This Privacy Policy describes the policies and procedures of ArcLine Ventures, LLC (“we,” “us,” or “Alethro”) regarding the collection, use, and disclosure of information when you use the Alethro website (the “Service”), including alethro.com and any related applications operated by us.
We respect your privacy and have designed Alethro to minimize the personal information we collect. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
1. The short version
The Alethro cost calculator is designed to run primarily in your web browser. The drug names, insurance plan selections, deductible figures, dose, quantity, and zip code you enter into the calculator are processed locally in your browser and used to compute and display estimates. We do not maintain a server-side database of individual users’ calculator inputs. We do not require you to create an account.
Limited information is logged at the infrastructure level (request logs, server logs) for security, abuse prevention, and operational diagnostics. We do not currently use third-party analytics, advertising networks, or behavioral-tracking pixels on this site.
2. Information you provide directly
Calculator inputs
When you use the prescription cost calculator, you provide information including the drug name, dose, quantity, insurance plan, deductible status, and zip code. This information is processed in your browser. If you choose to share a result link, the inputs are encoded into the URL itself and are not separately stored.
Communications
When you contact us by email or other means, we receive your name, email address, and any content you choose to share. We retain these communications as needed to respond and for our records.
3. Information collected automatically
Server logs
When you visit any website, your browser automatically sends standard request information to the hosting infrastructure, including your IP address, user-agent string, referrer URL, requested URL, and timestamp. We retain these logs for security, abuse detection, and operational purposes for a reasonable period (typically up to 90 days), after which they are deleted or aggregated.
Aggregated, non-personal information
We may collect aggregated, anonymized information about how the Service is used, such as the total number of calculations performed or the popularity of certain drug pages. This information is not linked to identifiable individuals and is used to improve the Service.
Backend lookup metadata
When the calculator queries our backend formulary lookup service (which retrieves real-time formulary tier information from public web sources via search and language-model APIs), we transmit the plan identifier and drug identifier you selected. We may cache the resulting tier information for up to 30 days to improve speed and reduce cost. We do not transmit identifying information about you (no IP, no user identifier) along with these queries beyond what is necessary for routing.
4. Cookies, local storage, and similar technologies
We do not use third-party advertising cookies, behavioral-tracking cookies, or analytics cookies as of the date above. We may use limited essential cookies or browser local storage for functional purposes, such as remembering your preferences within a single session. If we add analytics or other non-essential tracking technologies in the future, we will update this Privacy Policy and provide a consent mechanism where required by applicable law.
We honor browser-based opt-out signals where required, including the Global Privacy Control (GPC) signal under California law. We do not knowingly track users across third-party websites or services.
5. How we use information
We use the limited information we collect to:
- Operate, maintain, and provide the features and functionality of the Service
- Diagnose technical problems, prevent fraud and abuse, and ensure the security and integrity of the Service
- Respond to your inquiries, support requests, and feedback
- Comply with applicable laws, regulations, and legal processes
- Enforce our Terms of Service and protect the rights, property, and safety of Alethro, our users, and the public
6. How we share information
We do not sell, rent, lease, or trade information about you. We may share information in the following limited circumstances:
- Service providers. We work with third-party service providers who perform services on our behalf. These providers may process limited information solely to provide their services and are contractually bound to maintain confidentiality. Current providers include: Vercel (hosting), Neon (database), OpenAI (language-model API for formulary extraction), Tavily (search API for formulary discovery), LlamaIndex (PDF parsing), and email providers used for transactional communications. Our service providers operate under their own privacy policies, which we evaluate before engaging.
- Legal compliance. We may disclose information when required by law, court order, subpoena, or other valid legal process; to respond to government or regulatory requests; to enforce our Terms of Service; or to protect the rights, property, or safety of Alethro, our users, or the public.
- Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction. We will provide notice on this site or by email before any such transfer.
- With your direction. We share information with third parties when you direct us to do so, such as by sharing a calculator result link.
7. Your privacy rights
Depending on your state of residence, you may have rights under applicable privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Washington My Health My Data Act (MHMDA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), and similar laws in other states (collectively, “State Privacy Laws”).
