LUCYRX HEALTHCARE SOLUTIONS, INC.
PRIVACY POLICY

Last Updated: April 22, 2026

At LucyRx Healthcare Solutions, Inc. (“LucyRx”), your privacy is important to us. Our Privacy Policy describes the information we collect, how we collect the information, the reasons we collect information, and how we share or use the information we collect. This Privacy Policy also describes the choices you have with the information we collect, including how you can manage, update, or request to delete information.

Please take a moment to carefully review this Privacy Policy. You may scroll through this Privacy Policy or use the headings below. It is important that you understand this Privacy Policy. By using our Platform, you are agreeing to the terms of this Privacy Policy. If you have any questions or concerns about this Privacy Policy, you may Contact Us at any time.

Table of Contents

I. Who is LucyRx?

II. Key Terms & Definitions and Our Privacy Policy

  • When does our Privacy Policy apply?
  • When does our Privacy Policy not apply?
  • Our Privacy Policy and Terms of Use.

III. Personal Information

  • What is Personal Information?
  • What types of Personal Information do we collect?
  • HIPAA Protected Health Information
  • How do we collect your Personal Information?
  • How do we use your Personal Information?
  • How do we share your Personal Information?
  • AI Features
  • How do I access and correct my Personal Information?
  • California Privacy Rights and Disclosures

IV. Who May Use the Services?

V. Children’s Privacy

VI. Does LucyRx respond to Do Not Track or Global Privacy Control signals?

VII. Data Security

VIII. Changes to our Privacy Policy

IX. Contact Us

I. Who is LucyRx?

LucyRx is an independent, next-generation pharmacy benefit manager dedicated to redefining prescription care for plan sponsors, health plans, and third-party administrators (“Customers”). Our mission is to pioneer new and simpler paths to lower costs and better health outcomes for our Customers’ members. To achieve this, we leverage smarter technology and advanced digital solutions to deliver innovative, customer-centric pharmacy benefit services to our Customers. Through our proprietary technology platform, including our AI-powered analytics solution, we provide real-time insights into plan performance, plan modeling capabilities, and precise NDC-level rebate reporting to help enable our Customers to maximize affordability for their members.

LucyRx is not a medical group, health care provider, or telemedicine service. We do not deliver medical diagnosis or treatment. Instead, we work with plan sponsors, health plans, and third-party administrators to facilitate pharmacy benefit services. When you interact with our Customer, they are responsible for providing you with a HIPAA Notice of Privacy Practices describing their collection and use of your protected health information (“PHI”). When LucyRx collects or otherwise processes PHI about you from or on behalf of our Customers, we will only collect, use, and otherwise process such information as a “business associate” under the Health Information Portability and Accountability Act and its implementing regulations (“HIPAA”) and we are only permitted to collect, use, and otherwise process PHI as directed by our Customers, as set forth in our contractual arrangements with them or as otherwise permitted by applicable law.

II. Key Terms & Definitions and Our Privacy Policy

It is helpful to start by explaining some of our key terms and definitions used in this Privacy Policy.

Key TermsDefinition
our “App(s)”LucyRx, our mobile application.
“Personal Information”Any information relating to an identified or identifiable individual and any information listed here.
our “Platform”Our Website, App, and/or Software.
“Privacy Policy”This privacy policy.
“Products”Any products available for purchase on our Platform.
our “Services”Any services provided through our Platform.
the “Software”LucyIQ.
our “Terms of Use”Our terms of use located here.
our “Website(s)”Our websites and subdomains, including:
https://lucyrx.com/
“LucyRx,” “we,” “us,” or “our”LucyRx Health Solutions, Inc.

When does our Privacy Policy apply?

This Privacy Policy describes the types of information we may collect from you when:

  • You visit or use our Platform, including our Website and App;
  • We communicate in e-mail, text message, and other electronic messages between you and us; and
  • We communicate in person, such as on the phone.

When does our Privacy Policy not apply?

This Privacy Policy does not apply to information collected by any other website operated either by us or by a third party, unless the website is listed above or links to this Privacy Policy. It also does not apply to any website that we may provide a link to or that is accessible from our Platform.

