Privacy Policy

How we handle your data.

TheRxOS is a pharmacy analytics platform. We work with Protected Health Information under HIPAA and only on the terms in our Business Associate Agreement. This page tells you exactly what that means in plain English.

Last updated: 2026-05-09

01What we collect

Once you sign a Business Associate Agreement (BAA) with us, your pharmacy hands us claims data. That includes:

The scope is whatever your BAA says. If your BAA limits us to a subset, that's the subset we get.

02What we do with it

Three things, all on behalf of your pharmacy:

That's it. We don't use your data to train models for sale, build industry benchmarks we sell back to PBMs, or run market research for pharma manufacturers. The BAA forbids most of that anyway, and even where it wouldn't, we won't.

03Who we share it with

No one. We don't sell data. We don't share it with third parties for their purposes. Period.

The only exceptions are:

We're forming as a Public Benefit Corporation specifically so that "we don't sell pharmacy data" can't be quietly changed by a future board.

04Where it lives

05HIPAA compliance

TheRxOS operates as a Business Associate under HIPAA. Concretely that means:

If you want a copy of our security documentation or our subprocessor list, email us. We send it.

06How long we keep it

07Your rights

You can ask us to:

Email Stanley directly. We turn these around in days, not months.

08Changes to this policy

If we change anything material — what we collect, who we share it with, where it lives — we'll email every active customer before the change takes effect, and update the date at the top of this page. We don't quietly broaden things.

09Contact

Privacy questions, breach reports, BAA requests, audit follow-ups — all go to Stanley directly. There is no privacy-team inbox; there is one person, and it's him.

Stanley Warren
Founder & Privacy Officer · TheRxOS
Based Miami, FL