Say My Meds™ Privacy Policy
1. Introduction
Repp Medical Inc. ("Company," "we," "us," or "our") provides this Privacy Policy ("Policy") to explain how we collect, use, disclose, and safeguard information when you use our iOS application, Say My Meds™ (the "App"), and related services (collectively, the "Services"). The App helps individuals including elderly and impaired users and their family members or caregivers scan prescription labels, track medications, manage schedules, and receive AI-assisted reminders and support.
This Policy is designed to meet the requirements of Apple's App Store Review Guidelines and App Privacy disclosures, applicable U.S. state comprehensive privacy laws (including the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA")), and applicable U.S. state consumer health data laws (including Washington's My Health My Data Act, Nevada's Consumer Health Data Privacy Law (SB 370), Connecticut's Data Privacy Act, and New York's Health Information Privacy Act), to the extent each applies to our processing activities as described below.
By downloading, accessing, or using the App, you acknowledge that you have read and understood this Policy.
2. Scope and Our Role
This Policy applies to information collected through the App, our websites that link to this Policy, customer support interactions, and other related services. The Services are currently offered only to individuals and their authorized family members or caregivers located in the United States, on a direct-to-consumer basis.
2.1 Not a HIPAA Covered Entity or Business Associate
Repp Medical Inc. is not a HIPAA Covered Entity or Business Associate, and the App is not offered on behalf of, integrated with, or under contract with any healthcare provider, health plan, or healthcare clearinghouse. The App is intended for personal, self-directed use: you (or a family member or caregiver you authorize) enter, scan, and manage your own medication information. Accordingly, the Health Insurance Portability and Accountability Act ("HIPAA") does not apply to Company's handling of information collected through the App. Section 7 describes the state consumer-health-data and breach-notification laws that apply instead.
2.2 Our Role Under U.S. Privacy Laws
For personal information subject to U.S. state comprehensive privacy laws, Repp Medical Inc. acts as a "business" under the CCPA/CPRA and a "regulated entity" under Washington's My Health My Data Act, Nevada's Consumer Health Data Privacy Law, Connecticut's Data Privacy Act, New York's Health Information Privacy Act, and comparable state consumer health data laws, with respect to the information described in Section 3.
3. Information We Collect
We collect the categories of information described below. The exact data collected depends on how you use the App and the features you enable.
3.1 Account and Contact Information
Name, email address, and account credentials
Emergency contact or caregiver/family contact information you choose to add
Communications you send to us (e.g., support requests)
3.2 Device and Usage Data
Device identifiers (e.g., IDFV, advertising identifier where permitted), device model, and operating system version
App usage data, feature interactions, crash logs, and diagnostic data
IP address and approximate location derived from IP address
Log data such as access times, pages viewed, and referring URLs
3.3 Health and Medication Information
Because the App's core function is medication management, we collect health-related information directly from you, including:
Medication names, dosages, and instructions captured by scanning prescription labels (via camera/barcode scan)
Medication schedules, reminders, and adherence logs (e.g., doses taken, skipped, or delayed)
Optional health notes you choose to enter (e.g., allergies, conditions, prescriber name)
This information is not Protected Health Information ("PHI") under HIPAA, because it is collected directly from you for personal use rather than on behalf of a healthcare provider, health plan, or clearinghouse (see Section 2.1). It is, however, "consumer health data" under Washington's My Health My Data Act, Nevada's SB 370, Connecticut's Data Privacy Act, New York's Health Information Privacy Act, and similar state laws, and "sensitive personal information" under the CCPA/CPRA, see Sections 5, 7, and 11 for the protections that apply to it.
3.4 Caregiver and Family Access
If you choose to invite a family member or caregiver to help manage your medications and schedule, we will collect their contact information and share your medication and schedule information with them, limited to what is necessary for them to provide that assistance and only after you provide affirmative consent through the App. You may revoke this access at any time in the App's settings.
