WhatMeds® App Privacy Policy
The following is Humetrix's (“we,” “us,” “our,” or “Humetrix”) Privacy Policy (“Policy”) for the WhatMeds® mobile application (the “App”). A SHORTER PRIVACY NOTICE IS AVAILABLE HERE.
The App allows Users (defined below) to easily create a record about their health on their smartphone that they can make available to their healthcare providers in pharmacies, hospitals, outpatient clinics, emergency departments and in telemedicine encounters as well as with individual caregivers. The App generates a QR code that can be stored in a smartphone wallet or printed so that the record can be displayed to a healthcare provider by scanning the QR code using a smartphone or tablet.
“Users” or “you” in this Policy refers to individuals who download and use the app, not to healthcare providers who use their own smartphones or tablets to read the QR code generated by the App.
Humetrix is dedicated to protecting the privacy rights of Users of the App. Our policies with respect to the handling of Personal Data we collect from or about Users with respect to the App are described within this Policy.
“Personal Data” refers to information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to you or your household, and includes “personal information” or similar terms in applicable privacy laws.
We may change, add, or remove portions of this Policy at any time, and such changes shall become effective immediately upon posting. When posting a new Policy, we will release an App upgrade which will require the User to consent to the revised Policy in order to continue using the App.
This Policy applies when you interact with the App. It does not apply to third party websites that may be linked to or from the App; please review the privacy policies on those websites directly to understand their privacy practices.
Personal Data We Collect
We may collect the following Personal Data through the App:
- User-Provided Personal Data. Your contact information (e.g., name, email, or telephone number) in some circumstances, such as when you contact our support email or if you encounter problems with the app
- Personal Data Collected Automatically. Humetrix automatically collects technical data and related information about the User's device, operating system and application software that is gathered periodically to understand how Users are using the App, facilitate the provision of App updates, identify problems with the App, and provide product support to the User of the App.
The App is not supported via advertising and does not use the Personal Data it collects for advertising purposes. The App does not collect Personal Data about a User's online activities over time and across third-party Web sites or online services. The App is configured to automatically back up the information a User chooses to make available about themselves to the User's iCloud or Google Drive. Users may disable this feature in their device settings. No backup data is processed or stored by Humetrix.
How We Use the Personal Data We Collect
Humetrix may use any of the Personal Data we collect for the following purposes:
- Service functionality. Humetrix collects Personal Data provided by the User to provide the App's services, and conduct general business operations, such as accounting, recordkeeping, and audits.
- Service improvement. Humetrix uses automatically collected Personal Data to understand how Users are using the App, facilitate the provision of App updates, identify problems with the App, and provide product support to the User of the App.
- With your consent. Humetrix may use your Personal Data for any other purpose for which you provide Personal Data or as otherwise explained to you at the point of data collection.
How We Share the Personal Data We Collect
We may share your Personal Data (other than Health Data, defined below) with the following entities and for the following purposes:
- As required by law, such as to comply with a subpoena, or similar legal process;
- When we believe in good faith that disclosure is necessary to protect our rights, protect Users' safety or the safety of others, investigate fraud, or respond to a government request;
- To facilitate change of ownership or corporate organization. We may transfer to another entity or its affiliates or service providers some or all Personal Data in connection with, or during negotiations of, any merger, acquisition, sale of assets or any line of business, change in ownership control, or financing transaction. If the circumstances of the transaction allow it, we will provide you with notification about the transaction and in that notification explain the choices you may be able to exercise;
- With Service Providers: including cloud host providers and text messaging partners. On the Android version of the App, Humetrix uses software called Firebase Crashlytics to identify and fix any programming issues which could result in the App crashing. Humetrix does not use Firebase Crashlytics for purposes other than the ones stated above. Our providers do not independently use the information we disclose to them.
- With Your Consent: We may disclose your Personal Data for other reasons that we will describe at the time of data collection or prior to disclosing your information; or
- As otherwise provided in this Policy.
We do not share de-identified or pseudonymized information, nor do we share any Personal Data for automated decision-making purposes.
