Privacy policy
Effective date: January 1, 2026
SmugMe, LLC (“SmugMe”, “we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard information when you use our website and platform.
Information we collect
We may collect personal information including name, email address, mobile phone number, clinic affiliation, and account credentials when users register for the SmugMe platform.
How we use information
We use collected information to provide and operate the SmugMe platform, authenticate users, send billing notifications, improve system performance, and comply with legal requirements.
SMS communications
SmugMe may send SMS messages to registered platform users for:
- Account authentication (verification codes)
- Billing notifications
- Account and system-related updates
Users provide explicit consent to receive SMS messages during account onboarding or login activation. By providing a mobile number and agreeing to receive SMS messages, users acknowledge:
- Message frequency varies.
- Message and data rates may apply.
- Users may opt out at any time by replying STOP.
- Users may request assistance by replying HELP.
Once opted out, no further SMS messages will be sent unless the user re-subscribes by replying START. SmugMe does not send marketing SMS messages and does not sell or share mobile numbers with third parties for marketing purposes.
Healthcare and HIPAA
SmugMe operates under signed Business Associate Agreements (BAAs) with healthcare customers and their applicable subprocessors. We implement administrative, technical, and physical safeguards designed for HIPAA-regulated workloads, including encryption at rest and in transit, per-practice data separation, access controls, and audit logging. Protected Health Information (PHI) is processed and stored only within our HIPAA-eligible cloud environment and is never disclosed to third-party services that are not covered by a corresponding BAA. SMS messages sent by SmugMe do not contain PHI unless specifically configured by an authorized healthcare customer under applicable policies and agreements.
Data security
SmugMe applies industry-standard security practices including encryption in transit and at rest, role-based access controls, secure cloud infrastructure, audit logging, and regular review of subprocessor agreements.
Information sharing
We do not sell personal information. Information may be shared only with trusted service providers necessary to operate the platform or when required by law.
Contact us
If you have questions about this Privacy Policy, write to hello@smugme.ai or SmugMe, LLC, 5460 McGinnis Village Place, Suite 203, Alpharetta, GA 30005.