Privacy Policy
Last Updated: February 1, 2026
The short version
- Your health profile and supplement stack stay on your device by default.
- We never sell your personal information.
- We collect only what's needed to run the service — primarily your email.
- AI features process only the text you submit — not your full health profile.
- You can delete your data at any time.
The full legal details are below. If anything is unclear, email us at privacy@pharmaguide.io.
1. Introduction
PharmaGuide ("PharmaGuide," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website at pharmaguide.io, use our mobile application, or interact with our services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.
2. Information We Collect
We collect different types of information depending on how you interact with our Service:
2.1 Information You Provide Directly
- Account Information: When you create an account or join our waitlist, we collect your email address and, optionally, your name.
- Health Profile Data: To personalize your experience, you may choose to provide information such as your age bracket, biological sex, health goals, existing health conditions, and known allergies. This information is stored locally on your device and is not transmitted to our servers unless you explicitly choose to back it up.
- Supplement & Medication Data: Information about supplements and medications you scan or add to your stack, including product names, dosages, and timing. This information is stored locally on your device.
- Communications: When you contact us for support, provide feedback, or communicate with us, we collect the content of those communications along with your contact information.
2.2 Information Collected Automatically
When you access our website, we may automatically collect certain information:
- Device Information: Device type, operating system, unique device identifiers, and mobile network information.
- Log Data: IP address, browser type, pages visited, time spent on pages, and other diagnostic data.
- Usage Data: Information about how you use our Service, including features accessed and actions taken (collected in aggregate, anonymized form).
- Cookies and Similar Technologies: We use cookies and similar tracking technologies to track activity on our Service. See Section 7 for more details.
2.3 Information We Do NOT Collect
PharmaGuide is designed to minimize data collection. We do not collect:
- Your actual medical records or prescriptions
- Insurance information or Social Security numbers
- Payment card information (we do not process payments at this time)
- Precise GPS location data
- Photos from your camera (barcode scanning is processed locally)
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 To Provide and Improve Our Service
- Deliver the core functionality of PharmaGuide, including supplement scanning, interaction checking, and stack analysis
- Personalize your experience based on your health profile (processed locally on your device)
- Respond to your inquiries and provide customer support
- Analyze usage patterns to improve our Service (using aggregated, anonymized data only)
3.2 To Communicate With You
- Send you important updates about our Service, including security alerts and policy changes
- Provide you with news, special offers, and information about our products (you can opt out at any time)
- Respond to your comments, questions, and requests
3.3 For AI-Powered Features
Our AI Guidance Chat feature uses artificial intelligence to provide educational information about supplements and medications. This feature provides educational information only — it does not diagnose or prescribe. When you use this feature:
- The text you submit to the AI feature — which may include health-related context if you choose to include it — is processed by our AI systems to generate a response
- We may use third-party AI providers (such as Anthropic or OpenAI) to power these features
- AI conversations may be reviewed to improve the quality and safety of our responses
- We do not use your AI conversations for advertising purposes
- We do not automatically send your health profile or full stack data to AI providers — only the specific text you submit in the chat
3.4 For Safety and Compliance
- Detect, prevent, and address technical issues, fraud, or security concerns
- Comply with legal obligations and respond to lawful requests from authorities
- Enforce our Terms of Service and protect our rights
4. Data Storage & Security
4.1 What's Stored Where
| Data Type | Storage Location | Protection |
|---|---|---|
| Health profile, supplement stack, scan history | Your device only | Industry-standard encryption at rest |
| AI chat history | Your device (with optional cloud backup) | Industry-standard encryption at rest |
| Account email & preferences | Our secure servers | Encrypted in transit and at rest |
| Anonymous usage analytics | Our secure servers | Encrypted in transit |
4.2 Security Measures
We implement appropriate technical and organizational security measures, including:
- Industry-standard encryption for data in transit (such as TLS)
- Industry-standard encryption for data at rest on device (such as AES-256)
- Periodic security reviews and vulnerability assessments
- Access controls and authentication requirements
- Employee security training and confidentiality agreements
While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
4.3 Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required by law. When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are legally required to retain it.
5. Information Sharing
We may share your information only in the following limited circumstances:
5.1 Service Providers
We may share information with trusted third-party service providers who assist us in operating our Service, such as:
- Email Service Providers: To send you communications (e.g., MailerLite for newsletters)
- AI Providers: To power our AI Guidance Chat feature (e.g., Anthropic, OpenAI). We require these providers to handle data in accordance with our instructions and applicable law.
