Effective August 7, 2026
Privacy Policy
This policy explains what RxHero collects on its own website and apps, why, how we share it, and the choices you have. It is written to be read.
Looking for how we comply with privacy and health-information law?
See Section 9 — How we comply with privacy and health-information laws, and Section 10 — HIPAA and the Notice of Privacy Practices. Washington and Nevada residents: see our separate Consumer Health Data Privacy Policy.
1. The short version
RxHero (“RxHero,” “we,” “us,” or “our”) is a brand operated by BLOOM PROCESSING LLC. Our marketing website does not ask you medical questions. Before we connect you with care, we collect only your email, the state you live in, your age confirmation, and the general answers you give in our pre-visit questions. Your medical history and other health information are collected and stored by our telehealth platform partner on systems covered by the Health Insurance Portability and Accountability Act (“HIPAA”) — not by us. We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not currently run any third-party advertising or analytics trackers on this website.
2. Who we are and how to reach us
BLOOM PROCESSING LLC is the controller of the personal information described in this policy.
BLOOM PROCESSING LLC
30 N Gould St, STE #53088, Sheridan, WY 82801, USA
+1 (307) 218-4388 · support@rxhero.com
Support hours: 24 hours a day, 7 days a week
Privacy requests and questions: privacy@rxhero.com. This mailbox is monitored for rights requests, appeals, and questions about this policy.
3. Scope of this policy
This policy applies to information we collect through our websites, apps, and communications with you (the “Services”). It does not apply to the protected health information collected during your medical intake, which is handled by Remedora and the clinicians and pharmacies in the network under their own privacy practices, their HIPAA Notice of Privacy Practices, and our Telehealth Consent. Section 10 explains that boundary in detail.
4. Information we collect
Information you provide
- Pre-visit details:your email address, the state you live in, your confirmation that you are 18 or older, the treatment area you’re interested in, and the general (non-clinical) answers in our pre-visit questions.
- Account and contact information: name and contact details you provide, and messages you send us about orders, billing, or support.
- Payment information: processed by our third-party payment processors. We do not store full card numbers on our systems.
Information collected automatically
- Device and usage data: IP address, browser and device type, pages viewed, referring pages, and similar log data.
- Cookies and similar technologies: as described in Section 7. We currently set only cookies that are strictly necessary to operate the site.
Sources
We collect this information directly from you, automatically from your device when you use the Services, and from our service providers (for example, a payment processor confirming that a payment succeeded).
5. Information we deliberately do NOT collect
We do not collect your medical history, current medications, symptoms, diagnoses, lab results, photographs, or identity documents on our own website. Those are collected during the medical intake on Remedora’s HIPAA-covered platform. We do not store health answers from the intake in your browser (no cookies, localStorage, or session storage) or on our infrastructure. We also never put a health condition in a page URL, because URLs are disclosed to third parties through the referrer header.
6. How we use information
- To determine whether we can serve your state and set up your visit.
- To communicate with you about your requests, orders, and support.
- To process payments and prevent fraud.
- To operate, secure, maintain, and improve the Services.
- To measure the performance of our marketing, in a de-identified way.
- To comply with legal obligations and enforce our terms.
We do not use your information to make decisions that produce legal or similarly significant effects about you without human involvement, and we do not profile you for targeted advertising.
7. Cookies, analytics, and advertising
As of the effective date above, we do not run any third-party analytics, advertising, session-replay, or heatmap technology on this website. The only cookies we set are strictly necessary to operate the site.
If we introduce non-essential cookies or third-party tags in the future, we will do so under the following rules, which are binding on us:
- They will run only in the pre-visit (non-health) area of our site, never on any page that collects health information.
- We will present a consent banner that declines non-essential technologies by default, and we will honor recognized opt-out preference signals, including Global Privacy Control.
- Any conversion measurement that occurs after the medical intake begins will be server-to-server and de-identified. We will not attach health details, condition names, or intake answers to advertising identifiers.
