MyPeps Privacy Policy

Effective Date: July 22nd, 2026
Last Updated: July 22nd, 2026

MyPeps LLC (“MyPeps,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the information entrusted to us.

This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you:

  • Visit the MyPeps website;
  • Use a MyPeps mobile application;
  • Create or use a patient account;
  • Purchase a membership or service;
  • Schedule or participate in a telehealth appointment;
  • Upload laboratory results or other documents;
  • Communicate with Providers or support personnel;
  • Use health-tracking, artificial intelligence, or bloodwork-summary features;
  • Connect a wearable device or third-party health application; or
  • Otherwise interact with MyPeps.

Our websites, applications, portals, communication systems, AI features, and related technology and administrative services are collectively referred to as the “Platform.”

The Platform may facilitate access to physicians, nurse practitioners, physician assistants, and other licensed healthcare professionals (“Providers”). Providers may deliver clinical services through one or more affiliated or independently operated professional medical entities (“Clinical Entities”).

This Privacy Policy applies to information collected by or on behalf of MyPeps through the Platform. Certain health information maintained by a Clinical Entity or Provider may instead be governed by the Clinical Entity's Notice of Privacy Practices.

1. Important Information About HIPAA and Medical Records

The Health Insurance Portability and Accountability Act of 1996 and its implementing regulations are collectively referred to as “HIPAA.”

HIPAA does not apply to every organization or every type of information simply because health information is involved. HIPAA generally applies to covered healthcare providers, health plans, healthcare clearinghouses, and their business associates.

Depending on the applicable service and relationship:

  • A Clinical Entity or Provider may be a healthcare provider subject to HIPAA;
  • MyPeps may perform services as a business associate of a Clinical Entity;
  • MyPeps may separately collect information in its own capacity as a technology or administrative-services company; and
  • Certain information may not constitute protected health information under HIPAA but may remain protected under other federal or state privacy laws.

When MyPeps creates, receives, maintains, or transmits protected health information on behalf of a HIPAA-covered Clinical Entity, MyPeps will handle that information as required by HIPAA, the applicable business associate agreement, and other applicable law.

The Clinical Entity's Notice of Privacy Practices explains how the Clinical Entity and its Providers may use and disclose protected health information for treatment, payment, healthcare operations, and other legally permitted purposes.

This Privacy Policy does not replace an applicable Notice of Privacy Practices. Where this Privacy Policy conflicts with a Clinical Entity's Notice of Privacy Practices concerning protected health information, the Notice of Privacy Practices controls.

2. Information We Collect

The information we collect depends on how you use the Platform, which features you activate, which Clinical Services you request, and the legal requirements that apply.

A. Account and Contact Information

We may collect:

  • Full name;
  • Email address;
  • Telephone number;
  • Mailing address;
  • Billing address;
  • Username;
  • Password or other authentication credentials;
  • Account preferences;
  • Customer-support history; and
  • Communications preferences.
  • Health metrics

B. Identity and Eligibility Information

We may collect information needed to verify your identity, age, eligibility, or physical location, including:

  • Date of birth;
  • Age;
  • Photograph;
  • Government-issued identification;
  • State of residence;
  • Current physical location;
  • Electronic signature;
  • Identity-verification results; and
  • Information used to prevent fraud or unauthorized account access.

We will only collect government-issued identification or biometric identity-verification information when reasonably necessary and legally permitted.

C. Health and Medical Information

When you seek Clinical Services or use health-related Platform features, we may collect information such as:

  • Symptoms and health concerns;
  • Medical and surgical history;
  • Diagnoses;
  • Allergies;
  • Current and prior medications;
  • Vitamins, supplements, hormones, and peptides;
  • Treatment plans;
  • Prescription and refill information;
  • Provider notes;
  • Telehealth consultation information;
  • Laboratory orders and results;
  • Uploaded medical records;
  • Height, weight, body measurements, and vital signs;
  • Family medical history;
  • Pregnancy or breastfeeding status;
  • Biological sex and other clinically relevant demographic information;
  • Lifestyle, nutrition, sleep, exercise, or substance-use information;
  • Medication adherence;
  • Reported side effects;
  • Health goals and progress;
  • Messages exchanged with Providers;
  • Pharmacy and fulfillment information; and
  • Other information you choose to provide concerning your health.

Some of this information may be considered sensitive personal information, consumer health data, medical information, or protected health information under applicable law.

D. Laboratory Information

We may collect or receive:

  • Laboratory orders;
  • Test-kit requests;
  • Specimen-collection information;
  • Laboratory reports;
  • Biomarkers and reference ranges;
  • Testing dates;
  • Laboratory location;
  • Order status;
  • Payment status; and
  • Communications involving the laboratory.

We may receive this information directly from you, a Provider, a laboratory, an at-home testing provider, or another authorized source.

E. Prescription and Pharmacy Information

We may collect or receive:

  • Prescription details;
  • Medication name, strength, quantity, and dosage instructions;
  • Prescriber information;
  • Pharmacy selection;
  • Prescription status;
  • Refill requests;
  • Pharmacy communications;
  • Fulfillment and shipment information;
  • Delivery address;
  • Medication-related payments; and
  • Information concerning adverse reactions or medication concerns.

MyPeps does not itself manufacture medication. Prescription and dispensing information may be exchanged with Providers, Clinical Entities, and licensed pharmacies as necessary to facilitate treatment and fulfillment.

F. Payment and Transaction Information

When you purchase a membership, consultation, laboratory service, or other offering, we may collect:

  • Billing name and address;
  • Payment method type;
  • Partial payment-card details;
  • Transaction amount;
  • Purchase date;
  • Subscription status;
  • Invoice and receipt information;
  • Refund or chargeback information; and
  • Transaction identifiers.

Payment-card information is generally collected and processed by third-party payment processors. MyPeps may not directly receive or store your complete payment-card number.

G. Communications and Support Information

We may collect the contents of communications you send through:

  • Secure messaging;
  • Provider messaging;
  • Customer-support chat;
  • Email;
  • Text messaging;
  • Telephone calls;
  • Video appointments;
  • Surveys;
  • Feedback forms; and
  • Social-media communications directed to MyPeps.

Calls or video sessions will not be recorded unless we provide notice and obtain any consent required by law.

Messages exchanged as part of your medical care may become part of your medical record.

H. Documents, Photographs, and Files

We may collect files you upload, including:

  • Laboratory reports;
  • Medical records;
  • Insurance documents;
  • Identification documents;
  • Photographs;
  • Videos;
  • Prescription information;
  • Signed consent forms; and
  • Other documents you choose to submit.

I. Wearable and Connected-Device Information

If you choose to connect a wearable device, health application, or third-party data source, we may collect information authorized by you, such as:

  • Steps and physical activity;
  • Heart rate;
  • Sleep duration and patterns;
  • Calories or energy expenditure;
  • Weight;
  • Workout information;
  • Recovery metrics;
  • Respiratory information;
  • Blood glucose information, when supported;
  • Device identifiers; and
  • Dates and times associated with measurements.

The specific information received depends on the connected service and the permissions you select.

You may disconnect an integration through your account or the applicable third-party service. Disconnecting a service prevents future collection but may not automatically delete information previously received.

J. Information Collected Automatically

When you use the Platform, we and our service providers may automatically collect:

  • Internet Protocol address;
  • Browser type;
  • Device type;
  • Operating system;
  • Application version;
  • Device identifiers;
  • General geographic location;
  • Language and time-zone settings;
  • Referring website;
  • Pages or screens viewed;
  • Links clicked;
  • Date and time of access;
  • Session duration;
  • Platform interactions;
  • Crash reports;
  • Performance information; and
  • Security or fraud-detection information.

We may use cookies, software development kits, pixels, web beacons, log files, local storage, and similar technologies to collect this information.

