Privacy
How RxAccess handles the information it receives.
Updated
You can read the registry and use the eligibility checker without creating an account. This page explains which answers stay in your browser, which requests reach our server, and what we store when you contact us.
The eligibility checker
The eligibility calculation runs in your browser. Your insurance, income, household-size, and state answers are used on your device and are not sent to our servers. Selecting a medication sends its identifier to our server to update an aggregate demand count, described below. Closing the page discards the checker answers held in memory.
What we collect
- Search requests. The medication search sends the words you enter to our server to find matching results. Search words can appear in the page URL and browser history.
- Contact and corrections. We keep the details you submit so we can review and reply, as described below.
- API access requests. We store your name, email, stated use case, and whether the proposed use is commercial, to review and administer access.
- Network requests. Our hosting and delivery services receive technical information needed to handle requests, such as IP addresses and requested URLs. Infrastructure logs are separate from the aggregate counters described below.
Service providers process information to host the site, deliver messages, and prevent abuse. When Cloudflare Turnstile is configured on a form, its verification request includes a challenge token and IP address. These service operations are separate from optional Google Analytics.
Usage counts
We record limited usage events, such as starting or completing the checker and clicking a program or service link. The event records contain the event type, permitted category information, language, and time. They do not include checker answers, IP addresses, cookie identifiers, or account identifiers. Medication demand counts are recorded separately, as described below.
Some links to official programs and services include fixed referral tags identifying RxAccess as the source of the visit. These tags do not contain your checker answers, medication searches or a personal identifier. The destination site handles your visit under its own privacy policy.
Contact form
If you use the contact form, we collect the name, email address, topic, and message you submit. We use this only to read and reply to your message, and to administer the inquiry. Hosting and message-delivery providers process it to provide those services; we do not use contact messages for marketing. If you report a data correction, your message may be used internally to verify and fix the program or medication record you're describing.
Your message is screened automatically and rejected (not stored) if it appears to contain health details, a diagnosis, or financial information. The form's own on-page note asks you not to include those, since we only need enough detail to reply. We also record a one-way hash of the IP address you submitted from, never the address itself, solely to detect and limit abusive submission patterns; the hash is stored with the contact record for abuse prevention and is not published. A hash should not be treated as anonymous information.
We keep contact messages for as long as they might still be useful for the correction, question, or inquiry they concern. If you want a message and its details deleted, use the contact form again and ask, or reference the topic and approximate date of your original message.
Field reports
If you submit a field report (what happened with your patient assistance program application, the program and any medication selected, how long it took, the outcome, an optional tip), we ask for your email address once, to confirm a real person submitted it. We use that email only to send you a one-time confirmation link and, if you separately check the optional consent box, occasional updates about patient assistance programs; those are two different things, and checking one never turns on the other. Your email is not published or shown to other visitors. Hosting and email-delivery providers process it to provide the service.
Every field report is reviewed by a person before anything from it appears publicly. If approved, only the anonymous, dated content you wrote (a statistic your report contributes to, or a tip you left) appears on the Site, never your name or email. We automatically remove anything that looks like an email address, phone number, or web link from a tip before it's even reviewed, and an automated screen rejects submissions that match prohibited income, diagnosis, or dosage patterns. Automated screening may miss sensitive information, so please do not include it.
We keep the submission (including your email, for verification and moderation purposes, alongside the selected program and medication) for as long as the report might still be useful to keep the Site's statistics accurate. If you want your field report and email deleted, use the contact form with the email address you submitted it under and we will remove it.
Site analytics
With your permission, Google Analytics 4 (GA4) measures visits to selected general information pages. It is excluded from medication, program, search-results, eligibility-checker, contact, field-report, tracker, and API-key retrieval pages. On pages where it is enabled, we send a page address without its query string or fragment and suppress the referring-page address.
GA4 uses cookies and processes device and visit information. Its records can connect visits made using the same analytics identifier; this differs from our aggregate medication counters. Google processes information under its privacy policy.
GA4 loads only after you accept. Declining leaves the site usable. Your choice is stored in your browser. If Global Privacy Control is enabled, the site does not load GA4. We do not use these analytics to advertise or retarget you.
Medication demand counts
Selecting a medication in the checker or search, or opening a medication page, can send its identifier to our server. The demand counter stores a running total by medication, date, and source (checker, search, or page).
The counter table does not store IP addresses, session or cookie identifiers, device details, account identifiers, or other checker answers. It cannot count unique people or link one counter entry to another person's visit. This describes the counter table, not all network processing by the site and its service providers.
We may publish these aggregate totals as a Demand Index alongside the registry's coverage figures.
Global Privacy Control
When your browser sends Global Privacy Control, we treat it as a refusal of optional Google Analytics and do not load the Google tag. This does not prevent the network requests needed to deliver pages, process searches or forms, or record the limited first-party counts described above.
Medication pages
Medication pages use the aggregate demand counter described above. Google Analytics is excluded from these pages. Opening a page still makes a network request to our hosting and delivery services; the medication name is part of its URL.
Questions
This page describes the Site's practices as of the date below. If practices change (for example, if we add optional email alerts), this page will change first.
Updated: 09/04/26.