Effective Date: December 17, 2025

Last Updated: December 17, 2025

EveryDose Privacy Policy

EveryDose respects your privacy and understands how important the privacy of personal information is to you and our users. Please carefully read this privacy policy (the “Privacy Policy”) as it contains important information about your legal rights.

This Privacy Policy forms a part of the EveryDose Terms of Use (“Terms”), which are binding terms between EveryDose, Inc. (“EveryDose”, “We”, or the “Company”) and you. This Privacy Policy explains how information is collected, used and disclosed by the Company with respect to your access and use of EveryDose’s mobile application for the iOS and Android operating systems (the “App”) and our website, accessible at https://www.everydose.ai (the “Site”) (collectively, the “EveryDose Services” or “the Services”).

With respect to this document, the term “Personal Information” is used to indicate any piece of information or data that can be used to identify or contact you. Personal Information may relate to you as a user, or it may relate to an individual that is the subject of any profile that you create on their behalf, if you create a profile for another individual, including through EveryDose’s caregiver features.

Any other defined term that is not defined in this Privacy Policy has the meaning given that term in the EveryDose Terms of Use, as applicable.

PROTECTED HEALTH INFORMATION

EveryDose provides its Services in multiple contexts. In some cases, individuals use the Services independently as consumers. In other cases, individuals may access the Services at the direction of, or in connection with, a healthcare provider, health system, health plan, pharmacy, or other organization that has entered into a written agreement with EveryDose, including a Business Associate Agreement (“BAA”) (each, a “Customer Organization”).

When an individual accesses the Services in connection with a Customer Organization and a BAA is in place, certain information collected, used, or disclosed through the Services may constitute Protected Health Information (“PHI”) as defined under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). In those circumstances, the collection, use, disclosure, and safeguarding of PHI are governed exclusively by the applicable BAA and HIPAA, and not by this Privacy Policy. To the extent there is any conflict between this Privacy Policy and a BAA with respect to PHI, the terms of the BAA control.

When an individual accesses or uses the Services outside of a relationship with a Customer Organization, including through direct-to-consumer use of the EveryDose mobile application, information collected through the Services does not constitute PHI and is handled in accordance with this Privacy Policy.

Use of the Services by or through an organization that has not entered into a written agreement or BAA with EveryDose does not create a business associate relationship, healthcare provider–patient relationship, or any obligation on the part of EveryDose to treat information collected through such use as PHI.

For purposes of determining whether information is treated as Protected Health Information, EveryDose relies on whether a user account has been successfully associated with a Customer Organization within EveryDose’s systems. A user will be treated as accessing the Services in connection with a Customer Organization only after such association has occurred, such as through the successful completion of a Customer Organization–specific enrollment or activation process using an activation code, activation link, deep link, QR code, or similar identifier provided by EveryDose.

If a user accesses or uses the Services without completing such association, the user will be treated as a consumer user for purposes of this Privacy Policy, even if the user may have received information about the Services from a healthcare provider or other organization.

MedGuides are generated through use of our provider-facing services in connection with a Customer Organization. Information included in MedGuides is treated as Protected Health Information and handled in accordance with the applicable Business Associate Agreement and HIPAA.

MedGuides may be printed, downloaded, shared electronically, or otherwise distributed by healthcare providers, Customer Organizations, or users. Once a MedGuide is printed, downloaded, or shared outside of EveryDose’s systems, its handling, storage, and further distribution are outside of EveryDose’s control. EveryDose is not responsible for disclosures resulting from the loss, misplacement, or misdelivery of printed MedGuides or from the sharing of MedGuides by third parties, including healthcare providers, Customer Organizations, or users.

WHAT PERSONAL INFORMATION DO WE COLLECT?

We collect various Personal Information from you and certain devices that you may use, as further described below. This includes information collected through applications, registrations, and your use of the Services. We also collect Personal Information in connection with your inquiries. Collection starts from the time that you initially access our Services.

Information that we gather enables us:

  • to administer your account,
  • to provide you with the Services,
  • to send you communications regarding the services we offer,
  • to respond to your inquiries,
  • to obtain your feedback on our Services,
  • to understand who is using our Services and how the Services are performing,
  • to otherwise analyze user behavior and activity,
  • to personalize and improve our Services,
  • to conduct research activities,
  • to manage the security of the Services, and
  • to fulfill any requirements imposed on us by applicable laws and regulations.