K. Precise Location Information

Clinical Services may require confirmation of the state or jurisdiction where you are physically located at the time of treatment.

We may request precise location information only when reasonably necessary, such as to verify that a Provider is legally permitted to treat you in your location. We will request device permission when required.

You may disable device-level location access, but doing so may prevent you from receiving Clinical Services.

L. Information From Third Parties

We may receive information from:

  • Clinical Entities;
  • Providers;
  • Laboratories;
  • Pharmacies;
  • At-home testing companies;
  • Payment processors;
  • Identity-verification providers;
  • Scheduling and video-service providers;
  • Wearable-device companies;
  • Health applications you connect;
  • Shipping carriers;
  • Customer-support vendors;
  • Analytics and security providers;
  • Referral or business partners; and
  • Publicly available sources.

The information received may be combined with information we already maintain when legally permitted.

3. How We Use Information

We may use information for the following purposes.

A. Providing the Platform

We use information to:

  • Create and administer accounts;
  • Authenticate users;
  • Maintain account security;
  • Provide patient and Provider portals;
  • Schedule appointments;
  • Enable secure communications;
  • Process transactions;
  • Provide customer support;
  • Display laboratory information;
  • Operate health-tracking features;
  • Maintain subscription benefits; and
  • Provide requested Platform functionality.

B. Facilitating Healthcare Services

We may use information to facilitate Clinical Services, including to:

  • Connect you with a licensed Provider;
  • Confirm your identity and physical location;
  • Provide your information to the treating Provider;
  • Support clinical intake;
  • Facilitate telehealth appointments;
  • Enable Providers to review health information;
  • Facilitate laboratory ordering and review;
  • Transmit prescriptions to pharmacies;
  • Process refill requests;
  • Coordinate follow-up care;
  • Support communications between patients and Providers; and
  • Maintain medical or treatment-related records on behalf of a Clinical Entity.

Providers and Clinical Entities independently determine how to use medical information when making treatment decisions.

C. Laboratory and Pharmacy Coordination

We may use information to:

  • Submit laboratory orders;
  • Process test-kit requests;
  • Coordinate specimen collection;
  • Receive and display laboratory reports;
  • Alert you or your Provider when results are available;
  • Transmit eligible prescriptions;
  • Facilitate medication fulfillment;
  • Track order and shipment status;
  • Respond to pharmacy or laboratory inquiries; and
  • Process applicable payments.

D. Billing and Subscriptions

We may use information to:

  • Charge authorized payment methods;
  • Process recurring membership payments;
  • Provide receipts;
  • Administer cancellations;
  • Process refunds;
  • Detect unauthorized transactions;
  • Resolve billing disputes; and
  • Maintain accounting and financial records.

E. Communications

We may use your contact information to send:

  • Appointment confirmations and reminders;
  • Account notices;
  • Security alerts;
  • Laboratory notifications;
  • Prescription or pharmacy updates;
  • Billing notices;
  • Provider messages;
  • Customer-support responses;
  • Policy updates;
  • Service announcements; and
  • Marketing communications when permitted.

You may opt out of promotional communications, but you may continue to receive necessary transactional, administrative, security, and care-related messages.

F. Safety, Security, and Fraud Prevention

We may use information to:

  • Verify identity;
  • Protect accounts;
  • Detect fraud;
  • Prevent medication diversion or misuse;
  • Monitor suspicious activity;
  • Investigate security events;
  • Protect patients, Providers, and staff;
  • Enforce our agreements;
  • Maintain Platform integrity; and
  • Comply with legal and regulatory obligations.

G. Platform Improvement and Analytics

We may use information to:

  • Diagnose technical problems;
  • Measure Platform performance;
  • Understand how features are used;
  • Improve navigation and accessibility;
  • Develop new features;
  • Conduct quality assurance;
  • Evaluate customer-support performance; and
  • Improve the patient and Provider experience.

Where practical and legally required, we use aggregated or de-identified information for these purposes.

