Legal
Privacy Policy.
How Diem collects, uses, and protects your information.
Last updated: July 14, 2026
The Diem Brand, LLC (“Diem,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website, create an account, or use the Diem member portal and related services (collectively, the “Services”).
Diem is a technology platform. We are not a medical group, healthcare provider, or pharmacy. Clinical services are provided by independent, licensed physicians, and medications are dispensed by licensed U.S. pharmacies. Those providers and pharmacies are responsible for your care and, where applicable, act as “covered entities” under the Health Insurance Portability and Accountability Act (“HIPAA”). They maintain their own Notices of Privacy Practices that govern how they handle your health information.
By using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.
1. Scope of this Policy
This Policy applies to information we collect through our website and member portal. It does not apply to the independent physicians, pharmacies, or other third parties who provide services to you, each of which maintains its own privacy practices. We encourage you to review their notices directly.
2. Information we collect
Information you provide. We collect information you give us directly, including:
- Account and application information — your name, email address, password (stored only as a secure, one-way hash), U.S. state, wellness goals, and other details you submit when you request access or create an account.
- Health information — information you provide for clinical review and to receive care, which we transmit to the independent physicians and pharmacies who serve you.
- Payment information — when you make a purchase, your card details are collected and processed by our third-party payment processor. Diem does not store your full payment card number.
- Billing and order information — your billing address and related details needed to process and fulfill an order.
- Referral information — if you participate in our referral program, information related to referrals you send or receive.
- Communications — messages, support requests, and other information you send us.
Information collected automatically. When you use the Services, we automatically collect certain technical information, such as your IP address, browser type, device identifiers, pages viewed, and similar log data. We also use strictly-necessary cookies, as described below.
3. Cookies
We use only strictly-necessary cookies — for example, to keep you signed in, maintain your session, and protect the security of the Services. We do not use advertising, marketing, or cross-site tracking cookies, and we do not use analytics that track you across other websites. Because these cookies are essential to operate the Services, disabling them may prevent parts of the site from working. You can control cookies through your browser settings.
4. How we use information
We use the information we collect to:
- provide, operate, and maintain the Services;
- facilitate your access to independent physicians and pharmacies and transmit information necessary for your care;
- process payments and fulfill orders;
- create and secure your account and authenticate you;
- communicate with you about your account, orders, and the Services;
- operate our referral program;
- detect, prevent, and address fraud, abuse, and security issues;
- comply with legal obligations and enforce our terms; and
- analyze and improve the Services.
5. How we share information
We share information as follows:
- Care providers and pharmacies — with the independent, licensed physicians and pharmacies who review your information and provide products and services to you.
- Service providers — with vendors who perform services on our behalf, such as payment processing, email delivery, and cloud hosting, under contracts that require them to protect your information and use it only to provide those services.
- Legal and safety — when we believe disclosure is necessary to comply with law, respond to legal process, protect our rights, or protect the safety of any person.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
6. Health information and HIPAA
Because Diem is a technology platform and not a healthcare provider, we are generally not a “covered entity” under HIPAA. The independent physicians and pharmacies who provide your care are responsible for your protected health information and maintain their own Notices of Privacy Practices, which govern how they use and disclose that information. We handle the health-related information you provide in order to facilitate your care and protect it using the safeguards described below.
7. Data security
We use administrative, technical, and physical safeguards designed to protect your information — including encryption of data in transit and at rest, storing sensitive information on our servers rather than in your browser, hashing of account passwords, and access controls that limit who can access your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Data retention
We retain personal information for as long as necessary to provide the Services, comply with our legal, tax, and recordkeeping obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we delete or de-identify it.
9. Your rights and choices
Subject to applicable law, you may:
- access and request a copy of the personal information we hold about you;
- request that we correct inaccurate information;
- request that we delete your information; and
- opt out of non-essential marketing emails using the unsubscribe link in those messages. We may still send you transactional messages about your account or orders.
To make a request, contact us at privacy@diem-health.com. We may need to verify your identity before acting on your request.
10. California privacy rights
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”), provides you with additional rights.
Categories of personal information we collect. In the past 12 months, we have collected the following categories of personal information: identifiers (such as name, email address, and IP address); customer records (such as billing information); commercial information (such as orders); internet or network activity (such as usage data); general geolocation (such as your state); and health-related information you provide for care. We collect this information for the purposes described in “How we use information” above.
Your California rights. You have the right to:
- know the categories and specific pieces of personal information we have collected about you;
- delete personal information we have collected from you;
- correct inaccurate personal information;
- opt out of the “sale” or “sharing” of your personal information — note that we do not sell or share your personal information as those terms are defined under the CCPA; and
- not receive discriminatory treatment for exercising your privacy rights.
How to exercise your rights. Submit a request to privacy@diem-health.com. We will verify your request using information associated with your account. You may use an authorized agent to submit a request on your behalf, and we may require the agent to provide proof of authorization. We will respond within the timeframes required by law.
11. Children’s privacy
The Services are intended for adults 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us and we will delete it.
12. Third-party links
The Services may link to third-party websites or services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. Please review their policies.
13. Users outside the United States
The Services are intended for users in the United States. If you access the Services from outside the United States, you do so on your own initiative, and your information will be processed in the United States.
14. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after an update means you accept the revised Policy.
15. Contact us
If you have questions about this Privacy Policy or our privacy practices, contact us at:
The Diem Brand, LLC
Attn: Privacy
1209 Orange Street
Wilmington, DE 19801
privacy@diem-health.com