Legal
Privacy Policy
Last updated: March 13, 2026
RxPulse ("we", "us", or "the Platform") is an AI-native health platform. We take the protection of your personal information, especially health information, extremely seriously. This policy explains what we collect, why, how we protect it, and what rights you have.
RxPulse operates in the United States. We handle protected health information in line with the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules, and with the state privacy laws that apply where you live, including the California Consumer Privacy Act and the California Confidentiality of Medical Information Act for California residents.
We do not offer the service in the European Union or the European Economic Area, and this policy does not make GDPR commitments. If that changes, this policy changes with it before the service opens there.
1. Data We Collect
To provide clinical-grade health management, we collect and process the following categories of personal data:
Health Records
Medical conditions (ICD-10 coded), clinical encounters, care plans, risk assessments, and clinical analysis documents.
Vitals and Biometrics
Weight, blood pressure, SpO2, heart rate, and other physiological measurements collected from manual entry or connected devices.
Medications
Current, proposed, and historically prescribed medications including dosage, frequency, and contraindication information.
Laboratory Results
Blood tests, urinalysis, and other diagnostic results with LOINC coding, reference ranges, and clinical context.
Account and Authentication Data
Email address, name, and authentication credentials managed through our identity provider. We do not store passwords directly.
2. Purpose and Legal Basis
We use your information for the purposes below. Where a purpose is not needed to provide the service, it is optional and you can decline it without losing the rest:
| Purpose | Basis |
|---|---|
| Providing core health record management | Required to provide the service you signed up for |
| AI-powered health insights and recommendations | Your consent, given at sign-up and withdrawable at any time |
| Account authentication and security | Required to keep your account and records secure |
| Optional features (voice companion, notifications) | Your consent, per feature, withdrawable at any time |
| Progress tracking (streaks, points, badges) to personalize your experience | Optional. You can turn progress tracking off |
| Legal obligations and regulatory compliance | Required by HIPAA and applicable US state law |
3. Data Processors and Sub-processors
We use the following third-party services to operate the Platform. Each processor is evaluated for GDPR alignment, and we execute a Data Processing Agreement (DPA) or Business Associate Agreement (BAA) with each one before it processes production personal or health data:
Hosting and Delivery
Vercel (frontend hosting, serverless functions) and Cloudflare (CDN, DDoS protection). Data is processed in US data centers.
Database
Neon PostgreSQL, managed serverless PostgreSQL. Health data is stored encrypted at rest and in transit.
Authentication
Better Auth, self-hosted authentication. Manages user sessions and email/password authentication. All auth data is stored in our own database, no third-party has access to your health data.
AI and Voice Companion
Anthropic (the Claude models behind the AI companion), Google (Gemini models, including the voice companion), and ElevenLabs (voice), with fallback model providers for resilience. We minimize the context sent to these providers, and can pseudonymize identifying details such as your name before they reach a model. AI and voice features remain gated for protected health information until a Business Associate Agreement is in place with each provider.
4. Data Retention
We retain your data in accordance with the following principles:
- Health records: Retained for the period required by the state whose medical-record retention law applies to you, commonly six to ten years after the last entry and longer for records created while you were a minor. Records are not permanently deleted during that period.
- Account data: Retained for the duration of your active account. Upon account deletion, direct account identifiers are removed within 30 days. Health and legally required records remain under a pseudonymous internal record ID for at least 10 years as required by law. Because clinical narrative can contain identifying context, those retained records are not treated as anonymous data without controlled de-identification review. Deletion starts from this page (works with or without the app installed) or from Settings within the app. Sessions end immediately; there is a 14-day window to cancel by signing back in before the removal above becomes irreversible.
- AI interaction logs: Conversation history with the AI companion is retained for 12 months to improve personalization, then automatically purged unless you choose to retain it.
- Audit logs: System access and modification logs are retained for at least 10 years, consistent with our clinical-record retention period, for security and compliance purposes.
5. Your Rights
HIPAA gives you rights over your health information, and your state may give you more. These apply to you wherever you live in the US:
Right of Access
You may request a copy of all personal data we hold about you, including health records, in a structured format.
Right to Rectification
You may request correction of inaccurate personal data. For health records, corrections are appended (not overwritten) to maintain an audit trail.
Right to request deletion
You may ask us to delete your information. Medical-record retention law sets a floor we cannot go below, so where deletion conflicts with it we stop using the record for anything other than the legal obligation, and tell you which records those are and why.
Right to Data Portability
You may receive your health data in a machine-readable format (FHIR-compatible JSON) for transfer to another provider.
Right to Object
You may object to processing based on legitimate interest. You may also withdraw consent for optional features at any time without affecting the lawfulness of prior processing.
Right to Restrict Processing
You may request that we limit processing of your data while a complaint or rectification request is being resolved.
6. Data Security
We implement technical and organizational measures to protect your health data, including:
- Encryption in transit (TLS) and at rest
- Fail-closed row-level security on clinical database tables
- A 12-character minimum password length and database-authoritative session expiry
- Server-controlled roles with invite-only account provisioning
- Append-only audit logging of protected health information access
- Automated dependency and vulnerability scanning in our build pipeline
7. Contact Information
For questions about this privacy policy, to exercise your rights, or to file a complaint, please contact:
Responsible entity: RxPulse
Email: privacy@rx-pulse.com
Registered address: available on request via the email above.
If you believe your health information privacy rights have been violated, you may file a complaint with the US Department of Health and Human Services, Office for Civil Rights, at hhs.gov/hipaa/filing-a-complaint. We will never retaliate against you for filing one.
Legal References
- Health Insurance Portability and Accountability Act of 1996 (HIPAA), Privacy and Security Rules
- Health Information Technology for Economic and Clinical Health Act (HITECH), breach notification
- 42 CFR Part 2, where substance use disorder records apply
- California Consumer Privacy Act (CCPA), as amended by the CPRA
- California Confidentiality of Medical Information Act (CMIA)