This Privacy Policy does not apply to information collected from our Customers or our Customers’ members who log-in to the password-protected and secure portions of our Platform (“Secure Platform”). The Secure Platform allows our Customers who obtain the Services to perform certain functions or obtain the Services (such as pharmacy benefit services). All information collected and stored by us or added by Customers or our Customers’ members into such Secure Platforms is considered PHI and/or medical information and is governed by applicable state and federal laws that apply to that information, for example HIPAA. How we use and disclose such PHI is in accordance with the applicable Notice of Privacy Practices provided to you by our Customers. For detailed privacy information related to our collection and use of your information on behalf of our Customers who use our Services, please reach out to the relevant Customer directly. We are not responsible for the data security or privacy practices of our Customers, which may differ from those set forth in this Privacy Policy.

Our Privacy Policy and Terms of Use.

This Privacy Policy is incorporated into our Terms of Use, which also apply when you use our Platform.

III. Personal Information

What is Personal Information?

Personal information is information from and about you that may be able to personally identify you. We treat any information that may identify you as personal information. For example, your name and e-mail address are personal information.

What types of Personal Information do we collect?

We may collect and use the following personal information (hereinafter, collectively referred to as “Personal Information”):

Categories of Personal InformationSpecific Types of Personal Information Collected
Personal Identifiersa real name, e-mail address, unique personal identifier, online identifier, shipping address, or health plan name with member ID and member group number
Information that identifies, relates to, describes, or is capable of being associated with a particular individualname, username, shipping address, telephone number, or health plan name with member ID and member group number
Commercial informationrecords of products or services purchased, obtained, considered, or other purchasing or consuming histories or tendencies
Biometric informationfingerprints and facial recognition
Internet or other electronic network activity informationIP address, device ID, OS version, hardware, device language, operating system, browser type, browsing history, search history, advertising ID, and information regarding a consumer’s interaction with an Internet Web site, application, or advertisement
Geolocation dataIP-based information about your physical location or movements. This IP-based information can only identify your physical location or movements to a geographic region, such as town, city, state, and country, but cannot be used to identify your precise physical location or movements
Sensory dataAudio recordings of customer service phone calls
Professional or employment-related informationEmployer name, job title, and job role
Inferences drawn from other Personal InformationProfile reflecting a person’s preferences and characteristics, or derived data

HIPAA Protected Health Information

Some Personal Information we collect may constitute PHI as defined by HIPAA. As set forth above, your health plan, plan sponsor, or third-party administrator is responsible for providing you with a Notice of Privacy Practices describing their collection and use of your health information. We will only use and disclose PHI as permitted by HIPAA, other applicable law, and the applicable Notice of Privacy Practices. We may combine your PHI with Personal Information that we have either obtained from you or through a third-party, such as your health plan, plan sponsor, or third-party administrator where permitted by law.

How do we collect your Personal Information?

We collect most of this Personal Information directly from you. For example, when we speak to you by phone, text message, and e-mail. Additionally, we will collect information from you when you visit our Website or App and fill out forms, use the Software, or purchase our Services.

We may also collect Personal Information in the following ways:

  • From your mobile device.
  • When You Contact Us. When you contact LucyRx directly, such as when you fill out an online form or contact our Customer Support team, we will receive the contents of your message or any attachments you may send to us, as well as any additional information you choose to provide.
  • From third parties. We may collect Personal Information from third parties, such as ZoomInfo, to obtain information about our Customers’ or potential or prospective customers’ business.

We will also collect information automatically as you navigate through our Platform. We use the following technologies to automatically collect data:

  • Cookies. We and our service providers may use cookies, web beacons, and other technologies to receive and store certain types of information whenever you interact with our Platform or Services through your computer or mobile device. A “cookie” is a small file or piece of data sent from a website and stored on the hard drive of your computer or mobile device. Some of the cookies we use are “session” cookies, meaning that they are automatically deleted from your hard drive after you close your browser at the end of your session. Session cookies are used to optimize performance of the Website and to limit the amount of redundant data that is downloaded during a single session. We also may use “persistent” cookies, which remain on your computer or device unless deleted by you (or by your browser settings). We may use persistent cookies for various purposes, such as statistical analysis of performance to ensure the ongoing quality of our Platform and/or the Services. We and third parties may use session and persistent cookies for analytics and advertising purposes, as described herein. On your computer, you may refuse to accept browser cookies by activating the appropriate setting on your browser, and you may have similar capabilities on your mobile device in the preferences for your operating system or browser. However, if you select this setting you may be unable to access or use certain parts of our Platform or the Services. Unless you have adjusted your browser or operating system setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Platform.
  • Google Analytics. We use Google Analytics, a web analytics service provided by Google, Inc. (“Google”) to collect certain information relating to your use of our Platform. Google Analytics uses cookies, to help our Platform analyze how users use our Website. You can find out more about how Google uses data when you visit our Platform by visiting “How Google uses data when you use our partners’ sites or apps”, (located at www.google.com/policies/privacy/partners/). For more information, please visit Google and pages that describe Google Analytics, such as www.google.com/analytics/learn/privacy.html.
  • LinkedIn. We use LinkedIn cookies to, among other activities, store and track visits across websites. You can find more information on the data collected by LinkedIn by visiting their Privacy Policy: https://www.linkedin.com/legal/privacy-policy.
  • Salesforce. We use Salesforce, which utilizes cookies and tracking technologies stored on your computer, to enable us to analyze the use of our Platform. Salesforce evaluates the collected information (e.g., IP address, approximate geographical location, type of browser and device, duration of the visit, pages accessed, e-mail address, and form submission data) on our behalf in order to generate reports on the visit and the pages visited, form completion association, campaign source attribution, and to track e-mails that are opened. You can find more information on the data collected by Salesforce and its processing here: https://www.salesforce.com/company/legal/privacy/. You can find more information on the cookies used by Salesforce herehere, and here. If you generally do not want Salesforce to collect data, you can prevent cookies from being stored at any time using your browser settings.
  • ZoomInfo. We use ZoomInfo to obtain information about our Customers’ or potential or prospective customers’ business. You can find more information on the data collected by ZoomInfo by visiting their Privacy Policy: https://www.zoominfo.com/legal/privacy-policy.
  • Other third party tools. We use other third party tools which allow us to track the performance of our Platform. These tools provide us with information about errors, Platform performance, and other technical details we may use to improve our Platform and/or the Services.

BY CONTINUING TO ALLOW US TO USE ANY OF THE ABOVE DESCRIBED TECHNOLOGIES, YOU HEREBY CONSENT TO OUR RECORDING OF YOUR: (I) USE OF THE PLATFORM OR OTHER COMMUNICATIONS YOU MAY HAVE WITH OUR PLATFORM AND THE DISCLOSURE OF SUCH INFORMATION TO THIRD-PARTY COOKIE, WEB BEACON, PIXEL OR OTHER PROVIDERS; AND/OR (II) MOUSE MOVEMENTS, KEYSTROKES, NAVIGATION PATHWAYS, OTHER ACTIONS THAT YOU TAKE OR COMMUNICATIONS YOU MAY HAVE WITH OUR PLATFORM AND OTHER USE OF SUCH TOOLS AND OUR DISCLOSURE OF SUCH RECORDED INFORMATION TO THIRD-PARTY PROVIDERS OF SUCH TOOLS.

How do we use your Personal Information?

We may use your Personal Information for the following purposes:

  • Provide, support, personalize, and develop our Services, including monitoring and analyzing the effectiveness of content and features, and assisting you in completing the registration or enrollment process.
  • Process your requests, purchases, transactions, and payments, and/or to prevent transactional fraud.
  • Operate, maintain, supervise, administer, and enhance our Platform or the Services, including monitoring and analyzing the effectiveness of content on the Platform, aggregating site usage data, and improving overall performance, and related purposes which may include the use of artificial intelligence or machine learning.
  • Provide you with information, Products, or Services that you request from us or that may be of interest to you.
  • Promote and market our Platform and/or the Services to you. For example, we may use your Personal Information, such as your e-mail address, to send you news and newsletters, special offers, and promotions, or to otherwise contact you about Products or information we think may interest you. We also may use the information that we learn about you to assist us in advertising our services on third party websites. You can opt-out of receiving these e-mails at any time as described below.
  • To create, maintain, customize, secure your account with us.
  • To provide you with notices or information about your account.
  • To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses.
  • To notify you about changes to our Platform and/or the Services or any Products we offer or provide through them.
  • Fulfill any other purpose for which you provide it.
  • To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.
  • Anonymize and aggregate information for analytics and reporting.
  • To respond to law enforcement requests, court orders, and subpoenas and to carry out our legal and contractual obligations.
  • Authenticate use, detect fraudulent use, and otherwise maintain the security of our Platform and the safety of others.
  • To administer surveys and questionnaires.
  • To provide you information about goods and services that may be of interest to you, including through newsletters.
  • To allow you to participate in interactive features of our Platform.
  • To fulfill any other purpose for which we have collected it.
  • Any other purpose with your consent.

How do we share your Personal Information?

We may share Personal Information with third parties in certain circumstances or for certain purposes, including:

  • Our business purposes. We may share your Personal Information with our affiliates, vendors, service providers, and business partners, including our data hosting and data storage partners, analytics and advertising providers, technology services and support, and data security advisors. We may also share your Personal Information with professional advisors, such as auditors, law firms, and accounting firms.
  • Health plans, health plan sponsors, and third-party administrators. We may share limited Personal Information about you with our Customers to facilitate the provision of our Services on the Platform.
  • With your consent. We may share your Personal Information if you request or direct us to do so.
  • Compliance with law. We may share your Personal Information to comply with applicable law or any obligations thereunder, including cooperation with law enforcement, judicial orders, and regulatory inquiries.
  • Business transfer. We may share your Personal Information to a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of a bankruptcy, liquidation, or similar proceeding, in which Personal Information held by us about our users are among the assets transferred.
  • To enforce our rights. We may share your Personal Information to enforce any applicable terms and conditions and Terms of Use, and to ensure the safety and security of our Services and our users.
  • De-identified information. We may also disclose de-identified information, so that it cannot be reasonably used to identify any individual, with third parties for marketing, advertising, research, or any other purpose permitted by law.
  • To market our Products and Services. We may share your Personal Information with affiliates and third parties to market our Products and Services.
  • Third party analytics. We use third-party analytics to understand and evaluate how visitors interact with our Platform and/or the Services. These tools help us improve our Platform and/or the Services, performance, and your experience.

AI Features

Certain Artificial Intelligence (“AI”) features may be used to improve your experience or the overall experience of the Platform and Services. When we collect Personal Information from an individual or Customer who uses the Platform, we may use the Personal Information in conjunction with our AI features to provide the Products and Services, and other internal purposes permitted by applicable laws. AI-generated insights assist but do not replace human decision making; in particular, any decision that influences health coverage or access to qualified medical products or services will be reviewed by a human.

We may use information we collect to internally refine, improve, and train the models and algorithms that support our AI features, in accordance with applicable law. This helps us enhance AI-driven insights, improve recommendations, and contribute to better outcomes.

Your choices about how we share your Personal Information

This section of our Privacy Policy provides details and explains how to exercise your choices. We offer you choices on how you can opt out of our use of tracking technology, disclosure of your Personal Information for our advertising to you, and other targeted advertising. We do not control the collection and use of your information collected by third parties. These third parties may aggregate the information they collect with information from their other customers for their own purposes. You can opt out of third parties collecting your Personal Information for targeted advertising purposes in the United States by visiting the National Advertising Initiative’s (NAI) opt-out page and the Digital Advertising Alliance’s (DAA) opt-out page.

Each type of web browser provides ways to restrict and delete cookies. Browser manufacturers provide resources to help you with managing cookies. Please see below for more information.

For other browsers, please consult the documentation that your browser manufacturer provides.

If you do not wish to have your e-mail address used by LucyRx to promote our own Products and Services, you can opt-out at any time by clicking the unsubscribe link at the bottom of any e-mail or other marketing communications you receive from us or logging onto your Account Preferences page. This opt out does not apply to information provided to LucyRx as a result of a product purchase, or your use of our Platform and/or the Services. You may have other options with respect to marketing and communication preferences through our Platform.

You may also see certain ads on other websites because we participate in advertising networks. Ad networks allow us to target our messaging to users through demographic, interest-based, and contextual means. These networks track your online activities over time by collecting information through automated means, including through the use of cookies, web server logs, and web beacons. The networks use this information to show you advertisements that may be tailored to your individual interests.