8. How we share information
- Telehealth platform: Remedora Inc. (Remedora), which operates our patient intake, clinical record-keeping, e-prescribing, and pharmacy routing under a business associate agreement.
- Clinical partner and providers: our telehealth provider network, LocumTele, and the clinicians it supplies, to provide care if you proceed.
- Pharmacy: Rush Pharmacy, our licensed pharmacy partner, to prepare and ship any prescribed medication.
- Service providers: vendors that perform services on our behalf under contract (for example, hosting, email, and payment processing), limited by contract to using the information only to perform those services for us.
- Legal, safety, and business transfers: when required by law, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets.
We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not disclose it to data brokers. We have not done so in the preceding 12 months.
9. How we comply with privacy and health-information laws
This section describes the legal framework that governs our operations and the specific measures we use to meet it. It applies across every jurisdiction we serve (47 states — all except California, South Carolina, and New Jersey).
The laws that apply to us
- HIPAA and the HITECH Act (45 C.F.R. Parts 160, 162, and 164), including the Privacy, Security, and Breach Notification Rules — applied through the covered entities and business associates in our care delivery chain, as described in Section 10.
- Section 5 of the FTC Act, which prohibits unfair or deceptive practices, including making privacy representations we do not honor.
- The FTC Health Breach Notification Rule (16 C.F.R. Part 318), which reaches identifiable health information held by companies that are not covered by HIPAA.
- State comprehensive privacy laws in the states we serve, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Indiana, Tennessee, Kentucky, Nebraska, New Hampshire, Maryland, Minnesota, and Rhode Island. These laws treat information about health status as sensitive data requiring opt-in consent.
- State consumer health data laws, specifically the Washington My Health My Data Act and Nevada SB 370. Our separate Consumer Health Data Privacy Policy contains the disclosures those statutes require.
- State medical-record confidentiality, telehealth, and corporate-practice-of-medicine laws in each state where a clinician treats a patient.
- Communications laws, including the Telephone Consumer Protection Act and CAN-SPAM. We send marketing email and SMS only to people who opted in, and every message carries a working opt-out.
How we operationalize compliance
- Architectural separation. Our most important control is structural: our marketing website never collects protected health information. Medical intake happens on Remedora’s HIPAA-covered platform. PHI is not proxied through, logged by, or stored on our infrastructure.
- Business associate agreements. We maintain a BAA with Remedora Inc., and the covered entities in the care chain maintain the agreements HIPAA requires with their own downstream vendors, before any protected health information is exchanged.
- Written vendor contracts. Every service provider that touches personal information for us is bound by contract to use it only to perform services for us, to protect it, and not to sell it or use it for their own purposes.
- Data minimization. We deliberately keep the amount of personal information on our own systems small, and we do not collect health information we do not need.
- Tracking-technology review. No third-party script — analytics, chat, session replay, heatmap, or A/B tool — is added to the site without first confirming which zone it loads in. Scripts are prohibited on any page that collects health information.
- Safeguards. We use administrative, technical, and physical safeguards including encryption in transit, access controls on a least-privilege basis, and logging.
- Workforce training. Personnel with access to personal information receive privacy and security training appropriate to their role, and access is revoked when it is no longer needed.
- Breach notification. If identifiable health information we hold were breached, we would notify affected individuals, the Federal Trade Commission, and — where applicable — the Department of Health and Human Services and state regulators, within the deadlines those rules set. Our platform partner carries the parallel obligation for information held on its HIPAA-covered systems.
- Rights request handling. Requests to privacy@rxhero.com are logged, verified, and answered within the statutory deadline of the requester’s state, with an appeal path as described in Section 13.
- Periodic review. We review this policy and our practices when we change what we collect, add a vendor or tracking technology, enter a new state, or when applicable law changes.
