Legal

Privacy Policy

Last updated 2026-09-04

Pending legal review

This Privacy Policy is a factual description of how USPeptideRx's systems currently work, written for transparency. It has not yet been reviewed by counsel and should not be relied on as a complete or final Privacy Policy. Questions in the meantime: admin@uspeptiderx.com.

Who this covers

This policy describes how USPeptideRx handles information submitted through this site and platform: applications from physicians, clinics, pharmacies and business partners, and the patient information a prescriber enters when placing an order.

Information we collect

  • Applications. Practice or company name, contact name, email, phone, state, and — for a prescriber application — an NPI number.
  • Patient information. When a prescriber places an order, the platform stores what that order requires to be filled: the patient's name, date of birth, contact details, address, and the clinical and prescription information tied to the order.

How patient information is stored and who can see it

Patient records are stored in the platform's own database. For a prescriber and for the staff they delegate to, database-level access control — not just application logic — decides who can read a given record, so a mistake in a screen cannot widen it.

  • A prescriber can see only the patients saved under their own account. Health data connected from an app or device is scoped to their clinic rather than to them individually, so a prescriber sharing a clinic can see it too.
  • A delegated staff member (someone a prescriber has explicitly given access to help prepare orders) can see that prescriber's patients — all of them, not only the records that staff member entered — and no other prescriber's. That permission is checked again on every request, so revoking it takes effect immediately, not on some later sync.

Two limits work differently, and we would rather say so than let the paragraph above imply more than it should. Our own administrators are not restricted by the database from reading a patient record: their access is limited by the application, is used only to operate and support the service, and viewing a chart writes an audit entry. The rule that a patient must have granted their care team access before a prescriber can view their connected health data is likewise enforced by the application rather than by the database.

Who we share information with

  • The dispensing pharmacy. Order data is transmitted to a licensed 503A dispensing pharmacy so the prescription can be compounded or dispensed and fulfilled. USPeptideRx does not itself compound or dispense.
  • Email delivery. Account and order-related emails are sent through a third-party email delivery provider.

Access logging

Access to patient records is logged.

What this policy does not yet cover

In the interest of only saying what is true: this page does not state a data retention period, a formal deletion or erasure process beyond what is described above, a compliance certification of any kind (HIPAA, SOC 2, or otherwise), or a governing jurisdiction. None of those has been decided or committed to yet. They will be added once this page has been reviewed by counsel.

Questions

Email admin@uspeptiderx.com.