Privacy Policy

Last updated: July 16, 2026

This Privacy Policy explains how ToxIQ LLC ("ToxIQ," "we," "us," or "our") collects, uses, shares, and protects information in connection with the ToxIQ website and services (the "Service"). It applies to information we handle as a business. Where we process protected health information ("PHI") on behalf of a HIPAA covered entity, that processing is also governed by a Business Associate Agreement ("BAA"), which controls in the event of any conflict with this Policy.

1. Information we collect

We collect the following categories of information:

  • Account information — your name, email address, organization, and credentials you provide when you create an account or contact us.
  • Content you submit — questions you ask and files you upload (such as lab results in PDF, CSV, or image form), which may contain PHI when you have a BAA in place.
  • Usage data — logs, device and browser information, and interactions with the Service, used to operate, secure, and improve it.
  • Cookies and similar technologies — used to keep you signed in, remember preferences, and understand how the Service is used.
  • SMS opt-in information — if a patient chooses to receive text check-in reminders, the mobile phone number they enter and their consent record (timestamp and consent language), used only to send those reminders as described in Section 10.

2. How we use information

We use information to:

  • Provide, maintain, and secure the Service and generate interpretations you request;
  • Authenticate users and manage accounts and organization access;
  • Communicate with you about the Service, including support and administrative messages;
  • Monitor, troubleshoot, and improve performance, safety, and reliability;
  • Comply with legal obligations and enforce our Terms of Service.

We do not sell your personal information. We do not use PHI to train AI models, and we do not permit our subprocessors to use your Customer Content to train their models.

3. How we share information

We share information only as needed to run the Service:

  • Service providers (subprocessors) — including cloud hosting, database, and AI model providers that process data on our behalf under contractual confidentiality and security obligations.
  • Within your organization — if you access the Service under an organization plan, your administrators may have access to account and usage information for members.
  • Legal and safety — when required by law, to comply with legal process, or to protect the rights, safety, and security of users, the public, or ToxIQ.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to the protections described here.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. See Section 10 for our full text-messaging practices.

4. AI processing

To generate interpretations, the Service sends your inputs to third-party AI model providers that process the content solely to return a response to you. These providers are bound by contractual terms that prohibit using your content to train their models. Because AI outputs may be inaccurate or incomplete, they must be independently reviewed by a qualified professional before you rely on them.

5. Data security

We protect information using encryption in transit and at rest, role-based access controls, audit logging, and other administrative, technical, and physical safeguards appropriate to the sensitivity of the data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

6. Data retention

We retain information for as long as your account is active or as needed to provide the Service, and thereafter as required to comply with our legal obligations, resolve disputes, and enforce our agreements. Retention and deletion of PHI are governed by your BAA. You may request deletion of your account data as described below.

7. Your rights and choices

Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing. To make a request, contact us at contact@toxiq.us. If your information is PHI processed on behalf of a covered entity, please direct your request to that entity, which controls the record. You can also manage cookies through your browser settings.

8. Children's privacy

The Service is intended for professional use and is not directed to children under 18. We do not knowingly collect personal information directly from children.

9. International users

The Service is operated in the United States. If you access it from outside the United States, you understand that your information will be processed in the United States, which may have different data protection laws than your jurisdiction.

10. Text messaging (SMS)

We do not share, sell, rent, or otherwise provide your mobile phone number or messaging consent information to any third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are excluded from every information-sharing category in this Policy, including the service providers described in Section 3, and will not be shared with any third parties. Mobile information is used solely to send the check-in reminders described below.

By opting in, you agree to receive recurring automated text message check-in reminders from ToxIQ on behalf of your clinic. Message frequency varies. Message and data rates may apply. Reply STOP to unsubscribe or HELP for help.

Patients may opt in to text-message check-in reminders themselves, online. After completing a check-in at the clinic kiosk, a patient may enter their own mobile number and affirmatively consent on screen by checking a consent box that describes the messages, their frequency, and how to opt out. ToxIQ sends SMS reminders only to that number and only after this online opt-in; clinic staff cannot grant consent on a patient's behalf. Text messaging is optional and is not a condition of any treatment, program, or other service.

  • What we send — reminders to complete a required check-in. Messages include a link to the check-in page and contain no diagnostic information.
  • Frequency — varies; a patient is texted only on days they are selected for a check-in (typically a few messages per week).
  • Message and data rates — may apply, depending on the recipient's mobile plan.
  • Opting out — reply STOP to any message to stop all texts, or HELP for help. Opting out does not affect a patient's ability to check in through the public kiosk.
  • No sharing — mobile phone numbers, SMS opt-in information, and messaging consent are used only to send these reminders. ToxIQ does not share, sell, rent, or disclose this information to any third parties or affiliates for marketing or promotional purposes.

11. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

12. Contact

Questions about this Privacy Policy or our data practices? Contact us at contact@toxiq.us.