RxComplyRx
Product Security About FAQ
Sign in Request a demo

Privacy Policy

Effective date: July 17, 2026 · Last updated: August 24, 2026

ComplyRx ("ComplyRx," "we," "us," or "our") provides a clinical operations platform used by healthcare clinics ("Clinics," "Customers") to manage treatment tracking, controlled-substance inventory, DEA recordkeeping, and REMS (Risk Evaluation and Mitigation Strategy) program compliance for esketamine/Spravato treatment. This Privacy Policy explains what information we collect, how we use and protect it, and the choices available to you. It applies to our website, our web application, and related services (together, the "Services").

On this page

  1. Who this policy covers
  2. Our role & protected health information
  3. Information we collect
  4. How we use information
  5. Why we process information
  6. How we share information
  7. Sub-processors & service providers
  8. Use of AI in the Services
  9. Google API Services & Limited Use
  10. How we protect information
  11. Data retention
  12. Cookies, local storage & notifications
  13. Your choices & rights
  14. Notice for patients of a Clinic
  15. Children's information
  16. Where information is stored
  17. Changes to this policy
  18. Contact us

1. Who this policy covers

This policy covers two distinct groups of people, and it's important to understand which one applies to you:

  • Clinic staff and administrators who create an account and use the Services to do their jobs (clinicians, nurses, pharmacy/inventory staff, clinic administrators). For you, we act largely as an ordinary software provider — we describe below what account and usage information we collect about you directly.
  • Patients of a Clinic whose health information is entered into the Services by that Clinic's staff (for example, treatment charts, medication administration records, prior-authorization documents, or a completed PHQ-9 screening). ComplyRx does not have a direct relationship with patients and does not collect patient information from patients themselves except in the narrow, clearly-labeled cases described in Section 13 (for example, an emailed link to complete a PHQ-9 questionnaire, or a link to review and electronically sign an enrollment form).

This policy also covers visitors to our marketing website who are not yet Clinic customers (for example, if you submit a contact or demo-request form).

2. Our role & protected health information

Clinics use the Services to store and process protected health information ("PHI") as defined by the U.S. Health Insurance Portability and Accountability Act ("HIPAA") — including patient names, dates of birth, contact information, diagnoses, medications, treatment session data, prior authorization details, and REMS program submissions.

With respect to that PHI, the Clinic is the HIPAA Covered Entity and ComplyRx acts as its Business Associate under a Business Associate Agreement ("BAA") executed with each Clinic. We process PHI only as instructed by the Clinic and only to provide, secure, and support the Services — never for our own independent marketing or advertising purposes, and never to build product outside the scope the BAA and the Clinic's instructions permit.

If you are a patient with a question about how your specific health information is used, please contact your Clinic directly — they control that data and can direct you to their own Notice of Privacy Practices. See Section 13 for more detail.

3. Information we collect

A. Information Clinics and their staff provide to us

  • Account & identity data — name, work email address, role (admin/staff), and a hashed password (accounts are provisioned by a Clinic administrator; we do not offer public self-signup).
  • Clinic configuration data — clinic name, address, DEA registration number, prescriber credentials and signature, fax and email destinations for REMS submission, and similar practice-level settings.
  • Integration credentials — OAuth tokens for connected services the Clinic authorizes, such as a fax provider, Google Workspace, or Microsoft 365 mailbox, used solely to send required REMS submissions and related notifications on the Clinic's behalf.

B. Patient/clinical information entered by a Clinic (processed as a Business Associate)

  • Patient demographics (name, date of birth, sex, contact details, address).
  • Treatment records — dosing sessions, vitals, monitoring observations, adverse-event reports, and checkout details.
  • Medication-inventory and DEA recordkeeping data — lot/serial numbers, receipt/dispense/disposition records, and related controlled-substance audit trails.
  • Enrollment, prior-authorization, PHQ-9 screening, and other uploaded or generated clinical documents.
  • Communications records related to required regulatory submissions (for example, fax and email transmission logs to the REMS program).

We do not decide what patient information a Clinic collects or how long the Clinic wants a given record kept — those decisions belong to the Clinic.