3.5 Information from Apple Frameworks and Third Parties
| Third Party | Purpose | Data Shared |
|---|---|---|
| Amazon Web Services (hosting, storage, Amazon Bedrock AI) | Hosting the service, storing label photos, the AI assistant and label reading | Account data, label photos, medication names in AI requests, de-identified dose events. |
| OpenAI (only if it stays in use) | AI label reading and the assistant | Label photos, medication names, user questions |
| Google Firebase (Cloud Messaging, Crashlytics) | Push reminders, crash reports | Device push token, crash and diagnostic data |
| Google Sign-In / Sign in with Apple | Optional sign-in | Name, email, account identifier |
| U.S. National Library of Medicine (RxNav) | Medication name lookup | The medication name searched |
| Email provider (Amazon SES or current SMTP) | Verification codes and account emails | Name, email address |
| Pricing API (when enabled) | Cheaper-alternative suggestions | Medication name and strength only |
Apple on-device frameworks (Camera, Photos, Face ID, Speech, Notifications, and Health Data specific to Medications, Schedules, Dose History and Allergies) for the purposes of scanning, biometric sign-in, voice support, and reminders are processed or stored encrypted only on the user's device and not sent to us.
4. How We Use Information
We use the information described above to:
Provide, operate, maintain, and improve the App and Services, including medication reminders and schedule management
Power AI-assisted features, such as interpreting scanned prescription labels and providing plain-language reminders and support (see Section 4.1)
Share information with a caregiver or family member you have authorized, as described in Section 3.4
Authenticate users and secure accounts
Provide customer support and respond to inquiries
Send administrative communications, security alerts, and service updates
Monitor, detect, investigate, and prevent fraudulent or unauthorized activity
Comply with legal obligations and enforce our agreements
Conduct de-identified or aggregated analytics to improve the App
4.1 AI-Assisted Features
The App uses artificial intelligence including models accessed through Amazon Bedrock to help interpret scanned prescription information and provide reminders and plain-language support, particularly for elderly and impaired users. AI-generated output is provided for convenience and organizational support only. It is not medical advice, and it does not replace guidance from a licensed physician, pharmacist, or other qualified healthcare professional. Always confirm medication information with your prescription label, pharmacist, or prescriber.
Data sent to our AI service provider(s) for this purpose is processed under standard commercial data-processing terms (not a HIPAA Business Associate Agreement, which is not required given Company's role described in Section 2.1) and is not used by that provider to train its underlying models.
5. Categories of Personal Information (CCPA/CPRA Disclosures)
The table below summarizes, for the preceding 12 months, the categories of personal information we have collected and whether each category has been sold or shared for cross-context behavioral advertising, as required by the CCPA/CPRA.
| Category | Collected in Past 12 Months? | Sold or Shared for Cross-Context Advertising? |
|---|---|---|
| Identifiers (name, email, device ID) | Yes | No |
| Internet/network activity (app usage, diagnostics) | Yes | No |
| Geolocation (approximate, from IP) | Yes | No |
| Health & medication information (prescription scans, schedules, adherence logs) | Yes | No |
| Professional or account information | Yes | No |
| Inferences drawn from the above | Yes | No |
We do not sell personal information, and we do not use or share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.
We retain each category of personal information for the period described in Section 9. The business or commercial purposes for collecting and disclosing this information are described in Section 4. Health and medication information is additionally subject to Section 7.
6. How We Share Information
We do not sell personal information or health and medication information. We may share information as follows:
With a caregiver or family member you have explicitly authorized within the App (see Section 3.4)
With service providers and subprocessors who perform functions on our behalf (e.g., cloud hosting, AI-assisted features, analytics, customer support), under contractual confidentiality and security obligations, including the limitations on use required by the CCPA/CPRA for "service providers" and by Washington's My Health My Data Act and comparable state consumer health data laws (Nevada, Connecticut, New York) for "processors"
With professional advisors, such as auditors, lawyers, and insurers, where necessary
To comply with law, legal process, or governmental request, or to protect the rights, property, or safety of Company, our users, or others
In connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections
With your additional consent or at your direction
Beyond the categories above, we do not share your health and medication information with any third party including no sharing with data brokers, advertisers, or employers/insurers without your separate, opt-in consent, consistent with Section 7. Any subprocessors/third-party SDK vendors for disclosure for compliance with Apple, enterprise customers, and Washington's MHMDA are listed in section 3.5 above.
7. Consumer Health Data Laws (Washington, Nevada, Connecticut, New York, and Other States)
Because the App collects health and medication information but is not covered by HIPAA (Section 2.1), certain state laws that protect "consumer health data" outside of HIPAA apply instead. As of this Policy's Last Updated date, four states have enacted standalone consumer health data laws: Washington's My Health My Data Act ("MHMDA"), RCW 19.373; Nevada's Consumer Health Data Privacy Law, SB 370; Connecticut's Data Privacy Act, as amended by SB 3; and New York's Health Information Privacy Act. These laws apply based on where a user lives or where their data is collected, not where Company is located, and Company expects additional states to enact similar laws over time. Because Say My Meds™ is marketed and sold nationwide, Company applies the protections described in this Section 7 to all users regardless of state of residence, built to the strictest of these four standards, rather than limiting them to residents of the states listed above.
Consistent with these consumer health data laws, and applied uniformly nationwide, we:
Obtain your affirmative, opt-in consent before collecting health and medication information for a disclosed purpose, or collect only what is strictly necessary to provide the App's core functionality
Obtain a separate, additional opt-in consent before sharing health and medication information with any third party beyond what is described in Section 6
Do not sell health and medication information without your separate, signed written authorization (which we do not currently seek or use)
Do not use geofencing to identify, track, or target advertising to individuals near healthcare facilities
Allow you to withdraw consent and request deletion of your health and medication information including from archived or backup systems at any time, as described in Section 11
Washington residents have a private right of action to enforce MHMDA, and violations are also enforceable by the Washington Attorney General under the state Consumer Protection Act. Nevada's law is enforced solely by the Nevada Attorney General and does not include a private right of action. Connecticut's consumer health data provisions are enforced by the Connecticut Attorney General as part of the Connecticut Data Privacy Act. New York's Health Information Privacy Act is newly enacted, and its enforcement mechanism should be confirmed with counsel before nationwide launch. Because these laws differ in scope and remedies, Company has adopted the most protective terms among them as its nationwide baseline described above.
7.1 FTC Health Breach Notification Rule
To the extent the App qualifies as a vendor of "personal health records" under the FTC Health Breach Notification Rule, a breach of unsecured, identifiable health information will be addressed consistent with that Rule's notification requirements to affected individuals, the Federal Trade Commission, and, for larger breaches, the media independent of, and in addition to, the general security incident procedures described in Section 10.
7.2 General State Breach Notification Laws
All U.S. states require notification of affected individuals following a breach of certain categories of sensitive personal information, which generally include health and medication information. We maintain an incident response process designed to meet these notification obligations regardless of whether HIPAA or a health-data-specific law also applies.
8. International Users and Future Expansion
The Services are currently offered only to customers located in the United States, and this Policy is written accordingly. We do not currently knowingly collect personal data from individuals located in the European Economic Area, United Kingdom, or Switzerland.
Reservation of GDPR-equivalent protections: If we begin offering the Services to individuals located outside the United States, including in jurisdictions covered by the EU/UK General Data Protection Regulation ("GDPR"), we will, prior to doing so, update this Policy to include the applicable disclosures (including legal bases for processing, international transfer safeguards, and EU/UK representative contact details) and will apply GDPR-equivalent protections to those individuals' personal data including rights of access, rectification, erasure, restriction of processing, data portability, and objection, and, where applicable, a lawful basis for each processing activity.
9. Data Retention
We retain personal information, including health and medication information, only for as long as necessary to fulfill the purposes described in this Policy, including to satisfy legal, accounting, contractual, and reporting requirements, and for as long as you maintain an active account. When you delete your account or request deletion under Section 11, we will delete your health and medication information, including from archived or backup systems, within the timeframe described in our consumer health data privacy policy (see Section 7), except where retention is required by law. When information is no longer needed, we securely delete, destroy, or de-identify it in accordance with our data retention and disposal procedures.
