Check Eligibility

Legal

Privacy Policy

Direct Reta

Last Updated: February 1, 2026

1. Overview

Direct Reta (“Direct Reta,” “we,” “us,” or “our”) respects your privacy and is committed to protecting it through this Privacy Policy.

This Privacy Policy explains:

  • What information we collect about you when you visit directreta.com or use our telehealth and related services (the “Site” and “Services”);
  • How we collect, use, share, and protect that information; and
  • The choices and rights you have with respect to your information.

This Privacy Policy is incorporated into and made part of our Terms of Service. By accessing or using the Site or Services, you agree to this Privacy Policy. If you do not agree, do not use the Site or Services.

The Services are intended for users located in the United States and may only be used in certain U.S. states as described in our Terms of Service.

Direct Reta is not a medical group or healthcare provider. Medical services are provided by independent, third-party medical practices and licensed providers (“Medical Practices,” “Providers”) and prescriptions are filled by independent pharmacies (“Pharmacies”). Those entities have their own legal obligations with respect to medical information.

2. Relationship to HIPAA and Notice of Privacy Practices

In the course of providing the Services, Direct Reta may handle information that is considered Protected Health Information (“PHI”) under the Health Insurance Portability and Accountability Act (“HIPAA”).

When Direct Reta acts on behalf of Medical Practices and Pharmacies, it may act as a “business associate” under HIPAA.

Each Medical Practice and Pharmacy is a separate “covered entity” and maintains its own Notice of Privacy Practices, which describes in detail how your PHI is used and disclosed for treatment, payment, and healthcare operations.

This Privacy Policy is distinct from those Notices of Privacy Practices. To obtain a copy of a Medical Practice's or Pharmacy's Notice of Privacy Practices, please ask your Provider or Pharmacy directly.

When this Privacy Policy uses the term “Personal Information,” it includes both PHI and other information that identifies or can reasonably be linked to you, unless clearly stated otherwise.

3. Information We Collect

3.1 Information You Provide Directly

When you use the Site or Services, you may provide us with the following types of Personal Information:

  • Contact Information: name, mailing address, email address, phone number.
  • Account Information: username, password, security settings, communication preferences.
  • Demographic Information: date of birth, age, gender or gender identity, state of residence.
  • Health and Medical Information (PHI): medical history, current and past conditions, symptoms, medications, allergies; information about your use of GLP-1, dual-agonist, or triple-agonist medications (including retatrutide) and related treatments; family medical history, lifestyle information (e.g., smoking, alcohol, substance use); lab results, vital signs, and other clinical data provided or uploaded through the Services.
  • Identification Information:images of your driver's license, passport, or other government ID; live photos or selfies for identity verification.
  • Payment Information: payment card number, expiration date, billing address, and other payment details provided to our payment processors.
  • Communications and Content: messages you send to us, responses to questionnaires, surveys, intake forms, or assessments; feedback, reviews, or other content you submit.

3.2 Information Collected Automatically

When you visit the Site or interact with the Services, we and our service providers may automatically collect certain information by using cookies, pixels, and similar technologies, such as:

  • IP address and approximate location;
  • Browser type and settings;
  • Device identifiers and device type;
  • Operating system and version;
  • Referring and exit URLs;
  • Pages or screens viewed, links clicked, time spent on pages, and other usage data;
  • Dates and times of access and activity (“clickstream data”).

We use this information for analytics, security, personalization, and to improve the Site and Services. We treat this information as Personal Information when it is reasonably capable of identifying you.

3.3 Information from Third Parties

We may receive information about you from:

  • Medical Practices and Providers: clinical notes, prescribing information, and other PHI needed to provide or coordinate Services.
  • Pharmacies: dispensing information, medication history, refill information.
  • Service Providers: identity verification services, analytics providers, payment processors, marketing platforms, and other vendors.
  • Affiliates and Partners: where we operate related offerings or co-branded programs.
  • Public Sources: where allowed by law (e.g., publicly available professional or address data).