10. HIPAA and the Notice of Privacy Practices
HIPAA assigns duties by role, so it matters which entity does what:
- The covered entity is the provider organization whose licensed clinician evaluates you and, if appropriate, prescribes. The dispensing pharmacy, Rush Pharmacy, is also a covered entity. These are the parties that hold your medical record.
- The platform, Remedora Inc., operates the intake and clinical systems as a business associate under a BAA.
- RxHero (BLOOM PROCESSING LLC) is a marketing and technology brand. We are not a pharmacy, not a medical practice, and we do not hold your medical record.
Your Notice of Privacy Practices — the document describing how your protected health information may be used and disclosed and what rights you have over it — is issued by the treating provider organization, not by RxHero. It is presented to you during the medical intake, before any health information is collected, and you may request a copy at any time from the provider organization or by contacting us at privacy@rxhero.com and we will direct your request to the right entity.
Because RxHero’s own website does not collect protected health information, the information you give us before intake is governed by this policy and by the FTC and state laws described in Section 9 rather than by HIPAA. We treat it as sensitive regardless.
11. Data retention
We keep pre-visit information only as long as needed for the purposes described here or as required by law, then delete or de-identify it. In practice:
- Pre-visit details (email, state, age confirmation, treatment interest): up to 24 months from your last interaction with us, unless you ask us to delete them sooner.
- Support correspondence: up to 24 months after the matter is resolved.
- Transaction and billing records: as long as tax, accounting, and anti-fraud obligations require, typically seven years.
- Server and security logs: typically 90 days.
- Medical records: held by the treating provider organization and pharmacy, not by us, and retained under the record-retention law of the applicable state.
12. Security
We use administrative, technical, and physical safeguards appropriate to the information we hold, including encryption in transit, least-privilege access controls, and logging — and we intentionally keep the amount of personal information on our systems small. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Your privacy rights
Depending on where you live, you may have the right to confirm whether we process your personal information and access it; to correct inaccuracies; to delete it; to obtain a portable copy; to opt out of targeted advertising, sale, or profiling with legal effects; and to withdraw consent to processing of sensitive data. Because we do not sell personal information, share it for cross-context behavioral advertising, or profile users, the opt-out rights are satisfied by default.
How to make a request. Email privacy@rxhero.com or call +1 (307) 218-4388. We will verify your request — usually by confirming control of the email address we hold — and respond within the time your state requires (generally 45 days, extendable once where the law allows). You may designate an authorized agent to act for you; we may ask the agent for proof of authorization.
Appeals. If we decline your request, our response will tell you why. You may appeal by replying to that response or emailing privacy@rxhero.com with “Privacy Appeal” in the subject line. We will decide the appeal and explain our reasoning within the period your state sets (generally 45 or 60 days). If we deny the appeal, we will give you a method to contact your state attorney general to submit a complaint.
Sensitive data. Information indicating an interest in a health condition is sensitive data under most state privacy laws. We process it only to connect you with care at your request, and we do not use it for advertising.
Washington and Nevada residents have additional rights over consumer health data, including the right to withdraw consent and to have that data deleted. See our Consumer Health Data Privacy Policy.
We will not discriminate against you for exercising any of these rights.
14. Children’s privacy
The Services are for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
15. Third-party links
Our Services may link to third-party websites, including those of Remedora, Rush Pharmacy, and LocumTele. We are not responsible for the privacy practices of those sites; review their policies directly.
16. Where we operate
The Services are intended for use in the United States, and currently in 47 states — all except California, South Carolina, and New Jersey. Information we collect is processed and stored in the United States. If you access the Services from elsewhere, you do so on your own initiative.
17. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new effective date, and we will provide additional notice where required by law. Your continued use of the Services after an update means you accept the revised policy.
18. Contact us
Questions about this policy or your information? Email privacy@rxhero.com (privacy matters) or support@rxhero.com (general support), call +1 (307) 218-4388, or write to BLOOM PROCESSING LLC, 30 N Gould St, STE #53088, Sheridan, WY 82801, USA.