- Analytics Providers: To understand how our Service is used (anonymized data only)
- Cloud Infrastructure: To host our website and backend services
5.2 Legal Requirements
We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of PharmaGuide, our users, or the public.
5.3 Business Transfers
If PharmaGuide is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our Service before your information becomes subject to a different privacy policy.
5.4 With Your Consent
We may share your information with third parties when you give us explicit consent to do so, such as when you choose to share your supplement stack with a healthcare provider.
6. Your Rights & Choices
You have several rights regarding your personal information:
6.1 Access and Portability
You can access your personal information at any time through the app. You may also request a copy of your data in a portable format by contacting us.
6.2 Correction
You can update or correct your account information directly in the app or by contacting us.
6.3 Deletion
You can delete your account and associated data at any time. Since most of your health data is stored locally on your device, you maintain full control over it. To delete data stored on our servers, contact us at privacy@pharmaguide.io.
6.4 Marketing Opt-Out
You can unsubscribe from marketing emails by clicking the "unsubscribe" link in any email or by updating your preferences in your account settings. Note that you may still receive transactional or service-related communications.
6.5 Cookie Preferences
Most web browsers allow you to manage cookie preferences. You can set your browser to refuse cookies or delete certain cookies. Note that some features of our Service may not function properly without cookies.
6.6 Do Not Track
Some browsers include a "Do Not Track" (DNT) or "Global Privacy Control" (GPC) feature. We honor GPC signals where required by applicable law. For DNT signals, which lack a consistent technical standard, we apply the privacy protections described in this policy to all users regardless of DNT settings.
7. Third-Party Services
7.1 Cookies and Tracking Technologies
We use cookies and similar technologies for:
- Essential Cookies: Required for the Service to function properly (e.g., session management, security)
- Analytics Cookies: Help us understand how visitors interact with our website (collected in anonymized form)
We do not currently use marketing or advertising cookies. If this changes in the future, we will update this policy and provide you with appropriate notice and consent options.
7.2 Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.
7.3 AI Service Providers
Our AI Guidance Chat feature may use third-party AI services. When you interact with AI features:
- The text you submit is processed by our AI providers to generate responses
- We require AI providers to handle data in accordance with our instructions and applicable law
- We do not automatically share your health profile or stack data with AI providers — only the specific text you submit in the chat
8. Children's Privacy
Our Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA). We also recommend that users under the age of 18 use PharmaGuide only with parental or guardian guidance.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@pharmaguide.io. If we discover that we have collected personal information from a child under 13, we will delete that information promptly.
9. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
9.1 Your California Rights
- Right to Know: You can request information about the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You can request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You can request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: You can request that we limit how we use sensitive personal information (such as health-related data). Because health data is stored locally on your device by default, our use of sensitive personal information is already limited.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
9.2 Exercising Your Rights
To exercise your California privacy rights, contact us at privacy@pharmaguide.io or submit a request through our app. We will verify your identity before processing your request and will respond within 45 days as required by law.
9.3 Categories of Information
In the past 12 months, we have collected the following categories of personal information:
- Identifiers (email address, device identifiers)
- Internet activity (browsing history on our Service, interactions with our app)
- Health-related information (stored locally on your device)
9.4 Sensitive Personal Information
Health-related information you provide is considered sensitive personal information under California law. This information is stored locally on your device and is used only to provide you with personalized supplement and medication safety information. We do not use or disclose sensitive personal information for purposes other than those permitted under the CPRA.
9.5 Data Retention
We retain each category of personal information only as long as necessary for the purposes described in this policy. Account data is retained while your account is active and for up to 30 days after deletion. Analytics data is retained in anonymized form.
10. International Users
PharmaGuide is operated from the United States. If you access our Service from outside the U.S., please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located.
If you are located in the European Economic Area (EEA), United Kingdom, or other regions with data protection laws, you may have additional rights regarding your personal data — including the right to access, rectify, or erase your data, restrict or object to processing, and data portability. To exercise these rights, contact us at privacy@pharmaguide.io.
Because our local-first architecture stores most health data on your device rather than our servers, the scope of cross-border data transfers is limited primarily to account information and anonymized analytics.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via email for material changes (if you have provided your email)
- Post a notice on our Service for significant changes
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
PharmaGuide
Operated by B&Br Technology
Boston, MA 02101, United States
Privacy Inquiries: privacy@pharmaguide.io
General Inquiries: info@pharmaguide.io
We aim to respond to all privacy-related inquiries within 30 days.