4. Cookies, Pixels, and Other Tracking Technologies

4.1 What We Use

We and our service providers may use:

  • Cookies: small text files stored on your device;
  • Pixels / Web Beacons: tiny graphics embedded in pages or emails;
  • Session Replay / Analytics Scripts: to understand how users interact with key pages and forms;
  • SDKs and Embedded Scripts: in web or mobile applications.

These tools help us:

  • Operate and secure the Site;
  • Remember your preferences;
  • Measure and improve performance;
  • Understand how visitors use the Site;
  • Deliver and measure marketing and advertising (where permitted).

4.2 Use with Health Information

Consistent with current HIPAA and regulatory guidance, Direct Reta:

  • Does not intentionally configure third-party tracking tools to receive PHI (such as specific symptoms, diagnoses, or medication details) for advertising purposes;
  • Implements technical and contractual safeguards to reduce the likelihood that PHI is transmitted to third-party ad platforms;
  • May still use analytics tools (e.g., measuring page visits or conversion events) in a way designed to avoid sending PHI.

However, because IP address, device IDs, and browsing patterns can sometimes be linked to health-related activity, we treat tracking around account and consultation areas conservatively and configure tools to minimize risk.

4.3 Your Choices

Most browsers allow you to:

  • Set your browser to refuse or delete some or all cookies;
  • Receive alerts when cookies are being set.

If you disable cookies, some features of the Site or Services may not function properly.

Some advertising and analytics providers participate in industry opt-out programs (e.g., Digital Advertising Alliance and Network Advertising Initiative). Opt-outs may be browser and device specific and do not stop all advertising, but may limit certain interest-based ads.

4.4 "Do Not Track"

Some browsers offer a “Do Not Track” (DNT) setting. There is no common industry standard for how to respond to these signals, and Direct Reta currently does not respond to DNT signals. You may use the other control mechanisms described above to manage cookies and tracking.

5. How We Use Your Information

We may use Personal Information for the following purposes:

Providing the Services

  • Create and manage your account;
  • Facilitate telehealth consultations and related services;
  • Coordinate with Medical Practices and Pharmacies to provide physician-prescribed retatrutide and related weight-care services;
  • Process and fulfill prescriptions;
  • Provide customer support and respond to inquiries.

Personalization and User Experience

  • Remember your preferences and settings;
  • Customize content, forms, and recommendations;
  • Tailor aspects of the Site and Services to your interests.

Operations, Analytics, and Improvement

  • Operate, maintain, and improve the Site and Services;
  • Perform data analysis, research, statistics, and trend analysis;
  • Test, develop, and enhance features, products, and services;
  • Detect, prevent, and troubleshoot technical issues.

Marketing and Communications (Non-PHI)

  • Send you information about Direct Reta products, services, promotions, and educational content;
  • Administer surveys, newsletters, and events;
  • Conduct non-PHI-based targeted advertising and measurement (where permitted).

You can opt out of marketing emails and texts as described in Section 10.

Security, Fraud Prevention, and Legal Compliance

  • Authenticate users and manage access controls;
  • Protect against, identify, and investigate fraud, abuse, or security incidents;
  • Enforce our Terms of Service and other agreements;
  • Comply with applicable laws, regulations, court orders, and lawful requests.

De-identified and Aggregate Uses

  • Create de-identified or aggregated data sets that no longer identify you;
  • Use and commercialize such de-identified or aggregated data for research, analytics, product development, and other lawful purposes.

6. How We Share Your Information

We do not sell your PHI or share it with unaffiliated third parties for their own independent marketing of unrelated products.

We may share Personal Information as follows:

Medical Practices and Providers

  • To schedule and conduct consultations;
  • To support diagnosis, treatment, and ongoing care;
  • For treatment, payment, and healthcare operations permitted under HIPAA.

