Skip to the content
halfrx
← All providers and medications

What halfrx stores about you

halfrx records three things, one of them only if you ask for it. The web server keeps an access log for 14 days, and one thing you type can leave this server. Everything below names the table, the cookie or the endpoint it describes, so it can be checked rather than believed — this page was corrected within the hour when its first version claimed the site set no cookies and the chat set one. Last updated 11 September 2026.

Who is responsible

halfrx is operated by MonacoWebPix, a sole-trader business registered in Monaco under RCI 25P10884, C/o CATS, Le Forum, 28 Boulevard Princesse Charlotte, 98000 Monaco, Principality of Monaco. It decides what is collected and why, so it is the data controller under the EU and UK GDPR and Monaco's Law No. 1.565 of 3 December 2024 on the protection of personal data, and the “business” or “regulated entity” under the US state laws named below. Privacy requests go to privacy@halfrx.com. No data protection officer is appointed: nothing here is processed at the scale that requires one.

One cookie, and no third party watching

There is no Google Analytics, no Meta pixel, no advertising network and no fingerprinting. Nothing here follows you to another site, because nothing here knows you arrived from one.

Reading the site sets no cookie at all. Using the chat sets one, named halfrx_chat: a random identifier, readable only by the server, valid for one hour, so a follow-up question knows what the previous one was about. It holds no information about you — it is a key, and the thing it unlocks is described below.

Agreeing to the note the chat shows before your first question stores one entry, halfrx_chat_consent, in your browser's local storage, so the note is not shown again. It is not a cookie, it is never sent to the server, and clearing your browser's site data removes it. Because nothing here is used for advertising or tracking, there is no cookie banner: there is nothing to consent to.

What is recorded

A page counter
When a page loads, the browser posts its path to /api/hit, which adds one to a counter for that path on that date. The entry holds the path, the date and the number. Not your address, not your browser, not a visit identifier — there is nothing in the table that could be traced back to a person, because a count of visits to /cost on a Tuesday is not about anybody. Obvious bots are dropped by user agent before counting, and the user agent is not stored either. Reading a page sets no cookie and needs no identifier of any kind.
Clicks on paid links, and only those
Where an outbound link earns a commission, it goes through /go/ and the click is recorded as the card's name, the page you came from and the time. Links that earn nothing go straight out and are never counted. Every paid link says so beside itself, and a company under an open FTC action gets no paid link at all — see how the score is built.
Your email, if you ask for a price alert
Subscribing stores the address you type, the card you asked about and a random token used to confirm and to unsubscribe. It is used for that one purpose. It is not sold, not shared, not added to a mailing list and not used to contact you about anything else. Every alert carries an unsubscribe link, and unsubscribing stops it immediately. If you want the subscription deleted rather than marked unsubscribed, email privacy@halfrx.com and it will be.
What you send with “Something on this page wrong?”
The text you write, the page you sent it from and the time, plus an email address only if you add one to be answered at. It is stored on this server, read by the person who runs the site and used to check the page. The address is deleted when the report is closed; the text is kept. No cookie, account or network address is stored with it.

What leaves this server

The chat is the only feature that sends anything you type to another company. A question asked there is passed to DeepSeek, which generates the answer; the site sends the question and the card data it needs, and nothing else.

Your side of the conversation is also held here while it is happening — in the running process's memory, not in the database and not on disk. At most the last twelve exchanges, for at most an hour, and gone whenever the server restarts. Nothing about it is written down. The rate limiter that stops one visitor flooding the chat also holds addresses in that same memory for a short window, and nowhere else.

Nothing you type is sent until you have agreed to it. Before your first question the chat says where the question goes and asks you to confirm; until you do, nothing leaves the page. Once agreed, you can withdraw at any time by clearing your browser's site data, and the note will ask again.

If you would rather nothing you type left this server, do not use the chat — every figure it can quote is on a page you can read directly, and the whole catalog is published at catalogue.json.

Who else handles it

These are the only companies that touch anything a reader sends. Each processes it to provide its service to halfrx and nothing else; none is allowed to use it for its own purposes by the terms it offers halfrx.

