Privacy Policy

Privacy Policy

Effective Date: January 1, 2025  ·  Last Updated: August 2026

Veridose AI is designed for HIPAA-covered entities. We treat all pharmacy and patient data as protected health information (PHI) and apply the highest standard of care to its handling.

1. Who We Are

Veridose AI, Inc. ("Veridose," "we," "our," or "us") operates a clinical decision support platform for licensed pharmacies. We provide AI-assisted medication interaction checks, staff management tools, and patient safety workflows accessible at veridose.app.

2. Information We Collect

Pharmacy Account Information: When you create an account, we collect your pharmacy name, business address, lead pharmacist name, NPI or license number, and billing contact email.

Staff Information: Pharmacy administrators may add staff members. We collect staff names, license IDs, roles, and optionally email addresses for PIN delivery.

Patient & Clinical Data: Medication names, dosages, interaction check inputs, and check results are processed to provide the service. This data constitutes Protected Health Information (PHI) under HIPAA.

Voice Input: When using the voice transcription feature, audio is transmitted directly to our speech-to-text processor. Audio recordings are deleted immediately after transcription and are never stored on Veridose servers.

Usage Data: We collect logs of feature usage (e.g., number of checks run, session duration) for product improvement. These logs do not contain PHI.

Technical Data: IP addresses, browser type, and device identifiers are collected for security and fraud prevention purposes.

3. How We Use Your Information

We do not sell, rent, or trade your data to any third party. We do not use patient data for advertising purposes.

4. Data Sharing

Service Providers: We share data with third-party sub-processors strictly necessary to deliver the platform, including cloud infrastructure (Supabase / AWS), AI processing (OpenAI), email delivery (Resend), and transcription services. All sub-processors are contractually bound to appropriate data protection obligations.

Legal Requirements: We may disclose information if required by law, court order, or to protect the safety of individuals or the public.

Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, which will be bound by this policy.

5. HIPAA and Protected Health Information

Veridose is designed to operate as a Business Associate under HIPAA. We:

To request a BAA, email hello@veridose.io.

6. Data Retention

Medication check records and patient interaction data are retained for up to 5 years from the date of the interaction, in accordance with state pharmacy record-keeping requirements and federal guidelines. After 5 years, this data is automatically and permanently deleted from our systems.

HIPAA security audit logs (access and activity logs required under 45 CFR §164.530(j)) are retained for a minimum of 6 years from the date of their creation or last effective date.

Member (Personal Check) accounts and associated health data are retained for up to 5 years from your last activity. Inactive accounts with no activity for 5 years are automatically deleted. You may request earlier deletion at any time (subject to legal retention obligations).

Staff account data is retained for the duration of the pharmacy's subscription and for 1 year afterward.

Voice audio is never retained beyond the active transcription session — recordings are deleted immediately after transcription.

By using Veridose kiosk services or creating a Personal Check account, you consent to the storage of your medication and health data for the periods described above.

7. Security

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to production systems is restricted to authorized Veridose personnel via multi-factor authentication. We conduct periodic security assessments and maintain a vulnerability disclosure program.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

To exercise any of these rights, contact us at hello@veridose.io.

9. Cookies

Veridose uses essential session cookies required for authentication and security. We do not use tracking cookies, advertising cookies, or third-party analytics cookies that identify individual users.

10. Children's Privacy

Our platform is intended for use by licensed healthcare professionals. We do not knowingly collect personal information from individuals under the age of 18.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to account administrators by email at least 30 days before taking effect.

12. Contact Us

For questions about this Privacy Policy, data requests, or to report a security concern:

Veridose AI, Inc.
Email: hello@veridose.io
Privacy inquiries: privacy@veridose.io