Personal Data We DO NOT Collect
You may provide the following Personal Data to the App, but Humetrix does not have access to it:
- Health Data. A list of current medications, the names of the pharmacies where the medications were dispensed and the names of the providers who prescribed the medications. Users who are enrolled in a Medicare Part D program or Medicare Advantage plan with prescription drug coverage can download a list of their medications onto the App from the CMS Blue Button 2.0 API (collectively, “Health Data”).
Humetrix does not have access to Health Data and has no way to share Health Data with anyone, including with law enforcement. The only way for Health Data to be viewed or shared is for the User (or a person with access to the User's device who is able to access the App) to open the App and view or share Health Data through the App. The timeliness, accuracy, relevance, and completeness of Health Data is the sole responsibility of the User.
When you create a profile, you create a medication list for yourself by connecting to Medicare or manually entering your medications. You also have the option to create a medication list for any other person for whom you are a caregiver. Once you create an additional profile for another person, they must use their own confidential Medicare log-in credentials and affirmatively consent on the Medicare webpage to download their information to their profile in the app.
We do not use de-identified or pseudonymized information, nor do we use any Personal Data for automated decision-making purposes.
Using the App to Share your own Health Data
All Health Data collected by the App is encrypted and stored on your phone. You may also choose to upload select Health Data to our servers for the purpose of enabling you to share your Health Data with your healthcare provider. The health data uploaded cannot be read by Humetrix or its cloud service provider. The App enables you to determine exactly which medications you want to display to your healthcare provider when they scan your QR code.
Users may share the Health Data they record in the App with their healthcare provider or other third parties authorized by the User, at the User's sole discretion.
Data Retention
Humetrix does not retain any personal health information added by you to the WhatMeds app. The WhatMeds app stores information until you delete or edit that information in the App or delete the App. Humetrix may otherwise retain information as required by law.
Users' Choices
You may withdraw your consent to our data processing by deleting the profile in the App or deleting the app. Once you withdraw your consent all User Personal Information is permanently deleted. A User may also edit or delete any and all of the information they record in the App by using the edit function. When a User creates a QR code to share their personal information, this information is stored on a Humetrix server but cannot be read by Humetrix and is automatically deleted after 24 hours. To access, rectify, delete, or port data, Users should open the App and make their desired changes; the data in the app can be transferred to another device by creating a QR code in the app and scanning this code with another device. Users may contact us at the address below for technical support.
Please note: To process requests, we may need to verify identity, in which case we may require Users to provide us with Personal Data necessary for verification.
Security
Humetrix takes the security of your Personal Data seriously. Humetrix takes such actions as are reasonably necessary to prevent unauthorized access to information that it collects. Humetrix uses security and/or encryption technology, including SSL/TLS encrypted endpoints using the HTTPS protocol to secure information collected from Users when that information is transmitted to Humetrix's servers or to transmit such information to a browser in response to the scanning of the QR code produced by the App. Humetrix restricts access to information stored on its servers and secures the content by use of encryption technologies and other security methods. However, Humetrix cannot guarantee that these practices will prevent unauthorized attempts to access, use, or disclose the information it stores. For example, an unauthorized party could access information about the User by breaking into the User's phone. Users enter information into the App at their own risk and should take appropriate steps to maintain the security of their information and their device.
Children
The App is intended for Users age eighteen and older. We do not knowingly collect information from children. If we discover that we have inadvertently collected information from anyone younger than the age of 18, we will delete that information.
California Privacy Rights
Humetrix does not disclose personal information to third parties for those third parties' marketing purposes. Due to the privacy and security-by-design features of the App, Humetrix does not view or manipulate the personal data that a User makes a part of their record. For information on how to exercise your California privacy rights, please review the “Users' Choices” section above.
Data Protection Officer Contact, Questions, Complaints, and Other Contacts
If you have any questions about this Policy or Humetrix's policies and practices concerning the App, you can contact Humetrix by mail at the address below or by email to whatmeds.support@humetrix.com:
Humetrix
1155 Camino Del Mar, #503
Del Mar, California 92014
The contact information for Humetrix's Data Protection Officer is:
Dr Christopher R. Burrow
Humetrix
1155 Camino Del Mar, #503
Del Mar, California 92014
Phone: +1-858-259-8987
Email: cburrow@humetrix.com
Updated: March 20, 2026