Legal

Privacy Policy

The Pep Club provides telehealth-mediated compounded-medication services. This policy describes how we collect, use, protect, and disclose your information. It also carries the HIPAA Notice of Privacy Practices published by Arora Health and Aesthetics, LLC and the consumer-privacy disclosure required by California, Washington, Texas, and Nevada law.

Effective:
2026-09-02
Version:
1.1
Last reviewed:
2026-09-02

1.Introduction and scope

This Privacy Policy describes how The Pep Club Inc. and Arora Health and Aesthetics, LLC (together, “The Pep Club,” “we,” or “us”) collect, use, protect, and disclose information about you in connection with the platform at thepepclub.com and its mobile and web applications (the “Platform”).

Arora Health and Aesthetics, LLC (the “Group”) and the Group's engaged providers deliver the clinical services offered through the Platform. The Group is the covered entity under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) for the records of your care. The Pep Club Inc. does not provide clinical services: it is the management services organization, performing administrative, payment, technology, marketing, and other supportive activities for the Group and its providers, and it acts as a business associate of the Group for the protected health information it handles on the Group's behalf.

This Privacy Policy is published jointly and is your combined Notice of Privacy Practices and consumer privacy disclosure.

By using the Platform, you agree to the practices described here and you acknowledge receipt of the HIPAA Notice of Privacy Practices set out in this document.

2.Information we collect

We collect information that you provide to us, information generated by your use of the Platform, and information we receive from third parties.

2.1Information you provide

This includes, depending on how you use the Platform:

  • Identity and contact information: name, date of birth, address, email, mobile phone number, photo identification;
  • Medical intake information: health history, symptoms, current medications, allergies, hormones and metabolic protocols you are following or have followed, family history, and other PHI required by the Group and its providers to provide care;
  • Biomarker and laboratory results returned to your account from the CLIA-validated reference laboratory or partner laboratory adapter;
  • Consultation content: messages between you and your physician, video and audio recordings if a telehealth visit is recorded with your consent, signed clinical notes (SOAP);
  • Consent and authorization records: signed consents (telehealth, compounded medication, HIPAA), with timestamp, IP address, and user-agent metadata; and
  • Payment information collected by our payment processor (we do not store full card numbers ourselves).

2.2Information collected automatically

When you use the Platform we may automatically collect device, connection, and usage information, including IP address, browser type and version, operating system, referring page, pages viewed, links clicked, and approximate geolocation derived from IP. We use this information for security (rate-limiting, abuse detection), accessibility and performance debugging, and product analytics. We do not sell this information.

2.3Information from third parties

We may receive information from the CLIA-validated reference laboratory or partner laboratory adapter that processes your biomarker samples; from the Affiliated Pharmacy regarding prescription status and shipment; from your physician of record outside the Platform if you elect to share results; and from public sources during identity-verification review.

3.How we use your information

We use your information for the following purposes:

  • To provide the Platform, including processing your medical intake, scheduling and recording consultations, returning your biomarker results, and routing flagged findings to a physician;
  • To enable the Group and its providers to provide treatment and to direct the Affiliated Pharmacy to fill prescriptions;
  • To bill for and collect payment for the Platform and to provide receipts for HSA, FSA, or insurer-reimbursement purposes;
  • To communicate with you about your account, appointments, prescriptions, kit shipments, and clinical messages from your care team;
  • To maintain audit logs, security monitoring, abuse detection, and operational integrity of the Platform;
  • To comply with our legal obligations, respond to lawful requests, defend our legal rights, and enforce our Terms;
  • To improve and develop the Platform; and
  • To send you, where you have opted in, optional educational or marketing communications.

We use AI-assisted summarization to generate educational interpretations of your biomarker results. These summaries are produced by Anthropic's Claude API. The AI pipeline is described in the Terms of Service.

4.HIPAA Notice of Privacy Practices

The Notice of Privacy Practices set out below is also published on its own, as a printable document you can keep, at the HIPAA Notice of Privacy Practices page. Both surfaces render the same text from one shared source, so the copy you print and the copy inside this policy cannot drift apart.

This is version 1.2 of the Notice, effective 2026-09-02.