H. Legal and Regulatory Compliance

We may use information to:

  • Comply with laws, regulations, court orders, and legal process;
  • Respond to lawful government requests;
  • Conduct audits;
  • Maintain required records;
  • Investigate complaints;
  • Report suspected fraud or illegal activity;
  • Protect legal rights;
  • Respond to privacy or security incidents; and
  • Meet healthcare, pharmacy, consumer-protection, and data-protection obligations.

4. Artificial Intelligence and Automated Features

MyPeps may provide artificial intelligence or machine-learning features that help users organize, summarize, or understand laboratory information and other health-related information (“AI Features”).

AI Features may include:

  • Plain-language laboratory summaries;
  • Explanations of biomarkers;
  • Identification of trends in uploaded results;
  • Educational questions or prompts;
  • Organization of health information;
  • Suggested questions to discuss with a Provider; and
  • Administrative or customer-support assistance.

AI Features Are Not Independent Medical Providers

AI-generated information is educational and informational unless it has been separately reviewed and adopted by a licensed Provider.

AI Features do not independently:

  • Diagnose medical conditions;
  • Establish a provider-patient relationship;
  • Prescribe medication;
  • Modify a prescription;
  • Replace clinical judgment;
  • Provide emergency services; or
  • Guarantee accurate or complete results.

Users should discuss abnormal results, symptoms, medications, and treatment decisions with a licensed Provider.

Information Processed Through AI Features

Depending on the feature, AI systems may process:

  • Laboratory values;
  • Biomarker names;
  • Reference ranges;
  • User questions;
  • Health goals;
  • Symptoms voluntarily entered by the user;
  • Previous AI interactions; and
  • Other information necessary to generate the requested response.

Before identifiable health information is sent to an external AI vendor, MyPeps will provide any notice, consent, or authorization required by applicable law.

Where reasonably possible, MyPeps may limit or remove direct identifiers before transmitting information to an AI service provider.

AI Service Providers

MyPeps may use qualified third-party vendors to support AI Features. Those vendors may process information only as permitted by their agreements with MyPeps and applicable law.

Where a vendor creates, receives, maintains, or transmits protected health information on behalf of a covered entity, MyPeps or the applicable Clinical Entity will require an appropriate business associate agreement when legally required.

Training and Product Improvement

MyPeps will not permit an external vendor to use identifiable protected health information to train a generalized public AI model unless such use is legally permitted and supported by any required authorization.

MyPeps may use:

  • De-identified information;
  • Aggregated information;
  • Synthetic information;
  • User feedback; and
  • Non-identifying usage information

to evaluate, test, secure, and improve AI Features, as permitted by law.

5. De-Identified and Aggregated Information

We may create information that has been aggregated or de-identified so that it does not reasonably identify an individual.

We may use de-identified or aggregated information to:

  • Improve the Platform;
  • Analyze general health and usage trends;
  • Develop educational resources;
  • Improve AI systems and algorithms;
  • Conduct research;
  • Measure business performance;
  • Improve security; and
  • Develop new products or services.

When information is de-identified under applicable law, we will not attempt to re-identify it except as legally permitted for testing whether the de-identification process is effective.

We may disclose de-identified or aggregated information to service providers, research collaborators, business partners, and other parties when permitted by law.

6. How We Disclose Information

We may disclose information as described below.

A. Clinical Entities and Providers

We may disclose information to Clinical Entities, Providers, and authorized clinical support personnel to facilitate:

  • Medical evaluation;
  • Treatment;
  • Prescribing;
  • Laboratory review;
  • Follow-up care;
  • Healthcare operations;
  • Medical-record maintenance; and
  • Other requested Clinical Services.

Clinical Entities and Providers may use and disclose protected health information as described in their Notice of Privacy Practices.

B. Laboratories and Testing Providers

We may disclose information to laboratories and testing providers to:

  • Order tests;
  • Confirm identity;
  • Coordinate specimen collection;
  • Process payment;
  • Perform testing;
  • Deliver test kits;
  • Return results; and
  • Resolve support issues.

C. Pharmacies

We may disclose information to pharmacies to:

  • Transmit prescriptions;
  • Verify patient and prescriber information;
  • Determine medication availability;
  • Facilitate payment;
  • Dispense medication;
  • Arrange shipment;
  • Process refills; and
  • Address medication or fulfillment concerns.

D. Service Providers

We may disclose information to vendors performing services for us, including:

  • Cloud hosting;
  • Data storage;
  • Cybersecurity;
  • Identity verification;
  • Payment processing;
  • Telehealth video;
  • Scheduling;
  • Secure messaging;
  • Email and text delivery;
  • Customer support;
  • Analytics;
  • AI processing;
  • Laboratory integrations;
  • Pharmacy integrations;
  • Wearable-device integrations;
  • Accounting;
  • Legal compliance; and
  • Business operations.

Service providers are permitted to process information only for authorized purposes and are subject to contractual or legal obligations appropriate to the information involved.

E. Connected Applications and Devices

When you direct us to connect the Platform to another service, we may disclose information to or receive information from that service according to your instructions and permissions.

Information held by the third party is governed by that party's privacy policy. Review the third party's policies before enabling an integration.

F. Affiliates and Corporate Entities

We may disclose information among MyPeps affiliates and related entities when reasonably necessary to operate the Platform, provide Services, maintain security, or support business administration.

Access will be limited according to legal requirements and business need.

G. Business Transactions

Information may be disclosed as part of an actual or proposed:

  • Merger;
  • Acquisition;
  • Financing;
  • Investment;
  • Reorganization;
  • Bankruptcy;
  • Sale of assets; or
  • Transfer of all or part of the business.

Any recipient will be required to handle information consistently with applicable law. We will provide additional notice when legally required.

H. Legal Requirements

We may disclose information when we reasonably believe disclosure is necessary to:

  • Comply with a law, regulation, subpoena, warrant, court order, or legal process;
  • Respond to a lawful request from a regulator or government agency;
  • Investigate suspected fraud or illegal activity;
  • Protect the rights or safety of MyPeps, users, Providers, or others;
  • Prevent serious harm;
  • Enforce contracts and policies; or
  • Establish, exercise, or defend legal claims.

I. With Your Direction or Consent

We may disclose information when you direct us to do so or provide legally valid consent or authorization.

Examples include sending records to another healthcare provider, connecting a wearable service, or transmitting a prescription to your chosen pharmacy.

7. Our Approach to Advertising and Health Information

MyPeps does not sell protected health information.

MyPeps does not disclose protected health information to advertising platforms for their independent advertising purposes unless the disclosure is expressly authorized by the individual and otherwise permitted by law.

We do not intend to use information from:

  • Medical intake forms;
  • Provider communications;
  • Laboratory reports;
  • Prescriptions;
  • Medical records;
  • AI bloodwork summaries; or
  • Authenticated patient-portal activity

to target third-party advertising.

MyPeps may advertise its services using limited information collected from public, unauthenticated portions of its website, such as cookie identifiers, device information, general geographic area, and interaction with general marketing pages, subject to applicable law and available privacy choices.

We will not intentionally place third-party advertising trackers within authenticated treatment, messaging, laboratory, prescription, or medical-record areas of the Platform.

Some disclosures involving analytics or advertising cookies may be legally considered a “sale,” “sharing,” or use for targeted advertising under certain state privacy laws even when no money is exchanged. Where applicable, MyPeps will provide a “Your Privacy Choices” or “Do Not Sell or Share My Personal Information” mechanism.

8. Cookies and Similar Technologies

We and authorized vendors may use cookies, pixels, web beacons, local storage, mobile identifiers, software development kits, and similar technologies.

Types of Technologies We May Use

Essential technologies help provide core features, security, authentication, fraud prevention, and account functionality.

Preference technologies remember settings, language, and user choices.

