Last updated October 7, 2026
Effective date: July 1, 2026.
This Privacy Policy explains how RUO Codes ("we," "us," or "our") handles information when you visit or use RUO Codes, its related website features, and its linked mobile app. For a privacy question or request, use our Contact page.
Sign-in and sign-up are provided by Clerk. Account information processed for authentication can include your name, email address, sign-in and session information, and the account identifier Clerk provides to us. We use Clerk to authenticate accounts; this application does not store your sign-in password in its own application tables. When you complete the RUO acknowledgment, we store the acknowledgment, its version and timestamp, your confirmation that you are at least 21, and your sale-alert preference in Clerk account metadata. Saved Stack Builder stacks and Protocol Journal records are stored in our application database and linked to your Clerk account. Journal records can include protocols, compounds, schedules or doses, and notes you enter. Do not enter patient names or other sensitive or personally identifying medical details in these features.
If you watch a vendor, our database stores the vendor and Clerk account identifiers, an email address and display name for delivering notices, your email and push-alert preferences for that vendor, and a one-click unsubscribe token. The linked mobile app can request notification permission and send an Expo push token associated with your account to our server. Expo tokens are used to route notifications through Expo's push service. You can remove a watched vendor or update its email and push preferences in the account features; you can also remove a registered push token from the app.
When you ask to receive sale notices, the app can send vendor sale alerts and a weekly digest by email through Resend. Emails use watchlist and alert-preference information. The token in a sale-email unsubscribe link removes that vendor from your watchlist. The weekly-digest unsubscribe link turns off email alerts for watchlist entries associated with that email address, without itself deleting those entries.
If you submit a vendor review, the app stores the vendor, Clerk account identifier, display name, rating, optional service ratings, service date, genuine-experience confirmation, review text, and timestamps. If you comment on a coupon, the app stores the coupon, Clerk account identifier, displayed author name, comment, and timestamps. Approved reviews and comments may be displayed publicly with the displayed author name and content. You can delete your own review or comment through the available site controls. Coupon votes store the coupon, your Clerk account identifier, whether the coupon worked, and timestamps.
If you request a COA checklist by email, we store the email address and request source in our subscriber records and record the requested download. The app sends the requested email through Resend. Other emailed lead-magnet downloads can also collect an email address, save its source, and record a download. Our code does not show a separate recurring marketing newsletter signup as part of the COA checklist request. The one-time checklist email does not contain a site-provided unsubscribe link.
The Contact form sends your first and last name, email address, reason for contacting us, and message to our inbox through Resend. A vendor submission is saved in our database with the vendor name, website, any coupon code and description, and submitter email. Its contact name and optional phone number are included in the notification email, not those database columns. Issue reports can include issue type, reporter name and email, vendor and coupon information, and a description; the report is emailed through Resend rather than saved as an issue-report table in the application database.
If you use the AI-assisted COA check, selected PDF pages are rendered into images in your browser. Image pages and rendered PDF-page images are sent to OpenAI for analysis, and the resulting review is returned to your browser. The analyzed upload is not written by this feature to an application file store or database. The request is processed in server memory to call the AI provider. We cannot confirm the provider's retention, use, or model-training practices from our application code. Do not upload material you are not comfortable sharing with that provider.
The Stack Builder AI advisor sends any free-text research goal and current compound names you provide to OpenAI. The compound suggestion feature, including suggestions accessed through Protocol Journal, also sends compound names to OpenAI. OpenAI returns generated advice or suggestions to the app. If you save generated content as a Stack Builder stack or Protocol Journal record, that record is stored in our application database linked to your Clerk account, as described above. We cannot confirm OpenAI's retention, use, or model-training practices from our application code. Do not enter patient names, contact details, or other personal or sensitive identifiers in AI free-text fields.
Our code records first-party vendor outbound-click events for aggregate reporting. A recorded click can include vendor and coupon identifiers, product key, a normalized source-page path, bot classification, and timestamp. The outbound-click record does not include a name, account identifier, email address, IP address, or user-agent value.
For public-form abuse protection and rate limiting, the server computes a SHA-256 hash of the request IP address and stores the hash, form route, a timestamp, and, for some checklist requests, a hash of the email address. These are hashes, not a promise of irreversible anonymization. The rate-limit-attempt table is pruned opportunistically for entries older than 25 hours when a periodic insertion reaches its cleanup trigger. COA analysis also uses IP-based in-memory rate limits.