10. Data Security
We implement technical and organizational measures designed to protect personal information and health and medication information against unauthorized access, disclosure, alteration, and destruction, including encryption in transit (e.g., TLS) and at rest, network segmentation, access controls, multi-factor authentication for administrative access, vulnerability management, and periodic security risk assessments. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
11. Your Privacy Rights
11.1 U.S. State Privacy Rights (CCPA/CPRA and Comparable State Laws)
Depending on your state of residence, you may have some or all of the following rights with respect to your personal information, subject to certain exceptions:
Right to know / access the specific pieces and categories of personal information we have collected about you
Right to delete personal information we have collected from you, subject to certain exceptions
Right to correct inaccurate personal information
Right to opt out of the sale or sharing of personal information, and of targeted advertising (we do not currently engage in either — see Section 5)
Right to limit the use and disclosure of sensitive personal information, where applicable
Right to non-discrimination for exercising your privacy rights
Right to appeal a denial of a privacy rights request
Right to designate an authorized agent to submit requests on your behalf
11.2 Washington Consumer Health Data Rights (MHMDA)
If Washington's My Health My Data Act applies to your health and medication information, you additionally have the right to:
Confirm whether we are collecting, sharing, or selling your consumer health data, and access that data
Withdraw your consent to our collection or sharing of your consumer health data at any time
Request deletion of your consumer health data, including from archived or backup systems, even if you previously consented to its collection
To exercise any right described in this Section 11, contact us using the details in Section 16. We will verify your identity before responding, consistent with applicable law, and will respond within the timeframe required by the applicable law (generally 45 days). We honor opt-out preference signals, such as the Global Privacy Control, where legally required.
11.3 Notice of Financial Incentives
We do not offer any financial incentive, discount, or other benefit in exchange for the collection, sale, or retention of personal information.
12. Children's Privacy
The App is not directed to children under 16, and we do not knowingly collect personal information from children under 16, other than a parent or guardian's own use of the App to manage a minor family member's medications, which is treated as caregiver/family access under Section 3.4. If we learn that we have collected personal information from a child in violation of applicable law, including the Children's Online Privacy Protection Act ("COPPA") where applicable, we will take steps to delete it.
13. Cookies, Tracking Technologies, and Apple App Tracking Transparency
The App and any associated websites may use cookies, SDKs, and similar tracking technologies for analytics, security, and functionality. Where the App engages in tracking as defined by Apple's App Tracking Transparency ("ATT") framework i.e., linking data with third-party data for advertising, or sharing data with data brokers we will request your permission via the ATT prompt before doing so, and will honor your choice.
14. Automated Decision-Making
We do not use your personal data to make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement. AI-assisted features described in Section 4.1 provide reminders and organizational support, not medical or legal decisions. If this changes, we will update this Policy and provide any notices, access rights, or opt-outs required by applicable law, including any CPRA automated decision-making technology regulations.
15. Changes to This Policy
We may update this Policy from time to time. We will post the revised Policy with an updated "Last Updated" date and, for material changes — including changes to the health and medication information we collect or share — provide additional notice and, where required by Washington's MHMDA or similar law, obtain new consent before the change takes effect. Your continued use of the App after changes take effect constitutes acceptance of the revised Policy, to the extent permitted by law.
16. Contact Us
If you have questions, concerns, or requests regarding this Policy or our data practices, please contact:
Repp Medical Inc.
Attn: Repp Medical Inc. Privacy Officer
3100 Ray Ferrero Jr. Blvd
Davie, FL 33314
Email: support@saymymeds.com
Phone: 813-449-4336
If you are a California resident and believe we have not adequately addressed your concern, you may contact the California Privacy Protection Agency (CPPA) or your state Attorney General's office. If you are a Washington resident, you may contact the Washington State Attorney General's Office regarding MHMDA. Residents of other states may have the right to contact their respective state Attorney General.