Privacy
FormularySignal Privacy Notice
Effective date: April 25, 2026. FormularySignal is an automated, software-generated and AI-assisted public-data monitoring service designed to run without patient data. Do not submit protected health information, patient identifiers, prescriptions, medical records, addresses, dates of birth, or individual treatment details.
Operator: FormularySignal. Contact: support@formularysignal.com. No professional review is claimed. This notice describes the current low-data design rather than promising a regulated healthcare or compliance service.
Data Collected
The service may collect work email, organization name, selected plan, billing identifiers from Stripe, watchlist terms, webhook URLs, additional report recipients, one-time billing-token metadata, and delivery preferences.
Data Use
Collected data is used to create checkout sessions, maintain subscriptions, generate customer-specific shortage watchlist reports, send service emails, provide support, and keep delivery and debugging records.
Processors
Stripe processes payments and billing metadata. Zoho Mail, Resend, or another transactional email provider may process report-delivery emails. Hosting and database providers may process service logs and stored watchlist configuration.
Payments
Payments are processed by Stripe. FormularySignal does not store card numbers.
Health Data
The service is not intended to receive PHI. If PHI is submitted accidentally, contact support promptly. The submitted data should be deleted from service systems where feasible, and the customer may be asked to resubmit a clean organization-level watchlist.
Retention and Deletion
Customer account and watchlist data is retained while a subscription or launch-pilot relationship is active. Delivery logs and public-data snapshots may be retained for debugging and source-history review. Customers may request deletion of account-specific data by contacting support, subject to billing, security, abuse-prevention, and backup-retention needs.
Security
FormularySignal is designed to minimize sensitive data collection. Production launch should use HTTPS, managed secrets, restricted database access, verified payment webhooks, and transactional email providers. No system can guarantee absolute security.
Cookies and Analytics
The current service does not include advertising cookies or third-party analytics scripts. If analytics are added before public launch, this notice should be updated.