Pharmacies

  • To fill and ship prescriptions, including compounded medications prepared by licensed U.S. 503A pharmacies;
  • To handle refills, substitutions where appropriate, and medication questions.

Service Providers and Vendors

  • Companies that host our Site or applications;
  • Payment processors;
  • Identity verification services;
  • Analytics and security vendors;
  • Customer support platforms;
  • Cloud infrastructure and backup providers.

These service providers may access Personal Information only as needed to perform services for us and are contractually required to protect it, including through Business Associate Agreements where required by HIPAA.

Affiliates and Related Entities

Our parent, subsidiary, or affiliated entities, if any, for purposes consistent with this Privacy Policy.

Marketing and Analytics Partners (Non-PHI)

Advertising networks, social media platforms, and analytics providers may receive limited information (such as cookie IDs, device data, or generalized event data) to help us measure and improve marketing effectiveness and reach appropriate audiences, where permitted by law and our configuration.

We do not ask these partners to use PHI for targeted advertising.

Corporate Transactions

In connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or other corporate transaction, your information may be transferred as part of that transaction, subject to applicable law.

Legal, Safety, and Compliance

  • To comply with applicable laws, regulations, legal processes, or governmental requests;
  • To protect the rights, property, or safety of Direct Reta, our users, Medical Practices, Pharmacies, or others;
  • To detect, prevent, or respond to fraud, security incidents, or illegal activity.

With Your Direction or Consent

When you direct us to share information with a third party or explicitly consent to such sharing.

7. Aggregate and De-identified Information

We may create and use aggregate or de-identified information that does not identify you. For example:

  • Combining usage data from many users to understand trends;
  • Removing identifying fields from a data set and applying additional safeguards so information cannot reasonably be re-identified.

We may use or share such information for any lawful purpose, including research, analytics, and product development, without further notice or compensation to you.

8. Retention of Personal Information

We retain Personal Information for as long as reasonably necessary to:

  • Provide the Services and maintain your account;
  • Support ongoing treatment and medication management;
  • Comply with legal, regulatory, and recordkeeping obligations;
  • Resolve disputes and enforce our agreements;
  • Maintain security and prevent fraud or abuse.

Medical and billing records may be retained for periods required by healthcare, pharmacy, and tax laws, which may be several years or longer. When information is no longer needed, we will delete, de-identify, or anonymize it, subject to applicable law and our data retention policies.

9. How We Protect Your Information

We use administrative, technical, and physical safeguards designed to protect Personal Information from accidental or unlawful destruction, loss, alteration, unauthorized access, disclosure, or misuse. Protections include:

  • Encryption of PHI and other sensitive data in transit and at rest;
  • Access controls and role-based permissions;
  • Multi-factor authentication where appropriate;
  • Network and application security measures;
  • Logging, monitoring, and security assessments;
  • Workforce training on privacy and security.

However, no method of transmission over the internet or electronic storage is perfectly secure. We cannot guarantee absolute security. Any transmission of information is at your own risk.

The security of your account also depends on you:

  • Use a strong, unique password;
  • Keep your login credentials confidential;
  • Log out of your account when using public or shared devices;
  • Promptly notify us at security@directreta.com if you believe your account has been compromised.

10. Communications and Marketing

10.1 Service and Transactional Communications

By using the Services and providing contact information (such as your email address and mobile number), you consent to our sending:

  • Account-related notices;
  • Appointment reminders;
  • Prescription or refill notifications;
  • Security alerts and important updates;
  • Other transactional or administrative messages.

These communications are considered part of the Services and, in many cases, you cannot opt out of them while continuing to use the Services.

10.2 Email Marketing

With your consent where required by law, we may send you:

  • Newsletters;
  • Product or service updates;
  • Special offers, promotions, or event invitations;
  • Educational content related to metabolic health, weight care, and physician-prescribed therapies such as retatrutide.

You may opt out of marketing emails at any time by:

Opting out of marketing emails does not affect transactional or service-related communications.