In some cases, you will provide Personal Information to us in connection with your use of the Services, and in other cases, we may collect this information automatically when you visit or interact with the App, the Site, or other aspects of the Services.
We provide more detail about the types of data we collect below:

Information You Provide to Us

  • Contact Information: Information about you, such as name, email address, gender, birthday, phone number, and zip code.
  • Voluntary Information: If you communicate with us voluntarily, we collect all information that you provide to us, including your contact information.
  • Health-Related Information: Certain features of the Services allow you to input information including, but not limited to, your medications, dosage, medication schedules, health measurements, assessments, doctor information, and pharmacy information. In addition, health-related information may be made available to the Services by your healthcare provider or Customer Organization through use of our provider-facing services or Electronic Health Record (“EHR”) systems maintained by your healthcare provider or Customer Organization. Such information may be used to support features of the Services, including the generation of medication summaries or educational materials such as MedGuides.
  • Caregiver Information: Information, such as name, phone number, address, and email address of your caregivers or other individuals you designate within the Services.

Information Collected Automatically

  • Device Information: We automatically collect certain technical information when you use the Services, including IP address, device details, operating system details, a unique device identifier, language of your operating system, and time zone.
  • Tracking Technologies: We may use various methods or technologies to store or collect your usage information, including your visits to or interactions with our Services (“Tracking Technologies”). We may use these Tracking Technologies for a variety of purposes, including but not limited to, uses deemed to be necessary or useful to assess the performance of our Services (including as part of our analytic practices or otherwise to improve our Services) or uses required to offer you enhanced functionality when accessing our Services (including identifying you when you sign in to the Services or for keeping track of your specified preferences).

WHAT INFORMATION DO WE SHARE WITH THIRD PARTIES?

We do not sell your Personal Information. We will not share the Personal Information we have collected from you, except as described below.

This section describes how we share Personal Information that is not subject to a Business Associate Agreement (“BAA”). To the extent information constitutes Protected Health Information (“PHI”) governed by an applicable BAA, the collection, use, and disclosure of such PHI are governed exclusively by the BAA and applicable law, and not by this Privacy Policy. This may include information presented through features such as MedGuides, where applicable.

We may share your information, including Personal Information, in the following circumstances:

  • Service Providers. We may share your information, including Personal Information, with service providers who have a contractual relationship with us in connection with the operation, maintenance, and improvement of our Services.
  • Customer Organization. If you access EveryDose in connection with a program offered by a Customer Organization, we may provide Personal Information about you to the Customer Organization, including data related to your use of, and interaction with, the Services.
  • Research and De-Identified Data. We may share de-identified information with our research partners, including research institutions, healthcare systems, and healthcare providers, for research purposes and for improvement of our Services. We may also share aggregated, de-identified information with third parties for industry analysis, demographic profiling, and other similar purposes.
  • Offers and Communications. While we will never disclose your Personal Information to other businesses for their marketing purposes, we may send you offers that promote the products of other businesses. We intend these offers to benefit you, your health, or your experience with our Services. You may opt out of these offers by following the directions in the Services or by contacting us as described at the end of this Privacy Policy.
  • With Your Consent. We may share your information when you give us your consent to do so, including when we notify you that the information you provide will be shared in a particular manner and you provide such information.
  • Legal and Compliance. We may share information when we believe in good faith that we are lawfully authorized or required to do so, or that doing so is reasonably necessary or appropriate to comply with applicable laws, regulations, legal processes, or lawful requests from public authorities, including responding to subpoenas, warrants, or court orders.
  • Enforcement and Protection. We may share information to enforce or apply this Privacy Policy, the Terms of Use, or our other policies or agreements, or to investigate misuse of our systems or protect the rights, property, or safety of EveryDose, our users, or others.
  • Business Transfers. We may share or transfer Personal Information in connection with, or during negotiations of, any merger, sale of company assets, financing, acquisition, or similar transaction, where Personal Information may be disclosed or transferred as one of our business assets

We are not responsible for the actions of service providers or other third parties, nor are we responsible for any additional information you provide directly to any third parties

MODIFYING YOUR INFORMATION

You can access, modify, and delete certain Personal Information through the EveryDose Services. You may also request deletion of your Personal Information by contacting us at support@everydose.ai. We will take reasonable steps to delete or update Personal Information that we control, subject to applicable law and our data retention practices. In some cases, information may remain in archived or backup systems for recordkeeping, security, or legal purposes, as permitted or required by law.

If you access the Services in connection with a Customer Organization, certain information may be maintained by that Customer Organization or governed by applicable law or contractual obligations, including a Business Associate Agreement. In such cases, EveryDose may be unable to delete, modify, or amend that information. Requests to access, amend, or delete information that is governed by a Business Associate Agreement or otherwise maintained by a Customer Organization must be directed to the applicable Customer Organization in accordance with its policies and applicable law.

Please note that if you decide to delete your Personal Information, we may retain and use de-identified or aggregated information that does not constitute Protected Health Information for our business purposes, as permitted by law. Any de-identification or use of Protected Health Information is governed exclusively by the applicable Business Associate Agreement and not by this Privacy Policy. Additionally, deleting the EveryDose App from your mobile device does not automatically delete your account or Personal Information unless you separately request deletion as described above.

INTERNATIONAL RESIDENTS

Our Services are only intended for residents of the United States. If you are located outside the United States and choose to provide information to us, your information will be stored and processed in the United States. By using EveryDose, you consent to the collection, transfer, use, storage and disclosure of your information as described in this Privacy Policy.

LINKS TO OTHER WEBSITES OR APPS

Our Services may link to or refer to websites or mobile device services that we do not control. Any Personal Information you provide on the linked pages is provided directly to this third party and is subject to the third-party provider’s privacy policy. This Privacy Policy does not apply to such other websites or services, and we are not responsible for the privacy practices or content of any website or service not controlled by us. If you have any concerns, we urge you to review the terms of those other websites or services for more information about their applicable policies.

AGE REQUIREMENTS

Our Services are designed for and exclusively available to individuals who are 18 years of age or older. Should we discover that a user under 18 has submitted Personal Information to us without the requisite parental consent, we will promptly remove this information from our records.

COMPREHENSIVE COMPLIANCE WITH STATE PRIVACY LAWS

EveryDose is committed to protecting the privacy and personal information of our users, adhering to the stringent standards set forth by state privacy laws across the United States. Our Privacy Policy is designed to ensure compliance with the laws of the states in which we operate, including but not limited to the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), and others as applicable.

Data Rights and Choices: To the extent required by applicable state law, we provide you with the rights to access, correct, delete, and obtain a copy of your personal information. Additionally, you may have the right to opt-out of certain uses of your personal information, such as the sale of personal data, targeted advertising, and profiling, depending on your state’s laws.

Transparency and Disclosure: We maintain transparency about the types of personal information we collect, the purposes for which we use it, the categories of third parties with whom we share it, and the specific pieces of personal information we have collected about you.

Opt-Out of Personal Information Sales: We provide all users with the option to opt-out of the sale of their personal information where applicable, by emailing us at support@everydose.ai. Although EveryDose does not sell personal information, we respect and comply with state law definitions and requirements regarding the sale of personal information.

Children’s Privacy: Consistent with the Children’s Online Privacy Protection Act (COPPA) and state law requirements, we do not knowingly collect personal information from children under the age of 13 (or a higher age threshold as prescribed by applicable state laws) without obtaining parental consent.

Updates and Modifications: Our Privacy Policy and practices are reviewed and updated regularly to comply with the evolving landscape of state privacy laws. We commit to keeping you informed of any significant changes that affect your rights and choices regarding your personal information.

Contact Information: For any questions, concerns, or exercise of your privacy rights, please contact us at support@everydose.ai. We are dedicated to respecting your privacy rights and will respond to your inquiries and requests in accordance with applicable state laws.

CHANGES TO THIS PRIVACY POLICY

Any information that is collected is subject to the Privacy Policy in effect at the time such information is collected. We may, however, modify and revise our Privacy Policy from time-to-time. If we make any material changes to this policy, we will notify you of such changes by posting them on the Services or by sending you an email or other notification or message, and we will indicate when such changes will become effective. By continuing to access or use the Services after those changes become effective, you are agreeing to be bound by the revised policy.

QUESTIONS? CONTACT US

If you have any questions, comments, requests, or concerns related to this Privacy Policy, please contact us at support@everydose.ai. If you would like to request to access or correct your Personal Information, please contact us at support@everydose.ai.