4.1Who this Notice covers

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Arora Health and Aesthetics, LLC (the “Group”) and the Group's engaged providers (your “Provider”) deliver the clinical services described in this Notice. The Group is the covered entity under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) for the records of your care. This Notice applies to all records relating to your care that are created or retained by the Group and its engaged providers, in electronic or paper form, including information collected through the patient portal.

The Pep Club Inc. does not provide clinical services. It is the management services organization for the Group: it performs administrative, payment, technology, marketing, and other supportive activities for the Group and its Providers, and it acts as a business associate of the Group for the protected health information (“PHI”) it handles on the Group's behalf.

In this Notice, “we,” “us,” and “our” mean the Group and its engaged providers, together with The Pep Club Inc. acting on the Group's behalf.

This is version 1.2 of the Notice, effective 2026-09-02. It replaces every earlier version.

4.2Our duties

We are required by law to:

  • Maintain the privacy and security of PHI about you;
  • Give you this Notice of our legal duties and privacy practices with respect to PHI;
  • Notify you, without unreasonable delay and no later than sixty (60) calendar days after discovery, in the event of a breach of unsecured PHI that involves you; and
  • Follow the terms of the Notice currently in effect.

We reserve the right to change the terms of this Notice and to make the new terms effective for all PHI that we maintain, including PHI created or received before the change. When we make a material change, we will post the revised Notice at thepepclub.com/hipaa-notice, raise the version number, update the Last reviewed date, and make a copy available on request.

4.3Permissible uses and disclosures without your written authorization

We may use and disclose your PHI without a separate written authorization for the following purposes:

  • Treatment: to provide, coordinate, or manage your healthcare, including disclosure to the Group's engaged providers, the affiliated compounding pharmacy that dispenses your prescriptions, the reference laboratory that processes your biomarker samples, and other providers involved in your care.
  • Payment: the services are offered on a cash-pay basis, so we generally do not use or disclose PHI for insurance billing. We may use PHI to process your payment, verify your billing information, and send you billing communications. If you choose to seek reimbursement from your insurer independently, we may provide you with documentation of the services rendered at your request.
  • Healthcare operations: to run the Group's practice and the patient platform, including quality assessment and improvement, reviewing provider performance, licensing and accreditation activities, training, audit, and general administrative activities.
  • Public health activities: to public-health authorities authorized by law to collect information for preventing or controlling disease, injury, or disability; reporting medication-related adverse events to public-health authorities authorized by law to receive such reports; and reporting child abuse or neglect to authorized agencies.
  • Victims of abuse, neglect, or domestic violence: to a governmental authority authorized by law to receive such reports, where we reasonably believe abuse has occurred.
  • Health-oversight activities: to agencies overseeing the healthcare system, government benefits, or regulatory programs (for example, state pharmacy boards, state medical boards, the HHS Office for Civil Rights), including audits, investigations, inspections, and licensure.
  • Judicial and administrative proceedings: in response to a valid subpoena, court order, or other lawful process.
  • Law enforcement: in limited circumstances permitted by HIPAA, including court orders, certain identification requests, and reports of crime victims.
  • Decedents: to coroners, medical examiners, and funeral directors as necessary.
  • Research: if approved by an Institutional Review Board (IRB) with appropriate privacy protections in place.
  • Health or safety threats: to prevent a serious and imminent threat to the health or safety of you or another person, where the disclosure is to someone reasonably able to prevent or lessen the threat.
  • Specialized government functions: for military and veterans' activities, national security, protective services for the President, or correctional institutions as permitted by law.
  • Workers' compensation: as required by applicable state workers' compensation laws.
  • As required by law: any other use or disclosure required by federal, state, or local law, including disclosures to state licensing boards and mandatory reporting obligations.

4.4Appointment reminders and treatment alternatives

We may use and disclose PHI to contact you as a reminder about appointments or follow-up consultations, by email, by text message, or by a message in the patient portal. We may also use your PHI to tell you about treatment alternatives or other health-related benefits and services that may be of interest to you.

If you would prefer that we contact you by a particular method or at a particular address, tell us and we will accommodate reasonable requests. Communications that constitute “marketing” under HIPAA are covered by the authorization section below, not by this one.

4.5Business associates

We may disclose PHI to third-party “business associates” that perform services on our behalf, such as data storage, platform infrastructure, identity and authentication, email delivery, error monitoring, and payment processing.

HIPAA requires a written business associate agreement with each provider that creates, receives, maintains, or transmits PHI on our behalf, obliging that provider to protect the privacy and security of your PHI. We maintain an internal register of these providers and the status of each agreement, and we publish the current provider list in the Privacy Policy so that you can see exactly which vendors are in our information supply chain.

4.6Uses and disclosures requiring your written authorization

For uses and disclosures of PHI not described above, we will obtain your written authorization. The following always require your written authorization, except in the narrow exceptions HIPAA itself recognizes:

  • Marketing communications that constitute “marketing” under HIPAA;
  • Any sale of PHI;
  • Any use or disclosure of psychotherapy notes;
  • Most uses and disclosures of PHI for research purposes, other than research approved by an Institutional Review Board as described above; and
  • Outreach from the affiliated pharmacy to its existing patients about The Pep Club services, which requires the patient's separate written authorization under 45 CFR 164.508(a)(3). Outreach without that specific authorization is prohibited.

You may revoke any written authorization at any time by writing to privacy@thepepclub.com. Revocation is effective from the time we receive it and does not affect uses or disclosures we already made in reliance on the authorization.

4.7Your individual rights under HIPAA

You have the following rights with respect to PHI about you. To exercise any of them, write to the Privacy Officer at privacy@thepepclub.com.

  • Right to request restrictions. You may ask us to restrict how we use or disclose your PHI for treatment, payment, or healthcare operations. We are not required to agree to every request; if we agree, we will comply with the restriction except in an emergency. You may also direct us not to disclose to a health plan information about a service you paid for in full out of pocket, and we will honor that direction except where disclosure is required by law.
  • Right to confidential communications. You may ask us to communicate with you about your PHI by alternative means or at alternative locations (for example, secure email, an alternate phone, or a P.O. box). We will accommodate reasonable requests.
  • Right to inspect and copy your records. You may inspect and obtain a copy of the medical record and billing record we maintain for you. We will respond to a written request within thirty (30) days. A reasonable, cost-based fee may apply for copies in accordance with HIPAA and applicable state law. We will provide an electronic copy where you request one and our systems can produce it.
  • Right to amend your records. If you believe information in your record is incorrect or incomplete, you may submit a written amendment request. We may deny the request if the information was not created by us, is not part of the record we keep, is not part of the information you would be permitted to inspect, or is accurate and complete. If we deny the request, we will explain in writing, and you may submit a statement of disagreement to be filed with your record.
  • Right to an accounting of disclosures. You may request an accounting of disclosures of your PHI made by us in the six (6) years prior to your request, with the exceptions HIPAA recognizes (disclosures for treatment, payment, or healthcare operations; disclosures made to you; and disclosures made pursuant to a valid authorization). The first accounting in any twelve-month period is free; a reasonable, cost-based fee may apply to additional requests.
  • Right to breach notification. You have the right to be notified of any breach of unsecured PHI that involves you, as required by the HIPAA Breach Notification Rule (45 CFR 164.400 to 164.414) and applicable state law. The section below describes how we do that.
  • Right to a paper copy of this Notice. You may request a paper copy of this Notice at any time, even if you have agreed to receive it electronically.

4.8Breach notification

If we discover a breach of unsecured PHI, we will notify you without unreasonable delay and no later than sixty (60) calendar days after discovery, in accordance with 45 CFR 164.404. Notice will be sent to the email address or postal address on file with your account and will describe what happened, the types of PHI involved, the steps you can take to protect yourself, what we are doing in response, and how to contact us for more information.

Where a breach involves the unsecured PHI of more than five hundred (500) individuals, we will also notify the Secretary of the U.S. Department of Health and Human Services and, where required by 45 CFR 164.406, prominent media. Where a breach involves fewer than five hundred (500) individuals, we will report it to the Secretary on the HHS Breach Portal at the close of the calendar year.

4.9How to file a complaint

If you believe your privacy rights have been violated, you may file a complaint with us by writing to the Privacy Officer at privacy@thepepclub.com. Include your name, your account email, and a description of the concern. We will investigate and respond.

You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at 200 Independence Avenue SW, Washington, DC 20201, by phone at 1-877-696-6775, or online at www.hhs.gov/ocr/privacy/hipaa/complaints. We will not retaliate against you for filing a complaint.

4.10Privacy Officer and contact

The Privacy Officer is responsible for the privacy and security of PHI handled by the Group and by The Pep Club Inc. on the Group's behalf. Direct privacy questions, data-subject requests, and HIPAA-rights requests to the Privacy Officer at privacy@thepepclub.com.

You may also reach the Privacy Officer by telephone at 1-888-737-0567.

Written privacy requests may also be directed to the Privacy Officer using the contact options on the Contact page.

5.Rights under state privacy law

The rights described in the Notice above are your HIPAA rights and they apply to PHI. Where a state privacy law applies and the data in question is not PHI subject to HIPAA, you may have additional rights to data portability, deletion, and correction. The state-specific addenda below describe those rights. You exercise them the same way: email privacy@thepepclub.com from the address associated with your account.

6.How we disclose your information

We disclose your information only as described in this Privacy Policy. We do not sell PHI. We do not share PHI with advertisers. We disclose PHI only to (a) you and your designees, (b) the Group, its providers, and the Affiliated Pharmacy for treatment and dispensing, (c) the service providers and subprocessors listed below, (d) other parties with your written authorization, and (e) as required or permitted by law.

7.Service providers and subprocessors

The following service providers may process PHI or other personal information on our behalf. HIPAA requires a written Business Associate Agreement with each service provider that creates, receives, maintains, or transmits PHI on our behalf. We maintain an internal register of these providers and the status of each agreement, and we publish this list so you can see exactly which vendors are in our information supply chain.

ProviderPurpose
NeonManaged PostgreSQL database (PHI at rest)
ClerkIdentity, authentication, session management
VercelApplication hosting and edge delivery
ResendTransactional and clinical email delivery (the live email transport)
Amazon Web Services (SES)Standby email delivery (not in use; retained as a fallback transport)
TelegramInternal operational alerting to our own staff (no PHI is transmitted; enforced by an automated build gate and a runtime check)
Anthropic (Claude API)AI-assisted educational summarization of biomarker results
UpstashRedis-based rate limiting and webhook idempotency
SentryError monitoring (PHI-scrubbed payloads)
StripePayment processing (no PHI; payment-card and billing data only)

If our list of service providers or subprocessors changes materially, we will update this Privacy Policy and update the Last reviewed date. For changes that affect how PHI is processed in a way that would require new authorization under HIPAA, we will notify you and obtain authorization where required.

8.Data retention

We retain information for the following minimum periods:

  • PHI in the designated record set: at least six (6) years from the date of creation or the date last in effect, in accordance with 45 CFR 164.530(j);
  • Billing and tax records: at least seven (7) years to meet IRS recordkeeping rules;
  • Consent and authorization records: for the duration of the consent plus six (6) years thereafter;
  • Security audit logs (including the chain-hash tamper-evident PHI access log): at least six (6) years; and
  • State-mandated retention periods that exceed the above, where applicable to your state of residence.

When the applicable retention period expires, we will delete or de-identify the information unless we are required by law to retain it longer (for example, in connection with an ongoing legal matter).

9.Children

The Platform is not intended for individuals under twenty-one (21) years of age and we do not knowingly collect information from anyone under twenty-one. If we learn that we have collected information from a person under twenty-one, we will delete it promptly. If you believe a person under twenty-one has provided information to us, please contact privacy@thepepclub.com.

10.California residents (CCPA / CPRA)

Where the California Consumer Privacy Act applies and the data in question is not PHI subject to HIPAA, you have the right to:

  • Know what personal information we collect, use, disclose, and sell;
  • Delete personal information collected from you, subject to legal-retention exceptions;
  • Correct inaccurate personal information;
  • Opt out of any “sale” or “sharing” of personal information for cross-context behavioral advertising (we do not sell or share for these purposes);
  • Limit the use and disclosure of sensitive personal information;
  • Receive a copy of your personal information in a portable format; and
  • Non-discrimination for exercising your rights.

