's privacy policy if this matters to you.
13. Changes to This Policy
We may update this Privacy Policy from time to time — for example, if we
add a new feature that changes what data Elixis collects or where it
goes. We will update the "Last updated" date above when we do, and, for
material changes, we will make reasonable efforts to notify licensed
users (such as through an in-app notice or release notes).
14. Contact Us
If you have questions about this Privacy Policy or how Elixis handles
data, contact us at:
PixelWeave
Email: info@pixelweave.tech
Website: https://elixis.pixelweave.tech
Elixis