Legal informationPrivacy Policy

Privacy Policy

The short answer

Effective August 12, 2026. Pharma Fix LLC operates PharmaFix. Authorized reports are transmitted to the hosted analyzer for transient processing, while limited credit, payment-reference, restore, session, contact, and technical metadata may be retained to operate the service.

Who operates PharmaFix

PharmaFix is operated by Pharma Fix LLC, 166 Industrial Loop Bay 3, Staten Island, NY 10309. Privacy and support questions may be sent to info@pharmafix.ai.

Scope

This Policy applies to the PharmaFix website, analyzer, credit purchase and restoration features, and contact or lead forms operated through this site. It does not govern third-party providers' independent services and notices.

Report data you submit

  • Supported report fields may include fill date, BIN, group, NDC, and amount paid.
  • The report is transmitted over HTTPS to the hosted analyzer and processed transiently to return the requested result.
  • The app is designed not to persist the raw report, claim rows, report NDCs and amounts, generated PDF or CSV, or analysis result in its application database or saved-report history.
  • Do not upload patient names, member IDs, prescription numbers, full dates of birth, addresses, Social Security numbers, or other direct patient identifiers.
  • A patient-name header check can reject some files, but no automated check can prove that a report is de-identified, HIPAA compliant, or free of all sensitive information.

Other information we process

  • Purchase email, credit balance, credit-ledger entries, payment-event and checkout references, and transaction status.
  • Restore-request email and hashed, single-use restore-token metadata. Restore links currently expire after 30 minutes.
  • An essential signed browser-session cookie used to reconnect the browser to credit access. The current cookie lifetime is up to 180 days unless it is cleared sooner.
  • Theme preference stored locally in the browser.
  • Name, pharmacy name, email address, and message or context voluntarily submitted through a contact or lead form.
  • For a submitted website lead, business-contact providers may receive name, email, website-lead source, disclosure version, and lifecycle timestamps. Pharmacy name is retained in the contact system used by PharmaFix and is not included in the separate follow-up contact record.
  • Technical request information that hosting and security systems may process, such as IP address, user agent, timestamps, route, response status, and diagnostic logs. The app is designed not to log report rows or detected patient names.

Why we process this information

  • Provide the requested analysis and browser-generated exports.
  • Process checkout, grant and consume credits, prevent duplicate grants, and maintain the credit ledger.
  • Send a requested one-time credit-restore link and respond to support requests.
  • Record and manage a requested pre-launch or contact-form follow-up without automatically enrolling the person in messages or workflows.
  • Maintain availability, diagnose errors, prevent abuse, and comply with applicable legal obligations.

Service providers

Current product data flow

Provider categoryRoleReport data
Hosting and security providersHost the website and analysis endpointReceive the uploaded request for transient processing and may process technical infrastructure logs
Payment processorCheckout and payment processingDoes not receive the uploaded report; processes payment, email, amount, and payment references
Database and account providersCredit source of truth, ledger, restore-token metadata, and submitted contact metadataThe app is designed not to store report rows or analysis results there
Email-delivery providerTransactional credit-restore emailDoes not receive uploaded report rows or generated results
Business-contact providersProcess contact information voluntarily submitted through website formsDo not receive report data, payment data, credit balances, authentication data, or restore links

Retention and deletion

Uploaded report content is intended to exist only for the analysis request and is not intentionally retained by the app after the response. Restore tokens expire after 30 minutes, although security and audit metadata may remain for a limited period. Credit-account and ledger records may be retained while credits remain available and as reasonably necessary for payment records, dispute handling, fraud prevention, and legal obligations. Final fixed retention schedules require operator and counsel approval before paid launch.

Your choices and requests

You may clear the essential session cookie or local theme setting in your browser, but clearing the session cookie can disconnect local credit access until you use restore by email. Requests to access, correct, or delete retained personal information may be sent to info@pharmafix.ai and will be handled subject to identity verification and legal recordkeeping requirements.

HIPAA and sensitive report information

PharmaFix does not represent that removing patient names alone makes a report de-identified or HIPAA compliant. Whether HIPAA, a business associate agreement, state law, or other requirements apply depends on the parties, data, contracts, and use. Upload only information you are authorized to use and obtain qualified legal and compliance advice when required.

Changes

Material changes will be posted here with a revised review or effective date. If the product begins storing report history, adds analytics, changes providers, or enables live payments, this Policy must be updated before that change is released.

Related reading