C. Information collected automatically

  • Usage & device data — pages viewed, actions taken, timestamps, browser/device type, and IP address, used for security, troubleshooting, and improving the Services.
  • Audit & activity logs — a record of who did what and when within the Services (for example, who viewed or edited a record), which we maintain to support the Clinic's own compliance and security obligations.
  • Cookies and local/session storage — used to keep you signed in, remember your interface preferences (such as light/dark theme), and support core functionality. See Section 10.

C-1. The ComplyRx mobile apps (iOS and Android)

The ComplyRx mobile applications provide the same Services described in this policy inside a native app. In addition to the practices above, the mobile apps use the following device capabilities. Each is optional, requested through the operating system's standard permission prompt, and can be revoked at any time in your device settings:

  • Camera — used only to scan medication box barcodes and labels for inventory intake and treatment verification. Images and barcode data are processed for that workflow; the camera is never used for any other purpose.
  • Face ID / Touch ID / fingerprint — used only to unlock the app after it has been in the background. Biometric matching is performed entirely by your device's operating system; ComplyRx never receives, stores, or transmits your biometric data — the app is only told whether the unlock succeeded.
  • Notifications — used for treatment-timer reminders and operational alerts. Notifications shown on a lock screen are designed to contain patient initials only, never full names or other identifying details.
  • App badge and vibration — used to surface how many patients are currently ready and to accompany reminders.

The mobile apps contain no advertising, no third-party analytics or tracking SDKs, and do not access your contacts, photos, or location. All data handling otherwise follows the practices described in the rest of this policy, including the Business Associate commitments in Section B.

D. Information from website visitors who are not Clinic users

If you fill out a contact form, request a demo, or otherwise reach out to us through our marketing website, we collect the information you choose to provide (such as your name, email, organization, and message) so we can respond.

4. How we use information

We use information to:

  • Provide, operate, secure, and maintain the Services, including patient charting, inventory/DEA recordkeeping, and REMS submission workflows;
  • Authenticate users and enforce clinic-level and role-based access controls;
  • Generate and transmit required regulatory forms and submissions on a Clinic's behalf, at that Clinic's direction (for example, faxing or emailing a completed monitoring form to a REMS program);
  • Detect, investigate, and prevent fraud, unauthorized access, and other security incidents;
  • Provide customer support and respond to Clinic inquiries;
  • Maintain audit trails required for controlled-substance and regulatory compliance;
  • Improve and troubleshoot the Services (for example, using de-identified or aggregated usage patterns); and
  • Comply with our legal obligations, including our obligations under a Clinic's Business Associate Agreement.

We do not sell personal information or PHI, and we do not use PHI to serve targeted advertising.

5. Why we process information

We process information because it is necessary to perform our contract with the Clinic (our Customer), to comply with legal and regulatory obligations that apply to healthcare recordkeeping (including HIPAA and DEA requirements), and — for limited operational purposes like security monitoring and service improvement — based on our legitimate interest in operating a safe and reliable platform, balanced against your privacy interests.

6. How we share information

We disclose information only as described here — never as a general matter of course:

  • With the Clinic itself — the Clinic that entered or manages a record can access it, subject to its own internal role-based permissions.
  • With service providers acting on our behalf — see Section 7 for the categories of vendors we use and why. These providers are contractually bound to protect the information and to use it only to provide services to us.
  • For required regulatory submissions — a completed monitoring form or related documentation is transmitted (by fax or email) to the applicable REMS program, exactly as a Clinic's own staff would otherwise do manually.
  • To comply with law — if required by valid legal process such as a subpoena, court order, or similar legal obligation.
  • To protect rights and safety — where we believe in good faith that disclosure is necessary to investigate or prevent fraud, security incidents, or harm to any person.
  • In connection with a corporate transaction — such as a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections and, where PHI is involved, in a manner consistent with HIPAA.

We do not disclose PHI to any third party for that third party's own independent marketing purposes.