To exercise a CCPA right, email privacy@thepepclub.com from the address associated with your account. We will verify your identity before fulfilling any request. We will respond within forty-five (45) days; if more time is needed, we will notify you of the extension.

California residents may also designate an authorized agent to make requests on their behalf in accordance with CCPA regulations. We may contact you to confirm the agent's authority before processing the request.

11.Washington residents (My Health My Data Act / MHMDA)

The Washington My Health My Data Act (RCW 19.373) imposes additional requirements on the collection of “consumer health data” (“CHD”) by entities operating in Washington or serving Washington residents. CHD includes information that identifies a consumer's past, present, or future physical or mental health status, including health condition, treatment, diagnoses, medications, biometric data, gender-affirming care, reproductive health, and precise location related to health services.

Categories of CHD collected. For Washington residents, the categories include all information described in the Information We Collect section above to the extent it relates to your health status, plus IP-derived approximate location.

Purposes of collection. All purposes described in the How We Use Your Information section above.

Sources. Directly from you; automatically through Platform use; from the CLIA-validated reference laboratory or partner laboratory adapter; from the Affiliated Pharmacy; from third parties you instruct to provide records.

Disclosure to third parties. CHD is shared only with the service providers and subprocessors named above in this Privacy Policy, and only as required to deliver the Platform.

Your rights under MHMDA. Washington residents may (a) confirm whether we are processing CHD about them, (b) access CHD, (c) request deletion of CHD, (d) withdraw any previously granted consent, and (e) appeal any denied request. To exercise these rights or to file an appeal, email privacy@thepepclub.com. If an appeal is denied, you may also contact the Washington State Office of the Attorney General.

12.Texas and Nevada residents

Texas (TDPSA). Texas residents have rights similar to those described under CCPA, including the right to confirm processing, access, correction, deletion, portability, and to opt out of targeted advertising, sale of personal data, or certain profiling. We do not sell personal data for monetary or other valuable consideration.

Nevada (SB220). Nevada residents may submit a request to opt out of any future sale of their “covered information” as defined in NRS 603A. We do not currently sell covered information.

To exercise a Texas or Nevada right, email privacy@thepepclub.com from the address associated with your account. We will verify your identity before fulfilling any request.

13.Cookies and tracking technologies

The Platform uses strictly necessary cookies for authentication, session management, and security (CSRF protection, rate limiting). We use a limited set of first-party analytics cookies to understand aggregate Platform usage and to debug performance. We do not use third-party advertising cookies and do not participate in cross-context behavioral advertising. Your browser may allow you to disable non-essential cookies; doing so will not impair the core functionality of the Platform.

14.How we protect your information

We maintain administrative, physical, and technical safeguards designed to protect your information against unauthorized access, use, alteration, or disclosure. Safeguards include encryption in transit (TLS) and at rest, role-based access control with explicit per-procedure authorization, tenant isolation enforced at the database row-security layer, audit logging with a chain-hash tamper-evident chain for every PHI read and mutation, automated tests that block authorization regressions in continuous integration, and signed-webhook verification for every external integration.

No system is perfectly secure. While we strive to protect your information, we cannot guarantee its absolute security. If you suspect your account has been accessed by someone else, contact us immediately at security@thepepclub.com.

15.Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we make a material change, we will post the revised policy here and update the Last reviewed date. For changes that materially affect how we handle PHI, we will notify you by email at least thirty (30) days before the change takes effect. Continued use of the Platform after that date constitutes acceptance of the revised Privacy Policy.

16.How to contact us; complaint procedure

Privacy questions, data-subject requests, and HIPAA-rights requests: privacy@thepepclub.com.

Security incidents: security@thepepclub.com.

General support: hello@thepepclub.com. Additional support channels are listed on the Contact page.

You may also file a HIPAA complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at 200 Independence Avenue SW, Washington, DC 20201, by phone at 1-877-696-6775, or online at www.hhs.gov/ocr/privacy/hipaa/complaints. We will not retaliate against you for filing a complaint.

Questions about this document? privacy@thepepclub.com

Last reviewed: 2026-09-02

This Privacy Policy is provided by The Pep Club for transparency about its information practices. It is not a substitute for legal advice. Counsel review is ongoing; consult your own attorney for advice tailored to your situation.