1. Who we are & who this is for
AllyOS is a B2B clinical decision-support and practice-operations platform operated by RenuviaMD® PLLC ("RenuviaMD," "we," "our," or "us"), curated by Armando A. Falcon, MD. Access is restricted to verified licensed healthcare providers. AllyOS is not a patient records system and is not intended for, marketed to, or to be used by patients or consumers.
AllyOS collects, stores, and processes no patient protected health information (PHI) as defined under HIPAA. The point-of-care tools (the Visit Packet, calculators, screens) run entirely in your browser; any patient data you enter stays on your device, is held only for the active session, and is cleared when you close the encounter. It is never transmitted to or stored on our servers. Accordingly, AllyOS is not a HIPAA business associate, and no Business Associate Agreement is required or offered.
2. Information we collect
We collect only what is needed to run a provider account. We do not collect patient data of any kind.
- Identity & professional information: your full legal name, professional credentials, National Provider Identifier (NPI), practice or clinic name, and state of licensure.
- Contact information: email address and, optionally, phone number.
- Account credentials: a one-way encrypted password hash (we never store your password in plaintext).
- Usage & technical data: pages and features used, session timestamps, IP address, browser and device type — used to operate, secure, and improve the platform.
- Ally questions: the de-identified clinical questions you submit to Ally (our AI assistant). These contain clinical terms only and never patient identity — see §4.
3. Your NPI — used only to verify you are a licensed provider
We verify your NPI against the public NPPES (National Plan and Provider Enumeration System) registry solely to legitimize and gate access to the platform for verified providers. We do not use your NPI for any other purpose — never for ordering, billing, payment, fulfillment, prescribing, marketing, profiling, resale, or any commercial transaction — and we do not share your NPI with pharmacies, suppliers, or fulfillment partners. AllyOS does not sell, source, broker, or distribute peptides or any drug; there is no order flow your NPI could feed.
4. Ally (AI assistant)
Ally is the cloud reasoning component of AllyOS. It is provided only de-identified clinical questions — it never receives a patient name, date of birth, medical-record number, or other identifier. Questions are processed by our third-party AI provider to generate an answer; we do not attach patient identity to them and do not store them in any patient record. Ally responses are decision-support only, may be incomplete or in error, and must be independently verified before any clinical use.
5. How we use information
- Account management: creating, securing, and authenticating your account.
- Provider verification: confirming your NPI/licensure to gate access (see §3).
- Platform operation & improvement: running the service, fixing bugs, analyzing usage to improve features and content.
- Communications: transactional emails (account, security) and, where you opt in, product updates.
- Legal compliance: meeting obligations under applicable law and protecting the rights and safety of users and RenuviaMD.
6. How we share information
We do not sell, rent, or trade your personal information. We share it only in these limited cases:
- NPPES verification: your NPI is submitted to the federal NPPES lookup to verify your credentials.
- Service providers: infrastructure vendors (hosting, the AI provider, email delivery) who process data on our behalf under appropriate agreements.
- Legal requirements: when required by law, court order, or governmental authority, or to protect rights and safety.
We do not share your information with pharmacies, drug suppliers, or fulfillment partners, because we do not sell or source product.
7. Data security
All data between your browser and the platform is encrypted in transit using TLS. Account data stored in our databases is encrypted at rest, and passwords are stored only as one-way hashes. Access to production data is restricted to authorized personnel on a need-to-know basis, and we review our security practices periodically. No method of transmission or storage is 100% secure; in the event of a breach affecting your personal information, we will notify you as required by applicable law.
8. Cookies
We use a session cookie to keep you signed in and to remember basic preferences (such as theme). We do not use persistent advertising cookies or cross-site tracking. You can configure your browser to refuse cookies, but some features (such as login) may then not work.
9. Data retention
We keep your account information for as long as your account is active or as needed to provide the service. If you request deletion, we will delete or anonymize your personal information within 30 days, subject to any legal, regulatory, or fraud-prevention retention obligations. Patient data is never retained because it never reaches us.
10. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal information, and to opt out of non-transactional communications. To exercise these rights, contact us using the details below; we will respond to verifiable requests within 30 days.
11. Changes to this policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with a new "last updated" date. We encourage you to review it periodically.
12. Contact us
RenuviaMD® PLLC
Privacy inquiries: privacy@renuviamd.com — confirm
Support: support@renuviamd.com — confirm
Mailing address: [business mailing address — confirm]
This is a plain-language draft for the prototype and is not a substitute for a final privacy policy reviewed by qualified counsel. The bracketed items above must be replaced with confirmed contact details before publication.
← Terms of Service · AllyOS →