Privacy Policy
Veridose AI is designed for HIPAA-covered entities. We treat all pharmacy and patient data as protected health information (PHI) and apply the highest standard of care to its handling.
1. Who We Are
Veridose AI, Inc. ("Veridose," "we," "our," or "us") operates a clinical decision support platform for licensed pharmacies. We provide AI-assisted medication interaction checks, staff management tools, and patient safety workflows accessible at veridose.app.
2. Information We Collect
Pharmacy Account Information: When you create an account, we collect your pharmacy name, business address, lead pharmacist name, NPI or license number, and billing contact email.
Staff Information: Pharmacy administrators may add staff members. We collect staff names, license IDs, roles, and optionally email addresses for PIN delivery.
Patient & Clinical Data: Medication names, dosages, interaction check inputs, and check results are processed to provide the service. This data constitutes Protected Health Information (PHI) under HIPAA.
Voice Input: When using the voice transcription feature, audio is transmitted directly to our speech-to-text processor. Audio recordings are deleted immediately after transcription and are never stored on Veridose servers.
Usage Data: We collect logs of feature usage (e.g., number of checks run, session duration) for product improvement. These logs do not contain PHI.
Technical Data: IP addresses, browser type, and device identifiers are collected for security and fraud prevention purposes.
3. How We Use Your Information
- To provide the Veridose platform and its clinical decision support features
- To send staff welcome emails and PIN reset notifications
- To maintain audit logs for regulatory compliance
- To detect and prevent unauthorized access or misuse
- To respond to support requests and inquiries
- To improve the accuracy and safety of our AI models (using de-identified data only)
We do not sell, rent, or trade your data to any third party. We do not use patient data for advertising purposes.
4. Data Sharing
Service Providers: We share data with third-party sub-processors strictly necessary to deliver the platform, including cloud infrastructure (Supabase / AWS), AI processing (OpenAI), email delivery (Resend), and transcription services. All sub-processors are contractually bound to appropriate data protection obligations.
Legal Requirements: We may disclose information if required by law, court order, or to protect the safety of individuals or the public.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, which will be bound by this policy.
5. HIPAA and Protected Health Information
Veridose is designed to operate as a Business Associate under HIPAA. We:
- Sign Business Associate Agreements (BAAs) with all covered entity customers
- Apply administrative, physical, and technical safeguards to all PHI
- Limit PHI access to staff with a legitimate need to access it
- Delete voice audio immediately after transcription
- Maintain audit logs of all PHI access and processing events
To request a BAA, email hello@veridose.io.
6. Data Retention
Medication check records and patient interaction data are retained for up to 5 years from the date of the interaction, in accordance with state pharmacy record-keeping requirements and federal guidelines. After 5 years, this data is automatically and permanently deleted from our systems.
HIPAA security audit logs (access and activity logs required under 45 CFR §164.530(j)) are retained for a minimum of 6 years from the date of their creation or last effective date.
Member (Personal Check) accounts and associated health data are retained for up to 5 years from your last activity. Inactive accounts with no activity for 5 years are automatically deleted. You may request earlier deletion at any time (subject to legal retention obligations).
Staff account data is retained for the duration of the pharmacy's subscription and for 1 year afterward.
Voice audio is never retained beyond the active transcription session — recordings are deleted immediately after transcription.
By using Veridose kiosk services or creating a Personal Check account, you consent to the storage of your medication and health data for the periods described above.
7. Security
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to production systems is restricted to authorized Veridose personnel via multi-factor authentication. We conduct periodic security assessments and maintain a vulnerability disclosure program.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access a copy of the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (subject to our retention obligations)
- Withdraw consent where processing is based on consent
- Lodge a complaint with your supervisory authority
To exercise any of these rights, contact us at hello@veridose.io.
9. Cookies
Veridose uses essential session cookies required for authentication and security. We do not use tracking cookies, advertising cookies, or third-party analytics cookies that identify individual users.
10. Children's Privacy
Our platform is intended for use by licensed healthcare professionals. We do not knowingly collect personal information from individuals under the age of 18.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to account administrators by email at least 30 days before taking effect.
12. Contact Us
For questions about this Privacy Policy, data requests, or to report a security concern:
Veridose AI, Inc.
Email: hello@veridose.io
Privacy inquiries: privacy@veridose.io