Legal
Privacy Policy
Last updated: May 10, 2026
1. Introduction
This Privacy Policy explains how Protocol MD ("Protocol MD," "we," "us," or "our") collects, uses, shares, and protects your personal information when you visit our website, complete the assessment, communicate with our affiliated providers, or otherwise use our services (collectively, the "Services").
Protocol MD is a technology and marketing platform operated by Protocol Studios LLC. Clinical services, including patient consultations, prescriptions, and ongoing care, are provided by independently owned and operated professional corporations through our affiliated provider network. Information you share with our affiliated providers in the course of clinical care is protected by the Health Insurance Portability and Accountability Act (HIPAA) and is governed by our HIPAA Notice of Privacy Practices.
2. Information we collect
Information you provide directly
- Contact information (name, email address, phone number, shipping address)
- Demographic information (date of birth, sex, state of residence)
- Health and wellness information (goals, symptoms, training history, medical history, current medications, lab results you upload)
- Payment information (processed and stored by our third-party payment processor; we do not store full card numbers)
- Communications you send to us, our affiliated providers, or our care team
Information collected automatically
- Device and connection information (IP address, browser type, operating system, device identifiers)
- Usage information (pages visited, time on site, referring URLs, click patterns)
- Cookies and similar technologies (see Section 7)
3. How we use your information
We use the information we collect to:
- Match you to a US-licensed physician credentialed in your state
- Facilitate clinical care through our affiliated provider network
- Process payments and arrange compounding pharmacy fulfillment
- Communicate with you about your assessment, prescription, shipment, and ongoing care
- Improve our Services, troubleshoot issues, and develop new features
- Comply with legal obligations and respond to lawful requests
- Detect, prevent, and address fraud, security incidents, and prohibited activity
4. How we share your information
We share your information with:
- Affiliated providers. Our network of independently practicing US-licensed physicians who review your case and provide clinical care.
- Compounding pharmacies and laboratories. 503A compounding pharmacies that dispense your prescribed protocol, and partner laboratories that process bloodwork ordered through the Services.
- Service providers. Vendors that help us operate our Services, including hosting, payment processing, customer support, email/SMS delivery, and analytics. Each is contractually obligated to handle your information consistent with this Policy and applicable law.
- Legal and safety. Authorities and other parties when we believe disclosure is required by law, necessary to enforce our Terms, or appropriate to protect the rights, property, or safety of Protocol MD, our users, or others.
- Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred to the successor entity, subject to this Policy.
We do not sell your personal information for monetary consideration. For information about your rights to opt out of certain "sharing" under California and other state privacy laws, see our Do Not Sell or Share My Personal Information notice.
5. Your rights and choices
Depending on your state of residence, you may have rights regarding your personal information, including:
- The right to access the information we hold about you
- The right to correct inaccurate information
- The right to delete certain information
- The right to opt out of targeted advertising, sale, or certain "sharing" of your information
- The right to limit our use of sensitive personal information
- The right to non-discrimination for exercising any of these rights
To exercise any of these rights, contact us at hello@protocolmd.com. We will respond consistent with applicable law.
6. Data retention and security
We retain your information for as long as your account is active, as needed to provide the Services, and as required by applicable law (including medical record retention requirements that apply to our affiliated providers, which may exceed your account term).
We implement technical and organizational measures designed to protect your information, including encryption in transit and at rest, access controls, and regular security assessments. No system is perfectly secure; we cannot guarantee absolute security.
7. Cookies and tracking technologies
We use cookies, pixels, and similar technologies to operate our Services, remember your preferences, measure performance, and (with your consent where required) deliver advertising. You can manage cookie preferences through your browser settings or our cookie preferences interface.
8. Children's privacy
Our Services are not intended for, and we do not knowingly collect information from, children under 18. If you believe we have collected information from a child under 18, please contact us and we will take steps to delete the information.
9. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Services or by email. The "Last updated" date at the top of this page reflects the most recent revision.
10. Contact us
Questions about this Policy? Email hello@protocolmd.com.