Analytics technologies help us measure Platform performance and understand general usage.

Advertising technologies, when used on public marketing pages, help measure campaigns and present relevant advertisements.

Cookie Choices

You may be able to manage cookies through:

  • A MyPeps cookie-preference center;
  • Your browser settings;
  • Mobile operating-system settings;
  • Advertising-industry opt-out tools; and
  • Global Privacy Control signals.

Disabling essential cookies may prevent portions of the Platform from functioning.

Global Privacy Control

Where required by law, we will treat a recognized Global Privacy Control signal as a request to opt out of the sale or sharing of personal information or targeted advertising for the browser or device sending the signal.

Do Not Track

Because there is no consistent industry standard for interpreting traditional browser “Do Not Track” signals, the Platform may not respond to those signals. We will respond to legally recognized opt-out preference signals such as Global Privacy Control where required.

9. Marketing Communications

MyPeps may use your email address or telephone number to send marketing communications when permitted by law.

You may opt out of:

  • Promotional email by using the unsubscribe link;
  • Promotional text messages by replying STOP; or
  • Other marketing by contacting us.

Opting out of marketing does not stop:

  • Appointment reminders;
  • Provider messages;
  • Laboratory notices;
  • Prescription updates;
  • Billing messages;
  • Security notices;
  • Policy updates; or
  • Other necessary service communications.

We will not use protected health information for marketing when HIPAA requires authorization unless we first obtain a valid authorization.

10. Security

MyPeps uses reasonable administrative, physical, and technical safeguards designed to protect information against unauthorized access, alteration, loss, misuse, or disclosure.

Safeguards may include:

  • Encryption during transmission;
  • Encryption at rest where appropriate;
  • Access controls;
  • Multi-factor authentication;
  • Password protections;
  • Workforce training;
  • Audit logging;
  • Vendor review;
  • Risk assessments;
  • Security monitoring;
  • Backup procedures;
  • Incident-response planning; and
  • Policies governing access to health information.

No internet transmission, electronic storage system, or security program can be guaranteed to be completely secure. You should protect your password, devices, email account, and authentication information.

Notify us promptly if you believe your account or information has been compromised.

11. Data Breach Notification

MyPeps maintains procedures to assess and respond to suspected privacy and security incidents.

When required by applicable law, MyPeps will notify affected individuals, Clinical Entities, regulators, law enforcement agencies, consumer-protection authorities, or other parties following a qualifying breach.

Depending on the information and entities involved, notification requirements may arise under HIPAA, the Federal Trade Commission Health Breach Notification Rule, state medical-information laws, state data-breach laws, or other applicable requirements.

12. Data Retention

We retain personal information only for as long as reasonably necessary to:

  • Provide the Platform and requested Services;
  • Maintain your account;
  • Support Clinical Services;
  • Complete transactions;
  • Meet legal and regulatory obligations;
  • Maintain medical and business records;
  • Resolve disputes;
  • Prevent fraud;
  • Enforce agreements;
  • Protect safety and security; and
  • Exercise or defend legal claims.

Retention periods vary according to the type of information and applicable law.

Medical records may be retained by Clinical Entities or Providers for periods required by state medical-record laws and professional obligations.

Laboratories, pharmacies, payment processors, and other independent third parties maintain information according to their own legal obligations and retention policies.

When information is no longer reasonably required, we may delete it, de-identify it, or securely isolate it from further use, subject to legal requirements.

13. Your Privacy Rights and Choices

Depending on where you live and which laws apply, you may have the right to:

  • Confirm whether we process your personal information;
  • Request access to personal information;
  • Request a portable copy of certain information;
  • Request correction of inaccurate information;
  • Request deletion of certain information;
  • Opt out of the sale or sharing of personal information;
  • Opt out of targeted advertising;
  • Limit certain uses of sensitive personal information;
  • Withdraw consent where processing depends on consent;
  • Appeal the denial of a privacy request; and
  • Not receive discriminatory treatment for exercising a privacy right.

