ThriveMed Privacy Policy and SMS Terms & Conditions
Effective Date: August 12, 2026
Last Updated: August 12, 2026
1. Overview
Thrivemed.ai (“ThriveMed,” “we,” “us,” or “our”) is committed to protecting your personal information and health data. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard information when you:
Visit or use Thrivemed.ai or another ThriveMed website, application, or digital service that links to this Privacy Policy;
Create or maintain a ThriveMed account;
Use our digital twin modeling tools, wearable integrations, health-guidance features, or related services;
Communicate with us by telephone, voicemail, email, or SMS/MMS text message; or
Otherwise interact with ThriveMed.
This Privacy Policy also includes the terms that apply to ThriveMed’s conversational SMS messaging program.
By using ThriveMed’s websites or services, you acknowledge the practices described in this Privacy Policy.
ThriveMed does not sell, rent, or trade your personal information or health data.
2. Scope of This Privacy Policy
This Privacy Policy applies to the personal information collected through ThriveMed’s websites, applications, digital health services, communications, and other services that link to this policy.
It does not apply to websites, applications, devices, or services operated independently by unaffiliated third parties, even when those services are linked to or integrated with ThriveMed. Those organizations maintain their own privacy practices, and we encourage you to review their privacy policies before providing information.
3. HIPAA and Protected Health Information
ThriveMed is designed to support compliance with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) where HIPAA applies.
Depending on the service and relationship involved, ThriveMed may act as a healthcare provider, covered entity, business associate, or technology service provider. Information that qualifies as protected health information (“PHI”) will be collected, used, maintained, and disclosed in accordance with applicable HIPAA requirements and contractual obligations.
If ThriveMed processes your PHI on behalf of a healthcare provider or another covered entity, that organization’s Notice of Privacy Practices may also apply. If this Privacy Policy conflicts with an applicable Notice of Privacy Practices concerning PHI, the Notice of Privacy Practices will control.
Where required by HIPAA, ThriveMed enters into Business Associate Agreements with service providers that create, receive, maintain, or transmit PHI on our behalf.
4. Information We Collect
We collect information necessary to operate our platform, provide personalized services, maintain your digital twin, communicate with you, and protect the security of our services.
4.1 Account and Contact Information
We may collect:
Your name;
Email address;
Mobile or telephone number;
Mailing address;
Date of birth;
Account credentials;
Communication preferences; and
Other information you submit when creating or updating an account.
4.2 Health and Biometric Information
Depending on the services you use, we may collect:
Biomarkers and biometric measurements;
Biomechanical information;
Laboratory and diagnostic results;
Medical and health history;
Medication, treatment, or care information;
Physical and mental health information;
Nutrition, activity, sleep, and recovery information;
Lifestyle information and behavioral patterns;
Health goals, preferences, and values; and
Information relating to ThriveMed’s Biome, Connectome, Exposome, and Spiritome domains.
Some of this information may qualify as sensitive personal information or PHI under applicable law.
4.3 Digital Twin and Simulation Information
We may generate and maintain information derived from the data you provide, including:
Personalized digital twin models;
Health simulations and projections;
Intervention recommendations;
Risk indicators;
Health trends and patterns; and
Evidence-based health insights.
These models and outputs may change as new information becomes available.
4.4 Self-Reported Information
We may collect information that you voluntarily submit through:
Questionnaires;
Health assessments;
Surveys;
Website forms;
Account features;
Support requests;
Telephone or text conversations; and
Other communications with ThriveMed.
4.5 Wearable and Integration Data
With your authorization, we may receive information from connected:
Wearable devices;
Healthcare systems;
Laboratories;
Health applications; and
Third-party health platforms, such as Whoop.
The information we receive depends on the permissions you grant and the features made available by the connected service. You may be able to disconnect an integration through your ThriveMed account settings or through the third party’s platform.
4.6 Appointment, Billing, and Transaction Information
When applicable, we may collect:
Appointment requests;
Scheduling information;
Billing information;
Payment information;
Insurance-related information;
Subscription information;
Purchase history; and
Transaction records.
Payment information may be processed directly by a third-party payment processor. ThriveMed may not receive or retain complete payment-card information.
