Skip to main content

Privacy policy

Effective date: January 1, 2026

SmugMe, LLC (“SmugMe”, “we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard information when you use our website and platform.

Information we collect

We may collect personal information including name, email address, mobile phone number, clinic affiliation, and account credentials when users register for the SmugMe platform.

How we use information

We use collected information to provide and operate the SmugMe platform, authenticate users, send billing notifications, improve system performance, and comply with legal requirements.

SMS communications

SmugMe may send SMS messages to registered platform users for:

  • Account authentication (verification codes)
  • Billing notifications
  • Account and system-related updates

Users provide explicit consent to receive SMS messages during account onboarding or login activation. By providing a mobile number and agreeing to receive SMS messages, users acknowledge:

  • Message frequency varies.
  • Message and data rates may apply.
  • Users may opt out at any time by replying STOP.
  • Users may request assistance by replying HELP.

Once opted out, no further SMS messages will be sent unless the user re-subscribes by replying START. SmugMe does not send marketing SMS messages and does not sell or share mobile numbers with third parties for marketing purposes.

Healthcare and HIPAA

SmugMe operates under signed Business Associate Agreements (BAAs) with healthcare customers and their applicable subprocessors. We implement administrative, technical, and physical safeguards designed for HIPAA-regulated workloads, including encryption at rest and in transit, per-practice data separation, access controls, and audit logging. Protected Health Information (PHI) is processed and stored only within our HIPAA-eligible cloud environment and is never disclosed to third-party services that are not covered by a corresponding BAA. SMS messages sent by SmugMe do not contain PHI unless specifically configured by an authorized healthcare customer under applicable policies and agreements.

Data security

SmugMe applies industry-standard security practices including encryption in transit and at rest, role-based access controls, secure cloud infrastructure, audit logging, and regular review of subprocessor agreements.

Information sharing

We do not sell personal information. Information may be shared only with trusted service providers necessary to operate the platform or when required by law.

Contact us

If you have questions about this Privacy Policy, write to hello@smugme.ai or SmugMe, LLC, 5460 McGinnis Village Place, Suite 203, Alpharetta, GA 30005.