The application request logger records a request identifier, HTTP method, redacted route, and response status. Its application logger is configured to redact request URLs and cookie and authorization headers and does not serialize the request body. Logs or network records held by hosting, database, identity, email, AI, analytics, or other providers are governed in part by their own practices, which this code cannot establish.
The website loads a Google tag configured with Google Ads identifier AW-18297367733. The application analytics helper also directs selected custom events to Google Analytics 4 measurement ID G-5H0V08ZZC8, and calls the Replit Project Analytics tracker when the analytics global is available. Events can include event names, vendor, product, or coupon identifiers, page or interface labels, and outcome flags. The event properties in the reviewed code do not include form messages, names, email addresses, or account identifiers. Google and Replit may receive browser, device, pageview, network, and other information through their analytics or advertising services, and may use cookies or similar technologies under their own policies. The actual services, settings, and retention enabled for a production deployment should be confirmed with the operator and providers.
Clerk sign-in can use session cookies or browser storage controlled by Clerk. The admin session uses an application cookie. The theme preference is saved in browser local storage; it is not a theme cookie. Google or Clerk may set additional technologies as described in their own documentation. You can manage browser storage and cookie settings in your browser; blocking necessary sign-in storage can prevent account features from working.
We use information to authenticate accounts, remember watchlists and alert preferences, provide requested sale notices and downloads, display and moderate submitted reviews and comments, process votes, respond to forms, evaluate uploaded COA images, prevent abuse, keep the site secure, and understand first-party vendor click activity. Information is made available to service providers needed for those features, including Clerk for sign-in, Resend for email, Expo for push delivery, OpenAI for requested COA analysis, Google for advertising and analytics, Replit for hosting and, when available, project analytics, and our database providers. Their own retention, security, and processing terms may also apply.
Reviews and comments that the site makes public, public vendor submissions after editorial action, and information you choose to post are visible to visitors. We may disclose information if required by law, to protect the site or users, or to handle a legal claim. We do not sell personal information. We also do not receive personal identifiers in the first-party outbound-click records described above. This no-sale statement is our stated policy; it is not a finding about how a third-party advertising provider classifies every transfer under every privacy law.
The application does not define a fixed deletion period for account-linked watchlists, push tokens, coupon votes, user reviews or comments, saved Stack Builder stacks, Protocol Journal records, checklist subscriber records, lead-magnet download records, or vendor submissions. Those records can remain in the application database until someone removes them or a separate account or data-handling process is performed. Reviews and comments have user deletion controls; watchlists and push tokens have removal controls. The source reviewed does not implement an account-wide delete operation that also removes every associated application record. We cannot state how long Clerk, Resend, Expo, Google, OpenAI, hosting, database backups, or mailboxes retain their records.
The specific rate-limit attempt records described above have an opportunistic cleanup for records older than 25 hours. COA rate-limit counters are in-memory. These limited behaviors are not a general retention schedule for other data.
This site and its services are intended only for people aged 21 or older. Users must truthfully confirm they are at least 21 when completing the account's RUO acknowledgment. The service is not intended for children, and we do not knowingly seek personal information from anyone under 21. If you believe a person under 21 has submitted personal information, please contact us so the request can be reviewed.
We use safeguards visible in the application, including authenticated account checks, origin validation for relevant requests, protected session-cookie settings, HTTPS security headers, and hashed IP and email values for public-form abuse controls. No website, transmission, or storage system can be guaranteed secure. Do not send passwords in forms, and only provide personal information or COA documents you choose to share.
Depending on where you live and whether the relevant law applies, you may have rights to know, access, correct, delete, or obtain a portable copy of personal information; to appeal a decision; to opt out of sale, sharing for targeted advertising, or certain profiling; or to limit certain sensitive-information uses. We do not sell personal information. The configured Google Ads tag may send online identifiers or activity to Google; please contact us through the Contact page with a rights request or question, including if you wish to ask about an advertising-related opt-out. We will verify and respond as required by applicable law. We do not promise that every statutory right applies to every visitor or that every opt-out preference signal is recognized by the current implementation.
We may revise this Policy as the service changes or the law requires. The current version and its updated date will be posted on this page. Where a law requires further notice or consent, we will follow that requirement. The application does not have a dedicated email system for announcing Privacy Policy changes. Please review this page periodically.