CompanyWhat it doesWhereWhat it sees
netcup GmbHHosts the application server, the database and the web server's access logsGermanyEverything this site stores
Cloudflare, Inc.DNS, TLS and caching in front of the serverUnited States, and its network worldwideEvery request passes through it, with the address it came from
DeepSeekWrites the chat's answersPeople's Republic of ChinaThe text of a chat question — only after you agree to send it — and the catalog entries the answer needs
ResendDelivers price-alert emailUnited StatesYour address and the alert. Not yet in use: alerts queue and nothing is sent until it is switched on

Three of them are outside Monaco and the EU. Cloudflare is in the United States and relies on the EU–US Data Privacy Framework and the European Commission's standard contractual clauses. DeepSeek is in China, which has no adequacy decision from either the EU or Monaco; that transfer happens only for a chat question you have chosen to send after being told where it goes. Resend is in the United States and is not in use yet: nothing is sent to it until price alerts are switched on. halfrx sells nothing it holds, and gives nothing to advertisers, data brokers or affiliate networks — a network is told only that a click on its link happened.

What never leaves your browser at all

The appeal letter builder and the prior authorization pack run entirely in your browser. The state you pick, the denial reason, the diagnosis, the letter that comes out — none of it is sent anywhere, stored anywhere or seen by anyone here. That is deliberate: they are the two places on this site where a reader would be typing something medical about themselves.

Server logs

The web server keeps ordinary access logs — address, path, time, user agent — the way every web server does, for debugging and abuse. They are not joined to anything above and are not used for analytics. Cloudflare sits in front of the site and keeps its own logs under its own terms.

How long each thing is kept

  • Chat questions and answers: in memory only, for at most an hour, never written to disk.
  • The web server's access logs: rotated daily and deleted after 14 days.
  • A price-alert subscription: until you unsubscribe; deleted on request, with the messages queued to it.
  • An error report: any email address in it until the report is closed, then deleted; the text is kept.
  • The page counter and the paid-click log: kept, because neither holds anything that identifies a person.

Consumer health data: Washington, Nevada and similar laws

Washington's My Health My Data Act, Nevada's SB 370 and similar state laws protect information that identifies a person and relates to their health — and a question about taking a weight-loss drug can be that. This section is halfrx's consumer health data privacy policy.

  • What can be consumer health data here: the text of a chat question, if you put something about your own health in it; a price-alert subscription, because an address next to a drug's name says something about you; and an error report, if you write about your own health in it.
  • Why it is collected: the question, only to answer it; the subscription, only to send the alert you asked for; the report, only to check the page.
  • Who it is shared with: the question with DeepSeek, which writes the answer, and only after you agree; the subscription with the email provider in the table above, once alerts are switched on; the report with nobody. Nobody else, and never sold.
  • Your rights: to know what is held about you and who it was shared with, to have it deleted, and to withdraw consent. Write to privacy@halfrx.com; we answer within 45 days. If we refuse, reply asking us to reconsider and we will answer that within 45 days too, with how to complain to your state attorney general if you still disagree.

Your rights, whichever law you are under

Wherever you live, you can ask to see, correct or delete what halfrx holds about you, and to take a copy. Under the GDPR you can also object to or restrict processing, and complain to the Autorité de Protection des Données Personnelles (APDP) or to the data-protection authority where you live. California, Virginia, Colorado, Connecticut, Texas and the other US states with privacy laws give their residents the same rights to know, correct and delete; halfrx is below the size at which most of them apply and honors them anyway. halfrx does not sell or share personal information, uses no targeted advertising and does no profiling, so there is nothing to opt out of — a Global Privacy Control signal is respected by default because nothing would be done without it. An authorized agent may make a request for you with your signed permission. You will not be treated differently for using any of these rights.

Children

This site is written for adults making decisions about prescription medication and is not directed at children. No age is collected, so none is verified.

Asking for your data, or its removal

Two records here can belong to a person. A price-alert subscription is keyed by the address you gave: email privacy@halfrx.com from that address and it will be returned or deleted. The web server's access logs hold the IP address a request came from, the path, the time and the browser's user agent, and are deleted after 14 days; tell us the IP address and roughly when, and any matching lines are returned or deleted before then. There is nothing else to return: the page counter and the click log contain no identifier that could be matched to anyone.

Changes

If what this page describes changes, this page changes with it, and a material change is logged at corrections the same way a wrong price is. This is the version in force today.

Getting in touch

privacy@halfrx.com for anything about your data, corrections@halfrx.com if a figure here is wrong — a correction reaches the page faster than a complaint does — and hello@halfrx.com for anything else. By post: MonacoWebPix, C/o CATS, Le Forum, 28 Boulevard Princesse Charlotte, 98000 Monaco, Principality of Monaco.

Something on this page wrong? Tell us

Please leave out anything about your own health. How a report is handled: privacy.