Privacy Policy & Notice of Health Information Practices
Last Updated: September 11, 2026
Finally Clear™ (“Finally Clear,” “we,” “us,” or “our”) is committed to protecting your personal information and your Electronic Protected Health Information (“ePHI”). This Privacy Policy explains how we collect, use, disclose, and protect your information when you access our website, use our screening tools, book virtual clinical consultations, or communicate with us via short message service (“SMS”) text messages, phone, or email.
We provide telehealth care coordination and administrative services connecting patients in Arizona, Georgia, and Tennessee with licensed healthcare providers. Because we operate in healthcare, our practices strictly comply with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the Health Information Technology for Economic and Clinical Health Act (“HITECH”), the Telephone Consumer Protection Act (“TCPA”), and applicable mobile carrier A2P 10DLC compliance standards.
1. Information We Collect
We collect information directly from you, automatically through your interactions with our site, and through our clinical intake workflows:
- Contact & Demographic Identifiers: Full legal name, date of birth, home address, state of residence, email address, and mobile phone number.
- Protected Health Information (PHI): Medical history, acne history, past treatment records, photographic images of your skin, pregnancy status, reproductive safety attestations, lab requisitions, and clinical intake notes.
- Billing & Payment Information: Payment card details and transaction history. Financial payment processing is handled securely by our third-party payment gateway (Stripe) in compliance with PCI-DSS standards; Finally Clear does not directly store raw payment card numbers.
- Technical & Usage Metadata: Limited server logs and sanitized device data. We do not transmit unhashed medical context or identifiable user data to commercial advertising networks.
2. HIPAA Compliance & Protected Health Information (PHI)
When you submit health information, diagnostic questionnaire responses, or photos through our screening funnel, that information constitutes Protected Health Information governed by HIPAA.
- Business Associate Agreements (BAAs): We only transmit PHI through secure infrastructure governed by signed Business Associate Agreements. This includes our electronic health record (“EHR”) partners, HIPAA-compliant customer relationship management systems, encrypted data pipeline bridges, and laboratory partners.
- Server-Side Data Sanitization: We do not deploy standard, unvetted client-side tracking pixels (such as the default Meta Pixel or Google Analytics tags) on pages that collect patient health conditions or booking actions. All marketing conversion signals pass through server-side privacy middleware that strips personal identifiers, redactions, and IP addresses before transmitting non-identifiable telemetry.
- Permitted Uses: Your PHI is accessed strictly for healthcare treatment, coordination with your licensed clinician, laboratory routing (e.g., Quest Diagnostics or Labcorp), electronic prescription delivery to your chosen retail or partner pharmacy, and mandated compliance with the FDA iPLEDGE Risk Evaluation and Mitigation Strategy (REMS) program.
3. SMS, Text Messaging & A2P 10DLC Compliance
Finally Clear utilizes Application-to-Person (“A2P”) 10DLC compliant messaging infrastructure to send transactional, clinical, operational, and customer support SMS text messages.
- Explicit Opt-In Consent: You must provide clear, affirmative consent to receive SMS communications from Finally Clear by actively checking our consent checkbox during the screening or checkout process. Consent is not a condition of purchasing any goods or services.
- Message Categories: Messages sent to your mobile device may include:
- Consultation booking confirmations and provider schedule links.
- FDA iPLEDGE REMS timeline alerts, 7-day pickup window warnings, and monthly check-in reminders.
- Laboratory draw reminders and negative test photo upload prompts.
- Abandoned registration reminders and account management notices.
- STRICT NO-SHARING / NO-SALE POLICY FOR MOBILE DATA:
Mobile phone numbers, SMS opt-in consent data, and text messaging records will NEVER be sold, rented, leased, traded, or shared with any third parties or affiliates for their own marketing or promotional purposes. Your SMS opt-in data is excluded from all third-party lists and will only be utilized by Finally Clear and our authorized, BAA-bound service providers to deliver direct healthcare and account messaging.
- Message Frequency & Costs: Message frequency varies based on your clinical appointment schedule, monthly lab requirements, and iPLEDGE compliance dates. Standard message and data rates may apply depending on your mobile carrier.
- Opt-Out Instructions: You may cancel or revoke your SMS consent at any time by replying STOP to any text message received from Finally Clear. After texting STOP, you will receive one single confirmation message verifying that your number has been unsubscribed. No further automated SMS messages will be sent unless you re-enroll.
- Customer Support (HELP): If you experience issues or need assistance with text notifications, reply with the keyword HELP to our number or contact our patient support desk at support@finallyclear.com.
4. How We Disclose Your Information
We do not sell, rent, or commercialize your personal information or health records. We share information only under the following lawful circumstances:
- Treating Clinicians & Clinical Teams: With the licensed Physicians, Physician Assistants, Nurse Practitioners, and clinical staff providing your medical evaluations and prescriptions.
- Dispensing Pharmacies: With your chosen local retail pharmacy or our designated backup mail-order partner pharmacy to fulfill your prescribed medication.
- Diagnostic Laboratories: With CLIA-certified laboratories (such as Quest Diagnostics or Labcorp) to generate blood and pregnancy monitoring orders.
- Federal Regulatory Bodies (FDA iPLEDGE REMS): With the federal iPLEDGE program administrators as strictly mandated by federal law governing isotretinoin distribution.
- Legal & Regulatory Obligations: When required by law, subpoena, court order, or to prevent severe, imminent harm to health or safety.
5. Data Security Standards
We implement administrative, technical, and physical safeguards designed to exceed industry standards. All data in transit is encrypted using Transport Layer Security (TLS 1.3), and all databases storing patient records or PHI are encrypted at rest using AES-256 bit encryption. Administrative staff and clinical providers must authenticate through role-based permissions and mandatory Multi-Factor Authentication (MFA).
6. Your Legal & Privacy Rights
Under HIPAA and state privacy laws, you possess the right to:
- Inspect, review, or request a digital copy of your electronic medical records.
- Request a correction or amendment to your health records if you believe information is inaccurate.
- Request an accounting of disclosures of your health information.
- Revoke your consent to SMS communications or email marketing at any time.
To exercise any of these rights, submit a written request to privacy@finallyclear.com.
7. Contact Information
If you have questions regarding this Privacy Policy, our HIPAA security practices, or our SMS communications, contact our Compliance Office at:
Finally Clear™
Attn: Privacy & Compliance Officer
Email: support@finallyclear.com
Phone: (480) 555-0199
Website: www.finallyclear.com