7. Sub-processors & service providers

To provide the Services we rely on a limited set of vetted infrastructure and communication providers, each bound by contract (and, where PHI is involved, a Business Associate Agreement) to safeguard information and use it only to provide services to us:

CategoryPurpose
Cloud database & application hostingSecure storage of application data and hosting of the web application.
Static site / content delivery hostingHosting and delivery of the website and application front end.
Fax transmission providerSending required regulatory monitoring forms to the REMS program by fax, at a Clinic's direction.
Email service providers (customer-connected)Sending required regulatory submissions and questionnaire links by email, using a mailbox the Clinic itself authorizes and controls.
AI/document-processing providerAssisting with document data extraction, form auto-fill, and similar automation features. See Section 8.
Transactional email provider (ComplyRx-operated)Sending account and service emails we originate — staff invitations, password resets and similar notices. Distinct from the customer-connected mailboxes above, which a Clinic authorizes and controls.
Payment processingProcessing Clinic subscription payments. Receives Clinic billing contact and payment details; receives no patient information.
Identity providerAuthenticating staff sign-in and managing multi-factor authentication.
Cloud compute providerRunning the automated processes that submit required regulatory forms on a Clinic's behalf.
Manufacturer copay & patient-support programSubmitting a patient's enrollment to the medication manufacturer's copay-support program, at a Clinic's direction and where the patient has agreed to enroll. Operated by the program sponsor, not by ComplyRx.
Benefits & prior-authorization clearinghouseChecking pharmacy benefits and submitting prior-authorization requests to payers on a Clinic's behalf.
SPRAVATO REMS programReceiving the enrollment and monitoring forms the program requires, at a Clinic's direction. Operated by the program sponsor, not by ComplyRx; a Clinic's obligations to the program are set by the program itself.

We maintain an up-to-date list of sub-processors and will notify Clinics of material changes as required by our agreements with them.

8. Use of AI in the Services

Certain features use a third-party AI model to help extract information from uploaded documents (for example, reading a pharmacy label, a prior-authorization letter, or a patient intake form) or to answer natural-language questions about a Clinic's own aggregated, clinic-scoped data in our analytics tool. These requests are made through a vetted AI provider under contractual terms that prohibit using the submitted content to train that provider's general-purpose models. Any suggested extraction is always presented to Clinic staff for review and confirmation before it is saved — the Services do not make unreviewed clinical decisions.

9. Google API Services & Limited Use

ComplyRx's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

  • What we access. When a Clinic administrator connects a Google Workspace mailbox, we request only the gmail.send scope (permission to send email on the connected account's behalf) and the userinfo.email scope (the connected account's email address, shown in Settings so the Clinic can see which mailbox is connected). We never read, list, modify, or delete any email in the connected mailbox, and we do not receive or store any Gmail message content.
  • How we use it. The send permission is used solely to transmit required regulatory submissions (for example, SPRAVATO REMS monitoring and enrollment forms) and related questionnaire links from the Clinic's own verified mailbox, at the Clinic's direction.
  • Transfer. Google user data is never sold and never transferred to third parties, including data brokers, advertisers, or any third-party AI/ML service. It is never used for advertising, lending or credit decisions, or any purpose other than providing the sending feature the Clinic connected it for.
  • AI/ML. No Google user data is used to develop, improve, or train any AI or machine-learning model, and no Google user data is transmitted to the AI provider described in Section 8. The AI features of the Services operate only on documents and data a Clinic uploads directly — never on Gmail data.
  • Protection, retention & deletion. OAuth tokens are stored encrypted at rest, are accessible only to the connected Clinic's authorized workflow, and are protected by the safeguards described in Section 10. Disconnecting the integration in Settings removes the stored tokens from our systems, so ComplyRx can no longer use them. That does not by itself revoke the underlying authorization at the provider — to withdraw it there as well, revoke access at myaccount.google.com/permissions (Google) or the equivalent Microsoft account page.

10. How we protect information

We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, including:

  • Encryption of data in transit (TLS) and at rest;
  • Role-based access controls and row-level data isolation between Clinics ("multi-tenant" access controls), so one Clinic cannot see another Clinic's data;
  • Audit logging of access to and changes made within clinical records;
  • Least-privilege access for our personnel, granted only as needed to provide support or maintain the Services;
  • Ongoing monitoring and periodic review of our security configuration.

No system can be guaranteed 100% secure. If we become aware of a security incident affecting PHI, we will notify affected Clinics in accordance with HIPAA and our Business Associate Agreement, and Clinics remain responsible for any patient notifications required under applicable law.

11. Data retention

We retain information for as long as a Clinic's account is active and as needed to provide the Services, including to meet the recordkeeping periods required for controlled-substance and other regulatory compliance (which can be several years). When a Clinic's account is closed, we retain or return data as required by our agreement with that Clinic and applicable law, and otherwise securely delete or de-identify it. Append-only compliance and audit records (such as DEA transaction logs) are, by design, never altered or deleted during the required retention period.

12. Cookies, local storage & notifications

We use cookies and browser local/session storage that are strictly necessary to keep you signed in, remember basic interface preferences (like light/dark mode), and maintain security — we do not use third-party advertising or cross-site tracking cookies. If you enable push notifications (for example, to be alerted when a patient is ready for their next treatment step), your browser stores a subscription token used solely to deliver those notifications; you can disable this at any time in your device or browser settings, or in the Services' own notification settings.

13. Your choices & rights

If you are Clinic staff: you may access or update your own account profile within the Services, and a Clinic administrator can update or remove your account access. Depending on your location, you may also have rights to request access to, correction of, or deletion of your personal account information — contact us using the details in Section 17, or your Clinic administrator.

If you are a patient of a Clinic: your rights regarding your health information — including rights to access, amend, or receive an accounting of disclosures of your records — are exercised through your Clinic, which is the party responsible for that information under HIPAA. See Section 13.

14. Notice for patients of a Clinic

If your healthcare provider uses ComplyRx, some of your health information may be stored in our systems. We do not control what information a Clinic collects about you, how long it is kept, or who at that Clinic can see it — those choices, and the obligation to give you a Notice of Privacy Practices, belong to your Clinic.

In a small number of cases, we may contact you directly at your Clinic's request and using contact information your Clinic provides — for example, to send you a secure link to:

  • electronically review and sign a REMS enrollment form; or
  • complete a PHQ-9 depression screening questionnaire.

These links are single-purpose, time-limited, and access-controlled. We do not use the information you submit through them for any purpose other than delivering it back to your Clinic and, where applicable, transmitting the required regulatory submission.

Text messages (SMS)

If you tell your Clinic that you agree to receive text messages, your Clinic may use ComplyRx to send you the secure links described above by text instead of email. These messages are sent on behalf of your Clinic and are limited to links to forms and questionnaires your Clinic has asked you to complete — typically no more than four messages a month, and never marketing.

  • Consent — texts are sent only after you have told your Clinic you agree to receive them. Agreeing is never a condition of receiving care.
  • Opting out — reply STOP to any message to stop receiving texts. Reply HELP for help. Message and data rates may apply.
  • Your mobile number — your phone number and text-message consent are used only to deliver these messages. They are not shared with third parties or affiliates for marketing or promotional purposes.
  • Delivery — messages are sent from your Clinic's own phone system, which your Clinic has connected to ComplyRx, so the number you see is your Clinic's and your replies reach your Clinic. Message content is kept to the minimum needed to deliver the link and never names a medication or diagnosis.

For any question about your specific medical records, please contact your Clinic directly.

15. Children's information

The Services are intended for use by healthcare clinic staff and are not directed to children. Patient information for a minor may be entered into the Services by a Clinic in the ordinary course of that minor's care, subject to the Clinic's own policies and applicable law — we do not independently collect information from children.

16. Where information is stored

We store and process information in the United States. If we engage a service provider located outside the United States, we require appropriate contractual safeguards for any transfer of information.

17. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to the Services or our practices. If we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice to Clinics. Continued use of the Services after an update constitutes acceptance of the revised policy.


18. Contact us

Talking Bird LLC

Attn: Privacy — ComplyRx

Email: vmathews@complyrx.ai

Clinics with questions about our Business Associate Agreement or sub-processor list should contact their designated ComplyRx account representative.

RxComplyRx
ProductSecurityAboutFAQPrivacyTermsSign in
© 2026 Talking Bird LLC. All rights reserved.