Overview
This Privacy Policy explains what information RefillopsAI, Inc ("Refillops", "we", "us") collects through refillops.co and the Refillops application, how we use that information, who we share it with, and the choices you have. It applies to pharmacy owners, managers, technicians, and other authorized users of the service.
Refillops is workflow software for pharmacy teams. It organizes refill requests, rejected claims, prior authorization follow-ups, prescriber messages, patient updates, and inventory blockers. It is not a pharmacy management system, a payer portal, or a source of medical, coverage, or clinical advice.
What Refillops does
We provide a hosted workspace where pharmacy teams enter, track, and resolve blocked prescriptions. To deliver that workspace we process account information you give us, workflow content your team enters, and operational telemetry about how the product is used. This Policy describes each category in plain language below.
Information we collect
We collect only the information needed to run the service, support your team, secure the platform, and meet our legal obligations.
- Account information. Name, work email, password (stored as a cryptographic hash), role, and the workspace you belong to.
- Contact and demo request information. Information you submit through our contact, sales, or demo forms — including pharmacy name, pharmacy type, location count, prescription volume range, and your message.
- Pharmacy organization information. Workspace settings, location list, team membership, role assignments, and operational preferences.
- Product usage data. Pages opened, features used, queue actions taken, response times, and aggregate workflow performance indicators used to operate and improve the product.
- Workflow data entered by users. Free-text notes, owner assignments, statuses, SLA timers, internal comments, and similar operational records.
- Prescription workflow metadata. When users enter it: drug name, payer, prescriber, rejection codes, PA status, and similar metadata used to drive the blocked queue.
- Message drafts. Patient update drafts and prescriber message drafts created in the product. Drafts are workflow content owned by your workspace and are not sent on your behalf without explicit user action.
- Uploaded documents or claim text. Files, screenshots, or claim text that users choose to attach to a case. We process these only to render and store them inside the workspace.
- Billing and payment information. If billing is connected, our payment processor handles card data directly; we receive transaction metadata (plan, amount, last four digits, billing contact) and never the full card number.
- Cookies and device data. Session cookies, consent preferences, IP address, browser, operating system, and similar device data. See our Cookie Policy.
Pharmacy teams decide what to enter into the product. We ask you not to enter information you don't need for workflow purposes — see the AI and workflow section below.
How we use information
- Operate, host, and secure the service.
- Create and manage user accounts and workspaces.
- Provide workflow features — the blocked queue, prior auth tracker, rejected claim desk, inventory watch, patient and prescriber drafts, and reports.
- Generate draft patient and prescriber messages and review-ready summaries from the workflow data your team enters.
- Communicate with you about support requests, security incidents, product changes that affect how the service works, and billing.
- Measure aggregate product performance, fix bugs, and improve features.
- Meet legal and regulatory obligations, respond to lawful requests, and enforce our agreements.
AI and intelligence features
Refillops does not train external AI models on your pharmacy data. Any assistive suggestions inside the product run on your workflow data only, are scoped to your account, and never include patient-identifying content in third-party model training pipelines.
- Suggestions, drafts, and summaries are workflow support only. A trained team member must review and approve before any message is sent or any patient or prescriber action is taken.
- Refillops does not make clinical, dispensing, coverage, insurance, billing, or medication decisions. It surfaces blockers, owners, and next actions for humans to act on.
- We ask users to avoid entering unnecessary sensitive personal data (for example, free-text clinical notes) into workflow fields when it is not required to resolve a blocker.
User content and ownership
Workflow data your team enters and content you upload into the service belong to your pharmacy or organization. We process that content on your behalf to deliver the service and provide support. We do not sell user content, and we do not use it to train external AI models. You can request export or deletion at any time using the contact details at the end of this Policy.
Third-party services
We rely on a short list of vendors to run the service. Each one processes data only for the purpose described and is bound by a written agreement.
- Hosting, authentication, and database. Lovable Cloud (Supabase) hosts the application database, manages authentication, and stores uploaded files in the workspace.
- Transactional and product email. Resend delivers transactional emails such as sign-in links, notifications, and support replies.
- Payments. If billing is connected, our payment processor handles card data directly. We receive only transaction metadata.
- Analytics. If analytics cookies are consented to, we use privacy-respecting analytics to understand aggregate product usage. No analytics are loaded before consent.
Data retention
Operational workflow data is retained for the life of your account and for 30 days after cancellation, unless a longer period is required by law or your written agreement. Audit logs are retained for 12 months. You can request export or deletion at any time.
Security
We use standard industry security practices to protect the service: encryption of data in transit and at rest with the hosting provider, scoped database access, environment separation, principle-of-least-privilege access for the team, audit logging, and regular review of dependencies.
No system is perfectly secure. We do not currently advertise HIPAA, SOC 2, HITRUST, payer, pharmacy board, or other certifications. If you require a specific certification to use the service, contact us before signing up so we can confirm fit. Report a suspected vulnerability or incident to security@refillops.co.
Your rights and choices
Depending on where you live, you may have the right to access, correct, export, restrict, or delete personal information we hold about you, and to object to or withdraw consent for certain processing.
- Access and export. Workspace admins can request a structured export of your workspace data.
- Correction. Most account and workspace fields can be edited from settings. For anything that can't, contact us.
- Deletion. You can request deletion of your account and associated workspace data subject to legal retention requirements and reasonable backups.
- Marketing choices. Marketing emails are opt-in and separate from transactional emails. Manage them on the Email Preferences page or by clicking unsubscribe in any marketing message.
- Cookie choices. Set or change cookie preferences in the cookie banner or on the Cookie Policy page.
To exercise a right, email privacy@refillops.co. We may need to verify your identity before we respond.
Children
Refillops is workplace software for pharmacy teams. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact privacy@refillops.co and we will delete it.
International users
The service is operated from the United States. If you access it from another country, you understand that information will be transferred to, stored, and processed in the United States by RefillopsAI, Inc and the vendors listed above.
Changes to this Policy
We may update this Policy as the product evolves. Material changes will be communicated in-product or by email to workspace admins before they take effect.
Contact us
Privacy questions, requests, and complaints can be sent to privacy@refillops.co. For security issues, email security@refillops.co. Our mailing address and phone number are in the contact card below.