How do I access and correct my Personal Information?

You may Contact Us to access your Personal Information inform us of any changes or errors in any Personal Information we have about you to ensure that it is complete, accurate, and as current as possible or to delete your account. We may also not be able to accommodate your request if we believe it would violate any law or legal requirement or cause the information to be incorrect.

California Privacy Rights and Disclosures

If you are a resident of California, the laws in California may provide you with additional rights and disclosures regarding our processing of your Personal Information.

California Civil Code Section 1798.83 (California’s “Shine the Light” law) permits users of our Platform and/or the Services that are California residents and who provide Personal Information in obtaining products and services for personal, family, or household use to request certain information regarding our disclosure of Personal Information to third parties for their own direct marketing purposes. If applicable, this information would include the categories of Personal Information and the names and addresses of those businesses with which we shared your Personal Information with for the immediately prior calendar year (e.g., requests made in 2026 will receive information regarding such activities in 2025). You may request this information once per calendar year. To make such a request, please Contact Us using the information below.

IV. Who May Use the Services?

LucyRx operates subject to state and federal regulations, and the Platform and/or the Services may not be available in your state. You represent that you are not a person barred from enrolling for or receiving the Services under the laws of the United States or other applicable jurisdictions in which you may be located. Access to and use of the Platform and/or the Services is limited exclusively to users located in states within the United States where the Platform and/or the Services is available. The Platform and/or the Services are not available to users located outside the United States. Accessing the Platform and/or obtaining the Services from jurisdictions where content is illegal, or where we do not offer the Platform and/or the Services, is prohibited.

V. Children’s Privacy

We do not knowingly collect or sell Personal Information from children under the age of 18. If you are under the age of 18, do not use or provide any information on or to the Platform or through any of its features. If we learn we have collected or received Personal Information from a child under the age of 18 without verification of parental consent, we will delete it. If you are the parent or guardian of a child under 18 years of age whom you believe might have provided us with their Personal Information, you may Contact Us to request the Personal Information be deleted.

VI. Does LucyRx respond to Do Not Track or Global Privacy Control signals?

Some web browsers have a “Do Not Track” feature. This feature lets you tell websites you visit that you do not want to have your online activity tracked. These features are not yet uniform across browsers. Our Platform is not currently set up to respond to those signals.

Some web browsers and browser extensions permit you to broadcast the Global Privacy Control signal (“GPC Signal”) as specified at https://www.globalprivacycontrol.org. Our Platform is not currently designed to honor the GPC Signal.

VII. Data Security

We have taken steps and implemented administrative, technical, and physical safeguards designed to protect against the risk of accidental, intentional, unlawful, or unauthorized access, alteration, destruction, disclosure, or use. The Internet is not 100% secure and we cannot guarantee the security of information transmitted through the Internet. Where you have been given or you have chosen a password, it is your responsibility to keep this password confidential.

The sharing and disclosing of information via the internet is not completely secure. We strive to use best practices and industry standard security measures and tools to protect your data. However, we cannot guarantee the security of Personal Information transmitted to, on, or through our Services. Any transmission of Personal Information is at your own risk. We are not responsible for the circumvention of any privacy settings or security measures contained on our Platform, in your operating system, or mobile device.

VIII. Changes to our Privacy Policy

We may update our Privacy Policy periodically to reflect changes in our privacy practices, laws, and best practices. We will post any changes we make to our Privacy Policy on this page with a notice that the Privacy Policy has been updated on our Website’s homepage and our App’s home screen. If we make material changes to our practices with regards to the Personal Information we collect from you, we will notify you by email to the e-mail address specified in your account and/or through a notice on the Platform. The date this Privacy Policy was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable e-mail address for you, and for periodically accessing the Platform and reviewing this Privacy Policy to check for any changes.

IX. Contact Us

If you have any questions, concerns, complaints or suggestions regarding our Privacy Policy or otherwise need to contact us, you may contact us at the contact information below or through the “Contact Us” page on the Platform.

How to Contact Us:

LucyRx Healthcare Solutions, Inc.
Telephone: 559-312-2808
E-mail: privacy@lucyrx.com