Health Data Privacy Policy
Effective date: October 30, 2025
Last Updated: October 30, 2025
This Health Data Privacy Policy (“Policy”) describes how Tarsus Pharmaceuticals, Inc. (“Tarsus,” “we,” “us,” or “our”) processes “Consumer Health Data” or “Regulated Health Information” as that term is defined under applicable state law (collectively “Health Data”), about consumers who reside in the states of Nevada, Washington, New York, and any other applicable U.S. jurisdiction in connection with all Tarsus operations as well as websites (including xdemvy.com), mobile applications, and digital services where this Policy is linked or posted (“Services”). Please carefully read this Policy as it contains important information concerning your Health Data and how we use it.
This Policy describes how we process Health Data about you. This Policy does not apply to: (i) Protected Health Information (“PHI”) governed by the Health Insurance Portability and Accountability Act (“HIPAA”), such as when PHI about you is processed in the context of patient support or programming efforts that we sponsor; (ii) health information that is used to engage in public or peer-reviewed scientific, historical, or statistical research that adheres to all other applicable ethics and privacy laws; or (iii) personal data, which is governed by our Privacy Policy.
Health Data does not include other data that does not meet the definition of “Consumer Health Data” or “Regulated Health Information” under applicable law, such as aggregate or deidentified data. To the extent that we process deidentified data, we will maintain and use the data in deidentified form and will not attempt to reidentify the data unless permitted by applicable law. Deidentified data that is reidentified and otherwise qualifies as Health Data is subject to this Policy.
We collect the following categories of Health Data:
- Individual health conditions, treatment, diseases, or diagnoses;
- Social, psychological, behavioral, and medical interventions;
- Use or purchase of prescribed medications;
- Bodily functions, vital signs, symptoms, or measurements;
- Diagnoses or diagnostic testing, treatment, or medication;
- Information that could identify your attempt to seek health care services;
- Payment information that relates to your physical health (such as insurance details);
- Any other health-related information that you voluntarily disclose to us, including through any interactive tools or otherwise through the Services; and
- Any inferences based on the above categories or derived or extrapolated from non-health information that identify your past, present, or future physical or mental status.
We collect Health Data from the following categories of sources:
- Directly from you when you share it with us through the Services, including through any interactive tools;
- Directly from you, your caregiver, or a third party within the context of our responsibilities under the Federal Food, Drug, & Cosmetic Act, such as adverse event and product complaint reporting;
- From third-party sources, such as public or government sources, companies that provide marketing or advertising services, and social media platforms; and
- Through our service providers that support the Services. This may include the use of cookies, pixels, web beacons, and similar technologies to collect information about you over time and across different websites, including the Services.
We collect, use, and disclose Health Data for the following business purposes:
- To provide, operate, maintain, and protect our Services, including through the use of AI tools that help us provide the Services;
- To analyze and improve our Services, including developing new products or services (in accordance applicable privacy law);
- To identify potential clinical research opportunities and to facilitate and conduct research for potential publication;
- To communicate with you, respond to your inquiries, and send you information by email, postal mail, telephone, text message, notifications, interactive AI tools or channels, or other means, including promotional content about our products and services. We may also process your Health Data to inform our marketing or advertising efforts to provide more relevant content;
- To enhance and help us better understand your browsing experience, needs, and preferences and provide consistent, personalized services and experiences in our Services;
- To protect the security or integrity of the Services;
- To protect us, our users, and the public, and comply with applicable law, regulation, or legal process, including to validate user information for fraud and risk detection purposes, resolve disputes and protect the rights of users and third parties, respond to claims and legal process (such as subpoenas and court orders), fulfill our reporting obligations, and monitor and enforce compliance with our contracts, and otherwise detect, prevent, or stop any activity that may be illegal, unethical, or legally actionable; and
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Health Data held by us about our customers is among the assets transferred.
We disclose some or all of the above categories of Consumer Health Data for the purposes described above with the following third parties and affiliates:
- As legally required in relevant legal proceedings and otherwise to the extent required or explicitly permitted by applicable law, including cooperating with law enforcement investigations and requests;
- Clinical research organizations, researchers, and healthcare institutions we collaborate with for research activities, in compliance with applicable law;
- Third-party providers that support find-a-provider or similar services;
- Service providers that support the Services (such as providers of data hosting and analytics services, IT and security vendors, marketing and advertising providers, communications and customer service providers, and product fulfilment and delivery vendors) and professional advisors (such as attorneys, consultants, or accountants);
- Third parties within the context of a merger or similar business transaction; and
- Other third parties at your direction.
Your Privacy Rights
Depending on your place of residency, you may have some or all of the following rights regarding your Health Data, subject to applicable law and certain exceptions:
- Right to Confirm and Access: If you ask us, we will confirm whether we are collecting, sharing, or selling your Health Data. You may request that we provide you with a copy of the Health Data that we maintain about you. At your request, we will provide a list of all third parties and affiliates with whom we have shared or sold your Health Data.
- Right to Correct: If your Health Data that we maintain is inaccurate and you would like us to correct it, you may request that we make changes to it.
- Right to Withdraw Consent: Where we have relied on your consent or authorization for certain processing of your Health Data, you may withdraw that consent or authorization at any time, including if we requested your authorization to “sell” your Health Data.
- Right to Delete: You may request that we delete the Health Data we maintain about you.
- Right to Appeal: If we deny your request to exercise any of the above rights, you may request to appeal this decision.
To exercise any of the above rights, you or your authorized agent may do so by following the instructions in “Contact Us” below. To process your request, we may ask you to verify your identity by confirming your name, e-mail address, phone number, or other identifiable information that we have in our records, such as your most recent interaction with us, if applicable.
Updates to this Policy
We may update this Policy from time to time and notify you in accordance with law, which may include email or other notice posted to the Services. Any changes to this Policy will become effective when we notify you of the changes. Your use of the Services following any such updates will constitute your acceptance of such updates.
Contact Us
For questions about our Policy, to make choices about receiving promotional communications, or to request to exercise a right described in this Policy, you can contact us through any of the methods listed below: