ComplyRx
← Back to home

Privacy Policy

Effective date: July 17, 2026 · Last updated: July 17, 2026

ComplyRx ("ComplyRx," "we," "us," or "our") provides a clinical operations platform used by healthcare clinics ("Clinics," "Customers") to manage treatment tracking, controlled-substance inventory, DEA recordkeeping, and REMS (Risk Evaluation and Mitigation Strategy) program compliance for esketamine/Spravato treatment. This Privacy Policy explains what information we collect, how we use and protect it, and the choices available to you. It applies to our website, our web application, and related services (together, the "Services").

1. Who this policy covers

This policy covers two distinct groups of people, and it's important to understand which one applies to you:

This policy also covers visitors to our marketing website who are not yet Clinic customers (for example, if you submit a contact or demo-request form).

2. Our role & protected health information

Clinics use the Services to store and process protected health information ("PHI") as defined by the U.S. Health Insurance Portability and Accountability Act ("HIPAA") — including patient names, dates of birth, contact information, diagnoses, medications, treatment session data, prior authorization details, and REMS program submissions.

With respect to that PHI, the Clinic is the HIPAA Covered Entity and ComplyRx acts as its Business Associate under a Business Associate Agreement ("BAA") executed with each Clinic. We process PHI only as instructed by the Clinic and only to provide, secure, and support the Services — never for our own independent marketing or advertising purposes, and never to build product outside the scope the BAA and the Clinic's instructions permit.

If you are a patient with a question about how your specific health information is used, please contact your Clinic directly — they control that data and can direct you to their own Notice of Privacy Practices. See Section 13 for more detail.

3. Information we collect

A. Information Clinics and their staff provide to us

B. Patient/clinical information entered by a Clinic (processed as a Business Associate)

We do not decide what patient information a Clinic collects or how long the Clinic wants a given record kept — those decisions belong to the Clinic.

C. Information collected automatically

C-1. The ComplyRx mobile apps (iOS and Android)

The ComplyRx mobile applications provide the same Services described in this policy inside a native app. In addition to the practices above, the mobile apps use the following device capabilities. Each is optional, requested through the operating system's standard permission prompt, and can be revoked at any time in your device settings:

The mobile apps contain no advertising, no third-party analytics or tracking SDKs, and do not access your contacts, photos, or location. All data handling otherwise follows the practices described in the rest of this policy, including the Business Associate commitments in Section B.

D. Information from website visitors who are not Clinic users

If you fill out a contact form, request a demo, or otherwise reach out to us through our marketing website, we collect the information you choose to provide (such as your name, email, organization, and message) so we can respond.

4. How we use information

We use information to:

We do not sell personal information or PHI, and we do not use PHI to serve targeted advertising.

6. How we share information

We disclose information only as described here — never as a general matter of course:

We do not disclose PHI to any third party for that third party's own independent marketing purposes.

7. Sub-processors & service providers

To provide the Services we rely on a limited set of vetted infrastructure and communication providers, each bound by contract (and, where PHI is involved, a Business Associate Agreement) to safeguard information and use it only to provide services to us:

CategoryPurpose
Cloud database & application hostingSecure storage of application data and hosting of the web application.
Static site / content delivery hostingHosting and delivery of the website and application front end.
Fax transmission providerSending required regulatory monitoring forms to the REMS program by fax, at a Clinic's direction.
Email service providers (customer-connected)Sending required regulatory submissions and questionnaire links by email, using a mailbox the Clinic itself authorizes and controls.
AI/document-processing providerAssisting with document data extraction, form auto-fill, and similar automation features. See Section 8.

We maintain an up-to-date list of sub-processors and will notify Clinics of material changes as required by our agreements with them.

8. Use of AI in the Services

Certain features use a third-party AI model to help extract information from uploaded documents (for example, reading a pharmacy label, a prior-authorization letter, or a patient intake form) or to answer natural-language questions about a Clinic's own aggregated, clinic-scoped data in our analytics tool. These requests are made through a vetted AI provider under contractual terms that prohibit using the submitted content to train that provider's general-purpose models. Any suggested extraction is always presented to Clinic staff for review and confirmation before it is saved — the Services do not make unreviewed clinical decisions.

9. How we protect information

We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, including:

No system can be guaranteed 100% secure. If we become aware of a security incident affecting PHI, we will notify affected Clinics in accordance with HIPAA and our Business Associate Agreement, and Clinics remain responsible for any patient notifications required under applicable law.

10. Data retention

We retain information for as long as a Clinic's account is active and as needed to provide the Services, including to meet the recordkeeping periods required for controlled-substance and other regulatory compliance (which can be several years). When a Clinic's account is closed, we retain or return data as required by our agreement with that Clinic and applicable law, and otherwise securely delete or de-identify it. Append-only compliance and audit records (such as DEA transaction logs) are, by design, never altered or deleted during the required retention period.

11. Cookies, local storage & notifications

We use cookies and browser local/session storage that are strictly necessary to keep you signed in, remember basic interface preferences (like light/dark mode), and maintain security — we do not use third-party advertising or cross-site tracking cookies. If you enable push notifications (for example, to be alerted when a patient is ready for their next treatment step), your browser stores a subscription token used solely to deliver those notifications; you can disable this at any time in your device or browser settings, or in the Services' own notification settings.

12. Your choices & rights

If you are Clinic staff: you may access or update your own account profile within the Services, and a Clinic administrator can update or remove your account access. Depending on your location, you may also have rights to request access to, correction of, or deletion of your personal account information — contact us using the details in Section 17, or your Clinic administrator.

If you are a patient of a Clinic: your rights regarding your health information — including rights to access, amend, or receive an accounting of disclosures of your records — are exercised through your Clinic, which is the party responsible for that information under HIPAA. See Section 13.

13. Notice for patients of a Clinic

If your healthcare provider uses ComplyRx, some of your health information may be stored in our systems. We do not control what information a Clinic collects about you, how long it is kept, or who at that Clinic can see it — those choices, and the obligation to give you a Notice of Privacy Practices, belong to your Clinic.

In a small number of cases, we may contact you directly at your Clinic's request and using contact information your Clinic provides — for example, to send you a secure link to:

These links are single-purpose, time-limited, and access-controlled. We do not use the information you submit through them for any purpose other than delivering it back to your Clinic and, where applicable, transmitting the required regulatory submission.

For any question about your specific medical records, please contact your Clinic directly.

14. Children's information

The Services are intended for use by healthcare clinic staff and are not directed to children. Patient information for a minor may be entered into the Services by a Clinic in the ordinary course of that minor's care, subject to the Clinic's own policies and applicable law — we do not independently collect information from children.

15. Where information is stored

We store and process information in the United States. If we engage a service provider located outside the United States, we require appropriate contractual safeguards for any transfer of information.

16. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to the Services or our practices. If we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice to Clinics. Continued use of the Services after an update constitutes acceptance of the revised policy.


17. Contact us

Talking Bird LLC

Attn: Privacy — ComplyRx

Email: vmathews@complyrx.ai

Clinics with questions about our Business Associate Agreement or sub-processor list should contact their designated ComplyRx account representative.