Privacy Policy
Last updated: July 16, 2026
1. About this policy
This Privacy Policy explains what information Therisse ("Therisse," "we," "us") collects when you visit therisse.com or use our services, how we use it, who we share it with, and the choices you have. By using our services, you agree to this policy.
Your medical care is provided by MDI Medical Group PC and its network of independently licensed, board-certified physicians. MDI is a HIPAA-covered entity and holds your protected health information ("PHI"), including your medical history, intake responses, and prescriptions. Therisse handles the storefront, billing, and support, and is not a HIPAA-covered entity. This policy covers the information Therisse handles; the medical information you provide during your consultation is governed by MDI's own Notice of Privacy Practices.
2. Information we collect
Information you provide to us. Your name, email address, phone number, and shipping and billing address when you create an account or place an order; payment information, which is processed by our payment provider (we never see or store your full card number); and any messages you send to our support team.
Information we collect automatically. When you use our website, we collect standard technical and usage information, such as your IP address, general location, device and browser type, the pages you view, and how you arrived at our site. We collect this using cookies and similar technologies (see Section 8).
Information from other sources. We may receive limited information from our partners, such as confirmation of an order or shipment, so we can keep your account up to date.
Medical information. The health information you provide during your medical intake and consultation, including your symptoms, medical history, and prescriptions, is collected and held by MDI Medical Group PC on its HIPAA-compliant platform, not by Therisse. We do not store your medical records on therisse.com.
3. How we use your information
We use the information Therisse collects to:
- Provide, operate, and improve our services
- Process your orders, payments, and subscriptions
- Connect you with MDI's medical platform when you begin care
- Send you order confirmations, account notices, and service updates
- Respond to your questions and provide customer support
- Send you marketing communications, which you can opt out of at any time
- Measure and improve the performance of our marketing
- Detect and prevent fraud, and keep our services secure
- Comply with our legal obligations
4. How we share your information
We do not sell your personal information. We share it only as needed to run our service:
- Medical providers. When you begin care, we pass your name, email, and phone number to MDI Medical Group PC so it can create your patient record. From there, MDI collects and manages your medical information under its own privacy practices.
- Service providers. Companies that help us operate, including payment processing, order fulfillment, hosting, email delivery, customer support, and analytics. They may only use your information to perform services for us.
- Advertising and analytics partners. Partners that help us understand how our site is used and measure the performance of our advertising, using cookies and similar technologies. We do not share your medical information with advertising partners.
- Legal and safety. When required by law, such as in response to a subpoena, court order, or regulatory request, or to protect the rights and safety of our users and others.
- Business transfers. In connection with a merger, acquisition, or sale of assets, in which case your information may be transferred as part of that transaction.
5. Your medical records and HIPAA
Therisse is not a HIPAA-covered entity and does not store or process protected health information on its own systems. Your PHI is held by MDI Medical Group PC on its HIPAA-compliant platform.
To access, correct, or request a copy of your medical records, or to request MDI's Notice of Privacy Practices, contact MDI directly or use the patient portal accessible from any clinician message you receive. See our HIPAA Notice for more.
6. Your choices and rights
You can:
- Access or update the personal information Therisse holds about you
- Request that we correct or delete it, subject to legal and recordkeeping requirements
- Opt out of marketing emails using the unsubscribe link in any message
- Manage cookies and opt out of interest-based advertising (see Section 8)
Depending on where you live, you may have additional rights under state privacy laws, including in California, Colorado, Connecticut, Texas, Virginia, and other states with comprehensive privacy laws. These may include the right to know what personal information we collect, to access or correct it, to request deletion, to opt out of targeted advertising or the sale or sharing of personal information, and to appeal a decision on your request. We do not discriminate against you for exercising these rights.
To exercise any of these rights, email support@therisse.com. We will verify your request using the email address associated with your account. To access or amend your medical records, contact MDI directly per Section 5.
7. Consumer health data (Washington and Nevada)
If you are a resident of Washington or Nevada, additional protections apply to consumer health data under the Washington My Health My Data Act and the Nevada Consumer Health Data Privacy Act. We collect and use such data only to provide the services you request and for the purposes described in this policy, and we do not sell it. We do not use consumer health data for targeted advertising. You may exercise your rights to access, delete, or withdraw consent, and to appeal a decision, by emailing support@therisse.com.
8. Cookies, analytics, and advertising
We use cookies and similar technologies to run the site, keep you signed in, understand how our site is used, and measure the performance of our advertising. Some of these technologies are provided by analytics and advertising partners.
You can manage cookies through your browser settings and opt out of interest-based advertising through your device's ad settings or industry tools such as the Digital Advertising Alliance. Where required, we honor the Global Privacy Control (GPC) browser signal as a request to opt out of the sale or sharing of personal information. We do not respond to legacy "Do Not Track" signals, as there is no common standard for them.
9. Data security
We use industry-standard safeguards, including encryption in transit and at rest, to protect your information, and we limit access to authorized personnel. Payment data is handled by our payment provider, a PCI-DSS Level 1 service provider. No method of transmission or storage is completely secure, but we work to protect your information and review our practices regularly.
10. Data retention
We keep your information for as long as your account is active and as needed to provide our services, and afterward as required to meet our legal, tax, and recordkeeping obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we delete or de-identify it.
11. Children
Therisse services are intended for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will note material changes by updating the "Last updated" date above and, where appropriate, by email.
13. Contact
Questions about this Privacy Policy or your Therisse account? Email support@therisse.com.
For medical records, contact MDI Medical Group PC directly via the patient portal or as instructed in their Notice of Privacy Practices.