The rights you may have
- Right to know / access. Request information about what personal information we hold about you and how we use it.
- Right to delete. Request that we delete personal information we hold about you, subject to legal exceptions.
- Right to correct. Request that we correct inaccurate personal information we hold about you.
- Right to opt out of sale or sharing. Direct us not to sell or share your personal information for cross-context behavioral advertising. We do not currently sell or share personal information for these purposes.
- Right to limit use of sensitive personal information. Direct us to limit our use of certain sensitive personal information. We do not collect such information beyond what is necessary to provide the Service.
- Right to non-discrimination. You will not be discriminated against for exercising any of these rights.
- Right to data portability. Request a copy of personal information we hold about you in a machine-readable format.
- Right to withdraw consent. Where processing is based on consent, you may withdraw consent at any time.
How to exercise your rights
To exercise any of these rights, contact us using the information in Section 13 below. We will verify your identity before responding to substantive requests, typically by confirming information you provide matches what we have on file. We will respond within the time required by applicable law (generally 45 days under CCPA/CPRA, with one possible 45-day extension; 30 days under MHMDA; 45 days under VCDPA, CPA, CTDPA, and UCPA).
Authorized agents
California residents may designate an authorized agent to make a request on their behalf. The agent must provide written, signed authorization, and we may require you to verify your identity directly with us before honoring the request.
Appeals
If we deny your request, you may appeal our decision by replying to our denial response. We will respond to your appeal within the time required by applicable law (typically 45 to 60 days). If we deny your appeal, you may have the right to contact your state attorney general.
8. Consumer health data (Washington MHMDA)
The Washington My Health My Data Act (MHMDA) provides specific rights to Washington residents regarding consumer health data. Although we believe we do not collect “consumer health data” as defined in MHMDA in a manner that triggers the act’s obligations (because calculator inputs are processed in your browser and not stored on our servers), we provide this notice for transparency:
- We do not sell consumer health data.
- We do not collect consumer health data beyond what is necessary to provide the Service in your browser.
- We do not share consumer health data with third parties for advertising or marketing purposes.
- If you are a Washington resident, you may exercise rights specific to consumer health data, including the right to confirm, withdraw consent, delete, and access third parties with whom data has been shared. Contact us at the address in Section 13 to exercise these rights.
9. Data retention
We retain information only for as long as necessary to fulfill the purposes for which it was collected, comply with our legal obligations, resolve disputes, and enforce our agreements. Specifically:
- Server access logs: typically up to 90 days, then deleted or aggregated
- Communications you send to us: retained for as long as needed to respond and for our records, typically up to 24 months unless a longer retention is required by law
- Backend formulary cache (plan identifier + drug identifier + tier data): up to 30 days, then refreshed; this cache is not personally identifiable
10. Security
We use reasonable administrative, technical, and physical safeguards to protect the information we hold, including encryption in transit (HTTPS), encrypted storage of API credentials, access controls on our infrastructure, and regular security reviews of our service providers. No method of transmission over the internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.
11. Children
The Service is not directed to and is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us at the address in Section 13 and we will take appropriate steps to delete it. For users between the ages of 13 and 18, we encourage parental involvement and supervision.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the date of the most recent change. If we make material changes, we will notify you by posting a notice on the Service home page or by other means as required by applicable law. Your continued use of the Service after changes become effective constitutes acceptance of the revised Privacy Policy.
13. International users
Alethro is operated from the United States and is intended for users in the United States. If you access the Service from outside the United States, your information will be processed in the United States, which may have data-protection laws that differ from those in your country. By using the Service, you consent to such processing.
14. Operator and contact
Alethro is operated by ArcLine Ventures, LLC, an Illinois limited liability company. For privacy questions, requests to exercise your rights, deletion requests, or any other inquiry, contact us via the contact page or by emailing privacy@alethro.com.
For mail correspondence, contact information is available on our contact page. Please include sufficient information to identify yourself (such as the email address you have used to communicate with us) so we can verify and respond to your request.