4.7 Communications Information
When you contact ThriveMed, we may collect:
Emails and support requests;
Mobile and telephone numbers;
SMS and MMS message content;
Voicemail messages;
Call and message logs;
Dates, times, and duration of communications; and
Call recordings or transcripts when those features are enabled and permitted by law.
4.8 Device and Usage Information
We may automatically collect certain technical information, including:
IP address;
Browser type;
Device type and device identifiers;
Operating system;
Internet service provider;
Login and authentication activity;
Pages or features accessed;
Referring URLs;
Dates and times of access;
Platform interactions; and
Diagnostic, security, and performance information.
5. How We Collect Information
We may collect information:
Directly from you;
Through your use of ThriveMed’s websites, applications, and services;
From healthcare providers or members of your authorized care team;
From connected devices and third-party platforms you authorize;
Through cookies and similar technologies;
Through telephone, voicemail, email, and text communications;
From organizations through which you access ThriveMed; and
From service providers that support our operations.
6. How We Use Your Information
We may use your information to:
Create, operate, and update your personalized digital twin;
Generate simulation-based recommendations aligned with your health goals;
Provide evidence-based insights across ThriveMed’s Biome, Connectome, Exposome, and Spiritome domains;
Integrate information from authorized wearable devices, healthcare systems, and third-party platforms;
Create and manage your account;
Authenticate users and prevent unauthorized access;
Provide, personalize, maintain, and improve ThriveMed’s platform and services;
Respond to your questions, inquiries, and support requests;
Process appointments, transactions, and subscriptions;
Communicate with you about your account, services, security, and relevant health information;
Protect against fraud, misuse, security incidents, and unlawful activity;
Maintain required healthcare, business, and regulatory records;
Enforce our agreements and policies;
Comply with applicable laws and regulatory obligations; and
Establish, exercise, or defend legal claims.
Where permitted, we may use aggregated or de-identified information to improve our platform, simulation engine, clinical algorithms, research methods, and services.
We will not attempt to re-identify properly de-identified information except when permitted by law to determine whether our de-identification procedures remain effective.
ThriveMed does not use identifiable health information to train generally available artificial intelligence models unless there is an appropriate legal basis, applicable safeguards, and any authorization or consent required by law.
7. How We Disclose Information
ThriveMed does not sell, rent, or trade your personal information or health data.
We may disclose information in the following limited circumstances.
7.1 Healthcare Providers and Care Teams
We may disclose information to healthcare practitioners, care teams, laboratories, or healthcare organizations when you authorize the connection or when the disclosure is otherwise permitted by law.
7.2 Service Providers
We may provide information to vendors that perform services on our behalf, including providers of:
Cloud hosting and data storage;
Communications services;
Cybersecurity services;
Platform maintenance;
Technical support;
Payment processing;
Authentication;
Analytics; and
Professional or administrative services.
Service providers may access information only as necessary to perform services for ThriveMed and are prohibited from using it for their own independent purposes.
Where required, vendors that create, receive, maintain, or transmit PHI on ThriveMed’s behalf must enter into a Business Associate Agreement.
7.3 White-Label and Business Partners
If you access ThriveMed through a healthcare organization, insurer, employer, wellness provider, or other white-label partner, that partner may receive information as described in:
Its privacy notice;
Its agreement with you; and
Its agreement with ThriveMed.
7.4 At Your Direction
We may disclose information to another person or organization when you request or authorize us to do so.
7.5 Legal and Safety Requirements
We may disclose information when we reasonably believe disclosure is necessary to:
Comply with a law, regulation, subpoena, court order, or valid legal process;
Respond to an authorized government request;
Investigate suspected fraud, abuse, or security incidents;
Enforce our agreements or policies;
Protect ThriveMed’s rights or property; or
Protect the health, rights, safety, or security of our users or the public.
When legally permitted and appropriate, we may notify you before responding to a request for your information.
7.6 Business Transfers
Information may be transferred as part of a proposed or completed merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar business transaction.
Any recipient will remain subject to applicable privacy and security obligations.
8. SMS Terms & Conditions
8.1 SMS Program Description
ThriveMed uses Dialpad, a third-party communications provider, to facilitate telephone, voicemail, and SMS/MMS communications.
ThriveMed’s SMS program is intended for conversational, two-way communications. Messages may be used to:
Respond to inquiries you submit;
Answer your questions;
Provide customer support;
Address requests you make;
Continue conversations you initiate; and
Provide information directly related to an existing conversation.
ThriveMed’s conversational SMS program is not used to send promotional offers or advertising messages.
8.2 Information Processed Through Dialpad
When you communicate with ThriveMed through Dialpad, ThriveMed and Dialpad may process:
Your name;
Your mobile telephone number;
SMS and MMS message content;
Voicemail messages;
Call or message dates and times;
Communication duration;
Communication logs; and
Call recordings or transcripts when enabled and permitted by law.
Dialpad processes this information as a service provider to ThriveMed in accordance with its applicable agreements and privacy practices.
8.3 SMS Consent
You may consent to receive conversational text messages from ThriveMed by:
Initiating a text-message conversation with ThriveMed;
Checking an optional SMS consent box on a ThriveMed form;
Requesting text-message communication during a telephone or in-person conversation; or
Otherwise expressly asking ThriveMed to communicate with you by text message.
Consent to receive text messages is not a condition of purchasing or receiving any ThriveMed product or service.
If you initiate a text conversation with ThriveMed, you consent to receive responses that are relevant to your inquiry or request.
8.4 Message Frequency
Message frequency varies based on the nature of your conversation, your requests, and your interactions with ThriveMed.
8.5 Message and Data Rates
Standard message and data rates may apply according to your mobile carrier and service plan.
Mobile carriers are not responsible for delayed or undelivered messages.
8.6 Opting Out
You may opt out of receiving text messages from ThriveMed at any time by replying STOP to any ThriveMed text message.
After replying STOP, you may receive one final confirmation message stating that you have been unsubscribed. ThriveMed will stop sending text messages to your number unless you initiate another conversation or otherwise provide consent to receive messages again.
8.7 Help and Customer Support
For assistance with ThriveMed’s SMS program, reply HELP to any ThriveMed text message.
You may also contact ThriveMed customer support at:
Website:https://www.thrivemed.us
Privacy Email:privacy@thrivemed.ai
8.8 Mobile Information and Consent Data
ThriveMed does not sell or rent your mobile information.
No mobile information will be shared with third parties or affiliates for their marketing or promotional purposes.
Text-message originator opt-in data and consent will not be shared with third parties, except with service providers that help ThriveMed deliver its messaging services. These service providers are permitted to use the information only to provide services to ThriveMed and not for their own purposes.
8.9 Sensitive Information and Emergencies
Standard SMS and MMS communications may not be encrypted. Do not send highly sensitive medical, financial, payment, or identification information by text unless ThriveMed instructs you to use an approved secure method.
Text messaging should not be used for emergencies. If you believe you are experiencing a medical emergency, call 911 or your applicable local emergency number immediately.
9. Call Recording and Transcription
When enabled, ThriveMed may record or transcribe telephone calls for:
Documentation;
Quality assurance;
Training;
Security;
Regulatory compliance; and
Service improvement.
When required by law, ThriveMed will provide notice or obtain consent before recording or transcribing a call.
If you do not want a call to be recorded or transcribed, notify the ThriveMed representative at the beginning of the call. When reasonably available, we will provide another communication method.
Recordings, transcripts, and related communications may contain personal information or PHI and will be protected accordingly.
10. Cookies and Similar Technologies
ThriveMed may use cookies, web beacons, pixels, software development kits, and similar technologies to:
Authenticate users;
Maintain secure sessions;
Remember preferences;
Operate platform features;
Diagnose technical problems;
Measure platform performance;
Understand how the platform is used; and
Protect against fraud and unauthorized activity.
We may use analytics cookies to understand platform use in an aggregated manner. ThriveMed does not use identifiable health information to create cross-site advertising profiles.
You may manage cookies through your browser or device settings and, where available, through ThriveMed’s cookie-preference tools. Disabling cookies may prevent certain features from functioning properly.
11. Aggregated and De-Identified Information
We may create aggregated or de-identified information that cannot reasonably be linked to you.
We may use and disclose this information for lawful purposes, including:
Improving the ThriveMed platform;
Improving clinical algorithms and digital twin models;
Conducting research and statistical analysis;
Measuring service effectiveness;
Developing new features; and
Supporting operational planning.
Where information has been de-identified under HIPAA or another applicable law, ThriveMed will maintain it in de-identified form and will not attempt to re-identify it except as permitted by law.
12. Data Retention
We retain personal and health information for as long as reasonably necessary to:
Maintain your account;
Provide the services you request;
Fulfill the purposes described in this Privacy Policy;
Maintain required healthcare, business, and transaction records;
Resolve disputes;
Enforce our agreements; and
Comply with legal, regulatory, and contractual obligations.
Communications processed through Dialpad may be retained according to ThriveMed’s account configuration, contractual arrangements, operational requirements, and applicable law.
You may request deletion of your account and associated information. However, ThriveMed may retain certain information when required or permitted by healthcare, tax, insurance, legal, security, contractual, or recordkeeping requirements.
Aggregated or properly de-identified information may be retained for a longer period, including indefinitely, because it cannot reasonably be linked to you.
13. Data Security
ThriveMed uses reasonable and appropriate administrative, technical, and physical safeguards designed to protect personal information and PHI.
Depending on the information and services involved, these safeguards may include:
Encryption during transmission and storage;
Role-based access controls;
Authentication and account-security measures;
Audit logging and access monitoring;
Workforce privacy and security training;
Vendor security reviews;
Business Associate Agreements where required;
Vulnerability management;
Security testing;
Incident-response procedures; and
Backup and recovery measures.
No website, platform, telephone system, email service, text-message service, or electronic storage method is completely secure. Therefore, ThriveMed cannot guarantee absolute security.
You are responsible for protecting your password and account credentials. Notify ThriveMed promptly if you believe that your account or information has been accessed without authorization.
14. Your Privacy Rights and Choices
Depending on your location, relationship with ThriveMed, and applicable law, you may have the right to:
Access personal information maintained about you;
Receive a copy of your information;
Correct or update inaccurate information;
Request deletion of certain information;
Restrict or object to certain processing;
Withdraw consent for optional processing;
Disconnect wearable devices and third-party integrations;
Request data portability in a machine-readable format;
Opt out of text messages by replying STOP; and
Submit a complaint concerning ThriveMed’s privacy practices.
If HIPAA applies to your information, you may also have the right to:
Inspect and obtain a copy of your PHI;
Request an amendment to your PHI;
Request restrictions on certain uses and disclosures;
Request confidential communications;
Receive an accounting of certain disclosures; and
Receive a copy of the applicable Notice of Privacy Practices.
These rights are subject to applicable exceptions and legal record-retention requirements.
To exercise a privacy right, contact privacy@thrivemed.ai. ThriveMed may need to verify your identity before fulfilling your request.
If ThriveMed processes information on behalf of another healthcare organization, we may direct your request to that organization.
ThriveMed will not discriminate against you for exercising a privacy right granted by applicable law.
15. Children’s Privacy
ThriveMed’s services are not directed to individuals under 18, and we do not knowingly collect personal information directly from individuals under 18 without appropriate authorization from a parent, guardian, healthcare provider, or other authorized representative.
If you believe that a minor has provided personal information to ThriveMed without appropriate authorization, contact us at privacy@thrivemed.ai. We will review the matter and take appropriate action, including deleting information when required.
16. Third-Party Services and Links
ThriveMed’s platform may include links to or integrations with websites, devices, applications, and services operated by third parties.
ThriveMed does not control and is not responsible for the content, security, or privacy practices of unaffiliated third parties. Your interactions with those services are governed by their own terms and privacy policies.
Connecting a third-party service to ThriveMed authorizes the transfer of information according to the permissions you select and the third party’s applicable policies.
17. International Data Transfers
ThriveMed and its service providers may process and store information in the United States and other countries where they operate.
If you access ThriveMed from outside the United States, your information may be transferred to a country whose data-protection laws differ from those in your jurisdiction. Where required, ThriveMed will use appropriate safeguards for international data transfers.
18. Changes to This Privacy Policy
We may update this Privacy Policy as our platform, services, technologies, or legal obligations evolve.
When changes are made, we will update the “Last Updated” date at the beginning of this policy. If a change materially affects how we collect, use, or disclose personal information, we may provide additional notice through email, the ThriveMed platform, or a prominent website notice as required by law.
Where applicable law requires consent to a change, ThriveMed will request that consent separately.
19. Contact ThriveMed
If you have questions, concerns, complaints, or requests concerning this Privacy Policy, contact:
ThriveMed
Website:https://www.thrivemed.us
Privacy Email:privacy@thrivemed.ai