These rights are subject to exceptions. For example, we may retain information necessary to provide requested Services, comply with healthcare recordkeeping requirements, complete transactions, detect fraud, protect security, or establish legal claims.

Rights involving protected health information maintained by a Clinical Entity should be submitted according to the applicable Notice of Privacy Practices.

Submitting a Privacy Request

You may submit a request through:

Contact Us Page (working on structure) or contact@mypeps.com

We may need to verify your identity before processing a request. Verification may require confirmation through the email address associated with your account or provision of additional identifying information.

We will only request information reasonably necessary to verify the request.

Authorized Agents

Where permitted by law, you may designate an authorized agent to submit a request. We may require proof of the agent's authority and may ask you to confirm your identity directly.

Appeals

When applicable law provides an appeal right, you may appeal our denial by contacting us at contact@mypeps.com and writing “Privacy Request Appeal” in the subject line.

14. California Privacy Notice

This section applies to California residents to the extent MyPeps is subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”).

Categories of Personal Information

Depending on your interactions with MyPeps, we may collect the following statutory categories:

  1. Identifiers, such as name, email address, postal address, IP address, telephone number, account identifier, and government-issued identification.
  2. Customer-record information, such as contact, billing, payment, and service information.
  3. Characteristics protected under California or federal law, such as age, sex, disability information, or other demographic information when voluntarily provided or clinically relevant.
  4. Commercial information, such as purchases, memberships, subscriptions, transaction history, and service preferences.
  5. Internet or electronic-network activity, such as browsing, device, cookie, session, and Platform-interaction information.
  6. Geolocation information, such as general location and, when necessary and authorized, precise location used to confirm eligibility for Clinical Services.
  7. Audio, visual, or similar information, such as photographs, uploaded files, customer-support recordings where notice and consent are provided, and telehealth video transmissions.
  8. Professional information, when relevant to account use or voluntarily provided.
  9. Inferences, such as preferences or likely interests inferred from Platform interactions.
  10. Sensitive personal information, such as account credentials, precise geolocation, government identifiers, health information, medical information, sexual-health information, and certain demographic information.

Sources

We collect information from:

  • You;
  • Your device or browser;
  • Providers and Clinical Entities;
  • Laboratories;
  • Pharmacies;
  • Payment processors;
  • Connected devices or applications;
  • Service providers;
  • Business partners; and
  • Publicly available sources.

Business Purposes

We use these categories for the purposes described in this Privacy Policy, including:

  • Providing Services;
  • Facilitating healthcare;
  • Processing payments;
  • Operating subscriptions;
  • Communicating with users;
  • Maintaining security;
  • Preventing fraud;
  • Improving the Platform;
  • Complying with law; and
  • Conducting internal analytics.

Disclosure Categories

We may disclose these categories to:

  • Providers and Clinical Entities;
  • Laboratories;
  • Pharmacies;
  • Technology and service providers;
  • Payment processors;
  • Connected-device providers;
  • Professional advisers;
  • Government authorities;
  • Corporate-transaction participants; and
  • Other parties at your direction.

Sale and Sharing

MyPeps does not sell protected health information.

MyPeps does not knowingly sell personal information in exchange for money.

Certain advertising or analytics activities on public marketing pages could be considered “sharing” or a “sale” under the broad definitions of California law. California residents may opt out through:

  • The “Your Privacy Choices” link;
  • The “Do Not Sell or Share My Personal Information” link; or
  • A recognized Global Privacy Control signal.

MyPeps does not knowingly sell or share the personal information of individuals under sixteen years old.

Sensitive Personal Information

MyPeps uses sensitive personal information primarily to provide requested healthcare, Platform, security, identity-verification, payment, and legal-compliance functions.

Where MyPeps uses sensitive personal information for purposes that create a right to limit under California law, we will provide a method to exercise that right.

California Rights

Subject to applicable exceptions, California residents may request:

  • The categories of personal information collected;
  • The categories of sources;
  • The purposes for collection, use, sale, or sharing;
  • The categories of recipients;
  • Specific pieces of personal information;
  • Correction;
  • Deletion;
  • Portability;
  • Opt-out of sale or sharing;
  • Limitation of certain uses of sensitive information; and
  • Non-discriminatory treatment.

15. Other State Consumer-Health and Privacy Rights

Residents of certain states may have additional rights concerning consumer health information or personal data.

Applicable state law may provide rights to:

  • Confirm collection of consumer health information;
  • Access consumer health information;
  • Obtain a list of recipients;
  • Delete consumer health information;
  • Withdraw consent;
  • Prevent the sale of consumer health information;
  • Appeal a denied request; and
  • Provide separate authorization before certain disclosures.

MyPeps will process qualifying requests as required by the law applicable to the requesting individual.

When required, MyPeps may publish a supplemental Consumer Health Data Privacy Notice explaining practices under specific state health-data laws.

16. Children's Privacy

The Platform and Clinical Services are not directed to individuals under eighteen years old unless MyPeps expressly offers a legally compliant service for minors.

MyPeps does not knowingly allow a person under eighteen to create an independent patient account.

We do not knowingly collect personal information through the general Platform from a child under thirteen without legally valid parental consent.

Contact us if you believe a child has provided information without appropriate authorization. We will investigate and take appropriate action.

17. Third-Party Websites and Services

The Platform may contain links to or integrations with services operated by third parties.

This Privacy Policy does not govern information independently collected or controlled by:

  • Pharmacies;
  • Laboratories;
  • Payment processors;
  • Wearable-device companies;
  • Social-media platforms;
  • Shipping carriers;
  • External websites; or
  • Other unaffiliated services.

Review the applicable third party's privacy policy before providing information or enabling an integration.

MyPeps is not responsible for an independent third party's privacy or security practices.

18. Users Outside the United States

The Platform is intended for users in eligible jurisdictions within the United States unless MyPeps expressly states otherwise.

Information collected through the Platform is processed and stored in the United States.

Users outside the United States should understand that U.S. privacy laws may differ from the laws of their home jurisdiction. Accessing Clinical Services from an unauthorized jurisdiction is prohibited.

19. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • Changes to the Platform;
  • New services or integrations;
  • Changes to our information practices;
  • New legal requirements; or
  • Operational and security developments.

We will post the revised version and update the “Last Updated” date.

When legally required, we will provide additional notice or request consent before materially different practices apply to previously collected information.

20. Contact Us

Questions, concerns, or complaints about this Privacy Policy may be directed to:

MyPeps LLC
Attn: Privacy
California, 91302
Support Email: Contact@mypeps.com

For questions involving a medical record or a Clinical Entity's HIPAA practices, contact the privacy official identified in the applicable Notice of Privacy Practices.

21. Required Operational Disclosures Before Publication

The following items must be completed and verified before this Privacy Policy is published:

  • The full legal address of MyPeps LLC;
  • The applicable Clinical Entity or Entities;
  • MyPeps' exact HIPAA role;
  • The Clinical Entity's Notice of Privacy Practices;
  • The identity-verification vendor;
  • The telehealth and video vendor;
  • The secure-messaging vendor;
  • The payment processor;
  • The laboratories and at-home collection providers;
  • The pharmacies and medication-fulfillment model;
  • The AI model providers and exact information transmitted;
  • Whether AI vendors retain prompts or outputs;
  • Whether information may be used for AI training;
  • The wearable integrations offered;
  • The analytics and advertising technologies installed;
  • Whether advertising pixels appear on health-related pages;
  • Whether MyPeps sells or shares information under state-law definitions;
  • Data-retention periods;
  • Applicable state consumer-health-data laws;
  • The privacy-request submission process;
  • The cookie-consent and Global Privacy Control process;
  • The security-incident notification process; and
  • The contact information for MyPeps' privacy official.