10.3 SMS/Text Messaging

If you provide a mobile number and consent to receive text messages, we may send you:

  • Appointment reminders;
  • Security verification codes;
  • Important updates regarding your care or account;
  • Occasional promotional messages where permitted by law.

You can opt out of SMS marketing and most non-essential texts by replying “STOP” to any message. We may send a final confirmation message of your opt-out request. Standard message and data rates may apply.

We do not share SMS opt-in data or consent with third parties for their own marketing or promotional purposes.

11. Your Choices and Rights

11.1 General Choices

You may:

  • Update or correct certain account and profile information through your account settings;
  • Change communication preferences (email, SMS) via account settings or by contacting us;
  • Request deletion or deactivation of your Direct Reta account, subject to legal and medical record retention requirements.

We may decline requests that would:

  • Violate law or legal requirements;
  • Prevent us from meeting legal or regulatory obligations;
  • Impact the accuracy or integrity of required medical records.

11.2 U.S. State Privacy Rights (including California)

If you are a resident of California or certain other U.S. states with comprehensive privacy laws, you may have some or all of the following rights with respect to Personal Information not otherwise exempt (for example, some PHI is regulated by HIPAA and may be exempt from state consumer privacy statutes):

  • Right to Know / Access: To request that we disclose the categories and specific pieces of Personal Information we have collected about you, the sources, purposes, and categories of third parties to whom it was disclosed.
  • Right to Delete: To request deletion of Personal Information we collected from you, subject to legal and operational exceptions (e.g., medical records we must retain by law).
  • Right to Correct: To request correction of inaccurate Personal Information we maintain about you.
  • Right to Opt Out of “Sale” or “Sharing”:To opt out of certain disclosures of Personal Information for cross-context behavioral advertising or “sales” as defined by law. Direct Reta does not sell PHI, but some uses of cookies or advertising tools may be deemed “selling” or “sharing” under state law.
  • Right to Limit Use of Sensitive Personal Information: In certain states, to limit certain uses of sensitive personal information beyond what is reasonably necessary to provide the requested services.
  • Right to Non-Discrimination: To not be discriminated against for exercising your privacy rights.

To exercise these rights, you may contact us at:

Email: privacy@directreta.com

We may need to request additional information to verify your identity and state residency before fulfilling a request. You may also designate an authorized agent to submit certain requests on your behalf, subject to additional verification.

Because medical information and PHI are often subject to HIPAA and other health privacy laws, some requests may be handled under HIPAA rather than state consumer privacy statutes, and certain requests may be limited or denied where legally required (for example, if we must retain clinical records).

12. Children's Privacy

The Site and Services are intended for individuals 18 years of age or older. Direct Reta does not knowingly collect Personal Information from children under 18 through the Site or Services.

If you are under 18, do not use the Site or Services and do not provide any information about yourself.

If we learn that we have collected Personal Information from a child under 13 without verifiable parental consent, we will delete that information as soon as reasonably practicable.

If you believe we may have information from or about a child under 13, please contact us at privacy@directreta.com.

13. International Users

Direct Reta and the Services are intended to comply with the laws of the United States of America. We make no representation that the Site or Services are appropriate or available for use in other jurisdictions.

If you access the Site or Services from outside the United States:

  • You understand that your information will be transferred to, stored, and processed in the United States;
  • Data protection laws in the United States may differ from those in your country;
  • By using the Site or Services, you consent to this transfer and processing.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do:

  • We will revise the “Last Updated” date at the top of this page;
  • We may provide additional notice (such as by email or in-app notification) if changes are material.

All changes are effective when posted, unless otherwise specified. Your continued use of the Site or Services after any changes become effective constitutes your acceptance of the updated Privacy Policy. If you do not agree to the changes, you must stop using the Site and Services.

15. Contact Us and HIPAA Complaints

If you have questions, comments, or requests regarding this Privacy Policy or our privacy practices, please contact: