Legal

Privacy Policy

Last updated: April 23, 2026  ·  Effective: April 23, 2026  ·  Veriva LLC, Herndon, Virginia

Veriva is built on a simple principle: your health data belongs to you. We do not sell your personal information or health data to third parties, ever. We do not serve ads. This policy explains what we collect, why, and how we protect it.

Table of Contents
  1. Who We Are
  2. Information We Collect
  3. How We Use Your Information
  4. Third-Party Service Providers
  5. Payment Processing (Stripe)
  6. Epic FHIR Integration
  7. AI Features
  8. Caregiver Access
  9. Data Security
  10. Data Retention
  11. Your Rights and Controls
  12. Children's Privacy
  13. Changes to This Policy
  14. Contact Us

1. Who We Are

Veriva LLC is a Virginia limited liability company operating the Veriva medication management platform at veriva.health and app.veriva.health. We are the data controller for personal information collected through the Service. Questions about this policy can be directed to privacy@veriva.health.

2. Information We Collect

Information you provide directly

Information collected automatically

Information from Epic FHIR integration (optional)

If you choose to connect your Epic MyChart account, prescription data including medication names, dosages, frequencies, and prescriber information is imported into your Veriva account. See Section 6 for details.

3. How We Use Your Information

We use your information solely to provide and improve the Veriva Service:

We will never use your health data to serve you advertisements or sell it to data brokers, insurance companies, employers, or any other third parties.

4. Third-Party Service Providers

We share your data with a limited set of trusted service providers who help us operate the Service. Each provider is contractually bound to protect your data and may only use it for the purposes we specify:

Provider Purpose Data shared
Supabase Database and authentication hosting All app data (stored encrypted at rest)
Stripe, Inc. Payment processing Email address, payment card data (see Section 5)
Netlify Web hosting and serverless functions IP address, request logs
Anthropic, Inc. AI health companion feature Medication list and AI conversation messages (when you use AI features)
Resend Transactional email delivery Email address, email content

We do not share your data with any other third parties without your explicit consent, except as required by law.

5. Payment Processing (Stripe)

Premium subscription payments are processed by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. When you subscribe to Veriva Premium:

Subscription receipts are sent to your account email address. Your billing history is visible in your account settings.

6. Epic FHIR Integration

Veriva offers optional integration with Epic-connected health systems (including MyChart). This integration uses the industry-standard OAuth 2.0 and SMART on FHIR protocols:

7. AI Features

The Veriva AI health companion is powered by Anthropic's Claude API. When you use AI features:

AI responses are not medical advice. See our Terms of Service for the full medical disclaimer.

8. Caregiver Access

If you invite a caregiver to your Veriva account:

9. Data Security

We take data security seriously and implement industry-standard measures to protect your information:

No security system is perfect. In the event of a data breach affecting your personal information, we will notify you by email within 72 hours of discovery, as required by applicable law.

10. Data Retention

We retain your data for as long as your account is active. If you delete your account:

11. Your Rights and Controls

You have the following rights regarding your personal data:

To exercise these rights, contact us at privacy@veriva.health. We will respond within 30 days.

You can manage notification preferences, caregiver access, and Epic connections directly within the app at any time.

12. Children's Privacy

Veriva is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us at privacy@veriva.health and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes by email at least 14 days before the changes take effect. Your continued use of Veriva after the effective date constitutes acceptance of the updated policy.

The "Last updated" date at the top of this page reflects when the policy was last revised.

14. Contact Us

Questions, concerns, or requests regarding your privacy: